Do we have to spell it out to them?
Do we have to spell it out to them?
The only reason he got 1000+ emails is because you guys messed up.
Not even going into the whole idea of you releasing that end point with name leakage without somebody going 'oh hey.. do we have rate limiting?'.
Mistakes like this are signs of amateur hour.
Most likely they're implementing rate-limiting to appease people and prevent an ongoing spam issue. Or perhaps it was on their list for a while and just hasn't been an issue until now.
If it's IP based at let's say 10 over X attacker would have to lease 100 IP's.
In any case, rate limiting is the quickest mitigation prior to actual fix of the data leak in question.
"For example, we employ rate limits around sensitive actions, such as requesting money, to prevent them from being abused at scale."
We’d also like to address the claim of a “leaked” list of Coinbase emails and user names. This list (the size of which is less than one half of one percent of Coinbase users) was not the result of a data breach at Coinbase.
There are 2,040 names on the leaked list. Fun fact: that means there are about 408,000 Coinbase users total.