4 ms·
Fred from Coinbase here. There is no full list, and there is no leak. We're drafting a more formal response now.
by FredEE 13y ago
Fred from Coinbase here.
There is no full list, and there is no leak. We're drafting a more formal response now.
- sillysaurus3 13y agoWould you include in your response the reason why you're ignoring Homakov's security flaw reports, which were emailed to you at your whitehat@coinbase.com email address? https://news.ycombinator.com/item?id=7505757 https://news.ycombinator.com/item?id=7505757 A lot of people are getting nervous that you're not taking security seriously at Coinbase. Ignoring whitehat reports would seem to be a serious issue.
- jakejake 13y agoThey mentioned something about it on the thread that they were transitioning to a new system - plus the fact that nobody saw it as a vulnerability. I guess that's the reason
- tptacek 13y agoApropos nothing else and without judging the actual report you're referring to: if you set up a "whitehat@yourdomain" or "security@yourdomain" alias, you need to be responsive. You can't ignore good-faith messages because you don't think they're valid. You have to act like all good-faith messages are urgent. Those aliases are cheap insurance, but they aren't free: they'll cost you some tech support cycles.
- taylorbuley 13y agoCheap, sure, but they'll cost you plenty in "lost face" when we journos write that you ignored inbound alerts from the person who later published something out of frustration. Not just emails, either. See also event logging: https://www.schneier.com/blog/archives/2014/03/details_of_the_.html https://www.schneier.com/blog/archives/2014/03/details_of_th...
- haakon 13y agoSeriously, this. They are being nonchalant about this whole thing, but it may be damaging their most valuable asset - the community's trust in them. Just don't ignore repeated attempts to contact your whitehat address.
- jakejake 13y agoNot saying it was a good reason. Just that they did address the question.
- danielweber 13y agohttp://blog.shubh.am/full-disclosure-coinbase-security/ http://blog.shubh.am/full-disclosure-coinbase-security/ According to the original researcher, he mailed them and got no response, and got no response at all from several other attempts at contact,. I wouldn't be surprised one bit to find that the inbox for that address is full of spam and crackpots, but, like 'tptacek said, if you're going to have the list you had better dedicate resources to reading it.
- droopyEyelids 13y agoThey're actually downright expensive addresses to maintain, and they don't cost tech support cycles, they cost security engineer time. A basic tech support person might be able to fend off the dozens of word salad "security notifications" sent by ESL students, but as they get more complicated and no less often irrelevant, you need people who actually know how your infrastructure works. On top of the technical hassle comes the customer experience hassle of keeping a bunch of wanna be hackers happy as they demand rewards and their name on your site for their idea of a CRSF vulnerability that happens to have no basis in reality.
- tptacek 13y agoThe backlash against these aliases is perceptible, but remember that the worst-case scenarios we're talking about today, when those addresses aren't properly staffed, was the default case before they became a common feature of startups.
- mag00 13y agoHi, Ryan here - We've moved over to hackerone.com/coinbase, and emailed everyone at the whitehat@ address about the transition. We'll be getting in touch for the details and will get an autoresponder up on whitehat@. We don't view missed reports as a good thing, we'll do better and have already made improvements.
- haakon 13y agoTheir official response did not give any reason for ignoring the reports, nor did it even acknowledge that this happened. Disappointing.
- robogrowth 13y agoThen how am I on the list with an email I only use at coinbase? With my full email and name, and i'm getting spammed non-stop by this "non-important" security flaw in your system.. multiple times today and counting.
- rasz_pl 13y agoDidnt you run Iraqi ministry of information back in the day?
- pbreit 13y agoFred, some advice: make your public notice more sympathetic than that post.
- Allower 13y agoYou are a fucking dick for ignoring that guy..just saying