Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

111–120 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#111
post #74

Earlier quoted context omitted.

The commercials aren't there because people worship lawyers! I think most Americans aren't actually all that fond of lawyers. They're there because there is a lot of money at stake. When each new client can bring you tens or hundreds of thousands of dollars, you can afford to take out TV ads. It's the same reason "mesothelioma" was the most expensive keyword on Google.

"Mesothelioma" is a lucrative keyword because anyone who has mesothelioma has most likely been grievously injured by some commercial entity. I'm sure there's lots of scams revolving around it, but it's hard to imagine a clearer-cut justification for suing a company than that company negligently giving you terminal cancer. These two parent comments --- unintentionally, I'm confident --- give the impression that "mesot…

Apologies; there was honestly no snark intended.

I happen to think the conduct of the asbestos industry is a strong argument for a corporate death penalty. And executives who knowingly exposed workers to dangerous materials should be in jail.

My point was that legal ads are prominent because there is a lot of money at stake, not because everybody loves lawyers.

Re: Dropbox sued for June 19 Authentication Bug

#112
post #111

Earlier quoted context omitted.

"Mesothelioma" is a lucrative keyword because anyone who has mesothelioma has most likely been grievously injured by some commercial entity. I'm sure there's lots of scams revolving around it, but it's hard to imagine a clearer-cut justification for suing a company than that company negligently giving you terminal cancer. These two parent comments --- unintentionally, I'm confident --- give the impression that "mesot…

Apologies; there was honestly no snark intended. I happen to think the conduct of the asbestos industry is a strong argument for a corporate death penalty. And executives who knowingly exposed workers to dangerous materials should be in jail. My point was that legal ads are prominent because there is a lot of money at stake, not because everybody loves lawyers.

Don't apologize; I'm not taking you to task. And sure, there's a lot of ads because there's a lot of money at stake. But that's also in some ways a good thing: it ensures that everyone harmed by (say) asbestos is aware that there are remedies available to them.

Re: Dropbox sued for June 19 Authentication Bug

#113
post #96
post #78

The number of comments supporting Dropbox in this thread astonish me. It seems like people think that such "engineering" mistakes are acceptable in the software/web industry. But let me ask you: What if a construction engineer made a little mistake (humans err right?) when building that bridge? Maybe nothing happens but believe me he will get sued and no one here would object. Sure, in the latter example people could…

You assume that the word "engineering" means the same thing in bridge building vs. software development. It doesn't. These activities are no more alike than software development is to, say, writing novels. If you really want to compare software to bridges, imagine that humans had written the same simple program millions of times over thousands of years. We'd be pretty good at it by now. (Even that analogy, though, do…

I do understand the difference between engineering in the "real world" and the "software world". There is no doubt that the latter is immensely more complex (see Fred Brooks).

Nonetheless, in cases where somebody may get hurt (physically, emotionally, financially, etc) we have to make a greater effort. All I was saying is that we have to either lower our expectations of how good affordable software can be or accept much higher costs for it.

Dropbox love to advertise that they are an extremely safe solution to data storage, thus leading people to believe that their data is safe. Unless every line of code in the authentication module is reviewed and checked and tested, that statement cannot be true. So there is a paradox there.

I guess I may have positioned Dropbox too extremely, but Dropbox breaking is much worse than say a music application, some game or other non-critical software. And with Dropbox I believe that development should be approached more like NASA would do it than EA would. People can get hurt!

"As for Dropbox, when I see programmers jump all over other programmers for making a mistake, even a big mistake (or series of mistakes compounded), I think schadenfreude. People who engage in such gleeful condemnation are making an implicit claim to their own perfection. I'd think twice about doing that."

Believe me that that was not my intention. I am without not as good a programmer as anybody at Dropbox!

Re: Dropbox sued for June 19 Authentication Bug

#114
post #64

Earlier quoted context omitted.

I think in this case the critical issue was that they needed to focus 100% of their efforts on preventing the damage to those I emailed Dropbox asking if my account was accessed and they replied quickly saying no it wasn't. I think that's a perfectly good response. A mistake was made, and 1 person made a terrible decision to take advantage of it. I hope we can all rally around Dropbox and cut them some slack so they…

They can't multi-task, and send one PR guy out to send a batch of e-mails informing their users what happened? Literally everyone in the company was chasing down this one miscreant?

Think of how many customers would call and email them if they did a blast email. 1 million maybe? It would be a self inflicted ddos.

Re: Dropbox sued for June 19 Authentication Bug

#115
post #29
post #6

Shouldn't someone have to show actual damages in order to sue? The California Unfair Competition Act seems to be about unlawful, unfair or fraudulent business practices - I don't immediately see how that is relevant. My guess is this is going to just force Dropbox into some kind of settlement because it will be cheaper than fighting it. And the lawyers promoting this get a nice cut, of course. Does corporate insuranc…

A friend of mine was a corporate insurer. Whenever a large firm like dropbox made a clanger and got sued, the insurers would work out how much negligence there was involved. The insurers discussed the issue with the company and said "you were negligent here, here and here" therefore "we're only going to cover you to X So negligent actions are not covered by insurance, and some portion will still have to be coughed up…

> So negligent actions are not covered by insurance

Depends on the kind of insurance. E&O (errors & omissions) most assuredly does cover negligence.[1]

[1] http://en.wikipedia.org/wiki/Professional_liability_insuranc...

Re: Dropbox sued for June 19 Authentication Bug

#116
post #102
post #2

I'm sorry, but good. When you respond to such a serious issue with anything less than an immediate email announcement to your entire userbase, and especially if your eventual announcement is an unapologetic, obscure blog post stating something like "that wasn't supposed to happen"/"that wasn't okay", you show that you care very little about the integrity and safety of your users' data.

Everyone who was affected by the bug was notified by email, and Dropbox's CEO even gave them his phone number so that they could contact him. As I see it, that's the proper response to issues like this: informing everyone who was affected, and not panicking all the unaffected users.

I don't believe they can pinpoint "the affected users" (supposedly below 100) with such accuracy. It's not responsible to assume nobody else logged in from another location just because only one person logged into 100+ accounts.

It would have been easy to announce without panicking the existing users. By not announcing it at all, and trying to stay below the radar, you incite everyone who's unaffected and reads the news--or, at least, they did me. It's a cheap business move, not "the integrity of your data is our first priority".

Re: Dropbox sued for June 19 Authentication Bug

#117
post #102

Earlier quoted context omitted.

Everyone who was affected by the bug was notified by email, and Dropbox's CEO even gave them his phone number so that they could contact him. As I see it, that's the proper response to issues like this: informing everyone who was affected, and not panicking all the unaffected users.

I don't believe they can pinpoint "the affected users" (supposedly below 100) with such accuracy. It's not responsible to assume nobody else logged in from another location just because only one person logged into 100+ accounts. It would have been easy to announce without panicking the existing users. By not announcing it at all, and trying to stay below the radar, you incite everyone who's unaffected and reads the n…

This happened on a sunday originally, right? Hence a small number of users logging in to the website. Pinpointing affected users could be as simple as finding the small number of accounts which were logged into from new IP addresses. Alternatively, perhaps the auth server was logging failed attempts, even though the bug resulted in failed attempts being treated as successful attempts. That would make it ridiculously trivial to find all of the accounts compromised - any account accessed with an incorrect password from a new IP address. The number of attackers doesn't matter.

Admittedly, I don't work for Dropbox, and am not aware of the details of how they identifying affected users. I'm just pointing out that it would be very easy to identify affected users with high accuracy and almost no chance of false negatives.

Re: Dropbox sued for June 19 Authentication Bug

#118
post #117

Earlier quoted context omitted.

I don't believe they can pinpoint "the affected users" (supposedly below 100) with such accuracy. It's not responsible to assume nobody else logged in from another location just because only one person logged into 100+ accounts. It would have been easy to announce without panicking the existing users. By not announcing it at all, and trying to stay below the radar, you incite everyone who's unaffected and reads the n…

This happened on a sunday originally, right? Hence a small number of users logging in to the website. Pinpointing affected users could be as simple as finding the small number of accounts which were logged into from new IP addresses. Alternatively, perhaps the auth server was logging failed attempts, even though the bug resulted in failed attempts being treated as successful attempts. That would make it ridiculously…

What is your definition of small?

You don't think there were MANY accounts that logged in from new locations in that time frame? Think wireless networks...

I simply refuse to believe that with such a gigantic service they could determine that only X and Y were compromised by "one person" so accurately and so quickly--especially considering they haven't even implemented a build/deploy-time test suite that, among many other things, asserts that something like the auth system works actually works.

Your suggestion is pure speculation like you say, and, really, any application that logs something like "invalid auth" usually(!) immediately aborts the session (since that's the logical thing to do); it doesn't continue it...

Re: Dropbox sued for June 19 Authentication Bug

#119
post #24

THIS is the first time I read about this bug. How incredible is that not to tell your users about that? But okay, if at all I expect it from dropbox. It's already the second time they don't care about their promise so much (at least towards me). I will quit them just now. But to not say just bad things: This kind of info here on HN is so very much important. That is exactly why I read here, to read what I can't read…

I got an email notification from Dropbox on June 23rd as follows: Hi Lance, On June 19, 2011, we had a software bug that caused authentication issues. You can read more about it in our blog post. Our records show that your account wasn't improperly logged into during this time. We are writing to you because one or more users you share a Dropbox folder with logged into their account during that period. We have no reas…

that's really great to hear! I didn't. Just confirmed it again with searching through my (nearly completely archived) inbox and also the spam folder.

Re: Dropbox sued for June 19 Authentication Bug

#120
post #99
post #91

Earlier quoted context omitted.

> "boiling water may be hot" Most people don't equate 'boiling water' with 'coffee.' Sure you need to boil water to brew it, but I've never been handed a bubbling cup of coffee.

> "hot coffee may be hot"

"hot liquid" and "liquid so hot that it will burn my skin" are not necessarily the same thing. Unless you think that people should feel afraid of a hot bath or a hottub (or even going to a hot spring).

In more precise terms, 'boiling' is a subset of 'hot.'

Post reply on HN