Live data from Hacker News

Dropbox: Security update & new features

blog.dropbox.com

31–40 of 69 posts

Re: Dropbox: Security update & new features

#31
post #28
post #25

Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.

https://www.dropbox.com/help/175/en and a symlink?

Yeah, I understand ways to work around it.. it's more of why isn't it a feature? In SugarSync, Carbonite and Moxy I can quite literally do:

right click -> Sync Folder (or some variation thereof)

and it just works.

Re: Dropbox: Security update & new features

#32
post #5

Earlier quoted context omitted.

They wouldn't have to store your password in plaintext to determine that. They could just hash commonly used passwords and compare the hashes to yours.

If the number of salts used in the system is equal to the number of users, this could be expensive.

Assuming they use straight up salted sha256, my five year old core2 laptop does at least 10,000 per second, per core. They could check every user for the top 10k passwords for a few hundred bucks of EC2 time.

Re: Dropbox: Security update & new features

#33
post #9

I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use? Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge…

It would be useful info to know what triggered their email.

Re: Dropbox: Security update & new features

#34
post #22

I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone. http://code.google.com/p/google-authenticator/ Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.

A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.)

I looked into this recently when Dreamhost launched google-authenticator instead of two-factor auth. Disappointing.

Re: Dropbox: Security update & new features

#35
post #9

I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use? Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge…

I received it on two dropbox accounts. Different password on both. In fact I've never used the same password twice in my life.

Re: Dropbox: Security update & new features

#36
One of the more glaring security issues with Dropbox, is the way they are handling 3rd party integration.

Giving full access to some random new startup or app is NOT cool. Sure I don't have to, but people also like to try new stuff, and the integration is half the reason for using cloud services in the first place.

In fact this really applies to all 'platform' plays facebook, linkedin etc. Rather request minimum priviledges to inter-operate or authenticate, rather than sweeping authorizations.

Re: Dropbox: Security update & new features

#37
post #10
post #4

> In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time) This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext. UPDATE: Dropb…

Dropboxer here. We do not store passwords in plaintext, or unsalted. End sentence. :)

Mind telling us why we got the email? Since I never used the same password twice your official explanation is bullshit. It's looking more like you have no idea what someone did on your network so you just blasted out a mass email and forced people to change their password.

Re: Dropbox: Security update & new features

#38
post #34
post #22

I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone. http://code.google.com/p/google-authenticator/ Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.

A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.) I looked into this rec…

[deleted]

Re: Dropbox: Security update & new features

#39
post #25

Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.

It's a UI issue. Where would an arbitrary directory show up on other devices? How could you tell quickly which files on your device are being shared?

Re: Dropbox: Security update & new features

#40
post #31
post #28

Earlier quoted context omitted.

https://www.dropbox.com/help/175/en and a symlink?

Yeah, I understand ways to work around it.. it's more of why isn't it a feature? In SugarSync, Carbonite and Moxy I can quite literally do: right click -> Sync Folder (or some variation thereof) and it just works.

Because where are you going to put it on the other computers? So far dropbox has decided it's not worth the complication.

What you want is two clicks plus a confirmation popup and/or wizard. Moving a folder and making a shortcut is two drags and one extra click. It's not a big deal.

and it just works.

Post reply on HN