Live data from Hacker News

The Dropbox hack is real

troyhunt.com

421–430 of 557 posts

Re: The Dropbox hack is real

#421
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

I'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives. Which I suppose forces more awareness, but it doesn't instill a lot of confidence.

From https://haveibeenpwned.com/FAQs :

Why do I see my username as breached on a service I never signed up to? When you search for a username that is not an email address, you may see that name appear against breaches of sites you never signed up to. Usually this is simply due to someone else electing to use the same username as you usually do. Even when your username appears very unique, the simple fact that there are several billion internet users worldwide means there's a strong probability that most usernames have been used by other individuals at one time or another.

Re: The Dropbox hack is real

#422
post #396
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

Thad great that you use a password manager but the majority of Internet users probably don't. What's your point? Either way you look at it if Dropbox was breeches then it's the responsible thing for them to do, to disclose.

Re: The Dropbox hack is real

#423
post #420
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

Fun fact: Have I Been Pwned neither salts nor hashes the creds which it stores on its website, potentially making itself an interesting target for hackers[0] [0]: http://risky.biz/RB388

HIBP doesn't store passwords, it only stores usernames and email addresses.

Re: The Dropbox hack is real

#424

Earlier quoted context omitted.

No, lots of people use password managers. You should try one.

I tried lastpass and it's been nothing but a pain in the arse. I still use it but I frickin' hate it.

If you're on a Mac, 1Password is a monumentally better experience.

Re: The Dropbox hack is real

#425
post #297
post #50

Earlier quoted context omitted.

2FA is a major inconvenience. The login process goes from 1-2 sec to 30sec. Sometimes a lot longer (some 2FA do not seem to think it is critical to send the email or txt msg right away, and even when they do, email servers do not really work real time, and then you have the time it takes to find your phone, unlock, decline twice the iOS update prompt, go to the right app, find the right msg, copy the code, check it i…

You auth machines you use regularly so that login is 30 seconds once. That's not such a high penalty so that devices you've physically used are authorized and all others aren't.

I browse with tin foil hat settings so I authenticate multiple times a day.

Re: The Dropbox hack is real

#426
post #398
post #241

Earlier quoted context omitted.

Right, but you're assuming optimal response from every Dropbox user, when I'd assume the vast majority of Dropbox users aren't aware of best password practices (or are aware and only change passwords when forced anyway because 'I have nothing to hide'). The severity of the breach means Dropbox should be forcing password changes. I didn't even receive an e-mail notifying of the breach. Nothing in the spam filters, it'…

Honestly, I've found security bugs in Dropbox using it (oddly) as designed in the past and would never use it again; basically, as a non admin I could become an admin in a business account; reported the issue, had a call with them and it appeared they fixed it, but still it was a wtf moment for me given if you're an admin you are able to permanently delete all the data and according to Dropbox the data would not be r…

I agree that, ultimately, the only person who really cares about your security is you. That is certainly where the buck stops, and if a service has security you don't agree with stop doing business with them.

However, a forced password and session reset on accounts whose credentials have become public knowledge isn't "hand holding." It's SysAdmin101. It should be the first thing you do. Unless I'm misreading you, the stated stance is "Anyone using dropbox got what they deserved," but not everyone has the knowledge to perform a security audit. The user is not without blame or having made mistakes, but Dropbox isn't taking ownership of their own mistakes or being transparent to every affected user about what those mistakes were and/or led to. If they want to be a service that does hand-holding, they can give the correct advice. If they don't, they NEED to be transparent about what occurred and what information was released or the onus is entirely on them. Right now, they're doing neither. I think that is criminally negligent, though I'm certain no legal action will be taken.

I feel that lowering those expectations of a service only helps justify these shitty, lazy practices to others.

The only thing that would've been exposed in the breach relating to me are the e-mail address and password for that service itself (alongside all the crappy memes I stored there), but I'm not ready to watch the world burn from the sidelines. The security of others is just as much your personal security, and the more of it others sacrifice the more you'll be expected to do the same and suffer repercussions for not doing so.

Re: The Dropbox hack is real

#427
post #396

Earlier quoted context omitted.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

Except the one to your password manager :)

Well, yes :)

Re: The Dropbox hack is real

#428
post #309

Earlier quoted context omitted.

1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.

It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this g…

That isn't how 1Password works. Passwords are encrypted clientside, in a standalone native application.

Re: The Dropbox hack is real

#429

Earlier quoted context omitted.

Using a strong key and cipher, you should feel safe giving anyone your information.

Keys can still be cracked, and ciphers can be broken. Not giving anyone your information, if you don't have to, is always the preferred option.

If the construction 1Password standalone uses to encrypt passwords is broken, we have bigger concerns than our passwords.

Re: The Dropbox hack is real

#430
post #89

Earlier quoted context omitted.

My LogMeIn unique address gets tons of spam - their response was that I must have given it away elsewhere. I no longer use LogMeIn.

Same here. I have (at the last count) over 200 website/service specific email aliases. I very rarely use an alias for more than one service. However when I do start getting spam on that alias, and I contact the website concerned they always state it's my fault. My response? If I can, I stop using that website or service. My dropbox alias email started getting loads of spam about 2 years ago, I immediately junked that…

Is it necessarily service's fault? Could the e-mail address have been intercepted when some confirmation e-mail was being delivered? Not likely, I agree, but still...
Post reply on HN