Update on Coinbase Data Security
blog.coinbase.com
blog.coinbase.com
Enumeration isn't a fantastic idea, but given its ubiquity in various forms on major sites throughout the internet, I don't think it's worthy of all of this negative attention directed specifically at Coinbase either. I once wrote a program that could take a list of random emails and use Facebook to turn it into a CSV matching each email to a name, a list of their friends, their location, and interests. That should have been scandalous, but it wasn't.
We are acting as pawns in someone's revenge scheme against Coinbase.
Not necessarily. The duplicates are in exact order(quick check using sublime). Could have just been a double paste, happens very often.
The fear mongering (FBI et al) definitely seems unfounded.
> illustrates that someone is mad at Coinbase and is lashing out
That's an ad hominem attack.
> I don't think it's worthy of all of this negative attention directed specifically at Coinbase either
Agreed Coinbase is the target of a lot of negative attention. That does not discount that enumeration deserves any less attention, it's unnecessary and poses more risks than benefits (again I don't know of a single benefit when requesting funds - when sending funds it is understandable but still problematic).
> We are acting as pawns in someone's revenge scheme against Coinbase
You're giving people too little credit. Coinbase is bad at communicating (timing and message), bad communication pisses people of. They are also in a business that gets more scrutiny than other payment processors.
>That's an ad hominem attack.
No it isn't. I honestly wish that people would stop erroneously calling out logical fallacies. An ad hominem attack is refuting someone's argument by attacking their character in a way that has nothing to do with the discussion. For example, this is an ad hominem attack:
Obama: ObamaCare has insured 7.1 million people through the exchanges.
Sally: Oh sure, but what difference does that make - you're a muslim and want this country to fail!
That is an ad hominem. Because Obama being (or not being) a muslim is irrelevant to the discussion and is only used to impugn the character of Obama.
What is not an ad hominem attack is evaluating evidence of someone padding numbers to make Coinbase look bad and then determining that they must be biased against Coinbase. If you think evaluating evidence and coming to negative conclusions about someone is an ad hominem attack, then you are seriously mistaken.
Nice observation. I hadn't noticed it at a glance.
> combined with the possible but unfounded FBI/Fincen accusations, illustrates that someone is mad at Coinbase and is lashing out.
I agree. Those are bold accusations, and bold accusations require at least some proof.
Can you expand? I thought all accusations needed strong evidence.
> For starters, of the 2042 "leaked" emails, 1153 are unique.
Sure enough, when I sorted the email alphabetically I could see that whoever posted that Pastebin listed most of the emails twice to make the list look longer than it actually was.Then you are comparing security of virtual bank to something you did to Facebook back in the day.
The thing is that, if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches, a serious attacker could (or already did) create his own list using let's say a combination of linked in + bit coin related domains to:
1. Harvest valid emails of people employed in a bit coin sector.
2. Match them against coinbase.
3. Start phishing.
Really simple.
His attempt at misleading people by almost doubling the actual count shows that his intent was/is to make this worse than it is. It is likely that all he could find was 1153.
>if anything the guy who was doing this just did a quick proof of concept from a few lists and got matches
You don't know that. He could have been trying for weeks. The percentage of the internet that has Coinbase accounts is minuscule, and this attack requires one to correctly guess that a particular email is already attached to a Coinbase account. The fact that he falsely doubled the size of his list is a testament to this.
>Then you are comparing security of virtual bank to something you did to Facebook back in the day.
This wasn't that long ago, but my point was that this "vulnerability" is minor compared to other sites, yet the backlash against Coinbase seems to be far greater.
Maybe the file was written to via different threads using cross linked dictionary?
Do you know? No, you are speculating someone would double the size of a list as if nobody would ever figure that one out.
The bug that was filled was not even open for weeks. Again you are speculating without any facts.
http://blog.shubh.am/full-disclosure-coinbase-security/
You are comparing 'vulnerability' of a service meant for people to connect and find each other to a service that handles millions of dollars of users money.
Ridiculous.
So you are saying that this somehow endangered customer funds?
- There was no email leak from Coinbase. The source of the email list used against the API is unknown at this time.
- Someone who's savvy enough to call an an API in a multi-threaded fashion but doesn't know how to: cat email_list.txt | sort | uniq ? meh, unlikely.
- User enumeration hardly equals a vulnerability and the name you put on the account doesn't have to be your real name. I have "SMTDDR" on it. All you'd get is "SMTDDR".
Really, this is some kind of political-mud-slinging at Coinbase. Wake me up when you can pull my banking info or transfer my coins out of my account.
Sure, but they could also not care if there are duplicates. You don't need to polish your list output for a proof of concept code, whatever he needed to prove was proven.
It's not a vulnerability, it's data leakage. Sure you put a wrong name in, most people did not.
And it's not the name that's a concern it's leakage of email addresses that would be prime target for savvy hackers who want bitcoins.
If you could run random addresses against an API offered by a vendor that sells safes for high value valuables and get a match which houses have those safes you become a target.
Sure most people won't try to break in, but those are are in business of doing so will try.
And yet, most banks & payment processors do not do this, for good reason. Seems like Coinbase is suffering from some domain confusion.
However, the big differentiating factor between startups and financial service companies is the faith in them "making it right" when something does go wrong. At this point, we have little reason to believe that one huge security issue won't simply kill a startup like Coinbase and leave all of its account holders out in the cold. It seems pretty safe to say that wouldn't happen with any major bank in the US.
The reason you don't see it with banks is that they don't allow you to send money to an email address.
If I were a criminal blackhat would be nice to have user enumeration to confirm names on Coinbase so I could send personalized wallet stealing emails pretending to be from Coinbase.
The question is not for sending money but receiving or requesting money. I personally can't think of a single benefit to getting this information at time of requesting funds.
As a matter of fact, if the name was enumerated when sending money that would to some (very small) degree be acceptable as the sender stood to have a financial loss.
edit: grammar
I suppose you could send e-Transfers to random email addresses and then see if any are accepted, but that would cost you an absolute minimum of $0.01 per attempt and would probably have a terrible response rate.
Source: this is my day job.
Edit: sorry, forgot to mention this is Canada-specific.
Source: I live in Australia
If you don't trust them to hold on to your coins, use them purely an exchange and then pull them off onto an offline wallet.
That strikes me as an assumption. There's no way for them to know that there was no breach based off of the fact that no other information was provided. There are other ways to know that you were not breached, this one comes across as a very weak / naive reason.
Regardless, I do think Coinbase should try to prevent user enumeration.
Very confidence inducing.
So far I've seen :
1) A list of email addresses on pastebin, accompanied by a surreal claim of daily FBI & IRS data transfers and gag orders
2) Homakov's email to whitehat@ concerning a potential iframe vuln
What am I missing?
1) It's possible to determine if someone has a Coinbase account (no rate limit)
2) It's possible to find out someone's name if they have a Coinbase account (no rate limit)
3) Coinbase can be used to spam people through unsolicited messages (no rate limit).
Their response basically equates to "so what, nothing's wrong". They ignored the initial reports and marked the bug as won't fix.
Someone used this vulnerability to pull a bunch of example addresses and their response is "so what, nothing's wrong, probably wasn't us".
But these are three serious issues.
1) Why should anyone be able to figure this out without being a registered application? This is especially true given #3. And the lack of rate limiting is just irresponsible.
2) Why should anyone be able to ask Coinbase what my name is? Even if they allowed that, why can you do it without being a registered user of their API? Again, the lack of rate limiting is also irresponsible.
3) I understand it's purposeful that they'll treat anyone as having an account for the purposes of on boarding, that make sense. But the ability to send emails to anyone on the internet without risking my reputation is asking for trouble. Again, this should be heavily rate limited unless you've registered with them. Anyone can sign up for an Amazon SES account, but you have to go through a few hoops before you can start sending out 500 messages a second.
These statements read like Baghdad Bob to me. We don't agree, nothing is wrong, go about your business as if nothing had happened.
If their initial response was "that's all correct, we're looking into rate limiting and maybe requiring you to register to make API calls" that would have been the end of it.
If I want to send money to someone, I should call Coinbase and they should send the request. The response to me should be "sent" or "error". Imagine if whenever I paid a bill with my credit card the return was not just "success" or "failure" but "success", "current balance", and "mother's maiden name". Disclosing that extra information is totally unnecessary.
Making things easy to use is the answer to your question. Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.)
Many people will take the feature of presenting the name, so you have another layer of comfort while making the transaction (knowing it went to the right place, that you didn't introduce a typo) to be a feature. And those that don't want it don't have to provide their names.
Amazon won't tell you my name. Netflix won't tell you my name. Maybe to registered third parties, but not to random unauthenticated API callers.
> Rate limiting might help a tiny bit, but you can just register multiple accounts to get around it. (And no doubt someone would do that and make a fuss about it.)
But that adds a barrier, and would give them time to notice. Your argument is the equivalent of "why have locks, all doors can be forced open". Just because security isn't perfect doesn't mean it's not worthwhile.
If you want to sell something on Amazon, Amazon will tell other people your name. I sold some apps there to experiment with the whole process, and they attached my real name to it.
There is never a need for anyone to know your name from Netflix. However, with Coinbase, there is a need for other people to be able to recognize who they are doing a transaction with.
Why is this? They are not receiving money , they are sending money. The recipient needs to know the sender but why does the sender need to know that the recipient is a registered coinbase user or what their firstname and lastname is. Why does the response json of the request_money api need to return the user's name and couldn't the email and the transaction history page be the same when you send money to a registered or non-registered email until the recipient is in some sort of address book of the sender (perhaps after a valid transaction has happened between them). I have used chase and paypal and in both cases either I have to add the recipient to the address book and fill out the email address and first and last names or just use the email address.
Fortunately or unfortunately when you play in the financial services, you are held to a higher security standard. I really like coinbase, I hope they fix this simple problem and move on instead of denying its a problem.
That doesn't seem to be the case with Coinbase, they seem to give you the information when you propose a transaction.
But in the comment I was replying to was pointing out that Netflix never gives your ID to anybody, which is not a fair comparison because Netflix is in an entirely different business. Netflix customers never interact with each other. Coinbase users do interact, and identity is usually essential for interaction.
I chose Netflix simply because they were a large internet company. I think the idea that Coinbase is involved in transactions is a red herring here since they're giving the information out before the transactions are agreed upon by both parties.
If I proposed a Coinbase transaction with someone, I would fully expect that the other party would be told my name and possibly even my email.
Hope this helps clarify
(edited for formatting)
Do you also have measures to prevent evil janitor attacks like hardware keyloggers being planted at 4:00am? Do you have screens facing an open window to watch from across the street? Can I rent beside your offices, drill holes through the walls and set up spycams or gain entry? Not to sound alarmist but seems no exchange has given a thought to physical security meanwhile bank execs are dropped off at work by private guards specializing in counter-kidnapping operations, even though their money is fully insured and extremely difficult to steal. Bitcoin's are easy to steal.
Perhaps there are some bank executives for which this is true, but it is absolutely NOT the case for all banking executives. I work with some bank executives and they drive themselves to work in their own cars. The buildings DO have alarm systems and it is quite possible for the FBI to respond to physical threat incidents (because it is treated as a bank robbery) but otherwise there is little that is special in the way of physical security.
And for Coinbase, I believe the lack of special physical guards is appropriate. A high percentage ("up to 97%" according to https://coinbase.com/security ) of their coins are in cold storage and while I am not privy to the details of Coinbase's arrangements, keysharing and multiple physical storage locations that are off-premises are a reasonable precaution. They are vulnerable to hostage-taking or "3 thugs with guns" to the exact same extent (no greater) as any other company with a similar amount of protection.
I can't comment on protection against hardware keyloggers: it's a threat that they need to be prepared for. Cold storage is one major way of protecting against this threat, business insurance is another.
An armed guard, 24/7 security cameras (obvious and hidden) actively being watched by a human being, established passphrases for when the security service calls to check in, etc.
They are at as least as much risk as a physical bank branch, it's a bit of denial on their part if they aren't treating it that way.
I did read through their security about the backups being spread around different locations, but those are backups. They would need access to the cold wallet on a regular basis if 97% of funds are truly in there. Unlikely to happen but then again police here didn't expect criminals would remove huge concrete barriers with a stolen tractor, ram a shopping mall entrance, drive through the mall and ram a gated jewelry store but they did.
Not true. First of all, that would only be true if their net daily turnover were more than 3% of their total amount stored -- which it may not be. Even then, I would expect graduated levels of cold wallets: imagine one with another 2% that is down the street in a bank safe deposit box, 5 wallets with 50% of the deposits stored in a way that can only be accessed with cooperation of 4 people in different parts of the country ... that sort of thing.
I am, of course, just speculating: I don't know how Coinbase runs their system, I just know that they seem competent and that this is how I would run such a thing.
Simply writing that the rate limiting wasn't working correctly and you were fixing would have made all the difference in the world to me.
Now they can play it off so people who don't know any better won't move to another service.
This just isn't a bug.
That last sentence is doing a lot of lifting, out of its weight class.
This immediate "no it's not true" might reassure some folks, but it scares me because of how quick it is. Have you looked at the audit systems on your database?
"We believe this information is bogus but are investigating to make sure" is a better response, assuming you actually do investigate to make sure.
Why people want to hide their names? Personally I don't hide my name. But it is not too hard to understand that on "web-scale" there will be someone who is stalked, who has posted on suicide help forums, etc.
From Ryan McGeehan, director of security (user magoo):
> This behavior is mostly informational to an attacker and does not
> directly increase risk in any significant way
All information leaks are useful to an attacker. By themselves they are harmless, but can be combined with other information to successfully exploit a system.From bug reporter Shubham Shah (user zero):
> This request can now be replayed unlimited times, with unlimited email
> addresses inputted. Coinbase does not limit the rate of POST requests
> to /transactions/request_money
This should not be possible at all. The reporter must have made a mistake and forgot to mention the X-CSRF-Token needs to be updated each time. If it didn't need to be updated, this would be a basic CSRF vuln.All this being said, the real flaw here is the lack of rate limiting on transactions, for three reasons:
1. The spam will eventually mount up and ISPs will block their servers for days or weeks.
2. Their network and app stack is subject to DoS attacks unless they rate-limit transactions.
3. Harvesting of e-mail addresses would be stopped by basic rate limiting of email<->user queries.
The fact that the 2 factor auth can apparently be bypassed by attaching apps is another security vulnerability entirely. If that is what you are claiming is the case, then they should be immediately fixing this as soon as you reported it to them.
(For the lazy like me, who still want to learn new and useful words.)
I personally prefer Right click “Search with Google…” in Chrome: it has the upside of coming up with a definition when the word is actually rare -- so it prevents me from defining an word I didn't know simply because I’m not a native English speaker.
The few programs I use that don't support it actually drive me nuts because I've become so used to it.
The system language thing is a little annoying. It would be fantastic to be able to look up the random Spanish or Japanese word, but I understand the limitation.
Do we have to spell it out to them?
The only reason he got 1000+ emails is because you guys messed up.
Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'.
Mistakes like this are signs of amateur hour.
Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.
If it's IP based at let's say 10 over X attacker would have to lease 100 IP's.
In any case, rate limiting is the quickest mitigation prior to actual fix of the data leak in question.
"For example, we employ rate limits around sensitive actions, such as requesting money, to prevent them from being abused at scale."
We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase.
There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinbase users total.
This is a service that stores digital cash. It should be like an online Fort Knox, not "safe as Facebook" like that's some kind of high bar.
It's not just that this isn't a "large scale" leak; it's that they say it's not a leak at all; that this data was made available through some other combination of services that exposed it, not Coinbase. They don't provide any additional evidence (but few companies would) --- but it's a plausible argument.
That assumes the acknowledgement of whether a given email address is a member or not is not data in itself. That is arguable. For example, I know that in healthcare, merely confirming whether someone is a patient of yours is a violation.
But I agree with the larger point that the original disclosure is overblown.
Now we just need to make sure the data came from coinbase directly, which they refute. They say data comes from other services - mostly bitcoin related ones.
They believe it's not a risk to their users (never minds those users who are now targeted via e-mail leak because they have BitCoins).
"You’ll also find many leading payment services allow user enumeration"
They also do pattern monitoring and rate limiting. And instead of saying 'but they do it!' they should be saying 'they do it too, but we think this is a valid privacy issue that we need to fix'.
This is more or less 'If you don't get privacy implications , we will bullshit you so you don't panic and go elsewhere with your money. Everything is fine!'
I don't believe Coinbase should consider this a real "security threat". I believe that this is a negative side-effect of what may be a feature. It is certainly something that needs improvement, as I'm sure all of the people whose email has been leaked will tell you...
I'm not sure if Coinbase has an engineering blog or a similar outlet where they can speak to more developers directly but if they do not have one already, this may be the time to start. This could've been squashed entirely within a small development community but when left unsettled for so long, it is things like this that the news will latch onto and run with We all know how blown out of proportion things get when that happens.
Anyway, long story short... I hope Coinbase improves. As much as I hate to say that a tech company needs more representatie
a) using language that is very specific when making a denial b) also introducing a new Director of Security in the same post
However, I was also told at a party by a Coinbase employee that this is not true (which is why I filed the request to begin with.)
I am certain that they have a relationship.
In retrospect, it should have been a huge warning sign that the entire thing was bogus. At worst (for Coinbase), they have someone reporting a legit security issue with a bunch of jokes at the top.
I would consider it screamingly obvious that Coinbase reports stuff to the IRS, because they want to run a business, not be crushed to death.
I guess they could say "We have implemented a warrant canary at <url>" then 404, but perhaps their legal team wisely denied that one.
Oh, and I'm under a federal gag order too... or at least there's no way to prove that I'm not.
I have a Pastebin URL with 200 email addresses to prove the contrary. Why lie in PR?