Live data from Hacker News

The Dropbox hack is real

troyhunt.com

431–440 of 557 posts

Re: The Dropbox hack is real

#431
post #402

Earlier quoted context omitted.

Enable it everywhere you can, and just write down & guard the backup keys. Also, I don't use it, but 1password can store and backup 2FA keys so you can theoretically recover from a lost phone that way, depending on how you store the 1password vault. Not a replacement for backup keys necessarily.

Generally agree here, but I'm thinking about real scenarios in which I may never be able to recover anything. One scenario is traveling abroad and having my phone stolen/lost.

For an iPhone, a full backup via iTunes will include the authenticator app data, won't it?

And you'll be printing out emergency passwords when you set up two-factor either way.

Re: The Dropbox hack is real

#432
post #396

Earlier quoted context omitted.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

Except the one to your password manager :)

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secure is making up answers. So I wouldn't even be able to reset a large amount of very important passwords!

I wish we had a better alternative to passwords. Something that's actually good, solid, can't lose or forget. I get the feeling we won't have that until we can start implanting chips in ourselves.

Re: The Dropbox hack is real

#433

Earlier quoted context omitted.

Except the one to your password manager :)

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

You just immediately change the master password and delete previous versions of the database file ?

Re: The Dropbox hack is real

#434
post #396
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

my approach to this consists of 4 security "levels": 1. I have one "throw away" password for services I don't give a fuck about 2. 2 passwords for ordinary services (breach cannot cause any serious harm and I can reset the password over my e-mail) 3. 2 other passwords (pretty easy to memorise but almost impossible to guess) that I use for my school mail, IDE, other mail accounts 4. a unique password coupled with two factor auth I only use for my primary gmail - as long as I have ownership of that, I can restore access to basically any other account I use.

ad. 1: I find it a pretty good idea to also have a secondary junk mail for signing up to these services - just in case they give my e-mail to someone for spamming or get breached.

Re: The Dropbox hack is real

#435

Earlier quoted context omitted.

I'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives. Which I suppose forces more awareness, but it doesn't instill a lot of confidence.

A false positive from your perspective doesn't mean your email address isn't actually being used to sign up for things. My primary personal email address is routinely used by a small handful of other real people (all strangers) for all sorts of things - college applications, car insurance, some address books think it belongs to a cousin who gets included in a lot of group threads about reunions and full of photos. I'…

I wouldn't worry too much about false positives.

It's not that I'm worried, it's that it's a distraction. When the margin of error is high enough, it becomes less signal and more noise, which leads to either panic (spending all your time managing access credentials) or complacency (ignoring the indicators).

Re: The Dropbox hack is real

#436
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Genuinely curious, but what do you think the severity is? Everything I know about it (this article included) places the Dropbox leak very low in my sense of severity.

The severity stems from the unfortunate fact that a password leak retroactively, and silently, destroys your security across all sites that use the same or a similar password. Even if you started using the longest, randomised, two-factor-authenticated password system last year, all those forgotten or seemingly unimportant accounts are suddenly exposed.

Even when the exposed sites have minimal information or impact, minor information in aggregate adds up to a lot of danger for escalation and social engineering.

Now consider that there are huge swaths of people with the same password that they've use for email, banking, medicare, and everything else.

A proper response from Dropbox would be to explicitly and loudly inform every leaked email address (not just their current users) that they need to immediately change every password across any and all sites that might use the same leaked credentials.

Furthermore, Dropbox should set up a secure site with a unique link per email address that allows a user to key-in and check their memory against the exposed hash. I know that I have changed my password for Dropbox at least twice since 2012, but in 2012 I might have used an insecure password. Allowing me to figure it out before a nefarious party would allow me to better judge the potential personal impact.

Re: The Dropbox hack is real

#437

Earlier quoted context omitted.

Except the one to your password manager :)

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

How about using the password manager to store security question answers too? It's mildly inconvenient because each site seems to require at least three, but then you wouldn't risk forgetting them and you could use random generated strings instead of having to make them up.

Re: The Dropbox hack is real

#438

Earlier quoted context omitted.

Except the one to your password manager :)

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

Make sure you turn on 2FA on your password manager. That should allay most of those fears. (Of course you would still change the password if it was leaked somehow.)

Re: The Dropbox hack is real

#439
post #396
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

How many people were using password managers in 2012? The impact is huge because leaks are silently retroactive. Unless you have captured and changed every single possible account you ever created with the leaked 2012 credentials (before or after), you might still have a lot of exposure.

Re: The Dropbox hack is real

#440
post #436

Earlier quoted context omitted.

Genuinely curious, but what do you think the severity is? Everything I know about it (this article included) places the Dropbox leak very low in my sense of severity.

The severity stems from the unfortunate fact that a password leak retroactively, and silently, destroys your security across all sites that use the same or a similar password. Even if you started using the longest, randomised, two-factor-authenticated password system last year, all those forgotten or seemingly unimportant accounts are suddenly exposed. Even when the exposed sites have minimal information or impact, m…

That's true if your actual password is leaked, but as described in this post, it is very unlikely that actual passwords could be retrieved. Still a non-zero risk, but I could see a case that the severity of that risk is low.

The significantly greater issue imo is the leaking of email addresses and ensuing spam.

Post reply on HN