Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

101–110 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#101
post #64
post #2

I'm sorry, but good. When you respond to such a serious issue with anything less than an immediate email announcement to your entire userbase, and especially if your eventual announcement is an unapologetic, obscure blog post stating something like "that wasn't supposed to happen"/"that wasn't okay", you show that you care very little about the integrity and safety of your users' data.

I think in this case the critical issue was that they needed to focus 100% of their efforts on preventing the damage to those I emailed Dropbox asking if my account was accessed and they replied quickly saying no it wasn't. I think that's a perfectly good response. A mistake was made, and 1 person made a terrible decision to take advantage of it. I hope we can all rally around Dropbox and cut them some slack so they…

They can't multi-task, and send one PR guy out to send a batch of e-mails informing their users what happened? Literally everyone in the company was chasing down this one miscreant?

Re: Dropbox sued for June 19 Authentication Bug

#102
post #2

I'm sorry, but good. When you respond to such a serious issue with anything less than an immediate email announcement to your entire userbase, and especially if your eventual announcement is an unapologetic, obscure blog post stating something like "that wasn't supposed to happen"/"that wasn't okay", you show that you care very little about the integrity and safety of your users' data.

Everyone who was affected by the bug was notified by email, and Dropbox's CEO even gave them his phone number so that they could contact him. As I see it, that's the proper response to issues like this: informing everyone who was affected, and not panicking all the unaffected users.

Re: Dropbox sued for June 19 Authentication Bug

#104
post #48
post #35

Earlier quoted context omitted.

Why change their passwords? Isn't that FUD?

Yes and no :-) What else could a user do once damage is done? (before they started investigating, but after the fix was pushed)

The important thing about this bug is that it allowed log-ins without passwords. No passwords were compromised. Therefor, asking users to change their passwords would have been FUD, as well as making it more difficult to identify which users were affected by the person exploiting the bug (if almost every user logs in during 4 hours, you're going to have a lot of trouble identifying the <100 accounts who were accessed by the attacker).

Re: Dropbox sued for June 19 Authentication Bug

#105
post #74

Earlier quoted context omitted.

At some point in the last 50 years the US has developed a significant subculture of lawyer-worship. It's not unusual to see commercials hourly on TV asking for people who might have suffered in one way or another to contact a law firm for a lawsuit. Lawyers find "little people" who have been wronged, sue in court, pocket millions, then go on to the next case. Effective lawyers make a killing at this business, and don…

The commercials aren't there because people worship lawyers! I think most Americans aren't actually all that fond of lawyers. They're there because there is a lot of money at stake. When each new client can bring you tens or hundreds of thousands of dollars, you can afford to take out TV ads. It's the same reason "mesothelioma" was the most expensive keyword on Google.

"Mesothelioma" is a lucrative keyword because anyone who has mesothelioma has most likely been grievously injured by some commercial entity. I'm sure there's lots of scams revolving around it, but it's hard to imagine a clearer-cut justification for suing a company than that company negligently giving you terminal cancer.

These two parent comments --- unintentionally, I'm confident --- give the impression that "mesothelioma" is a get-rich-quick scheme for plaintiffs. But if a plaintiff actually has mesothelioma, I don't think it's anything to snark about.

Re: Dropbox sued for June 19 Authentication Bug

#106
post #81
post #59

Earlier quoted context omitted.

It was hot enough to melt her genitals and cause serious disfigurement. If she had spilled it anywhere, she would have been seriously injured... The coffee was scalding hot. The temperature of the coffee was from a corporate order intended to save a few bucks on having to re-brew coffee. The McDonald's corporation was negligent. In this case, Dropbox was horribly negligent. Releasing all of the data in my Dropbox fol…

How do you heat liquid water to more than 100°C? Coffee is supposed to be just below 100°C when you brew it, or it is not good. Goes for home made or McD coffee. Whatever, maybe in some parts of the world, the laws of physics don't apply and liquid water does not lose energy though evaporation... Back on topic: Dropbox is telling everybody that they are "encrypting" stuff on their drives. How do they decrypt without…

If you increase the atmospheric pressure, you can raise the boiling point of water well beyond 100°C. Of course, that has little to do with brewing coffee.

So you bring the water to a boil, and then let it sit for a minute, then pour it over the grounds. Then as the coffee steeps, the liquid further cools down. It is just below 100 when you brew it.... not when you drink it. It is much cooler when you drink it, (65 to 80 C).

Re: Dropbox sued for June 19 Authentication Bug

#107
post #92

Earlier quoted context omitted.

"So difficult to open that ....between her legs" Where is the logic there? Something is difficult to open so the immediate response is to put it between your legs? And it's a hot beverage? Sorry...that's idiotic. Zero dollars. Stop wasting the court's time. It doesn't matter what McD did or did not do. You are primarily responsible for your own well being. Nobody tricked her into thinking the coffee was iced tea. Nob…

Same logic: Sure that doctor gave you the wrong medicine, but you're responsible for your own well-being. How hard is it to Google the name of the medicine and see that it has nothing to do with your condition? How hard is it to remember that the medicine that the doctor told you he was writing a prescription for and the one that he actually wrote on the paper aren't the same? Stop wasting the court's time. Zero doll…

In addition to lambada's response about the doctor-patient relationship, there is also an expectation of common knowledge. You are not expected to know anything about the medicine given to you since that is the doctor's responsibility, but you are expected to take it as instructed. You are expected to know that if you do anything unusual with it you may be putting yourself in danger.

If you do something idiotic like crush it up into powder, then snort it at five times the dosage, that's on you. If you then go into shock and suffer a stroke, guess what.... zero dollars, stop wasting the court's time, you are an idiot.

Re: Dropbox sued for June 19 Authentication Bug

#108
Here's the actual complaint:

http://www.courthousenews.com/2011/06/24/Dropbox%2016.pdf

Claims (bracketed comments mine):

1. Unfair competition (per California's law) caused damages [by for instance causing people to pick Dropbox instead of some other less expensive storage solution.]

2. Invasion of privacy, for which punitive damages are being sought.

3. Negligence [for enabling that invasion of privacy], for which actual damages are being sought [whatever those might be... maybe things like, billable time being spent moving files off Dropbox?].

4. Breach of express warranty, for which the purchase price of Dropbox is sought.

5. Breach of implied warranty, for which the purchase price of Dropbox is sought.

Not a lawyer, am a security practitioner, somewhat versed in the issues here, and:

This probably doesn't go anywhere. Don't these cases have to pick up a certain amount of steam before they matter? My sense of it is, as bad as the security lapse at Dropbox appears to have been, it was an issue primarily for the geekerati; "my mom" probably doesn't care, and might even assume stuff like this happens all the time. If it did go somewhere, presumably Dropbox would just provide vouchers for refunds for people who want to close their accounts.

There is, as I understand it, still no formal standard of due care required for software vendors. There was no slam-dunk tort available for the plaintiffs in the CardSystems case, where a card processor lost millions of credit cards. Similarly, lapses in Microsoft code enabled tens of millions of machines to be compromised during the "summer of worms", and the class action case brought against it was dropped as well.

Meanwhile, contract law is of little use, because virtually every professional piece of software is shipped with an airtight contract limiting the vendor's liability for defects. This complaint alleges some form of breach of contract, but it's entirely possible that such a claim dies a quick death when reconciled against the Dropbox user agreement, which surely says something to the effect of "shit happens, if you can't deal, use an external hard drive instead".

For a 2005 perspective on the issue by two law professors, which reaches the conclusion that we need to create a whole new tort ("negligent enablement of cybercrime") to address the issue, check out:

http://www.law.suffolk.edu/faculty/addinfo/rustad/rustad.koe...

Without going into another 7 grafs of noodling about whether software liability is a good idea or not, let me just say one thing I'm fairly confident of: the industry cannot afford a "due care" standard for software. Security flaws happen all the time, in everything anyone ships. You don't hear about most of them. Simple supply & demand has driven software security bill rates to very high levels, and that's largely without any legal mandate that would effectively require everything to get assessed.

Re: Dropbox sued for June 19 Authentication Bug

#109

Here's the actual complaint: http://www.courthousenews.com/2011/06/24/Dropbox%2016.pdf Claims (bracketed comments mine): 1. Unfair competition (per California's law) caused damages [ by for instance causing people to pick Dropbox instead of some other less expensive storage solution. ] 2. Invasion of privacy, for which punitive damages are being sought. 3. Negligence [ for enabling that invasion of privacy ], for whi…

[deleted]

Re: Dropbox sued for June 19 Authentication Bug

#110
post #41

Earlier quoted context omitted.

I'd love to hear a professional chime in here. Does adding this to your Terms of Service actually have an impact? If the answer is yes, why are the woman and her lawyer suing Dropbox anyway? And if no, why do most Terms of Service include similar wording?

My guess, and IANAL, is that it would hold in many courts, but not in Californian ones. California seems to have little tolerance for contracts that restrict basic freedoms (e.g., non-compete agreements.) In this case the basic freedom is to be compensated according to the tort perpetrated, and not limited to a specified arbitrary amount.

My understanding is that these contract terms have teeth in California, just like everywhere else. An enforceable contract doesn't mean you can't sue Dropbox if they cough up your data to an attacker; it just means you sue for a tort instead of breach-of-contract.
Post reply on HN