Live data from Hacker News

Dropbox: Security update & new features

blog.dropbox.com

21–30 of 69 posts

Re: Dropbox: Security update & new features

#21

Good, solid response to the intrusion. I'm particularly happy about the two-factor opportunity. I have no problem re-authenticating every 60-90 days with an SMS sent to my phone, and _definitely_ want any new system to be two-factored before having access to my Dropbox.

The only issue is that a lot of programs (mobile apps, especially) seem to interact directly with the Dropbox API, which leaves no possible interface for a secondary authentication. Google gets around this by having app-specific passwords that you can generate and de-authenticate at will; it'll be interesting to see how Dropbox handles it.

Re: Dropbox: Security update & new features

#23
post #17

Earlier quoted context omitted.

How do you store them?

I believe the implication is that they are stored hashed and salted.

There are many different ways to salt and hash, some more secure than others (bcrypt and DES crypt() being two examples with vastly different levels of security).

Re: Dropbox: Security update & new features

#24
post #17

Earlier quoted context omitted.

How do you store them?

I believe the implication is that they are stored hashed and salted.

With regards to security, I'd rather not read into subtext. Hopefully they can provide a definitive answer.

Re: Dropbox: Security update & new features

#26
post #25

Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.

This is why I'm disappointed that end user open source software is in such decline right now. These kinds of "long tail" user needs will never be met by the proprietary software world. Well, this particular one might, but for every need that gets implemented, 10 more obscure needs will spring up behind it.

Dropbox is making fistfuls of money, and, like all proprietary software companies, they need to stay focused to maintain momentum.

Although it might not feel like it to most people, I think we're in still in the dark ages of software. Not quite as dark as the Microsoft era, but dark nonetheless. We just don't have the tools, infrastructure, and culture necessary for open source to really be a viable space for the typical, scattered programmer to spend their time. I'm optimistic that will change, but I'm not sure how long it will take.

Re: Dropbox: Security update & new features

#29
post #9

I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use? Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge…

I got one
Post reply on HN