Live data from Hacker News

The Dropbox hack is real

troyhunt.com

391–400 of 557 posts

Re: The Dropbox hack is real

#391
post #338

Earlier quoted context omitted.

Haha for me it's the opposite. My password never works in Dropbox. I think it's because they don't support spaces in passwords, but they don't tell you when you change your password. They just accept the change and then you can't login.

There are many sites with little exceptions like that. I think that their password filter allows the characters, but their backend input sanitization doesn't, so it cleans it up and inserts a transformed version of the pass without providing notification. I've found this happens particularly often with passwords with symbols like !, #, or ;.

In general, this is one of the most frustrating things with trying to secure yourself online. I have gone through like "I WANT TO USE PASSPHRASES" then gone to places like PAYPAL and had them have an upper limit on password length. It's absurd that they all have slightly different requirements. I am switching to a password manager now.

Re: The Dropbox hack is real

#392
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Non tech savvy? Everyone does this. It's practical.

Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Re: The Dropbox hack is real

#393
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

true... but unfortunately in this case (Dropbox) you would have gotten a notification about 4.5 years later ;-)

Re: The Dropbox hack is real

#394
post #392
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

No, lots of people use password managers. You should try one.

Re: The Dropbox hack is real

#395
post #378
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

This was a strange way to find out that I have a Tumblr account.

Exactly my reaction.

Re: The Dropbox hack is real

#396
post #392
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites.

I don't even know any of my passwords.

Re: The Dropbox hack is real

#397
What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost.

Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...

Re: The Dropbox hack is real

#398
post #241
post #226

Earlier quoted context omitted.

>> "Users need to know their passwords are exposed, and must be reset not as a preventative measure, but because they are almost certain to be compromised." This should be assumed regardless of what is known if it's know a breach happened; meaning basic password hygiene should be followed, and I'm the case of Dropbox, if a user had any plaintext files with passwords to other accounts (yes, people still do this) - the…

Right, but you're assuming optimal response from every Dropbox user, when I'd assume the vast majority of Dropbox users aren't aware of best password practices (or are aware and only change passwords when forced anyway because 'I have nothing to hide'). The severity of the breach means Dropbox should be forcing password changes. I didn't even receive an e-mail notifying of the breach. Nothing in the spam filters, it'…

Honestly, I've found security bugs in Dropbox using it (oddly) as designed in the past and would never use it again; basically, as a non admin I could become an admin in a business account; reported the issue, had a call with them and it appeared they fixed it, but still it was a wtf moment for me given if you're an admin you are able to permanently delete all the data and according to Dropbox the data would not be recoverable regardless of the time frame.

As for the average user, to be honest at the point I increaslying feel like people are responsible for their own security and if you that concerned a service won't notify you of a breach or make a mistake that to you is unforgivable — don't use them. Reason I take this position now is because increased you feel like all the hand holding related to security is dangerous long-term.

Re: The Dropbox hack is real

#399
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Genuinely curious, but what do you think the severity is?

Everything I know about it (this article included) places the Dropbox leak very low in my sense of severity.

Re: The Dropbox hack is real

#400
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Genuinely curious, but what do you think the severity is? Everything I know about it (this article included) places the Dropbox leak very low in my sense of severity.

The first time I saw the email I believed that Dropbox was taking it as a preventative measure because they thought they were breached -- not that they were breached. This information as hidden behind the link to more information in the email itself.
Post reply on HN