I know CB is not a financial company and they are not obligated to provide the same protections to consumers/customers.
Phishing is not the only reason why a customer would not like their bank to confirm that they have an account.
As a matter of fact in this situation, when someone sends a fund request, CB should never let the requesting party know the name of the account holder, unless the account holder explicitly gives them permission, maybe not even then.
With any other organization law enforcement would require a warrant to get basic confirmation if a customer has an account and the name on the account.
On the password reset form, there's a big difference between saying "That email does not exist in our system"/"Emailed password reset instructions" vs "If that account is registered, we will email you instructions".
If you say, "we don't allow two accounts with the same email address", you have the same issue as coinbase.
I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.
> I can't see how you can avoid making the experience for the duplicate user exactly the same as a new user.
The workflow diverges at the email verification step, before you grant any access to the site. Existing users get an email informing them that someone has tried to sign up a second time using their email address while new users get the standard email verification email.
I highly recommend not allowing account creation before email address verification. I have a difficult to spell last name, so I have one email address that contains my initials and a common word instead of my last name. You'd be surprised the number of people who don't know their own email address and the number of sites that allow people to sign up (and apparently transact significantly) without verifying email addresses. Off the top of my head, if I wanted to, I could steal one person's tax accounting account (I got confirmation that they filed their state taxes this year, and later confirmation their state accepted their filing), another person's car rental account, and a third person's business's trash service account. From time to time the one person tries to reset their car rental account password. I imagine I could reset the passwords for all of these accounts (and others) and get the last 4 digits of their credit card numbers and other personal information and use that as a starting point for gaining access to other accounts they own. In the case of the tax account, I could probably re-download the tax paperwork and get their SSN. Neither the tax accounting company nor the car rental agency replied when I informed them that accounts were set up with the wrong email addresses. (I also get business quotes from time to time. Hopefully some day I'll get email from a business or person who knows the person who keeps trying to reset their car rental account.)
If you have enough users who forget they already have an account and your signup process makes them get too far before verifying their email address, consider moving email verification earlier in your workflow.
I assume that was the original point - that on risque dating sites, the recover password system tries to hide membership.
Just because email address is known does not imply that other personal information should be given away.
Doesn't seem innocuous. Maybe coinbase ought to be making pseudonymity more easily accessible.
Stopping email address validation is, I think, impossible for a company like Coinbase, but revealing the name doesn't have to happen.
On the other hand, providing the first and last name could be very valuable to the users, though. If I send coins to bob@example.com, I'd like to see the real name behind that address.
On the other other hand, if anyone can make any first and last name they wish, then the safety of that goes away. Maybe I make b0b@example.com with the same real name.
EDIT The users agreed to have their names given to people they transact with. Does that include strangers attempting to transact with them? I'm thinking "no" but can see the other side.
(1) is opt-in on the recipient's side and fails with something like "that recipient email address doesn't have an account, the name doesn't match, or they haven't decided to allow name verification"
AND
(2) is only available on payments above your highest guess at the expected value of matching an account-email-name triple for spearphishing, and the error messages (and timings) are identical if the name doesn't match or the given email address doesn't have an account.
I imagine there are few profitable attacks where an answer "yes, email_address with name has a Coinbase account" costs a minimum of 100 USD to an attacker and getting an answer "Either email_address doesn't have an account, that name doesn't match our records, or they've chosen not to share their name" costs 0 USD. However, I'd have to think a bit more about that 100 USD minimum.
"This is the bullshit excuse they are trying to use to make it SEEM like its not a vulnerability."
Coinbase is deliberately misleading their users regarding privacy if they do not fix this issue!