Dropbox confirms it got hacked, will offer two-factor authentication
arstechnica.com
arstechnica.com
This is misleading.
> Some Dropbox customer accounts were hacked too, but this was apparently an unrelated matter.
Unrelated how? What I read was: "Our investigation found that usernames and passwords recently stolen from other websites... A stolen password was also used to access an employee Dropbox account"
This article dangerously leaves the impression that an intrusion was made into Dropbox's system to access the employee's account, and possibly an admin interface. In reality Dropbox let a spammer with a valid email and password look at someone's files.
All that together certainly adds up to an intrusion and is well within the definition of a "hack".
Sounds like employee error - using the same password for their dropbox account as on their LinkedIn account.
What flaw? It sounds like a Dropbox employee was simply reusing a password stolen on another site.
I have a Gmail tab opened just about 100% of the time I'm on the computer, so this would be very convenient for me as an alternative to having to remember passwords for sites that I visit once a month or less (and end up having to get a "password reset" link via email every time I log in anyway), and then I'd only have to keep my Gmail account secure (which I do via 2 factor).
EDIT: Disregard what I said, apparently the attacker had access to the Dropbox employee's Dropbox account.
Though, I do think it would often mitigate the damage from this type of security breach that it seems like we've seen so much of from big name tech companies lately. I'd guess that a majority of accounts created on the internet are pretty unimportant to the account creator, and with how often passwords are reused indiscriminately, the worst effect of these password leaks is often not the unauthorized access to all those accounts on the hacked site but rather the usernames and passwords themselves - which are very often reused for bank, email, etc. accounts. With my proposal, anyone who opted not to have a password wouldn't be vulnerable to that.
However, it fits the service's model well, so it works out in the end for YourPane.
We use Google Apps to host our email, and I've seen plenty of occasions where their systems don't deliver mail immediately. This "issue" used to generate a lot of calls when I was doing freelance consulting. "Bob sent me an email over 20 minutes ago and it's still not here." I'd get those calls all the time.
Imagine you're trying to get logged in somewhere and you have to wait an hour or two for an email to show up.
Considering a dropbox employee, corporate information, and internal security practices are on the line here: I think the author made the fair, ethical call.
That didn't happen. The employee account merely contained a list of email addresses.
RSA was hacked and the attackers could then get access to US military contractor internal data.
...
LinkedIn was hacked and the attackers could then get access to DropBox internal data.
Would the military contractors claim that they weren't hacked?
But making it sound as if Dropbox's security was compromised is misleading and inaccurate IMO.
If that weakest link happens to be an employee with a naive ideas about password security, it makes no difference.
This is the same silliness that makes people claim that social engineering isn't actually a security breach "oh they just phoned up the front desk and convinced them to be granted access, who would fall for that, that's not hacking!", yeah, no, someone just got 0wned.
Also, kindly avoid the linkbait title, dropbox did not get hacked, some of its users' account credentials were compromised on other sites.
The title of this submission matches the title of the article, matching recent HN policy. Users objecting to the phrasing may wish to flag the submission instead.
Dropbox today said a stolen password was "used to access an employee Dropbox account containing a project document with user email addresses."
(What else is being left around in data dumps?)
Gmail has allowed for such individual mail addresses for years:
username+loremipsum@gmail.com
Example:
johndoe+dropboxcom@gmail.com
Mails addressed to johndoe+dropboxcom@gmail.com will be delivered to johndoe@gmail.com. They are easy to identify, filter etc.
For client side encryption I have good experiences from BoxCryptor on Windows.
The last thing I want is double the number of apps on my phone as every single app has another 2-factor auth app to ship.
Just add yourself to Google Authenticator and be done with it. It doesn't require a Google account, you can use Google Authenticator as the generator of the 2-factor auth code and that's all.
LastPass uses Google Authenticator for 2-factor, and it works well.
One of the problems I've found with Dropbox is that I tend to use a shorter and easier to type password because I enter it on my phone in addition to my desktop.
Good passwords are great when you have a password manager, but in the app you're stuck with having to type it in. So my Dropbox password is weaker than I'd want just because apps mean I can't use a password manager. 2-factor can't come soon enough for me.
On a related note, 2-factor is one of the weaknesses I want addressed. The other one I'll bang on about is client-side encryption. If it's possible at all for someone to access their systems I still want to feel sure that someone can't access my files.
It's not that I limit my use of Dropbox, but I use it differently. That 1GB file in my account... that's a Truecrypt volume. The other files are just less sensitive.
So, a fair amount.
If we assume that the set of files users sync is similar to the set of files in their home directory then it is not a stretch to conclude that Dropbox deals with lots of music. Dropbox cannot do anything about the documents or family photos but they can save considerable bandwidth and disk space by deduplicating the music, or any other common media.
Since dropbox's biggest input cost is storage I could well see client side encryption having a consider effect on their profitability.
There are several systems with client side encryption, some of which also have de-duplication, and at least one of which has interesting crypto (bitcasa).
This is all unrelated to the authentication problem with dropbox today, though.
2) Do you not enjoy features like the web interface and public links? Those are one of my favorite parts of dropbox and they wouldn't work with client-side encryption.
You can have web interface with client-side encryption. Check aes.io (plug).
I was assuming that an employee account can in a more or less direct way access user files. Either way, it's not the first time they've been compromised and last time[1] client-side encryption would have certainly helped.
> Do you not enjoy features like the web interface and public links?
The web interface could work with client side encryption. I wouldn't mind having no encryption for publicly shared files.
[1] www.wired.com/threatlevel/2011/06/dropbox/
Recently, passwords have been stolen from some internet services. We've reset your password.
I'd have been shocked, but ultimately more respectful of:
We've had a security violation. You can read about it here. Your account wasn't affected, but we're resetting everyone's password just in case. So sorry about this.
However, using a work e-mail and the password you use at work on someone else's system was stupid. You can have faith in your own security measures, but not anyone else's. If you're going to re-use passwords, at least have a work one and an everything else one.
Other than that dropbox can't do much about people using the same passwords for different sites or social engineering attacks. You can educate and warn people about it, but it's ultimately up to the user to follow through.
It's not much, but at least you'll be notified when someone syncs their computer with your dropbox or adds your dropbox to their phone.