Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

21–30 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#21
post #17
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

I completely agree. Dropbox made a huge mistake. Dropbox is run by humans, and humans make mistakes, that's life. But when it came to communicate the issue they screwed up IMHO. I shouldn't need to subscribe to their blog RSS to know this kind of stuff.

They should have mailed everyone, encouraging users to change their passwords right away while they investigated the issue.

Re: Dropbox sued for June 19 Authentication Bug

#22
post #13

Earlier quoted context omitted.

Sure they were transparent? They didn't say what the bug was, how it was introduced, what they are doing to stop it happening again. They didn't email all their customers immediately.

No, I'm not sure they were all that transparent. I'm sure that in this situation and legal climate, the only way they could've potentially avoided a lawsuit was to try and keep it quiet (to the detriment of their user base.) Sadly, doing the right thing just makes you a target.

Potentially. But see how Lastpass dealt with a potential breach [1]. Have not heard of them being sued. I don't think "cover it up to avoid getting sued" is the right message.

[1] http://blog.lastpass.com/2011/05/lastpass-security-notificat...

Re: Dropbox sued for June 19 Authentication Bug

#23
post #19
post #17

Earlier quoted context omitted.

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

She was not mailed because there was no access to her account or did I read it wrong that everyone whose account was accessed was mailed? What should they have told her? "Someone could have accessed your account in the last few hours due to a bug, but that didn't happen. Nothing to worry about!"

They are not shy to advertise the security and privacy of the service, it would be an honest move to communicate the risks, too.

Re: Dropbox sued for June 19 Authentication Bug

#24
THIS is the first time I read about this bug. How incredible is that not to tell your users about that? But okay, if at all I expect it from dropbox. It's already the second time they don't care about their promise so much (at least towards me). I will quit them just now.

But to not say just bad things: This kind of info here on HN is so very much important. That is exactly why I read here, to read what I can't read anywhere else.

Re: Dropbox sued for June 19 Authentication Bug

#25
post #9

Earlier quoted context omitted.

...they're still a startup... What? Is this an excuse? They charge money for the service and they will pay for their mistakes.

Yes, they'll pay for this mistake through bad press and lost customers. A punitive lawsuit isn't going to improve anything in terms of making sure they don't do it again.

They won't lost customers if they don't tell them about the problems. The bad press is this, right here.

Re: Dropbox sued for June 19 Authentication Bug

#26
Say you run a small startup and accidentally push out a production bug like this. What should your response be?

Does it matter whether it's been reported by someone else or you discover it yourself? Does it matter whether you're a sole proprietor or a formal business entity? And in general should you form an entity to shield yourself from personal liability because of the remote chance something like this happens? Does it matter what type of content is exposed (passwords, file storage, bingo cards)? How do you decide?

Re: Dropbox sued for June 19 Authentication Bug

#27
I'm pretty torn.

On the one side, this was a realllly stupid mistake that should have been caught earlier, not by some external party who was kind enough to report it to them. I feel like the stakes should be raised a bit for companies who are keeping my data.

On the other side, fear of lawsuits leads toward less disclosure and meaningless PR announcements.

Re: Dropbox sued for June 19 Authentication Bug

#28
post #26

Say you run a small startup and accidentally push out a production bug like this. What should your response be? Does it matter whether it's been reported by someone else or you discover it yourself? Does it matter whether you're a sole proprietor or a formal business entity? And in general should you form an entity to shield yourself from personal liability because of the remote chance something like this happens? Do…

Immediately lock-down, then communicate to all affected before doing a root cause analysis and taking steps to ensure it doesn't happen again.

Dropbox faltered on the communication, and they made claims about their security which hasn't been backed up by practise.

They stated that they would communicate to those whose accounts were 'compromised', yet those 'affected' by this was literally every user they have. They should've communicated to all, as that is who has been affected.

They also state and sell based on security, and do give you the feeling that you are able to trust them, then when you do you find that they leave the door open. So their claims of security haven't been backed up by the practise of it.

Locking down was the right thing.

Communication was dire.

And there hasn't been a follow-up to demonstrate clearly that lessons were learned, and that it cannot happen again. Hell, we haven't even heard if there are now unit tests over this piece of code.

Just act ethically, clearly, and don't be afraid to have egg on your own face by coming clean. But when you do this, come fully clean and be transparent. Don't err, or dodge the details... just come clean, put your hands in the air and admit you screwed up, and then say why you've learned and why it really truly is not repeatable.

And if you've already had a security flaw or two preceding this... then stop what the hell you're doing, stop working on new features, and go back and check every line of code and look for every attack vector or flaw in your processes and put them right.

They sell on securing our data... I want them to be paranoid on my behalf.

Re: Dropbox sued for June 19 Authentication Bug

#29
post #6

Shouldn't someone have to show actual damages in order to sue? The California Unfair Competition Act seems to be about unlawful, unfair or fraudulent business practices - I don't immediately see how that is relevant. My guess is this is going to just force Dropbox into some kind of settlement because it will be cheaper than fighting it. And the lawyers promoting this get a nice cut, of course. Does corporate insuranc…

A friend of mine was a corporate insurer.

Whenever a large firm like dropbox made a clanger and got sued, the insurers would work out how much negligence there was involved.

The insurers discussed the issue with the company and said "you were negligent here, here and here" therefore "we're only going to cover you to XSo negligent actions are not covered by insurance, and some portion will still have to be coughed up.

Re: Dropbox sued for June 19 Authentication Bug

#30
post #24

THIS is the first time I read about this bug. How incredible is that not to tell your users about that? But okay, if at all I expect it from dropbox. It's already the second time they don't care about their promise so much (at least towards me). I will quit them just now. But to not say just bad things: This kind of info here on HN is so very much important. That is exactly why I read here, to read what I can't read…

I got an email notification from Dropbox on June 23rd as follows:

Hi Lance,

On June 19, 2011, we had a software bug that caused authentication issues. You can read more about it in our blog post. Our records show that your account wasn't improperly logged into during this time.

We are writing to you because one or more users you share a Dropbox folder with logged into their account during that period. We have no reason to believe that the login was improper, but in the unlikely event it was, there could have been access to the information in the following shared folder:

foldername

We are very sorry as this never should have happened. We are implementing additional safeguards to prevent this from happening again. If you have any questions please contact us at support@dropbox.com

- The Dropbox Team

Post reply on HN