Live data from Hacker News

The Dropbox hack is real

troyhunt.com

401–410 of 557 posts

Re: The Dropbox hack is real

#401

Earlier quoted context omitted.

You know what always gets me: PuTTY's website isn't served over HTTPS. That software everyone downloads to type all their firewall and router credentials into... is from a website not served over HTTPS. I see the download and signature links are, but if I could have this non-HTTPS website offer up different links to your web browser...

The downloads are all GPG-signed, so that shouldn't be an issue. You have the issue of the initial trust, but that applies to HTTPS too to a lesser extent.

How many people do you think download the application, then check the signature? Additionally, if you can spoof the download link on this HTTP page, you can also spoof the signature link, and provide a fake signature matching your malicious package.

Re: The Dropbox hack is real

#402

What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost. Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...

Enable it everywhere you can, and just write down & guard the backup keys.

Also, I don't use it, but 1password can store and backup 2FA keys so you can theoretically recover from a lost phone that way, depending on how you store the 1password vault. Not a replacement for backup keys necessarily.

Re: The Dropbox hack is real

#403

What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost. Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...

Me: Google Github Dropbox Dreamhost Amazon (store) Amazon (AWS) Microsoft RamNode Twitter Apple Facebook

Why wouldn't you enable it on Google and Apple? Those seem like the most important. You print out the backup codes and keep them safe.

Re: The Dropbox hack is real

#404
Funny, I just got an email a week ago saying they had noticed my password hadn't been changed in awhile (2012, which was interesting based on the article). Sounds like they knew about this and beefed up security.Or, they beefed up security on newer passwords but didn't cut over the old ones? The email did not mention any data theft, kinda wish it did. Too little, too late.

Re: The Dropbox hack is real

#405

Earlier quoted context omitted.

"Better" is subjective. I consider Google Drive much better, personally. Alternatives, though? Plenty: Google Drive, Box, OneDrive, iCloud Backup and iCloud Drive.. the list goes on with a simple Google search for "online storage"

Does google drive work the same way as Dropbox? Cross platform, acts as a folder in your home dir, selective sync, etc? Seriously ready to move on from Dropbox and my google fiber account comes with a free terabyte of google drive.

I've never set it up but I believe that you can get it to work the same way.

Install the desktop application: https://support.google.com/drive/answer/2374987 Change sync settings: https://support.google.com/drive/answer/2375083

Re: The Dropbox hack is real

#406
post #402

What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost. Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...

Enable it everywhere you can, and just write down & guard the backup keys. Also, I don't use it, but 1password can store and backup 2FA keys so you can theoretically recover from a lost phone that way, depending on how you store the 1password vault. Not a replacement for backup keys necessarily.

Generally agree here, but I'm thinking about real scenarios in which I may never be able to recover anything.

One scenario is traveling abroad and having my phone stolen/lost.

Re: The Dropbox hack is real

#407
post #403

What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost. Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...

Me: Google Github Dropbox Dreamhost Amazon (store) Amazon (AWS) Microsoft RamNode Twitter Apple Facebook Why wouldn't you enable it on Google and Apple? Those seem like the most important. You print out the backup codes and keep them safe.

I definitely want to enable it on the most important accounts, but I worry about the scenario where I lose my phone/wallet when traveling abroad.

Re: The Dropbox hack is real

#408
post #358
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

Also, LastPass uses a similar site, plus it's specific knowledge of your passwords (last time it was changed), to let you know if a password has been compromised. Not sure if 1Password does as well, but it seems like a fairly obvious feature to add.

1Password has a "Watchtower" feature that "identifies websites that are vulnerable to Heartbleed". Also under Security Audit are sections for Weak Passwords, Duplicate Passwords, and groupings of password ages (3+ years old, 1-3 years old, 6-12 months old for me). It does not appear to keep track of leaks/hacks.

https://watchtower.agilebits.com/

Re: The Dropbox hack is real

#409

Earlier quoted context omitted.

"Better" is subjective. I consider Google Drive much better, personally. Alternatives, though? Plenty: Google Drive, Box, OneDrive, iCloud Backup and iCloud Drive.. the list goes on with a simple Google search for "online storage"

Does google drive work the same way as Dropbox? Cross platform, acts as a folder in your home dir, selective sync, etc? Seriously ready to move on from Dropbox and my google fiber account comes with a free terabyte of google drive.

IIRC it has limited linux support, but works that way in windows/macOS. Another article today mentioned rclone, if you need linux support.

Re: The Dropbox hack is real

#410
post #249

So besides resetting the password, should one also unlink devices and apps?

You should probably audit the list and disconnect any you don't recognize, but you should probably be doing that periodically anyway with everything...
Post reply on HN