Live data from Hacker News

The Dropbox hack is real

troyhunt.com

371–380 of 557 posts

Re: The Dropbox hack is real

#371

Earlier quoted context omitted.

> It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party That sounds more like LastPass than 1Password, although I haven't looked at the new subscription offering. I don't give my passwords to 1Password.

You don't give your passwords to LastPass either, you give them encrypted random noise they can't do anything with.

Which does not change the parent post's point, that with LastPass you're still giving it to a 3rd party who could leak that information for brute forcing.

Re: The Dropbox hack is real

#372
Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Re: The Dropbox hack is real

#373
post #352

Earlier quoted context omitted.

Totally. You wanna talk about people forgetting? It seems everyone has totally forgotten (or forgiven) that Dropbox was mentioned specifically in the Snowden leaks as a source.

are there better alternatives though?

if you are willing to use a rather more complicated system with harder setup, syncthing.net is great, it syncs files between your computers without needing a cloud service.

For more similar alternatives, running owncloud on a VM is straightforward. And, of course the featureset is limited compared to Dropbox.

Re: The Dropbox hack is real

#374

Earlier quoted context omitted.

> It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party That sounds more like LastPass than 1Password, although I haven't looked at the new subscription offering. I don't give my passwords to 1Password.

You don't give your passwords to LastPass either, you give them encrypted random noise they can't do anything with.

And who, exactly, encrypts them for you?

Dropbox was also encrypting your passwords, FWIW.

Re: The Dropbox hack is real

#375

Earlier quoted context omitted.

The trouble is that no one actually implements the email standard from the IETF RFC documents. In fact, some people[0] even actively discourage doing so, despite there being little in the way of good reason to not. The argument essentially goes "well, users aren't going to be likely to use those characters, unless they're doing something bad, and they make it difficult to insert the email into the database." I feel l…

I mean, there are good reasons laid out in that document. "By RFC, email addresses are unique by mixed-case. Most (99.9+%) email systems do not treat email addresses as such." Think of the average user. Sometimes they're going to capitalize the first letter when putting in their email, and sometimes they aren't. You don't want to make it unusually difficult for them to log in. You -should- treat email the way that va…

> Think of the average user. Sometimes they're going to capitalize the first letter when putting in their email, and sometimes they aren't. You don't want to make it unusually difficult for them to log in.

With smartphone keyboards and the capitalization of the first letter of the first word in form input fields by default, this is a very common occurrence. If case was considered for uniqueness of email addresses, at best, people would be extremely annoyed. At worst, there would be a tremendous amount of leakage of sensitive information to random people (due to human errors in entering case sensitive addresses), chaos due to incorrectly delivered emails and fatigue in receiving mails intended for thousands of other people. In an alternate universe where this is true, email would never have been a killer application, only a quickly killed and abandoned one. :)

Re: The Dropbox hack is real

#376
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

I'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives.

Which I suppose forces more awareness, but it doesn't instill a lot of confidence.

Re: The Dropbox hack is real

#377
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

Damn, thanks for this. It seems that I've actually been pwned at some point.

Re: The Dropbox hack is real

#378
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

This was a strange way to find out that I have a Tumblr account.

Re: The Dropbox hack is real

#379
post #122

Earlier quoted context omitted.

For me, it's that 1Password runs locally and doesn't need to phone home, whereas LastPass is "cloud". Also, LastPass being owned by LogMeIn doesn't sit right with me, but that's definitely personal. No idea about Keepass(x), although I found that ecosystem to be confusing, with different apps for different platforms you might accidentally download a rouge one on e.g. your phone. I know, paranoia.

My mother is able to run keepass and she still has a problem with double clicking. But sure. Looking for yourself is not easy. You have to do something for yourself and not just throw money on some company that is depending on this one product. Not sure if your paranoia is directed the right way here though.

Just because the thing that works for another person isn't the same as what you do doesn't mean that you need to be insulting towards them.

Re: The Dropbox hack is real

#380
post #352

Earlier quoted context omitted.

are there better alternatives though?

"Better" is subjective. I consider Google Drive much better, personally. Alternatives, though? Plenty: Google Drive, Box, OneDrive, iCloud Backup and iCloud Drive.. the list goes on with a simple Google search for "online storage"

Does google drive work the same way as Dropbox? Cross platform, acts as a folder in your home dir, selective sync, etc? Seriously ready to move on from Dropbox and my google fiber account comes with a free terabyte of google drive.
Post reply on HN