Live data from Hacker News

Why was my email leaked?

forums.dropbox.com

151–160 of 265 posts

Re: Why was my email leaked?

#151
You know, it's funny because i got a very clever Pay Pal phishing e-mail this morning, linking to a PHP script hosted on renault-astrakhan.ru

What's worse is that i sent invitations to dropbox time ago to people that i have to now contact and say "Please be aware of this phishing e-mail disguised as a Pay Pal e-mail."

+1 for an alternative service, to be honest. Dropbox is very well done, but this is a good reason to stop using their service if they can't secure their clients' information.

It would greatly benefit them if they found the root of the problem, and reported if it were indeed an issue with them or one of the clients for dropbox.

Re: Why was my email leaked?

#152
post #134
post #64

Earlier quoted context omitted.

Google Drive, SpiderOak, SugarSync, Skydrive, Amazon Cloud Drive, Box.net.

Which of these use client side encryption?

Wuala.com does aswell (not mentioned in parent). They are a Swiss company and don't have a lot of traction in the US.

Re: Why was my email leaked?

#153

Earlier quoted context omitted.

Yup, especially Chris' behaviour is a no go. I don't know how the mods are affiliated with dropbox but if they are employees I wouldn't let them have any customer contact at all.

Yeah, Chris seems a bit of prick: "Just the fact that you listed your emails says it all."

Looks like Chris is battening down the hatches. His linked site[1] was up about an hour ago, but it redirects to a placeholder now. Also, he's deleted all but his first comment, wish I'd taken a screenshot of his other comments.

Tangentially related: It drives me nuts to deal with people whose default answers are "no," "you must be doing it wrong" and so on. Particularly the moderators who insisted someone must have guessed a ten digit random email address -- because Dropbox and its vendors couldn't POSSIBLY have ever done anything wrong, and it's MUCH more likely that a spammer magically brute-forced a 10 billion combination address! Grrr. I'm not sure what the right word is to describe that sort of personality, but such people should never have contact with customers. Or with me.

[1] http://cjwworld.cu.cc/

Re: Why was my email leaked?

#154
Sean, who also posted in the forums on page two and apologised for the moderator's behavior, contacted me by e-mail to send him the spam e-mails that I received. It looks like they're taking it seriously now :) Needless to say, I provided all details that I have (connection log, full mail source).

For those who are curious, this is what I received:

Hi Luc,

My name is Sean, I work on the User Security team at Dropbox. We'd like to look into the issue you repoted on the forums. If possible can you forward the emails in question directly to me (xxxx@dropbox.com).

Thanks. Sean

Re: Why was my email leaked?

#155
The part that made me laugh about all of this is the fact the moderators are saying that spammers most likely guessed all of the unique email addresses people are complaining have been spammed that are only used for Dropbox. That doesn't sound plausible at all, especially considering it's multiple people complaining of being spammed here.

Dropbox's customer service has really gone downhill, what happened?

Re: Why was my email leaked?

#156

Earlier quoted context omitted.

Entirely possible. The moderator's handling of this issue was pitifully bad but the assumption that Dropbox MUST be at fault here is ridiculous.

Dropbox may or may not be "at fault", but they've certainly got a problem. Even if the root cause turns out to be a common rootkit/trojan/botnet has started extracting and reporting email addresses from Dropbox clients on exploited customer machines, that's still a problem for Dropbox (and their customers) even though few people would call Dropbox "at fault" in that circumstance. And, the mods there held on to the "i…

"they've certainly got a problem"

If you mean they should sort out their forum moderation policies then I agree.

If you mean that this must be a technical problem on their part then I disagree. A 3rd party submitting their address book to a Friend Finder or similar tool would not be the responsibility of DropBox.

Re: Why was my email leaked?

#157
post #101
post #95

Earlier quoted context omitted.

Use a whole domain name, e.g. signup for dropbox with dropbox@tokenadult.com. You could do this with Google Apps Gmail by setting a catch-all forwarding address for the domain.

It's all fun and games until you get attacked by a spambot that tries blindly sending thousands of messages to @yourdomain.com

Yup. I used to do this with a personal domain. After a while I realized that the spam folder was filling up faster than I could manually empty it!

Re: Why was my email leaked?

#158
post #5
post #3

I also give out a separate email address to every service I sign up for. So far geico, mint, and dyndns have lost or sold my email address. I haven't gotten any spam on my dropbox account, but I've only had an account since 2012-10-02. I don't run any spam filtering, at all, and my email box is the catchall for my domain. These aren't just lucky guesses.

I'm surprised to see mint in that list. Have you contacted them in any way about this?

FWIW, I received spam to my unique address that I only use for turbotax. Mint is owned by Intuit, so it's possible that they lost all their emails.

Re: Why was my email leaked?

#160

Earlier quoted context omitted.

Yeah, Chris seems a bit of prick: "Just the fact that you listed your emails says it all."

Looks like Chris is battening down the hatches. His linked site[1] was up about an hour ago, but it redirects to a placeholder now. Also, he's deleted all but his first comment, wish I'd taken a screenshot of his other comments. Tangentially related: It drives me nuts to deal with people whose default answers are "no," "you must be doing it wrong" and so on. Particularly the moderators who insisted someone must have…

It's not just a 10-character address. It's a 10-character address on a non-standard domain (or so the conversation led me to believe). All without getting another email on that domain's catch-all address. If it was a spammer, who randomly-generated addresses on this domain, I would imagine that they would have been shotgunned across the whole domain. Not just hit that one single address.
Post reply on HN