Live data from Hacker News

Dropbox wasn't hacked

blog.dropbox.com

1–10 of 38 posts

Re: Dropbox wasn't hacked

#5
Would be interesting to know what third party service it was and how they were able to make that link.

Also the pastebin claimed such a large amount (6,937,081) of impacted users but only showed a really small sample that started with the letter 'b'. Based on that sample they were already covering letters (bf, bg, bh). So I doubt this is anywhere near the claimed amount.

Asking for 'BTC' to leak more (who wants to pay for a public list?) is also extremely suspect.

Re: Dropbox wasn't hacked

#6
So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook.

I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The end result for a poor user^ is the same.

(^Not me, of course. I use 1Password.)

Re: Dropbox wasn't hacked

#7
Once again, the "journalists" can't be arsed to do any actual work but instead parrot what they heard. Absolutely shameful on their part.

Edit: For those down-voting me, please explain how condemning factually incorrect "news" is bad? Thanks :-)

Re: Dropbox wasn't hacked

#8
post #5

Would be interesting to know what third party service it was and how they were able to make that link. Also the pastebin claimed such a large amount (6,937,081) of impacted users but only showed a really small sample that started with the letter 'b'. Based on that sample they were already covering letters (bf, bg, bh). So I doubt this is anywhere near the claimed amount. Asking for 'BTC' to leak more (who wants to pa…

Why do you trust the hacker? By definition, hackers are not the trustworthy kind. He may have 7 million emails and passwords from elsewhere and make bold claims to collect bitcoins from lower ranks of hackers. I initially thought that some smartass created a bunch of accounts and posted them to collect some bitcoins from the naive. Particularly, because emails are so similar, i.e. I speculated that he did that to simulate having a 7 million users database.

Re: Dropbox wasn't hacked

#9

Then it is great. They are saying that the leaked credentials were obtained from third-party services.

Isn't it obvious? The list giving such a small sample of b- usernames, the passwords all super-vulnerable to simple dictionary attacks, the request for money and what not. Some idiot got hold of a bunch of hashes (could even be from a previous dump), bruteforced a few hundreds and cross-referenced with known dropbox accounts. Voila.

Re: Dropbox wasn't hacked

#10
post #6

So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…

Start them with the idea that a few things matter far more than the others. Email because all password resets use it, file storage as any identity theft will probably try and use it, and so on.

Use a long pass phrase and two-factor authentication for the few things that really matter.

These are: your domain name seller, your email provider, your file storage provider.

If you suspect your family members will do a poor job of keeping their 2FA backup codes, or that they lose their phone often... then centralizing the 2FA codes through Authy and choosing a long backup phrase there allows your family to use their 2FA codes on more than one device.

Note: I haven't even said "unique pass phrase per site". Yes it would help, but simply having a long pass phrase with 2FA is probably going to be more helpful for those who already find LastPass or 1Password too much to use that they needed the same password everywhere.

Post reply on HN