Dropbox: Security update & new features
blog.dropbox.com
blog.dropbox.com
http://code.google.com/p/google-authenticator/
Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.
I looked into this recently when Dreamhost launched google-authenticator instead of two-factor auth. Disappointing.
First, get your password. Second, find your location. Third, steal your phone, which for most people, is almost always on their person. Finally, crack whatever security mechanism you have on your phone.
For someone to go through all that trouble ... you must be storing some very valuable info. If that's the case, may I suggest that Dropbox is probably not the right platform? In fact, any internet connected platform is probably not the right answer.
Edit: I was annoyed so long by this missing feature and - never did something myself. My bad.
If you have the same problem (one device paired with a couple of services, you want to migrate the accounts):
'/data/data/com.google.android.apps.authenticator2/databases' contains the sqlite3 file 'databases', which contains a table 'accounts' with your keys (and counter values, if necessary).
You should pay a lot more attention to the where the links go than where the email is from.
I see two ways to read this.
a) An employee happened to have a personal Dropbox account, and it was that personal account that was hacked, in exactly the same manner as the other accounts referenced. The employee probably used a different password on Dropbox's internal systems, and as a result there was no internal breach.
b) An employee account for an internal Dropbox system was hacked, and this internal account allowed the attacker to access the project file. In this scenario, even though Dropbox made no specific comments to this effect, we can assume that the attacker may have obtained access to Dropbox's internal networks, so who knows what they could have made off with.
It makes a huge amount of difference to me which of those two readings actually took place. In scenario (a), this all boils down to users (including one particular employee) using the same password on too many sites. In scenario (b), Dropbox could be hiding a much larger breach.
* Added ability to sync arbitrary directories
And I'm let down. Every single time.
Dropbox is making fistfuls of money, and, like all proprietary software companies, they need to stay focused to maintain momentum.
Although it might not feel like it to most people, I think we're in still in the dark ages of software. Not quite as dark as the Microsoft era, but dark nonetheless. We just don't have the tools, infrastructure, and culture necessary for open source to really be a viable space for the typical, scattered programmer to spend their time. I'm optimistic that will change, but I'm not sure how long it will take.
right click -> Sync Folder (or some variation thereof)
and it just works.
What you want is two clicks plus a confirmation popup and/or wizard. Moving a folder and making a shortcut is two drags and one extra click. It's not a big deal.
and it just works.
This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext.
UPDATE: Dropbox doesn't store in plaintext. I was incorrect to assume these were the only two possibilities. Confer child comments.
They could check passwords on login (before salting/hashing) against a blacklist of 'commonly used passwords'. This is probably the most secure method, as it only implies that users passwords are not on the blacklist, but does not imply plain text storage or unsalted hashes.
If they were not salting their hashes, then they could query their database for hashes that match the hashed version of commonly used passwords. Similar to the blacklist above, but implies that the passwords are stored unsalted, which is sad.
First, the password could be checked on login when it is sent in plaintext but not stored. Second, they could run an offline dictionary attack against the hashed password database.
Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge).
Giving full access to some random new startup or app is NOT cool. Sure I don't have to, but people also like to try new stuff, and the integration is half the reason for using cloud services in the first place.
In fact this really applies to all 'platform' plays facebook, linkedin etc. Rather request minimum priviledges to inter-operate or authenticate, rather than sweeping authorizations.
Commonly used? What do they mean by that? Aren't they supposed not to know my password?
What they can't do is randomly salt each stored password.