Live data from Hacker News

Dropbox investigating possible security breach

edition.cnn.com

1–10 of 17 posts

Re: Dropbox investigating possible security breach

#2
What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam. So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.)

Otherwise, it just doesn't make sense that spam is the first sign we'd see of problems.

So, my fellow HN readers, what's the explanation for this?

Re: Dropbox investigating possible security breach

#4

What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam . So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.) Otherwise, it just…

Or the opposite is true. Maybe the breach was major and the "hackers" aren't in it for fame and glory. But cash. Number one rule of a "professional hacker"; don't leave foot prints. That means you sell off the data you copied. Piece by piece. Email addresses are the easiest to sell.

Time will tell though.

What's troubling to me is Dropbox calling in outside auditors (experts). Means they really have no ideas what is happening. If it is a hack, it's damn good one.

Re: Dropbox investigating possible security breach

#6

What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam . So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.) Otherwise, it just…

Lets recap what i've witnessed in all of this:

My Dropbox account is registered to a@gmail.com but i've received the spam to b@gmx.de which i've recently used to invite 2 people to Dropbox.

So, this suggests to me that the breach has happened either on

a) some external party they use for sending out the invites/emails

b) their (separate) emailing servers (or servers particular for that function) have been breached

Either way, there is a leak somewhere...

Re: Dropbox investigating possible security breach

#7
post #4

What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam . So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.) Otherwise, it just…

Or the opposite is true. Maybe the breach was major and the "hackers" aren't in it for fame and glory. But cash. Number one rule of a "professional hacker"; don't leave foot prints. That means you sell off the data you copied. Piece by piece. Email addresses are the easiest to sell. Time will tell though. What's troubling to me is Dropbox calling in outside auditors (experts). Means they really have no ideas what is…

> What's troubling to me is Dropbox calling in outside auditors (experts). Means they really have no ideas what is happening. If it is a hack, it's damn good one.

Not necessarily. It's just that you might actually be blind to the problem if its your code so it's better to have a separate set of eyes looking at things.

Also, there might be problems in the code where you never imagined them - let alone the server setup which most probably are complex beasts in their own right...

Re: Dropbox investigating possible security breach

#8
post #3

I recommend encfs.

Speaking of encfs, has anyone else had problems using encfs under OSX Lion? OSX would occasionally freeze on me, and when I eventually uninstalled encfs, the problem went away. It might be a coincidence tho.

I've been using encfs for a long time now and I never had any issues, neither on Lion nor on Mountain Lion (developer previews)

I can really recommend http://boxcryptor.com/

Re: Dropbox investigating possible security breach

#9
post #4

What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam . So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.) Otherwise, it just…

Or the opposite is true. Maybe the breach was major and the "hackers" aren't in it for fame and glory. But cash. Number one rule of a "professional hacker"; don't leave foot prints. That means you sell off the data you copied. Piece by piece. Email addresses are the easiest to sell. Time will tell though. What's troubling to me is Dropbox calling in outside auditors (experts). Means they really have no ideas what is…

If Dropbox say there is no issue and there was no (serious) hack then it is far more credible having outside auditors substantiating the claim. I'd be more troubled if they didn't call in outside experts since Dropbox's existing people and processes are what allowed whatever attack it was to happen in the first place.
Post reply on HN