Live data from Hacker News

A recent security incident involving Dropbox Sign

sign.dropbox.com

41–50 of 76 posts

Re: A recent security incident involving Dropbox Sign

#41
post #40

Earlier quoted context omitted.

I did the same, but i still use Cryptomator for stuff like sensitive documents and the sorts, much like i would have used an encrypted image before using cryptomator. iCloud works great, and even if you trust Apple (which i do to some extent), your data is still only safe as long as nobody gains access to your devices. Once somebody has access to your devices, files are no longer encrypted. The choice of Cryptomator…

How do you sync the cryptomator vault safely, properly handling conflicts?

I use the regular iCloud sync method.

The Crytomator vault is personal, so i'm the only user, which means that conflicts are rather rare.

I've yet to experience synchronization conflicts with iCloud in my day to day usage, and i've been using iCloud since it was called MobileMe. I even ran with a local cache for a few years, and that never caused a problem either.

Re: A recent security incident involving Dropbox Sign

#43
This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them.

We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.

Re: A recent security incident involving Dropbox Sign

#44
post #43

This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them. We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.

It should also be a reminder for Dropbox that acquiring a product then allowing it to languish risking security vulnerabilities -- will, appropriately, have negative brand perception implications that affect your main product too.

Re: A recent security incident involving Dropbox Sign

#45
post #18

Earlier quoted context omitted.

Hashed passwords? Surely they mean hashed and salted passwords. Right? Right???

They were using SHA1, then they migrated. 68 million accounts dumped: https://www.theguardian.com/technology/2016/aug/31/dropbox-h... https://www.troyhunt.com/the-dropbox-hack-is-real/ now they first hash the password using SHA512 (with a per-account salt) then they hash the password with bcrypt (with the default strength) then they encrypt the password with a key that the application server runs with, but that is no…

That… seems excessive. Is it just security theater or actually useful somehow?

Re: A recent security incident involving Dropbox Sign

#46
> For those who received or signed a document through Dropbox Sign, but never created an account, email addresses and names were also exposed.

So they also leaked data of people who are not their customers, and who never agreed to have their information collected.

I doubt that flies under the GDPR.

Re: A recent security incident involving Dropbox Sign

#47

"Upon further investigation, we discovered that a threat actor had accessed data including Dropbox Sign customer information such as emails, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication." hashed passwords, API keys, OAuth tokens, MFA... Oh no.

I use Dropbox Sign API, so a little fearful our private data was accessed. API keys were leaked as part of this hack. It's unclear from press release if hackers used the API keys to access data/documents of customers.

April 24th they became aware of issue, reporting it over a week later. I'd also be curious on how long this problem went on before being detected on April 24?

I suppose more will come out in the coming days..

Re: A recent security incident involving Dropbox Sign

#48
post #43

This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them. We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.

Acquired in 2022? IMO that's enough time to bring their service up to the same security standard as the rest of their services, assuming it's a priority.

Google and others normally have a 6 month grace period for bug bounty reports in acquisitions.

Re: A recent security incident involving Dropbox Sign

#50

I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…

I used to love Dropbox, then they limited devices and storage so much it was barely worth it, and spamming me with nag popups all day to upgrade because my storage was near full sealed the deal and I just started using OneDrive (not much better but it's integeated and convenient, probably going to just go foss with a home server eventually). Another sad downfall of a once good company.
Post reply on HN