SaaS Vendors Should Learn The Art Of Security - Dropbox Issue
cloudave.com
cloudave.com
Unless this reveals actual information about the valid account, this a sev:informational finding on any professional assessment. In other words: you probably wouldn't even list it as a vulnerability.
I'm not sure I've ever seen an application that didn't have an account ID distinguisher somewhere in it. All you need is a place that generates "Permission denied" instead of "Not found".
Publicly calling out Dropbox for something that has extremely minimal real-world impact is bad form. Dropbox might care that there's a method to count accounts (I doubt it, since most of those accounts are free, so you can't work them back to financials), but it's not a matter of Internet safety and hygiene.
the public link feature was actually a proof of concept and never intended to stick around :)
but anyway, having this information doesn't let you do anything but get a rough count of our users, so saying it's a security issue is a stretch. there are no public-facing forms or inputs that take these values as input
However, I want to point out that I never said it is a security issue. I just said that it is not a best practice from the security point of view and it could be taken as a starting point for further poking and social engg stuff. I just want to make it clear here.
Not only that, but the title of your post was "SaaS Vendors Should Learn The Art Of Security Before They Open Shop". It's a bit late to walk the sentiment back now. Either come to the table with more information than you've shared, or take your lumps and apologize. I think you got it wrong.
Plus, anyone who has read my post properly (than asking me to read the comments here properly) can understand that I never said that their security is weak. I only told that their approach to resource enumeration offers an easy way for hackers to get started. I am not sure if you understand the argument I am making here from a purely security point of view. But, if you are familiar, I invite you to think along these lines and see if it is a good practice to have this kind of sequential naming system.
PS: Regd you second paragraph, I don't respond to childish talk. If you restrain and talk like an adult, I am happy to discuss this issue. This is not about me or you or Dropbox people, it is about possible issues such an approach can cause and its impact on cloud computing, in general. Since, I evangelize cloud computing, I care about issues like this and try to highlight it in my blog posts. If you are open to mature discussions on this topic, feel free to drop by my blog post and we can discuss further. Otherwise, this will be my last response. Thanks for your time anyhow.