It would be nice if someone would write a quick script to email these people notifying them. Maybe if I get more time tonight, I'll give it a shot. Otherwise, someone else could be the hero ;)
Dropbox invalidated the passwords for everyone who's on the list, according to anecdotal reports from people on Twitter. You should change your password anyway, of course.
Mail providers should be doing that already. I would be surprised if the gmail/hotmal/yahoo don't have responsive teams that disable hacked accounts and request password reset from a known IP or TFA.
Note that this was on Dropbox, not on any of the mail providers. Unless Google (et al) is going out of it's way to send emails to its users in the list, which would surprise me.
I think the point was that many people reuse their passwords, so if Google et al were proactive about it, they would force reset passwords for the emails in this leak. But I agree, that may be over-protective/paranoid in some sense...
You have to consider the chances that they might just think your warning is yet another phishing/scam email and ignore it; but then again, if these people have been reusing passwords everywhere, maybe not...
I agree, I would like to give it a try. The only problem is how do I ensure the information is valid. I am not going to try and access the accounts, as that would be unethical.
Would it be unethical to enter anyone's house without being invited to save the people in there from a huge fire burning the house?
Saving someone in immediate peril of death is a bit different to alerting someone that there's been a privacy breach, which they can then deal with themselves.
Maybe, but it could definitely be illegal. Anyone could have the right intentions, but make a mistake during an act of Good Samaritan-ship and get sued.
Apparently Dropbox already reset the passwords and sent an email. Source: TNW