Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…
Dropbox wasn't hacked
21–30 of 38 posts
Re: Dropbox wasn't hacked
#22Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…
Like the other set of credentials, there's a relative scarcity of gmail addresses. I'd expect dropbox accounts to be a pretty good sampling of email addresses. Either these have had gmail addresses removed (unlikely as a few are in there), or the list comes from somewhere where hotmail and yahoo are more popular that gmail - wonder where that would be?
Unless the numbers have shifted drastically in the last year: One or both of them are ahead of Gmail in most of the world, outside of tech circles.
Re: Dropbox wasn't hacked
#23Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…
Re: Dropbox wasn't hacked
#24[deleted]
The relevant question is:
"Have the company technical ability to deliver plain text user data if hit with legal warrant?"
If the answer is anything but "No" it is not for the privacy conscious.
Whether a person should use such service and will the burden of all around encryption will reduce usability too much is another question.
Re: Dropbox wasn't hacked
#25This shows more, why we need solutions like http://storj.io/
> DECENTRALIZED CLOUD STORAGE > Storj is based on the Bitcoin blockchain technology and peer-to-peer protocols to provide the most secure, private and efficient cloud storage.
"Regular" people, people that just want their stuff backed up and synced, do not necessarily know what "decentralized cloud storage", "Bitcoin blockchain" or "peer-to-peer protocols" are.
Also, Dropbox clearly stated that it was not hacked. I cannot imagine Dropbox storing passwords in clear text. To me, this "hack" looks like a scam trying to make easy Bitcoin money.
What we need is to make people aware of the security implications of using the same password everywhere.
Re: Dropbox wasn't hacked
#26So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…
The sad truth seems to be that Dropbox, iCloud and other cloud services are not safe enough for confidential or sensitive information.
Regardless whether or not Dropbox was hacked this time, they have been compromised in the past and most likely will be in the future.
In addition to security issues, there have been data loss and integrity issues, so cloud services are not safe for back ups either.
Re: Dropbox wasn't hacked
#27[deleted]
I love how companies wiggle out with encryption "in transit and in rest". The relevant question is: "Have the company technical ability to deliver plain text user data if hit with legal warrant?" If the answer is anything but "No" it is not for the privacy conscious. Whether a person should use such service and will the burden of all around encryption will reduce usability too much is another question.
The number of companies on the list is huge and include essentially all of the 'blockbuster' names in the tech industry, from IBM to Amazon to Fujitsu to Seagate to Apple to Symantec to F-Secure, etc. (I have a longer list here, although it has not been combed for law enforcement escrow and it is also not representative of the names on the patent search list [3]). Care must be taken to discern which patents would have applicability to serve orders such as those by National Security Letters or to comply with the decryption requirements of CALEA.
There's some scary stuff in there, like "Automatic recovery of TPM keys" (Lenovo) [4] and "Cloud key escrow system" (Microsoft) [5].
HP obtained a patent (in 2008) for PC backdoors [6].
[1] https://www.google.com/search?tbm=pts&hl=en&q=uspclass%3A%22...
[2] https://www.google.com/patents/EP2637350A2
[3] https://news.ycombinator.com/item?id=8452070
[4] https://www.google.com/patents/US8290164
Re: Dropbox wasn't hacked
#28Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…
I just can't fathom there being huge publicly available password lists with credentials that are still valid.
Re: Dropbox wasn't hacked
#29Once again, the "journalists" can't be arsed to do any actual work but instead parrot what they heard. Absolutely shameful on their part. Edit: For those down-voting me, please explain how condemning factually incorrect "news" is bad? Thanks :-)
Which journalists? Ars Technica posted an article with the qualifying word "apparently" in the title, weasel words like "appears" in the body, contacted Dropbox for comment, had obviously tested the password reset functionality since they mention it was sluggish. Their suggestion was "reset your password anyway, and turn on 2fa". None of this seems unreasonable.
* Cnet: "Hackers hold 7 million Dropbox passwords ransom". http://www.cnet.com/news/hackers-hold-7-million-dropbox-pass...
* Engadget: "Dropbox account passwords posted online and millions more might follow" http://www.engadget.com/2014/10/14/dropbox-log-in-posted-onl...
* Business Insider: "Nearly 7 Million Dropbox Passwords Have Been Hacked" http://www.businessinsider.com/dropbox-hacked-2014-10
Re: Dropbox wasn't hacked
#30So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…
Perhaps even lowers your security in ways.
Sharing the fact (with the internet) that you use a password manager, lowered your security already, technically speaking.
I find the idea to use one password (and a private key etc) to protect all my other accounts and passwords a bit strange, specially synced over 3rd party servers/services.
Not to mention when people use it on devices often discussed to have ways to eavesdrop on a user, android, iPhone. The security of the password vault is now equal to that of that particular device. (which could be as low as no security)