Live data from Hacker News

Dropbox wasn't hacked

blog.dropbox.com

21–30 of 38 posts

Re: Dropbox wasn't hacked

#21
post #15

Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…

The "latenightbootycalls" one is clearly fake. And the one with 900 accounts has a new bitcoin address, and the emails look auto generated.

Re: Dropbox wasn't hacked

#22
post #15

Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…

Like the other set of credentials, there's a relative scarcity of gmail addresses. I'd expect dropbox accounts to be a pretty good sampling of email addresses. Either these have had gmail addresses removed (unlikely as a few are in there), or the list comes from somewhere where hotmail and yahoo are more popular that gmail - wonder where that would be?

> or the list comes from somewhere where hotmail and yahoo are more popular that gmail -

Unless the numbers have shifted drastically in the last year: One or both of them are ahead of Gmail in most of the world, outside of tech circles.

Re: Dropbox wasn't hacked

#23
post #15

Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…

I got dropbox with an email starting with "al" and my email wasn't included in that list. So they are either not from Dropbox or only a subsection of the account they got hold of.

Re: Dropbox wasn't hacked

#24
post #19

[deleted]

I love how companies wiggle out with encryption "in transit and in rest".

The relevant question is:

"Have the company technical ability to deliver plain text user data if hit with legal warrant?"

If the answer is anything but "No" it is not for the privacy conscious.

Whether a person should use such service and will the burden of all around encryption will reduce usability too much is another question.

Re: Dropbox wasn't hacked

#25
post #18

This shows more, why we need solutions like http://storj.io/

This looks nice. But unfortunately, the headline is WAY to technical for "regular" people:

> DECENTRALIZED CLOUD STORAGE > Storj is based on the Bitcoin blockchain technology and peer-to-peer protocols to provide the most secure, private and efficient cloud storage.

"Regular" people, people that just want their stuff backed up and synced, do not necessarily know what "decentralized cloud storage", "Bitcoin blockchain" or "peer-to-peer protocols" are.

Also, Dropbox clearly stated that it was not hacked. I cannot imagine Dropbox storing passwords in clear text. To me, this "hack" looks like a scam trying to make easy Bitcoin money.

What we need is to make people aware of the security implications of using the same password everywhere.

Re: Dropbox wasn't hacked

#26
post #6

So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…

> So ... what's the lesson here for our non-nerdy friends & family?

The sad truth seems to be that Dropbox, iCloud and other cloud services are not safe enough for confidential or sensitive information.

Regardless whether or not Dropbox was hacked this time, they have been compromised in the past and most likely will be in the future.

In addition to security issues, there have been data loss and integrity issues, so cloud services are not safe for back ups either.

Re: Dropbox wasn't hacked

#27
post #19

[deleted]

I love how companies wiggle out with encryption "in transit and in rest". The relevant question is: "Have the company technical ability to deliver plain text user data if hit with legal warrant?" If the answer is anything but "No" it is not for the privacy conscious. Whether a person should use such service and will the burden of all around encryption will reduce usability too much is another question.

Here is a list of US patents for key escrow systems: 380/286 [1]. It is important to know that key escrow does not itself mean that the keys are escrowed to law enforcement, but in many cases it is obvious or it is spelled out explicitly: "In order to receive the information, law enforcement may submit a request to each of the entities identifying the communication session and their basis for authorization." [2] It is also important to know that law enforcement escrow systems may also apply under different categories, so this list has both type 1 and type 2 error.

The number of companies on the list is huge and include essentially all of the 'blockbuster' names in the tech industry, from IBM to Amazon to Fujitsu to Seagate to Apple to Symantec to F-Secure, etc. (I have a longer list here, although it has not been combed for law enforcement escrow and it is also not representative of the names on the patent search list [3]). Care must be taken to discern which patents would have applicability to serve orders such as those by National Security Letters or to comply with the decryption requirements of CALEA.

There's some scary stuff in there, like "Automatic recovery of TPM keys" (Lenovo) [4] and "Cloud key escrow system" (Microsoft) [5].

HP obtained a patent (in 2008) for PC backdoors [6].

[1] https://www.google.com/search?tbm=pts&hl=en&q=uspclass%3A%22...

[2] https://www.google.com/patents/EP2637350A2

[3] https://news.ycombinator.com/item?id=8452070

[4] https://www.google.com/patents/US8290164

[5] https://www.google.com/patents/US20120321086

[6] https://www.google.com/patents/EP1059578A2

Re: Dropbox wasn't hacked

#28
post #15

Interestingly enough, on the same pastebin site that the leak first appeared, we now have someone programmatically changing the account passwords in the leak: http://pastebin.com/LsKrspK5 There's another set of account credentials here: http://pastebin.com/jHEjBLrQ which are all starting with the letter A. It covers AA to AZ, and spans 900 accounts. Does this mean there's only ~24,000 accounts compromised? Strangely…

IMO service providers should, at the very least, have procedures in place to lock the accounts in the list then email everyone with an unlock link.

I just can't fathom there being huge publicly available password lists with credentials that are still valid.

Re: Dropbox wasn't hacked

#29
post #14
post #7

Once again, the "journalists" can't be arsed to do any actual work but instead parrot what they heard. Absolutely shameful on their part. Edit: For those down-voting me, please explain how condemning factually incorrect "news" is bad? Thanks :-)

Which journalists? Ars Technica posted an article with the qualifying word "apparently" in the title, weasel words like "appears" in the body, contacted Dropbox for comment, had obviously tested the password reset functionality since they mention it was sluggish. Their suggestion was "reset your password anyway, and turn on 2fa". None of this seems unreasonable.

> Which journalists?

* Cnet: "Hackers hold 7 million Dropbox passwords ransom". http://www.cnet.com/news/hackers-hold-7-million-dropbox-pass...

* Engadget: "Dropbox account passwords posted online and millions more might follow" http://www.engadget.com/2014/10/14/dropbox-log-in-posted-onl...

* Business Insider: "Nearly 7 Million Dropbox Passwords Have Been Hacked" http://www.businessinsider.com/dropbox-hacked-2014-10

Re: Dropbox wasn't hacked

#30
post #6

So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…

No offence, but in my humble opinion using 1password, or any password manager, does not make you a better or more secure user.

Perhaps even lowers your security in ways.

Sharing the fact (with the internet) that you use a password manager, lowered your security already, technically speaking.

I find the idea to use one password (and a private key etc) to protect all my other accounts and passwords a bit strange, specially synced over 3rd party servers/services.

Not to mention when people use it on devices often discussed to have ways to eavesdrop on a user, android, iPhone. The security of the password vault is now equal to that of that particular device. (which could be as low as no security)

Post reply on HN