Live data from Hacker News

The Dropbox hack is real

troyhunt.com

101–110 of 557 posts

Re: The Dropbox hack is real

#101
post #58

Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?

Keep your password written on a piece of paper in your wallet, with a few extra characters you need to remember to ignore.

or a few extra characters you need to add. As much as people say this is a bad idea, most of the people you would be trying to keep out, don't have access to your wallet.

I did this for a few months for a master password and set everything to forget the password so I used it several times a day. After a little while I can get rid of the paper and have a LONG random password that is committed to memory.

Re: The Dropbox hack is real

#103

Can someone in the know indicate how to BEST manage passwords for different services in a secure way in 2016? Should I be using password managers (à la 1Password, LastPassword and others), or use something like Keychain Access on Mac OS X (what are the Windows equivalents?), anything else? It's important to note that not everyone is well-educated on the matter, despite the fact that most people on HN are technical pe…

Password manager + two factor authentication whenever possible. As for the former: Opinions here differ but my recommendation would be not to trust a "cloud" password manager and employ an offline password manager instead. KeePass works great for instance and is open source and cross-platform.

Re: The Dropbox hack is real

#104
post #58

Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?

Keep your password written on a piece of paper in your wallet, with a few extra characters you need to remember to ignore.

Here's the advanced version, that let you use different, mostly uncorrelated passwords for different services. http://blog.jgc.org/2010/12/write-your-passwords-down.html

I have implemented a little program to generate such a square: http://loup-vaillant.fr/projects/password-generator

Though by now, I find this a little tedious. I'm thinking of using an encrypted password database, protected with a diceware generated password. That way I will be able to copy&paste my passwords instead of typing them by hand.

Re: The Dropbox hack is real

#105

Why isn't Dropbox reporting this? I'd have more respect for them if they were more honest about this.

They sent both me and my wife an email a couple of days ago regarding this, and have a Help Center page[0] for it:

    Hi ,
    
    We’re reaching out to let you know that if you haven’t
    updated your Dropbox password since mid-2012, you’ll be
    prompted to update it the next time you sign in. This is
    purely a preventative measure, and we’re sorry for the
    inconvenience.

    To learn more about why we’re taking this precaution,
    please visit this page on our Help Center. If you have
    any questions, feel free to contact us at
    password-reset-help%dropbox.com.

    Thanks,
    The Dropbox Team
[0]: https://www.dropbox.com/help/9257

Re: The Dropbox hack is real

#106
post #89
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

My LogMeIn unique address gets tons of spam - their response was that I must have given it away elsewhere. I no longer use LogMeIn.

Same here. I have (at the last count) over 200 website/service specific email aliases. I very rarely use an alias for more than one service. However when I do start getting spam on that alias, and I contact the website concerned they always state it's my fault. My response? If I can, I stop using that website or service.

My dropbox alias email started getting loads of spam about 2 years ago, I immediately junked that account, and set-up a new dropbox account (friends insist on sharing stuff over it...) - my old spammy dropbox alias is in the Dropbox leaked dump, my new current one isn't, which proves that this dump of credentials is from at least before 2015.

Re: The Dropbox hack is real

#107
post #58

Earlier quoted context omitted.

Keep your password written on a piece of paper in your wallet, with a few extra characters you need to remember to ignore.

or a few extra characters you need to add. As much as people say this is a bad idea, most of the people you would be trying to keep out, don't have access to your wallet. I did this for a few months for a master password and set everything to forget the password so I used it several times a day. After a little while I can get rid of the paper and have a LONG random password that is committed to memory.

And the average mugger most likely wouldn't know what to do with a long random string (or multiple). The bank notes next to them are much more interesting.

Re: The Dropbox hack is real

#108

Can someone in the know indicate how to BEST manage passwords for different services in a secure way in 2016? Should I be using password managers (à la 1Password, LastPassword and others), or use something like Keychain Access on Mac OS X (what are the Windows equivalents?), anything else? It's important to note that not everyone is well-educated on the matter, despite the fact that most people on HN are technical pe…

Download a password manager like Keepass, Lastpass or Password Safe:

https://en.wikipedia.org/wiki/List_of_password_managers

I use Keepass, it does exactly what I need.

Secure the password manager itself with a long password. Put your logins into it, and generate a unique random password for each one, then go to the website in question and change the password to the new one.

When you want to login to that website, open your password manager, copy the password to your clipboard and paste it in. Remove the password from the clipboard (Keepass does this automatically after about 10 seconds).

That is ALL you need to do. You could get into using keys, etc, to secure the password manager but if you have a long, unique password for the password manager, it shouldn't be necessary. I'm sure others can provide you with info on how to finesse the process using online password managers, etc, but what I've just described is the basics. Start simple, ramp it up later if you're the paranoid type (which you should be ;)

EDIT: Another thing, if you can use two-factor authentication, do it. I use this on my Google accounts, Paypal and my bank.

https://www.google.com/landing/2step/

https://www.turnon2fa.com/tutorials/how-to-turn-on-2fa-for-p...

Another edit: You can store more in the password manager than just passwords. I keep a scan of my signature in there in case I have to put it into one of those (admittedly insecure) PDF-type forms to "verify" I've signed something. I also make up stupid answers to password hint questions and these also go in the password manager, e.g. "First school" -> "Dr Magnus Pike's School for Aspiring Arsonists". Too easy for people to work out what my real first school is called.

Re: The Dropbox hack is real

#110
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

I use spamgourmet.com for the unique-email-per-service..

Sadly, it doesn't support 2FA.

Post reply on HN