Bitcoin Forum
April 19, 2024, 10:45:45 PM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Coinbase User Data Leak?  (Read 21459 times)
Zangelbert Bingledack (OP)
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


View Profile
April 05, 2013, 11:43:17 AM
 #1

http://www.reddit.com/r/Bitcoin/comments/1bq2p8/coinbase_publishes_your_name_and_email_publicly/

This looks bad.
1713566745
Hero Member
*
Offline Offline

Posts: 1713566745

View Profile Personal Message (Offline)

Ignore
1713566745
Reply with quote  #2

1713566745
Report to moderator
1713566745
Hero Member
*
Offline Offline

Posts: 1713566745

View Profile Personal Message (Offline)

Ignore
1713566745
Reply with quote  #2

1713566745
Report to moderator
"This isn't the kind of software where we can leave so many unresolved bugs that we need a tracker for them." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713566745
Hero Member
*
Offline Offline

Posts: 1713566745

View Profile Personal Message (Offline)

Ignore
1713566745
Reply with quote  #2

1713566745
Report to moderator
1713566745
Hero Member
*
Offline Offline

Posts: 1713566745

View Profile Personal Message (Offline)

Ignore
1713566745
Reply with quote  #2

1713566745
Report to moderator
1713566745
Hero Member
*
Offline Offline

Posts: 1713566745

View Profile Personal Message (Offline)

Ignore
1713566745
Reply with quote  #2

1713566745
Report to moderator
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
April 05, 2013, 11:44:26 AM
 #2

Oh hey.

https://coinbase.com/checkouts/6690dd13bc9b07e4c9f0217ecd7f8aed

Or hey.

https://coinbase.com/checkouts/672b4c4fdf589693aecb25289a3cd872

They never heard of noindex?
RaTTuS
Hero Member
*****
Offline Offline

Activity: 792
Merit: 1000


Bite me


View Profile
April 05, 2013, 11:50:14 AM
 #3

https://bitcointalk.org/index.php?topic=167890.0
one post below you ! Wink

In the Beginning there was CPU , then GPU , then FPGA then ASIC, what next I hear to ask ....

1RaTTuSEN7jJUDiW1EGogHwtek7g9BiEn
Severian
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
April 05, 2013, 11:54:52 AM
 #4

I had no idea their founder is a Goldman Sachs alum:

https://angel.co/fred-ehrsam/activity

Coinbase is the Bankers' Revenge.
Mark Oates
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
April 05, 2013, 11:59:08 AM
 #5

Sooo, I'm confused...

This is no different than a person selling something on their website with paypal, and in the form:

<input type="hidden" name="business" value="mysellingemail@myaddress.com ">

Except someone found a way to access the addresses of these prefab coinbase buy-now buttons that these merchants put into their websites?
jamesg
VIP
Legendary
*
Offline Offline

Activity: 1358
Merit: 1000


AKA: gigavps


View Profile
April 05, 2013, 12:05:23 PM
 #6

Here is a nice little google search of all the checkout pages: Do it
mccoyspace
Full Member
***
Offline Offline

Activity: 237
Merit: 101


View Profile WWW
April 05, 2013, 12:40:06 PM
 #7

This doesn't seem like that big of a deal. It's not like the instawallet / easywallet google hole.
Tonko
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
April 05, 2013, 12:53:02 PM
 #8

I had no idea their founder is a Goldman Sachs alum:

https://angel.co/fred-ehrsam/activity

Coinbase is the Bankers' Revenge.

An example that, even if you get a business side right, if you get shitty programmers, things won't fly.
lukestokes
Full Member
***
Offline Offline

Activity: 165
Merit: 102


Live life on purpose


View Profile WWW
April 05, 2013, 01:11:13 PM
 #9

Anyone else feel like this will be all over the news soon? The haters are surely looking for more mud to sling. I wonder if it will shake some coin free from loose hands who thought any transaction using Bitcoin is fully and completely anonymous.

http://www.foxycart.com: Helping developers create flexible, powerful, custom ecommerce in less time, while equipping merchants with the fastest checkout flow available to their customers. 60+ payment gateways, including Bitpay. Bitrated user: lukestokes.
Severian
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
April 05, 2013, 01:29:32 PM
 #10


An example that, even if you get a business side right, if you get shitty programmers, things won't fly.

They got the "get the money from the muppets" part of the business right anyway.
Zangelbert Bingledack (OP)
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


View Profile
April 05, 2013, 01:39:07 PM
 #11


This got moved here from Discussion for some reason. Seems serious enough, so I posted it there.
tylercrumpton
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
April 05, 2013, 02:42:31 PM
 #12

I commented with this on the Reddit post, but I'll put it here as well.

Quote
From my preliminary research here is what I see has happened:

When you add a "Buy with Bitcoin" button from Coinbase to your website (as a merchant), it allows the user to click the button to open a Coinbase page/popup to allow you to pay for an item, donate, etc. This button already displays your name, email, and address. When the googlebot comes crawling around your site, it finds the button, follows the link, and indexes the transaction page.

It does not appear that transactions themselves (an individual purchase) are indexed, nor do I see anyway that would be possible without a major mix-up on Coinbase's side. The only thing that google has cached is essentially a list of "Buy With Bitcoin" buttons.

Feel free to correct me if I missed something here, but I just wanted to help prevent the FUD of "OMG COINBASE ARE LIKE GOOGLE-POSTING MY PURCHASES".


brian_armstrong
Newbie
*
Offline Offline

Activity: 29
Merit: 0


View Profile
April 05, 2013, 02:52:57 PM
Last edit: April 05, 2013, 04:35:59 PM by brian_armstrong
 #13

Coinbase CEO here.

Just updated with a blog post: http://blog.coinbase.com/post/47198421272/data-on-public-merchant-pages

These are merchant checkout pages.  Your information is not going to be shown on one of these pages unless you created a "buy now" button, donate button, or checkout page and posted a public link to it somewhere as a merchant. Order pages are designed to be public so customers can reach them, but we messed up by making them publicly indexable and including merchant contact info there without being more explicit.  The email in particular should not have been included.  More details in the blog post.  Very sorry for the trouble on this!
lukestokes
Full Member
***
Offline Offline

Activity: 165
Merit: 102


Live life on purpose


View Profile WWW
April 05, 2013, 03:32:00 PM
 #14

Coinbase CEO here.

What we're looking at is a list of merchant checkout pages. It is the information merchants fill out on this page:

http://cl.ly/image/2P2s2a0j002e

Or https://coinbase.com/merchant_settings

Your information is not going to be shown on one of these pages unless you created a "buy now"/donate button or checkout page and posted a public link to it somewhere. Order pages are designed to be public so customers can reach them, although we should have taken more care to not make them easily indexible by Google.

The email in particular, although we encoded using hex encoding to make it more difficult to scrape, should not be shown on that page. We will take a look today at some ways to get it removed from the Google cache, and avoid having these pages indexed.

We will post a public response on our blog shortly.  Sorry for the scare!

Thank you for the update, Brian. I'm glad to see CEO's here in the forums. Right now, in the just-out-of-toddler stages of Bitcoin, this forum, the IRC channel and the Subreddit are the lifeblood of the system. Quick, honest communication is critical to keep things flowing.

http://www.foxycart.com: Helping developers create flexible, powerful, custom ecommerce in less time, while equipping merchants with the fastest checkout flow available to their customers. 60+ payment gateways, including Bitpay. Bitrated user: lukestokes.
MPOE-PR
Hero Member
*****
Offline Offline

Activity: 756
Merit: 522



View Profile
April 05, 2013, 04:28:43 PM
 #15


An example that, even if you get a business side right, if you get shitty programmers, things won't fly.

They got the "get the money from the muppets" part of the business right anyway.

A. They didn't get the business side right. At all.
B. A business composed of programmers will always fail. Because programmers suck. At life.

And here's a fine example of Ycombinator being the freakshow that it is:

Quote
It's one thing to lose people's bitcoins or randomly delay/cancel transactions (both of which Coinbase has been accused of). People know that bitcoin is still young and the companies supporting it are inexperienced, so they expect that.

We expect Central Casting "entrepreneurs" to lose our Bitcoins. Har har.

My Credentials  | THE BTC Stock Exchange | I have my very own anthology! | Use bitcointa.lk, it's like this one but better.
axus
Full Member
***
Offline Offline

Activity: 129
Merit: 100


View Profile
April 05, 2013, 04:55:20 PM
 #16

People were pointing out "innocuous" problems with Instawallet's website a while back.  It definitely makes you wonder.
Zangelbert Bingledack (OP)
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


View Profile
April 05, 2013, 06:27:51 PM
 #17

Well that's a relief. This had a lot of people freaking out on reddit, what with the Instawallet hack and other perpetual issues we start to wonder if everything is just randomly exploding. 
zedicus
Legendary
*
Offline Offline

Activity: 966
Merit: 1004

CryptoTalk.Org - Get Paid for every Post!


View Profile WWW
April 06, 2013, 06:08:28 AM
 #18

Coinbase CEO here.

Just updated with a blog post: http://blog.coinbase.com/post/47198421272/data-on-public-merchant-pages

These are merchant checkout pages.  Your information is not going to be shown on one of these pages unless you created a "buy now" button, donate button, or checkout page and posted a public link to it somewhere as a merchant. Order pages are designed to be public so customers can reach them, but we messed up by making them publicly indexable and including merchant contact info there without being more explicit.  The email in particular should not have been included.  More details in the blog post.  Very sorry for the trouble on this!


Thanks brian for chiming in.. as a coinbase user myself i echo lukestokes sentiment. 



Best,
Zedicus

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!