Live data from Hacker News

The Dropbox hack is real

troyhunt.com

41–50 of 557 posts

Re: The Dropbox hack is real

#41
post #6

Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well. I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices. For your critical services, keeping encrypted copies of your backup codes is a must.

this is probably a good time to set up Two-Factor Authentication (2FA) as well.

Note: Dropbox also supports U2F for 2FA, which provides much better protection agains phishing.

https://blogs.dropbox.com/dropbox/2015/08/u2f-security-keys/

Re: The Dropbox hack is real

#42
post #12

Self hosting is my way to go. Had enough of this. > My wife uses a password manager. If your significant other doesn't (and I'm assuming you do by virtue of being here and being interested in security), go and get them one now! 1Password now has a subscription service for $3 a month and you get the first 6 months for free. How about...not? There are tiny open source tools for every OS. You can do it locally, save it…

  a subscription service 
  for $3 a month and you 
  get the first 6 months 
  for free.
...and now, a word from our sponsors.

Re: The Dropbox hack is real

#48
post #6

Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well. I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices. For your critical services, keeping encrypted copies of your backup codes is a must.

If you use a YubiKey then you can move tokens between devices without needing to trust a third party, nor worry about them somehow being exfiltrated from your phone.

https://www.yubico.com/

Re: The Dropbox hack is real

#49

Earlier quoted context omitted.

I'd go with automatically stripping all utm_* query parameters from all URLs.

What's the harm?

Hello Michael,

We noticed some of the websites you read, and were wondering if you'd like to buy some stuff?

A lot of the stuff we're selling is directly related to what you were reading about just five minutes ago!

Are you interested in spending money on our stuff? Click here to find out more!

Would you like to fill out a survey, and be entered into a contest to win our stuff. It's fast, fun and easy! Try it now!

Here are some other articles we thought you might like. Is this ad irrelevant? Tell us how!

Re: The Dropbox hack is real

#50
post #6

Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well. I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices. For your critical services, keeping encrypted copies of your backup codes is a must.

2FA is a major inconvenience. The login process goes from 1-2 sec to 30sec. Sometimes a lot longer (some 2FA do not seem to think it is critical to send the email or txt msg right away, and even when they do, email servers do not really work real time, and then you have the time it takes to find your phone, unlock, decline twice the iOS update prompt, go to the right app, find the right msg, copy the code, check it is correct, etc etc).

Yeah if it is really a critical service and rarely used, we should. But if I have to wait 30sec in front of a login box every time I go on netfix or on amazon, you can bet their sales will go down the drain.

Post reply on HN