3 ms·
I am curious why Coinbase is not rate limiting that API call (temp-fix) or addressing this yet (even privately)? Granted it is not a critical flaw, but is havi
by fatbat 13y ago
I am curious why Coinbase is not rate limiting that API call (temp-fix) or addressing this yet (even privately)?
Granted it is not a critical flaw, but is having no limits over time really necessary for Coinbase API users?
- nwh 13y agoWhat do rate limit by? There's billions of IP addresses a spammer could use, captchas can be solved by offshore farms, there's almost nothing to go by.
- mathrawka 13y agoUser account.
- chandraonline 13y agoThe call is made on behalf of an user account using an API key. You could rate limit by either one and/or both.
- nwh 13y agoNothing really stopping somebody automating the creation of those either when you're up against people with ridiculous amounts of cost-free (read, botnet) resources to spam with. The Bitcoin reddit gets flooded with spam on an almost minutely basis despite reddits heavy rate limiting and captchas.
- chandraonline 13y agoI agree a lot of this becomes cat and mouse game but rate limiting is necessary for the health of their system if not to counter same basic spam prevention. Ideally you want to remove the incentive to spam, which in this case is figuring out emails that have registered coin base accounts that could later be phished.
- danielweber 13y agoLots of small businesses are perfectly happy to lock out foreign IP addresses on the slightest breeze, and it's probably a good result because for those businesses 1000 out of 1000 requests from the Eastern Hemisphere are hostile.
- nwh 13y agoAssuming malicious requests come from other countries would be foolhardy.
- danielweber 13y agoIf you are saying "malicious requests only come from foreign countries" then of course that is silly. But "for these businesses every connection from certain continents is an attack" is absolutely true. I've worked with these businesses, worked with their CEO on their business needs, and seen their internet traffic. They, really, have absolutely no need to interact with Asia. They aren't hotshot SV companies trying to become the global leader of VR selfies, they are just boring[1] businesses sending plain old physical goods to customers within a thousand miles of them. [1] Boring isn't a pejorative in my mind, but I know it is for some other people.
- barmstrong 13y agoYou can read some more information on our response here https://hackerone.com/reports/5200 https://hackerone.com/reports/5200
- fatbat 13y agoThanks for this! Perhaps an internal flag (to review) can be set when too many bounced emails come from a single api key?