> In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time) This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext. UPDATE: Dropb…
It's quite obvious from context that it's the latter. However, there is zero implication that they are storing passwords in plaintext. There are several ways to implement such a feature. First, the password could be checked on login when it is sent in plaintext but not stored. Second, they could run an offline dictionary attack against the hashed password database.
Dropbox: Security update & new features
41–50 of 69 posts
Re: Dropbox: Security update & new features
#42I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone. http://code.google.com/p/google-authenticator/ Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.
A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.) I looked into this rec…
First, get your password. Second, find your location. Third, steal your phone, which for most people, is almost always on their person. Finally, crack whatever security mechanism you have on your phone.
For someone to go through all that trouble ... you must be storing some very valuable info. If that's the case, may I suggest that Dropbox is probably not the right platform? In fact, any internet connected platform is probably not the right answer.
Re: Dropbox: Security update & new features
#43I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone. http://code.google.com/p/google-authenticator/ Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.
Re: Dropbox: Security update & new features
#44I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone. http://code.google.com/p/google-authenticator/ Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.
Re: Dropbox: Security update & new features
#45Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.
Re: Dropbox: Security update & new features
#46Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.
It's a UI issue. Where would an arbitrary directory show up on other devices? How could you tell quickly which files on your device are being shared?
Re: Dropbox: Security update & new features
#47Earlier quoted context omitted.
A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.) I looked into this rec…
Someone would need to not only have possession of your phone, but your password as well. So for a hacker to work this: First, get your password. Second, find your location. Third, steal your phone, which for most people, is almost always on their person. Finally, crack whatever security mechanism you have on your phone. For someone to go through all that trouble ... you must be storing some very valuable info. If tha…
Re: Dropbox: Security update & new features
#48The email they sent was unfortunate. It's from no-reply@dropboxmail.com. I presumed it was a phishing attempt.
You should pay a lot more attention to the where the links go than where the email is from.
Re: Dropbox: Security update & new features
#49I see two ways to read this.
a) An employee happened to have a personal Dropbox account, and it was that personal account that was hacked, in exactly the same manner as the other accounts referenced. The employee probably used a different password on Dropbox's internal systems, and as a result there was no internal breach.
b) An employee account for an internal Dropbox system was hacked, and this internal account allowed the attacker to access the project file. In this scenario, even though Dropbox made no specific comments to this effect, we can assume that the attacker may have obtained access to Dropbox's internal networks, so who knows what they could have made off with.
It makes a huge amount of difference to me which of those two readings actually took place. In scenario (a), this all boils down to users (including one particular employee) using the same password on too many sites. In scenario (b), Dropbox could be hiding a much larger breach.
Re: Dropbox: Security update & new features
#50The email they sent was unfortunate. It's from no-reply@dropboxmail.com. I presumed it was a phishing attempt.
Isn't it ridiculously easy to spoof the "from" address anyway? You should pay a lot more attention to the where the links go than where the email is from.