6 ms·
Wow, this company went through YC? I hope they only invested bitcoins... It's one thing to lose people's bitcoins or randomly delay/cancel transactions (both o
by Irregardless 14y ago
Wow, this company went through YC? I hope they only invested bitcoins...
It's one thing to lose people's bitcoins or randomly delay/cancel transactions (both of which Coinbase has been accused of). People know that bitcoin is still young and the companies supporting it are inexperienced, so they expect that. But exposing personal info and purchase history goes beyond any definition of 'unacceptable' or 'incompetent'. Over in the Reddit thread, they're already linking Facebook accounts with illicit transactions.
Users from Bitcointalk told Coinbase a week ago that they were starting to get phishing emails, which means someone has been mining this data for a while now. Yet there it is, still available through a simple Google search.
- niggler 14y ago"Yet there it is, still available through a simple Google search." Let's say, for some reason, you have some information from a site you own that you want to remove from Google search. How long does it take to remove it?
- apaprocki 14y agoI've had to do it before (business reasons) and it did not take that long -- on the order of 24-36 hours.
- nwh 14y agoThere's a link in the webmaster tool asking for speedy deletion. I'm assuming that means gone within hours.
- jlgaddis 14y agoRight, but only the owners/admins for that domain can use it. In other words, I couldn't request that a page on coinbase.org be removed -- only the Coinbase folks can.
- deleted 14y ago[deleted]
- tatsuke95 14y ago>"Wow, this company went through YC?" And was actively defended and supported the last time a thread came up questioning the issues that Coinbase was having: https://news.ycombinator.com/item?id=5427985 https://news.ycombinator.com/item?id=5427985 Turns out those questions were justified. They've outted people selling bath salts and god knows what else. So much for anonymity. Between this, MtGox, Instawallet, do we still believe Bitcoin is taking over the world?
- fyi80 14y agoYour problem is with YC supporting a company that violates the privacy of dangerous criminals, and not with YC supporting a company that provides a marketplace for selling illegal hazardous products?
- paulwithap 14y ago> dangerous criminals You don't really believe this, do you?
- atwebb 14y agoOf course, I believe that the DPRK is switching to BitCoin soon since illicit nuclear providers prefer it.
- paulwithap 14y agoSorry, I thought you were referring to people selling weed on Silk Road. Do you have any sources for this?
- smallegan 14y agoThis is not transaction data, anonymity has not been lost.
- mnutt 14y agoIt's really, really easy to see "data leak", see an email address, and assume that this is really bad. On the other hand, if you actually look at what these pages are, they're Checkout pages, not Transaction pages. Coinbase sellers generated these pages and intentionally linked to them. Someone even mentions this in the fourth comment on the linked page.
- umsm 14y agoI feel like this "data" could be embedded into an image and then no bots would ever get a hold of mass amounts of personal data...
- stuffihavemade 14y agoThat wouldn't do anything. If it's readable, it could be OCR'd.
- rubyrescue 14y agoThis is NOT a data leak. The guys building coinbase are incredibly savvy, dedicated founders. Please don't overreact without knowing what you are taking about. These pages are supposed to be searchable because they're like mini-store checkout pages.
- deleted 14y ago[deleted]
- waterlesscloud 14y agoIt is a data leak. The CEO says so right in this thread, when he says the email should not have been on the page.
- temphn 14y agoThese are seller pages, not user pages. Sellers are web indexed by default. You could argue that Coinbase shouldn't index these pages and that they should only be accessible from seller websites, but sellers have already made them public on the WWW. There's no "data leak".
- Irregardless 14y agoGiving out the emails associated with their accounts is a really bad idea. Having them indexed by Google is even worse, hence the phishing attempts.
- verroq 14y agoThese are sellers and their contact information. The whole point is that they are public.
- mbreese 14y agoHaving official public contact information, well, public, is fine - that's the point. But having the email addresses associated with merchant accounts isn't. Hence the phishing concern.
- joelrunyon 14y agoI'm still wondering why they have to publicly display those emails in relation to the accounts associated with it. Why can't those stay anonymous?
- barmstrong 14y agoCoinbase CEO here. Just updated with a blog post: http://blog.coinbase.com/post/47198421272/data-on-public-merchant-pages http://blog.coinbase.com/post/47198421272/data-on-public-mer... These are merchant checkout pages. Your information is not going to be shown on one of these pages unless you created a "buy now" button, donate button, or checkout page and posted a public link to it somewhere as a merchant. Order pages are designed to be public so customers can reach them, but we messed up by making them publicly indexable and including merchant contact info there without being more explicit. The email in particular should not have been included. More details in the blog post. Very sorry for the trouble on this!
- ntumlin 14y agoIt scares me that you're just going for "difficult to scrape" and "not make them easily indexible by Google." We don't want it to be hard to get our personal information, we want it to be impossible.
- baddox 14y agoDid you read the entire comment? Those are merchant listings, which means that the vast majority of them are probably intended to be public. You absolutely would not want that information to be impossible to obtain.
- w1ntermute 14y agoBut why would you want them to be "difficult to scrape" then? It should either be "not available" or "easily available". If I'm a merchant, wouldn't I want my info to be as easily available as possible?