Dropbox.com hacked?
pastebin.com
pastebin.com
http://www.techly.com.au/2014/10/14/dropbox-hacked-seven-mil...
"Dropbox has not been hacked. These usernames and passwords were unfortunately stolen from other services and used in attempts to log in to Dropbox accounts. We’d previously detected these attacks and the vast majority of the passwords posted have been expired for some time now. All other remaining passwords have been expired as well."
"In September 2014, a large dump of nearly 5M usernames and passwords was posted to a Russian Bitcoin forum. Whilst commonly reported as 5M "Gmail passwords", the dump also contained 123k yandex.ru addresses. Whilst the origin of the breach remains unclear, the breached credentials were confirmed by multiple source as correct, albeit a number of years old.
Compromised data: Email addresses, Passwords"
Is there some way to figure out exactly which password was compromised?
I will say that the passwords are usually very old, grabbed from some forums, and have probably been out in the wild for a while. So basically, as long as you don't use the same password everywhere for years, you're probably fine.
Type in your email address, you'll get the first two letters of the known password back. It should help to track down which service the password came from.
When the 5 Mil Gmail leak first happened, it was found to be a collection of gmail/pass combinations from other leaks and not a Gmail hack.
Known sources (and definitely not limited to these sites):
* Gawker (and related sites),
* Friendster,
* XTube,
* FileDropper,
* Daz3d/Bryce,
* eHarmony,
* Savage,
* Bioware,
* FreebieJeebies,
* PoliceAuctions,
* Bravenet,
* Filesavr.
If you recycled passwords, change them even if they're not in the email list. Turn on two factor for Google Accounts.
It seems more likely that a third-party website wasn't storing passwords correctly, was hacked, and this is the list of users that use a single password for everything.
Bille97... Billel... Billen... Billet... Billew...
Isn't it unlikely that so many alphabetically-similar accounts from the third-party site would use the same password for dropbox?
-> % cat 1000000\ email\ list.txt | sed 's/, */\n/g' | grep "@"| sort | uniq | wc -l
835694
-> % cat 1000000\ email\ list.txt | sed 's/, */\n/g' | grep "@"| sort | uniq | grep -i "^b[e-i]" | wc -l
11160
irb(main):001:0> (835694.0 / 11160) * 400
=> 29953.189964157707"Dropbox has not been hacked. These usernames and passwords were unfortunately stolen from other services and used in attempts to log in to Dropbox accounts. We’d previously detected these attacks and the vast majority of the passwords posted have been expired for some time now. All other remaining passwords have been expired as well."
Making unsubstantiated statements like "6,937,081 DROPBOX ACCOUNTS HACKED" and requests like "MORE BITCOIN = MORE ACCOUNTS PUBLISHED ON PASTEBIN" makes this whole thing seem like a scam.
Considering that Dropbox is most useful via the desktop/mobile app...meaning that the password is rarely entered...I treat my Dropbox password as if it were on a need-to-know basis...that is, I have no idea what it is and I have to jump through several hoops to retrieve it for the rare times when I need to login. I don't put anything too valuable on Dropbox, but better safe than sorry.
May it be because they didn't actually hack dropbox but just hacked about 400 accounts and hotmail users were easier targets because that demographic was more like our parents?
Also the list skips from b-e to b-i in 400 users, surely if there were 7 million email addresses this shouldn't be the case?
See: http://btc.blockr.io/address/info/1Fw7QqUgzbns7yWHH32UnmMxmM...
https://blog.dropbox.com/2014/10/dont-get-baited-by-phishing...
I also wonder if this effort was spurred by Snowden's criticism of their system?
Did they come from Dropbox? Not necessarily. Not everyone uses a unique username+password combination for each site.
A more accurate title would be something like: Dropbox accounts potentially compromised
Of course, even if they do, it could easily be passwords taken from some other service, matched to accounts where people use the same password for everything.
Not necessarily an indication of Dropbox itself being hacked.
Usually a salt would protect you from that, but look at how trivially easy all those passwords are.
Edit: due to the downvote, I'll remind the audience about this: http://codahale.com/how-to-safely-store-a-password/
http://www.wired.com/2014/04/dropbox-rice-controversy/
Anything you save can and will be used against you ...
Your private data is not safe in dropbox. The end.
Step 2. Change password