Coinbase: Responding to Firefox 0-days in the wild
blog.coinbase.com
Coinbase: Responding to Firefox 0-days in the wild
1–10 of 97 posts
Re: Coinbase: Responding to Firefox 0-days in the wild
#2HN discussion: https://news.ycombinator.com/item?id=20283922
Re: Coinbase: Responding to Firefox 0-days in the wild
#3Re: Coinbase: Responding to Firefox 0-days in the wild
#4Re: Coinbase: Responding to Firefox 0-days in the wild
#5This is among the critical differences between MtGox and Coinbase.
Re: Coinbase: Responding to Firefox 0-days in the wild
#6Re: Coinbase: Responding to Firefox 0-days in the wild
#7This is among the critical differences between MtGox and Coinbase.
Re: Coinbase: Responding to Firefox 0-days in the wild
#8Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard.
I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.
Re: Coinbase: Responding to Firefox 0-days in the wild
#9They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?
Re: Coinbase: Responding to Firefox 0-days in the wild
#10Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.