There is no full list, and there is no leak. We're drafting a more formal response now.
There is no full list, and there is no leak. We're drafting a more formal response now.
https://news.ycombinator.com/item?id=7505757
A lot of people are getting nervous that you're not taking security seriously at Coinbase. Ignoring whitehat reports would seem to be a serious issue.
Those aliases are cheap insurance, but they aren't free: they'll cost you some tech support cycles.
Not just emails, either. See also event logging: https://www.schneier.com/blog/archives/2014/03/details_of_th...
According to the original researcher, he mailed them and got no response, and got no response at all from several other attempts at contact,.
I wouldn't be surprised one bit to find that the inbox for that address is full of spam and crackpots, but, like 'tptacek said, if you're going to have the list you had better dedicate resources to reading it.
A basic tech support person might be able to fend off the dozens of word salad "security notifications" sent by ESL students, but as they get more complicated and no less often irrelevant, you need people who actually know how your infrastructure works.
On top of the technical hassle comes the customer experience hassle of keeping a bunch of wanna be hackers happy as they demand rewards and their name on your site for their idea of a CRSF vulnerability that happens to have no basis in reality.