Earlier quoted context omitted.
If the number of salts used in the system is equal to the number of users, this could be expensive.
They will just check your password against a list of 'bad' passwords when you log in. No need to brute force the stored hash.
Dropbox: Security update & new features
11–20 of 69 posts
Re: Dropbox: Security update & new features
#12> In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time) This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext. UPDATE: Dropb…
First, the password could be checked on login when it is sent in plaintext but not stored. Second, they could run an offline dictionary attack against the hashed password database.
Re: Dropbox: Security update & new features
#13> In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time) This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext. UPDATE: Dropb…
Dropboxer here. We do not store passwords in plaintext, or unsalted. End sentence. :)
Re: Dropbox: Security update & new features
#14Earlier quoted context omitted.
If the number of salts used in the system is equal to the number of users, this could be expensive.
They will just check your password against a list of 'bad' passwords when you log in. No need to brute force the stored hash.
Re: Dropbox: Security update & new features
#15I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use? Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge…
Re: Dropbox: Security update & new features
#16I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use? Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge…
Re: Dropbox: Security update & new features
#17Re: Dropbox: Security update & new features
#18Re: Dropbox: Security update & new features
#19The email they sent was unfortunate. It's from no-reply@dropboxmail.com. I presumed it was a phishing attempt.