Skip to content

Comment on Coinbase design allows for mass, targeted phishing of its usersparent

Comments

Coinbase CEO here. You can see an updated response on this issue here for more information: https://hackerone.com/reports/5200

I apologize in advance for the following unsolicited advice, but if there's anything that should have been learned from the press after the Gox implosion, it's that you absolutely must stay ahead on security and the perception of security. If you don't, the entire cryptocurrency ecosystem ultimately suffers. You have a responsibility far beyond your active userbase to be responsive and professional, rather than dismissive, especially when a whitehat is just offering up auditing. There's no obvious downside to rate limiting some types of API requests, so why not simply be responsive and do it?

Any info on why emails to whitehat@coinbase.com are being ignored?

EDIT: For what it's worth, judging by the upvotes, a lot of people are hoping for any answer.

Because Coinbase has moved the program out of email and into here: https://hackerone.com/coinbase

What they could do is turn it into an autoresponder at least with a link to that inside.

Yep, that's on the way!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.