Why was my email leaked?
forums.dropbox.com
forums.dropbox.com
Hi,
Thank you for your support request. Recently, we have been receiving a high volume of support requests and haven't been able to get back to you within a reasonable amount of time.
The volume of inquiries we receive on a daily basis prevents us from responding to all requests. Although requests from Pro and Teams users will be given priority assistance, we will do our best to get back to other inquiries when possible. If you are not a Pro or Teams user and you're looking to resolve your issue before we can respond, you may want to check out:
If you need to restore a large number of files and are unable to do so, please visit the following instructions to help us speed up the restoration for you:
If you are still experiencing problems, please reply to this message. We will try our best to get back to you, however we cannot guarantee a response. We're very sorry for the inconvenience.
Regards, The Dropbox Support Team
I managed to expedite things a bit by emailing the CEO directly -- drew@dropbox.com.
Taking money and then fail to deliver service or product is the very definition of scam/theft. But beyond having the state putting down regulations, is there any actions people can do without putting themselves at even higher risk (like bans)?
If you don't understand the difference - or more importantly why one of them bothers people and the other doesn't, you need to stop doing marketing or promotion really quickly. You're going to tarnish the brand of the product you're trying to push.
Do you want people's only lasting impression of Tonido to be 'oh, that's that company that was astroturfing Hacker News'?
"Your affiliation IS relevant when promoting services, because it means it's not an honest recommendation from a happy user, it's paid shilling."
That's not a fair criticism. In this case, there is an issue with dropbox, and he is pointing to a solution which obviates the problem at hand:
'Check out Tonido Cloud (http://www.tonido.com/cloud/) and host your own dropbox.'
I think the wording was poor, but reading into the website offering it is clear that the company doesn't have access to the local credentials. In this case, since the alternative doesn't suffer from the problem at hand, I think it's fair for him to mention the alternative.
I didn't downvote his post at first because it sounded like a genuine suggestion. I consider myself deceived.
The only way in which you could have been deceived is if you went into the discussion assuming no conflict of interest. Years of dealing with financial media and experts has rendered me incredibly cynical, so I focused on the author's claims (which, in this case, are true -- If the product acts as the website claims, the self-hosted solutions store credentials on your servers and not theirs.)
I recommend you read http://hastebin.com/raw/gefuxumubu, the zerohedge.com conflict of interest policy, for it drives home the key point that if you assume everyone has a conflict of interest you won't be deceived and you can focus on what was actually said
"We've seen many companies leak or improperly use your email addresses and other personal informations. The best solution is to host your own. Check out _____"
That would have been a proper sequitur and wouldn't come off as arbitrary pumping.
Oh how I wish that were the case, but there's a really strong mapping from HN and SV to finance (too much to mention in a reply, but I may try to flesh it out in a blog post one day)
When you post w/o disclosing, you make it seem like someone from this community has found your product interesting and is suggesting others try it. Instead of working for a company and trying to drum up business while disparaging a competitor.
Seriously, things like this reduces the likelihood that I'll ever try Tonido to nil. All you had to do was add "disclosure: I work for Tonido" to your post, if that is the case.
"your affiliation is quite relevant. When you are talking about something when you have a clear conflict of interest, you need to disclose it. Then at least the reader has the right context in which to make a decision."
I used to think the way you do. Then I entered the financial world. At this point, I've seen so many people talk up their positions without disclosing that I automatically assume everyone has a conflict of interest. Then something really strange happened: I stopped caring about the affiliations and really focused on the veracity of their statements.
I recommend you read http://hastebin.com/raw/gefuxumubu, which is a copy of the zerohedge.com conflicts of interest policy. We are all adults here, and a person's persuasion shouldn't somehow affect your ability to make a rational analysis of the arguments that a person lays out.
In this case, if you bothered to look at the offering, you would see that it indeed obviates the problem that dropbox has all of your emails: when you self-host, the accounts are stored on your servers
Note that I haven't actually tried the service, but this is based on my understanding of the offering. There may be vulnerabilities in their implementation. Who knows. But to immediately dismiss a remark because of a conflict of interest doesn't change the fact that the argument may be factually correct and germane.
My response is that it is all about context and community norms. Here, on HN, the norm is that if you're going to bash someone, and you work for a competitor, you disclose that. If you can't pass that small ethical hurdle, there are other companies I can send my money to. (Not to mention, That I consider it uncouth to bash a competitor like that)
In the financial world, things are probably different and you just assume some level of conflict from the beginning. And that's fine, so long as everyone knows the ground rules.
I've actually looked into Tonido a couple of times, so I already knew what the service was. I have a friend who was all ready to buy one of their plugs for their lab when their university got hooked up with Box.net (I think).I probably wouldn't have thought to question them had a) I not already known what Tonido was and b) they had already been downvoted, so I wasn't the only o e to put it together. For some reason, I always had reservations about it, and so this just cemented an already held feeling.
But, you are quite right that different communities have different norms.
This is a totally honest question as I looked when you wrote this and found no bashing.
That was the line I was referring to...
But it's not just how truthful the statement is, it also covers "why am I considering this statement at all?".
And the answer "because someone I trust has had the same problem, considered the available options, and recommends X" is very different to "because someone who works for X says use X".
The bit where Andy Y. says, "Oh, some spammer just guessed it" was funny. As if spammers needed to do dictionary attacks against the sort of tagged addresses that 0.1% of people use.
But it became hilarious when he said the same thing to the guy who uses 10-random-character tags. As if they would hit upon two different Dropbox addresses like that before the sun cooled to a cider.
The original complainant is much more patient than I am. If that's what I'd gotten as "support" on a paid service when reporting a security breach, I would have closed my account and told them to get fucked.
They're official representatives of Dropbox, even if they are unpaid. Their behavior is entirely on Dropbox, and the fact that Dropbox has farmed out its customer support to unpaid amateurs is possibly a worse realization than the fact that the clueless person was not an employee.
So it's a win win for Dropbox. Free forum support for low level day to day forum chatter and easily absolvable of any wrongdoing if they screw up.
The only question is, are people going to hold them accountable or not (by finding other solutions). I don't use them (I do my own syncing) and this display warns me off of starting to use them any time in the near future.
I agree with the end part of your response, but it's unknown if Forrest is a paid customer.
"Just the fact that you listed your emails says it all."That is just awful, and is an awkward example of why you may not want unpaid, mostly un-vetted volunteers as the public face of a company.
I was wary of this thread showing up on HN because I felt I was a bit unkind when posting in that thread, but Chris' comment towards me seemed completely unjustified. And he deleted a prior post along the same lines, hence why I quoted him on my next post.
You mean that tim-somespecificsite@mydomain.com was randomly compromised, but NO OTHER random email was mailed to me? No, that's not how spammers work. If they'd decided to spam tim-*, I would have gotten hundreds of emails...sigh...
Tangentially related: It drives me nuts to deal with people whose default answers are "no," "you must be doing it wrong" and so on. Particularly the moderators who insisted someone must have guessed a ten digit random email address -- because Dropbox and its vendors couldn't POSSIBLY have ever done anything wrong, and it's MUCH more likely that a spammer magically brute-forced a 10 billion combination address! Grrr. I'm not sure what the right word is to describe that sort of personality, but such people should never have contact with customers. Or with me.
On a side note, why the heck does dropbox have volunteers running their support forum? At this stage, cost savings isn't worth the reputation hit.
If I had to guess - I'd suspect three or four "nines" of their customer support workload comes from their "free tier" non-customers. (Having said that, there's evidence upthread in these HN discussions saying they're also dropping the support ball for paying, even team-account-sized paying customers - that's not OK...)
The guy who says that he had a truly random bunch of letters as his dropbox account is probably a better indicator, but it's hard to know if the guy ever leaked it himself.
Doesn't excuse the moderators being jerks, though.
Even though a service might desperately want to know my personal and/or business email address, and disguise that desire with the usual "Hey, just use your email address as your login username!", doesn't mean I have to comply. Unless they're prepared to accept responsibility to disclosure of my address, I feel perfectly happy taking the required measures to minimise those risks myself - no matter what they attempt to enforce with crappy email validation or ToS requirements.
(And, although Dropbox have finally arrived in their forum-thread ~24hrs late apologising for their "community moderators" calling their customers idiots, the responses from Nathan and especially Chris only strengthen my resolve to ignore any attempt by companies/services to gain access to my personal email addresses as part of their user databases.)
Do they in fact do this?
Yahoo! Plus has a much better system where you use a different base email address plus the sub-address rather than your regular address.
For example, if my account is "somebody@gmail.com" then you use somebody+dropbox@gmail.com. But with yahoo, you pick an alternate, e.g. "huggybear", and use that instead (huggybear-dropbox@yahoo.com). That way if a spammer seems the sub-addressed account, they can't send email to huggybear@yahoo.com unless they want to end up on Yahoo's blacklist.
I've had a great deal more success with Yahoo's sub-addressing than Google's.
So in my earlier example, if you wanted to sub-address ebay, amazon and hackernews you'd have huggybear-ebay@, huggybear-amazon@ and huggybear-hn@.
The big deal is that huggybear@ != someone@ and sending to huggybear@ won't reach someone@ and likely earns you a place on their blacklist (or some points towards ending up there).
When an address is "compromised" and starts to receive spam, I move the line to a "banned_recipients" file with an SMTP reject header listing the new email. That way, a human using an old address would get a bounce back with the new email.
[1] so that the argument about bruteforcing "common-service@domainname" can be avoided
I'm running with this rule in the access map:
/^from-.*@foobar.com$/ OK
That accepts all mail to an address prefixed with "from-" and (by default) rejects everything else. This way you can just make up the dummy-addresses on the fly.I remember being slightly worried about using such a simple prefix when setting it up initially. However I have never received mail to a from-* address that I didn't "create". Not once in over 6 years.
And disabling an address that has turned spammy is as easy as:
/^from-stuffit-expander@foobar.com$/ 554 No thanks.The fact that the guys email was blah.dropbox@blah.com meant it was a possibility that another site had been compromised and the email matched a keyword filter which allowed it to be easily guessed.
Its like passwords. MyPASSW0rDdropbox. If this is leaked it is fairly likely someone may try.. MyPASSW0rDfacebook.
They failed a bit further on. One obviously misread the thread and made a comment which isn't really acceptable.
Generally though it is the typical user forum thread. User repeatedly hammers the moderator with the same question. The user cannot elaborate. The moderator can only speculate due to lack of information. User doesn't find moderator answer acceptable, provides no further information and asks the same question.. both sides get annoyed.
It seems like the spam is to do with the data that Dropbox previously lost. An answer which a moderator actually provided.
Hi there,
We’ve been looking into these spam reports and take them seriously. Back in July we reported that certain user email addresses had leaked and some users had received spam as a result. At this time, we have not seen anything to suggest this is a new issue, but remain vigilant given the recent wave of security incidents at other tech companies. If you’ve received spam to an email account you only use for Dropbox, please send the message (including full headers) to support-security@dropbox.com to help our ongoing investigation.
Separately, we want to apologize for some of the dismissive responses from our volunteer moderators - since they aren’t employed by Dropbox, they don’t have visibility into issues like this. We want you to know that we've taken these reports seriously and began our investigation immediately.
I'm surprised (bordering on disappointed) that the initial response by the moderator Chris didn't trigger a Dropbox employee response almost immediately. Even given worst-case timing I'd expect a first thing next working day response in 16 hours - but for a potentially serious security related problem like this I really expected to see an immediate "Hey, thanks for the report - we're looking into this right now, can I contact you off-forum to get more details." from a Dropbox employee - preferably with an obviously security related job title.
I fully understand why Dropbox can't afford/justify providing high priority customer support to their free-tier customer base, but ignoring possible security breaches reported from the free-tier seems foolish, and allowing your crowd-sourced forum-based-customer-support to mishandle it like this is really sad.
Or better yet, doing actual support for paying customers?
There was nothing in that thread that requires moderation (other than the mods themselves)... so why are they even there?
if he has suddenly lost faith in dropbox, there are other services that are cheaper, like box.
Obviously we were very concerned, and spent days poring over server logs and trying to figure out where the breach was.
Turns out the service we used for newsletters (icontact) had been hacked. They never emailed to let us know. (They had a blog post up for a few days, then removed it, the slimy bastards!)
Since then we've used MailChimp, and had no problems.
We lost a lot of trust with customers since we had a kind of low-rent image to start with (discount software bundles). The worst part was they never really owned up to it - the blog post just said they were "investigating it". They never followed up, then they redesigned their site and the blog post mysteriously disappeared. Assholes.
Perhaps this is just a huge coincidence but I see three spam emails sent today plus another two sent this week. Some of them have cc recipients which seem legit addresses of other people, but I can't identify them. I never used Zendesk by the way.
Edit: here are the senders, in case it helps: no-reply@adsl.hu, no-reply@velkommenhit.no, no-reply@wdl.fr, no-reply@tataidc.co.in, no-reply@variationfm.com. Though it looks like these addresses may have been spoofed... the sender name is "{%FROM_NAME%}" in all of them.
Edit 2: It turns out Groupon Germany (former citydeal.de), which I checked out once with the same address, is responsible from what I can gather (link in german, but everything matches, company has yet to say anything): http://hukd.mydealz.de/diverses/groupon-verkauft-kundendaten...
http://thenextweb.com/insider/2013/01/31/yahoo-mail-users-st...
If you ever shared anything with somebody using Yahoo email your email is already in the wild.
From ".Вишняков@direct.nacha.org" <kohinoorwm87@lifesep.com> and ".Белов@fdic.gov" <runoffiz@smarterbythemonth.com> with subjects of "Declined Direct Deposit payment" and "Update of the security software is required!"
I do get lots of "random" spam sent to addresses like "fcbb3a43@<mydomain>.com" but I can't believe the moderators really think that a "random" guess would land on "<domain>.com@<mydomain>.com" sigh
This forum should be a PR beacon for awesome customer support!
They are representing the company as forum moderators whether they like it or not.
I agree with others that they should at least have the word "Volunteer" in their forum account title. Not just "Moderator".
You and I know they aren't dropbox employees, but I wouldn't expect most people to assume that. Thats a big problem.
I don't run any spam filtering, at all, and my email box is the catchall for my domain. These aren't just lucky guesses.
Also, the parent is Intuit which, IMO, is not exactly tops when it comes to data security and privacy.
The way it is worded, it seems like your e-mail may be used by Intuit for promotion or by third-parties bound by the same privacy policies, but certainly not sold for spam.
Same difference in my book. If you are not the original entity that I supplied my address to, and I get email from some 3rd party, that's SPAM. Sure, you could argue that it's in the T&C and that I "agreed" to it, but it's still SPAM the way I see it. And since it's a 3rd party, then that'd mean my information was sold (or otherwise bartered/traded).
How did you rule that out?
Seems highly unlikely that the situation this person described would result from anything other than dropbox being compromised in some way.
And, the mods there held on to the "it must be your fault, probably just an easily guessable email address + random bad luck" line _way_ past the point of credibility.
If you mean they should sort out their forum moderation policies then I agree.
If you mean that this must be a technical problem on their part then I disagree. A 3rd party submitting their address book to a Friend Finder or similar tool would not be the responsibility of DropBox.
They do seem to have a customer expectation and privacy problem though. If, as described by enough forum poster for it not to be a coincidence, email accounts created just for Dropbox's service and which are not trivially guessable are getting spammed - then Dropbox has somehow leaked customer data that customers had expectations of being private. If that were me, I'd consider myself to "certainly have a problem" - whether that problem is "my user database just got exposed via an SQLi attack", or "my contract with my newsletter emailing partner or customer support software service wasn't well thought through enough and they've used my clients email addresses without my/their permission".
While I agree that a 3rd party (or even a 3rd party app) uploading their addressbook is beyond Dropbox's control - that doesn't seem likely to be the cause from my reading of the first few pages of that forum thread this morning - I doubt the sort of person who creates "username.dropbox@example.com" style email addresses for Dropbox is likely to then add that address into a contact list where Facebook or Instagram style contact-mining apps are likely to find them.
It'll be interesting to see this as it pans out - I'm reasonably sure Dropbox or one of their partners (I'd put a small wager on Zendesk) or some malware targeting their client-app; is "leaking" username/emails.
Note that a third party will now have the second party's email address without Dropbox being in any way culpable.
It's possible that the feature was never used but it's hardly an obscure use case.
If someone was just trying things to see what worked he would see those emails.
I could be wrong and it's possible that some filtering was happening on the ISPs side, but you'd think that of the thousands of spams that get through, there would be some that looked like guesses.
I've also seen similar leaks from linkedin (obvious, since they acknowledged their hack), everydns, the nokia development forums (another obvious one that was acknowledged as compromised), namecheap.com and uneetee.com.
At least the former inspires hope that it could potentially lead somewhere.
I used to enjoy the reactions I'd get from store clerks and telephone reps when I give them my email address. "Oh, how you have an email address with our company name in it?" In recent years the reactions have turned kinda hostile, "What is your connection with our company?" and once "You can't have our company name in your email address." I gave up fighting and now I just use random strings.
As long as you use a secure password, and you don't use the same one. I don't see alot of difference, but the ability to sandbox each service to a list of email accounts, so that the attacker never knows the master account, would be an extra layer of security.
Utility exists here. I just don't think there's enough utility to justify the work.
End result is that everyone gets a unique email that can't be guessed, I can nuke an address as soon as it starts sending me spam (often) and my true inbox is typically completely clean.
I initially made the mistake of trusting my bank and utility billing systems with my real address. Turns out my power company had their database compromised, and when I called to inform them they refused to believe me (like Dropbox).
If I'm at Toys R Us or something, I'll just be like uh... "tru25@<mydomain>.com" so they don't question me. (Also, I chose Toys R Us as an example because when I went to sign up for a loyalty program, and they typed in "toysrus@<mydomain>.com" their cash register black screened and rebooted... !)
dropbox email -> qebcobk@yourdomain.com
Is it some kind of internship scam?
Is the point of volunteering to put it on your résumé for future employment opportunities in customer service?
This is the company's OFFICIAL forum, and therefore the conduct of the appointed "moderators" reflects that of the company.
So much for Dropbox...
Since then they have had more security problems/breaches, and admitted to user info being stolen.
Today's news isn't anything concrete... but their moderators were jerks, which makes the company look bad whether they are employees or not.
For those who are curious, this is what I received:
Hi Luc,
My name is Sean, I work on the User Security team at Dropbox. We'd like to look into the issue you repoted on the forums. If possible can you forward the emails in question directly to me (xxxx@dropbox.com).
Thanks. Sean
Wow, that moderator is really professional.
If not, it may be that the compromised list of addresses from summer of last year has finally reached evil hands.
Did $random-user share his dropbox email with someone else who was compromised?
Did $random-user save his dropbox email on a large service (like Yahoo), which he had compromised?
Did $random-user not update Java, Adobe, Windows, etc and have his machine compromised? Or in some other way leak information?
I'm not in any way excusing Db, but uncritically blaming them without other possible scenarios seems just as asinine.
Except you're wrong here - they've admitted they leaked all these unique email addresses, and it isn't actually some cataclysmic combination of coincidences that all these users were compromised. As would otherwise need to be the case.
Absolute Radio was hacked, not sure about the others.
What happened to you Dropbox?
I've noticed in the past few months I've been getting spam to a lot of site specific emails I've used under my Gmail catch all. It's as if a spammer had access to all email addresses I've used for incoming mail. I've talked with friends and found some have had the same problem.
So where are spammers getting the email addresses we've received email from?
1. There's a vulnerability in Gmail / Google Contacts.
2. Some widely used app I've allowed to access my email has been hacked or has been selling email addresses.
3. An Android app that requires access to my email is compromised, either intentionally or unintentionally.
The least likely one I haven't mentioned is that many independent companies have sold my emails which I find very unlikely.
So what's causing this to happen?
4. You're leaking your own email addresses.
Start by looking for malware on every device you touch.
EDIT: Looks like they're volunteers. But still.
Dropbox's customer service has really gone downhill, what happened?
I don't understand why the mods were so quick to defend DB, especially since they don't appear to have access to any privileged info. Dropbox has over 200 employees now and whatever precautions they take an occasional slip-up seems entirely possible.
"I also have a unique dropbox email address, it was compromised on 2/6, but I tracked it down to a friends system that was hacked. I had shared a dropbox folder with them, they got the email from my dropbox address. Virus on their system collected my dropbox email from their system."
What's worse is that i sent invitations to dropbox time ago to people that i have to now contact and say "Please be aware of this phishing e-mail disguised as a Pay Pal e-mail."
+1 for an alternative service, to be honest. Dropbox is very well done, but this is a good reason to stop using their service if they can't secure their clients' information.
It would greatly benefit them if they found the root of the problem, and reported if it were indeed an issue with them or one of the clients for dropbox.
- User/pass is saved in the 'Remembered password' area of browser (this is decodable by malware) - Email is screen-scraped by malware - Email is sniffed during login at a wifi hotspot (Password is encrypted, user/email may not be) - 3rd party apps that are linked to your dropbox account
I'm not saying that this wasn't caused by the database breach, but there are a TON of reasons that this could have happened. Some on Dropbox, some on the end users.
Don't expect your email address to stay private. That's what passwords are for.
There have been some research projects where unique and unguessable passwords were made in laboratory conditions and securely given to sites to see if they managed to leak. I trust those a lot more because they often lock up the email addresses and never use them. From what I recall some big companies did give out addresses they promised not to, but that's not a blanket condemnation of all businesses.
2013-02-28T18:05:18.865406+01:00 nfc postfix/smtpd[14995]: NOQUEUE: reject: RCPT from bl14-172-78.dsl.telepac.pt[85.247.172.78]: 504 5.5.2 <discus>: Helo command rejected: need fully-qualified hostname; from=<fuzzilyjg755@lanuschny.de> to=<X_dropbox@example.net> proto=ESMTP helo=<discus>The point being, using a pattern is easy to discover. Even if that pattern is a random set of characters.
Would spammers email this? Yes. Why? Because they bought an email list that someone generated using this method.
Not saying this is what happened here, but if you've entered in emails on a site, you open yourself up.
And how is a random pattern easy to discover? Quite coincidental that of the hundreds of addresses, just the three that are used for Dropbox are receiving spam in the past few days.
The spam I'm receiving is the kind of spam that you attempt to send to a non-tech audience (obvious phishing is obvious). The addresses were harvested, not carefully picked by looking at other addresses I used with my domain. The word "dropbox" is not even in the spammed addresses; they were school addresses. I never publicly mentioned I even went to that school. It are also three variants on the school's name, incredible that they picked just these three to spam.
As an aside, who knew so many people had "dropbox only" email accounts. One guy with 10 random letters/numbers he uses only for dropbox. Wow. Is this a thing?
This is the best way (that I know) to find out where your adress was leaked.
The mailserver is configured to push <anything>@mydomain.com to a catch-all mailbox, and the unique TO: lines make for exceptionally flexible filtering/easy identification when a company "loses" your email address.
While this is a thing, it's probably only common amongst folks who carry scars from years of adminning mailservers :)
On the other hand, too often as a user I feel I have to walk on egg shells to avoid upsetting some over sensitive petal of a forum mod. One misunderstood word and you are banned for life, with no appeal what so ever.
All of which leads me to think there should be some third party arbitration for this sort of thing.
There are companies that do this - in the US, we have the Better Business Bureau (BBB) and they handle this sort of thing for offline companies. The problem with this approach is one of cost - if I want my company to appear "In Good Standing" with the BBB, I have to pay $800 per year regardless of whether anyone files a complaint or praise with my company. Ouch. Good luck getting that to work on the web.
Proper client-side encryption, while often not appropriate in critical environments, is useful to protect against this type of situations.
Disclosure: I run AES.io
It's really absurd to expect that your information will actually be safeguarded by some entity that isn't you. As soon as you give any data to anyone, it's gone. You should pretty much assume it's public and get on with your life. Did ya'll catch that blog post up yesterday from the kid who deleted the USERS table at his job, because he was developing against a production database and running queries against it by hand? Experience has led me to believe that's the situation at like all things, everywhere, all the time. Ass clowns emailing around spreadsheets with user data; people getting malware installed on their Windows shit and entire infrastructure's data being compromised. It's a joke. Let's just always remember that while we're busting balls. But if you value your data, don't give it to anybody, ever.