Live data from Hacker News

The Dropbox hack is real

troyhunt.com

281–290 of 557 posts

Re: The Dropbox hack is real

#281

Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?

You can keep 1pass on an iOS device, and auth using fingerprint. Ultimately you're still going to need/want to know the actual underlying passwords to both iOS and 1pass, however.

Re: The Dropbox hack is real

#282
post #227

What really bothers be about this is that Dropbox hasn't bothered to reset the sessions. Even after I manually reset my password (which I wasn't prompted or forced to do btw), all my apps (iPhone, desktop etc) that have existing sessions wasn't expired. So for all I know, a hacker might already have an open session to my Dropbox and changing the password will not fix that Clarification edit: I did receive the e-mail…

I'm a lead at Syncplicity, a prominent competitor. Early in my career at Syncplicity I changed all of our desktop clients to use long-lived sessions that do not reset when the user's password is changed. For us, this is deliberate for a few reasons. Most of our customers authenticate via their employer's SSO (single sign on) and do not use any Syncplicity password management. We also do not believe that routine passw…

Maybe one could add a checkbox to allow users to do that when they want to. My Skype password was recently hacked and I'm very very happy that I could via one command logout all the clients. Sometimes it's a feature you really really want to react fast.

Re: The Dropbox hack is real

#283
post #243

Earlier quoted context omitted.

and AMEX passes the cost of that problem to all AMEX customers. You are still paying for it in the end.

how so? when a card is fraudulently used to make purchases, AmEx is not refunding you from their own pockets. they take back the money from the merchant it was fraudulently spent with (a chargeback). no loss at all on their side.

Which is then passed on to customers through slightly higher prices for goods.

Re: The Dropbox hack is real

#284

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?

I have a wildcard redirect so that @mydomain.com is forwarded to me. That way whenever I sign up for a service I just use, e.g., dropbox@mydomain.com.

Re: The Dropbox hack is real

#285
post #227

What really bothers be about this is that Dropbox hasn't bothered to reset the sessions. Even after I manually reset my password (which I wasn't prompted or forced to do btw), all my apps (iPhone, desktop etc) that have existing sessions wasn't expired. So for all I know, a hacker might already have an open session to my Dropbox and changing the password will not fix that Clarification edit: I did receive the e-mail…

I recently unlinked all my Dropbox sessions that were older than one month, which was a staggeringly high number to tell the truth. It would have been nice (and faster!) to have had a "panic button" that let me unlink everything all at once and only relink the things I needed to relink.

Re: The Dropbox hack is real

#286
post #277

Earlier quoted context omitted.

Doesn't that defeat the purpose? Surely anyone savvy enough to be dealing in black-market e-mail address lists is savvy enough to just remove everything after the + sign?

You never use the bare address. If it gets stripped then it gets binned.

What do 'bare address', 'stripped', and 'binned' mean in this context?

Re: The Dropbox hack is real

#287
post #271

Earlier quoted context omitted.

Is there a service (email host) that can give you "infinite email aliases"? (Yes, I know about the '+' in gmail, but I suspect the word is out on it)

You can setup wildcard alias in fastmail ( https://fastmail.com ) and literally create addresses on the fly when signing up/sharing your email.

Fastmail has a really nice subdomains feature - I have an alias in fastmail of 'shop@mydomain.com'. Any email for XXX@shop.mydomain.com gets delivered to shop+XXX@mydomain.com. Better than catchall, because all the spam gets sent to JohnSmith@mydomain.com, which is dropped.

Re: The Dropbox hack is real

#288

> 1Password now has a subscription service for $3 a month and you get the first 6 months for free. Don't pay for this people. Use the open source password manager Keepass http://keepass.info/

1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.

Re: The Dropbox hack is real

#289

Earlier quoted context omitted.

How come the salts aren't available? Did the attacker choose not to release them, or were they stored elsewhere?

Or were they really bad salts? Like a hash of the username?

Uh oh. You might be on to something. Salts are pretty much always stored right next to the hash, right? If the hack doesn't contain them, maybe they were doing something "clever" like that.

Re: The Dropbox hack is real

#290
post #158

Earlier quoted context omitted.

Whilst great info, unfortunately most of the sites that one would actually try to use this on don't accept addresses containing a "+" as valid. Another Google Mail trick is to use periods. Not as useful as the +, but for those sites that don't accept +, one can usually add in a few extra periods to place sites into buckets (multiple adjacent periods don't work). m.y.e.m.a.i.l@example.com

Unfortunately vendor sites such as apple.com don't realize xy@g and x.y@g are equivalent and will let people register both. If you accidentally click approve on the confirmation email then good luck getting Apple to remove the second account. Which is how my wife gets tons of email from Apple about a stranger's iTunes purchases along with other random items.

If you control the email address that the stranger registered to their Apple account, you could initiate a password reset, change the password, then login and change the email address to something that's not yours.

You probably just locked the stranger out of accessing their account though, so you probably shouldn't do this, unless said stranger is signing up for all kinds of services using your email address, in which case maybe they deserve it. :p

Post reply on HN