Live data from Hacker News

The Dropbox hack is real

troyhunt.com

461–470 of 557 posts

Re: The Dropbox hack is real

#461

Earlier quoted context omitted.

I tried lastpass and it's been nothing but a pain in the arse. I still use it but I frickin' hate it.

If you're on a Mac, 1Password is a monumentally better experience.

I am on a Mac - I'll check out 1Password thanks

Re: The Dropbox hack is real

#462
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Anyway, tech-savvy folk are more likely to setup their own file-sync server. It is the non-tech-savvy people who are the primary users of dropbox.

Not many tech-savvy people have time to set up and maintain a personal file sync service that works across their laptops, phones, and tablets.

Re: The Dropbox hack is real

#463
post #436

Earlier quoted context omitted.

The severity stems from the unfortunate fact that a password leak retroactively, and silently, destroys your security across all sites that use the same or a similar password. Even if you started using the longest, randomised, two-factor-authenticated password system last year, all those forgotten or seemingly unimportant accounts are suddenly exposed. Even when the exposed sites have minimal information or impact, m…

That's true if your actual password is leaked, but as described in this post, it is very unlikely that actual passwords could be retrieved. Still a non-zero risk, but I could see a case that the severity of that risk is low. The significantly greater issue imo is the leaking of email addresses and ensuing spam.

It took them _years_ to realize there'd been a breach, even though lots of users were noting that one must have happened right at the time.

What are the odds that they actually understand how badly they were breached?

Re: The Dropbox hack is real

#464
post #76
post #40

Earlier quoted context omitted.

I cannot agree more, I do the same, and invite everyone else to do so. - Useful as a canary of which website has been breached - Useful as a canary of which website sold your details - and if your details are in the wild, you can stop the spam by deleting the address Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.

For credit cards, check out privacy.com I recently started using it, works great.

geez, privacy.com, I wonder how much that domain cost.

I'm using a card from getfinal.com, which appears to be the same idea. So far so good, though it's not 100% disposable, I still have a plastic card who's number is no easier to change than a chase card.

Re: The Dropbox hack is real

#465

Earlier quoted context omitted.

If you're on a Mac, 1Password is a monumentally better experience.

Works great until it doesn't (multiple user profiles in your browser, HTTP auth, non-browser based stuff like VPNs).

Wouldn't multiple user profiles have their own extensions? If so, then just install the extension on that profile? IIRC 1Password was working on something related to that, so perhaps that has changed recently.

HTTP auth not working is a bit annoying, but it's not a massive deal when you can CMD+ALT+\ and copy-paste it. Same deal with non-browser based stuff.

Re: The Dropbox hack is real

#466

Earlier quoted context omitted.

1Password can do 2FA, also syncs between all your devices. And no trusted 3rd party cloud service.

Keeping all the keys (password and 2FA tokens) in 1Password means it isn't true 2FA anymore: https://blog.agilebits.com/2011/09/23/two-factor-or-not-two-...

They're actually talking about 2FA for 1password itself. Not supporting TOTP via 1password for other services.

Re: The Dropbox hack is real

#468
post #396

Earlier quoted context omitted.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

Except the one to your password manager :)

I've been pretty happy not even knowing that. (YubiKey OpenPGP smart card + pass) It feels natural for my password manager to be just another thing I have to unlock with a physical key. The security concerns in practice are similar to that of my house keys, so there's pleasantly little mental overhead.

Re: The Dropbox hack is real

#469

It never ceases to amaze me how people have bought into "cloud" computing. Its hard enough to protect your own data, on your own secure machine. Once you entrust your data to a third party you should have absolutely no doubt that it is at risk. The larger the organization that that third party is, the more inherently insecure it is. In the cloud, it only takes one careless, stupid, or inept person to expose the data…

I guess it depends on the data we are talking about? I have a huge photo library, but I'm not a professional photographer. I'm not going to sell any of the photos I have on my computer. So when Apple told me I could offload all that data to the cloud, and worry about it less (from a backup perspective), I said "absolutely". Sensitive data is more problematic. But the vast majority of people aren't handling "sensitive…

>I guess it depends on the data we are talking about?

Absolutely it depends.

> But the vast majority of people aren't handling "sensitive" data.

I don't think that is necessarily true, but it would depend on how you define "sensitive". If you are storing data in the cloud that you are happy sharing with the public, then security isn't an issue. However, many people backup all of their data in the cloud (you need look no further then OneDrive that comes with every copy of Windows 10). This includes their financial information, tax returns, intimate personal information, and other things that would horrify them if they were exposed to the public. Most do so without understanding the risks because cloud computing has been sold so heavily by the government, corporations, and media outlets.

And we aren't just talking about individuals. Many, if not most, corporations use cloud computing to store their data. This includes financial data, customer information, credit cards, account numbers, and everything else you can imagine.

I'm not trying to argue cloud computing doesn't have its uses. I have no problem using the Steam cloud to save my game in Civilization 5, regardless of how insecure their servers are. But the risks are very real any time you entrust your data (or anything else) to a third party, and they should be recognized.

Re: The Dropbox hack is real

#470
post #433

Earlier quoted context omitted.

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

You just immediately change the master password and delete previous versions of the database file ?

Not really. If someone gets into someone else's password manager they can easily get a copy of all usernames and passwords and, if they're quick enough, they can start resetting them / closing them / committing fraud.

So yeah change the password and delete previous versions is a good first step but everything else has already leaked to who knows where.

Post reply on HN