TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Coinbase design allows for mass, targeted phishing of its users

152 pointsby julespittabout 11 years ago

16 comments

homakovabout 11 years ago
There's another bug when you can substitute coinbase's iframe with your own, when you use coinbase button. This iframe can ask for username / password, and there's no way for user to distinguish fake iframe from real. They also not into replying emails on their whitehat@ address.
评论 #7505827 未加载
评论 #7506047 未加载
评论 #7506247 未加载
评论 #7506066 未加载
评论 #7506586 未加载
joezydecoabout 11 years ago
<i>&quot;Initially, Coinbase ignored me. My succession of emails to their official &quot;whitehat@coinbase.com&quot; domain were ignored until I posted that they weren&#x27;t replying on reddit&quot;</i><p>Deja vu, man.
评论 #7505226 未加载
评论 #7505346 未加载
abaloneabout 11 years ago
Meh, this is an extremely poor bug report despite the super-serious introductory tone. The &quot;proof of concept&quot; makes no sense. Quoting:<p><i>1. Scrape email addresses from bitcoin related websites, and organise them into a large list.</i><p>This has nothing to do with Coinbase.<p><i>2. Test for emails which are actual Coinbase accounts, and extract their First and Last names, associated to the emails.</i><p>Ok...<p><i>3. All sorts of panic happens.</i><p>Huh? How?<p>To prove &quot;panic&quot; he then leaps to a screenshot someone posted to Twitter of a money request email he generated. However,<p>a) It&#x27;s not clear whether this was sent via the coinbase money request feature or whether it was spoofed (or why it would even need to be spoofed).<p>b) It doesn&#x27;t even show usage of a firstname or lastname to &quot;assist&quot; in the spoofing.. which was the whole point of the bug report.<p>So it remains to be demonstrated how the exposure of firstname&#x2F;lastname could be exploited to significantly assist phishing, especially when weighed against the other design tradeoffs -- like accidentally irreversibly sending money to the wrong person.<p>The lack of responsiveness to the whitehat email is the bigger problem here, but now that they&#x27;ve joined HackerOne perhaps that will improve.
评论 #7505783 未加载
评论 #7505714 未加载
yerbatimeabout 11 years ago
Olaf from Coinbase here.<p>Ryan McGeehan of our security team has posted an official response at the bottom of this page:<p><a href="https://hackerone.com/reports/5200" rel="nofollow">https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;5200</a>
评论 #7505499 未加载
iancarrollabout 11 years ago
API rate limiting seems to be their best course of action, and it&#x27;s disappointing that they&#x27;re ignoring you.
评论 #7505179 未加载
评论 #7505839 未加载
andrewparkerabout 11 years ago
I received a phishing email from the author. I guess he must have scraped my email address from a blog post I wrote about bitcoin and coinbase.<p>While I am glad he has made attempts to contact Coinbase, I felt like live execution of the attack was spammy, so my first instinct was the block the domain of the sender&#x27;s email, which Coinbase passes through to me. In execution of his proof of concept, the author is likely badly ruining his spam score &#x2F; sender score.
评论 #7504788 未加载
评论 #7504766 未加载
300bpsabout 11 years ago
This is obviously a serious issue. One way to mitigate it is to use email addresses that have specific purposes.<p>firstinitiallastname@gmail.com is my &quot;public&quot; email address that is used for friends and what not.<p>genericemail@gmail.com is the email address I use for many retail sites.<p>I then have an email address dedicated to each commonly used site (Amazon, Coinbase, etc).<p>I also have Google two-factor authentication turned on for each email.
评论 #7505267 未加载
评论 #7504700 未加载
jyapabout 11 years ago
Apparently these names and email addressed have been gathered:<p><a href="http://pastebin.com/RzWipJFb" rel="nofollow">http:&#x2F;&#x2F;pastebin.com&#x2F;RzWipJFb</a><p>Source:<p><a href="http://www.reddit.com/r/Bitcoin/comments/21wx59/coinbase_emails_and_names_leaked/" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Bitcoin&#x2F;comments&#x2F;21wx59&#x2F;coinbase_ema...</a>
kzahelabout 11 years ago
Nice article. Coinbase should be paying you for your service!
评论 #7505378 未加载
lukashedabout 11 years ago
On the screenshow of Humayun Khan&#x27;s tweet it says &quot;Click here to create an account&quot;. Does this mean that every email address that&#x27;s not signed up with Coinbase yet will also get an email?
评论 #7505214 未加载
rdlabout 11 years ago
Ever so slight mitigation of this is that Coinbase uses SPF, but they use SPF with a fairly open list (just phish via Amazon SES, Mailgun, etc.). So phishing mail has some chance of getting marked down as spam by recipients if you make it appear to be from coinbase.com.<p>I&#x27;d probably go all-out and send from coinbasemail.com though.
评论 #7505655 未加载
pbreitabout 11 years ago
Divulging a name when presented with an email address is pretty bad and I&#x27;m not sure why it would be necessary.<p>Just confirming that an email address is in the system is fairly minor.
评论 #7505485 未加载
评论 #7505816 未加载
larrysabout 11 years ago
As someone who studies human nature I&#x27;d like to ask this question of the OP and anyone else who cares to answer. I&#x27;d seriously like to know this.<p>Why do people spend extensive time [1] documenting security flaws like this [2] and going to the trouble of informing the company. And then if that doesn&#x27;t work take more time to write up a blog post to get the info out?<p>What do they gain by doing so exactly? Is this a play for internet notoriety? Or a way to gain attention that results in future fame that leads to something later?<p>Or, is it as simple as it just makes them feel good (like &quot;hey why do you play poker&quot;) or is it they believe they are making the world a better place?<p>[1] Because this took considerable time.<p>[2] Yes I know the OP indicates he is a &quot;Information Security Enthusiast&quot;.
评论 #7505332 未加载
评论 #7505778 未加载
评论 #7505256 未加载
fatbatabout 11 years ago
I am curious why Coinbase is not rate limiting that API call (temp-fix) or addressing this yet (even privately)?<p>Granted it is not a critical flaw, but is having no limits over time really necessary for Coinbase API users?
评论 #7505038 未加载
评论 #7505345 未加载
arfliwabout 11 years ago
I don&#x27;t know if it&#x27;s related or not, but their website is running horribly slow right now. Took me about five minutes to initiate a buy order, as most clicks were non-responsive or took ages to load.
nbodyabout 11 years ago
I didn&#x27;t see any suggestion from the author, did I miss it?
评论 #7504698 未加载
评论 #7505138 未加载