Bypassing Two-Factor Authentication for Dropbox
qcert.org
qcert.org
http://www.slashgear.com/dropbox-hack-allows-bypass-of-two-f...
"It turns out that as long as someone has the username and password of your Dropbox account, they can bypass the two-factor authentication and log right into your account with a couple of clever tricks. Since Dropbox doesn’t verify email addresses when users sign up for a new account, a hacker can use a new email address that’s similar to an existing one by placing a period in somewhere, similar to how Gmail addresses work.
For this fake account, two-factor authentication is enabled and an emergency code is generated in case users ever lose their phone. The hacker will then login to the victim’s account, but will be prompted to enter the code for that account. However, the hacker will simply select that the victim lost their phone and they’ll be promoted for that emergency code.
Since the email address that the hacker signed up with is similar to the victim’s email address. the emergency code will work on the victim’s account. From there, the hacker can disable two-factor authentication and gain access into the victim’s Dropbox account. This is because that “baseballboy@yahoo.com” is registered as being the same “baseball.boy@yahoo.com,” just like how Gmail handles email addresses.
Of course, you have to know the user’s password before you can do this, but once you get a hold of it, it seems relatively easy to bypass Dropbox’s two-factor authentication. However, the security team that found the vulnerability is already said to be working with Dropbox to fix the bug."
(1) Dropbox is inconsistent about whether it ignores dots in the local part of an email address, and in some cases blurs the line between accounts with similar emails. If true, this needs to be fixed.
and
(2) Dropbox doesn't really use two-factor authentication, in the usual sense of "something you know plus something you have." I'm guessing this is due to their users liking the idea of having two-factor authentication, but in practice want to be able to access their account even if their phone is lost. So it turns into "something you know plus something you know." I'm inclined to think that this kind of not-really-two-factor-authentication is actually the correct approach for the kind of data you store on Dropbox, but it's something to think about when you're designing an account-recovery protocol.
With regards to point number 1, I don't understand how that bug could have existed uncaught. Yes, security is hard but when you're storing the most personal user data, you're obliged to make sure you actually keep it safe and protect it from unauthorized access.
Yet, with Dropbox, it appears that every so often that some time goes by, and we have yet another security issue. The worst I remember was when for a window of time, _anyone_ could login to _any_ dropbox user account without entering a valid password. No password. Just a valid username and you're in.
It's interesting to note that issue too had to do with authentication and authorization. Maybe it's time Dropbox should spend some time auditing their code to find other similar issues just waiting to be discovered?
As you pointed out, dropbox has shown they're not very secure. They lied about their server-side encryption too. But no one cares. It's far more profitable to make a reasonable pass at security, then try to deliver on the user experience and marketing.
Everyone I know in a security-conscious environment uses something else. Sadly, often MS Sharepoint. There are some big advantages to a system like Dropbox, but aside from some small startups, nothing in that space I'd actually recommend for business use.
(I work for Dropbox but don't speak for it in this capacity)
It is not generally the case that companies disclose quickly-patched vulnerabilities that were reported by white-hat security researchers. Example of a similar vulnerability with a similar response time by another company: https://blog.duosecurity.com/2013/02/bypassing-googles-two-f...
Researchers disclose a while after the vulnerability is patched. This is standard practice.
I am the researcher that disclosed this, and it was responsibly disclosed to Dropbox and later to the general public once we got confirmation that the vulnerability is patched.
you can email me at zouheir[dot]abdallah at gmail
HOWEVER, there are always ways around two-factor auth. Some sites have some special codes that you are advised to print and carry around with you. Some sites let you verify your personal information to turn it off.
What it comes down to is how secure are:
- the methods of disabling two-factor auth
- the methods involved when you lose your two-factor auth token/device
And let's not forget:
- the methods invovled when you forget your password
- customer service intervention methods (i.e. social engineering)
Putting a "Look we support two-factor auth! We are super secure!" message out there is always a red flag for me, as to how they have counter measures in place for the above scenarios are very important... as that is what the evil people will do.