Live data from Hacker News

The Dropbox hack is real

troyhunt.com

451–460 of 557 posts

Re: The Dropbox hack is real

#451

Earlier quoted context omitted.

"Better" is subjective. I consider Google Drive much better, personally. Alternatives, though? Plenty: Google Drive, Box, OneDrive, iCloud Backup and iCloud Drive.. the list goes on with a simple Google search for "online storage"

Does google drive work the same way as Dropbox? Cross platform, acts as a folder in your home dir, selective sync, etc? Seriously ready to move on from Dropbox and my google fiber account comes with a free terabyte of google drive.

The Windows and Mac clients create a folder in your home directory. There are ways to rename it, but essentially anything you put in the ~/Google Drive/ folder is synced just like Dropbox.

No native linux support is a bummer, but if you only need to use it there infrequently, the web client is quite capable for manual uploads and downloads.

Re: The Dropbox hack is real

#452
post #392
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

I'd argue with a password manager it's more pragmatic to have a different password everywhere. I know two passwords and use my manager for everything.

Re: The Dropbox hack is real

#453

Earlier quoted context omitted.

That's a solid point. I've generally avoided password managers because not knowing my (unique-per-service, strong) passwords makes me nervous in exactly the same way as not actually knowing the phone numbers of the most important N people in my life.

You'll get over that little hurdle once you realize that you can dump the anxiety of remembering a hundred password variants for different sites. And realistically speaking, you're probably not even using a hundred variants...or possibly even 10. If you're memorizing passwords, chances are your re-use frequency is nonzero. What's important is to keep a backup of your password database in a few places. I use KeePass b…

Thanks, I'll check into KeePass.

Re: The Dropbox hack is real

#454
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

I'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives. Which I suppose forces more awareness, but it doesn't instill a lot of confidence.

Its worth pointing out that other people can use your email address to create accounts. It's just a string of characters to type in.

They might not even know it's yours, like if your email is davidsmith@gmail and they fat-finger davidrsmith@gmail--boom, "you" now have an account.

Good services use double-opt-in to ensure that every account is actually tied to a correct and working email address. But not every service does this.

And even services that do use double opt-in would create a row in their database to note that a confirm email was sent out. If they never scrub those invite rows, "your" email address would still be in the DB when it's exfiltrated, even if the confirmation process was never completed.

Re: The Dropbox hack is real

#455
post #300

Earlier quoted context omitted.

How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?

Have email on you own domain is risky unless you active manage it. Otherwise forget to renew your domain once, all your credentials are gone...

You definitely need to remember to renew it, but a yearly repeating event in your calendar should be sufficient. That's hardly "active management".

Re: The Dropbox hack is real

#456

Earlier quoted context omitted.

Generally agree here, but I'm thinking about real scenarios in which I may never be able to recover anything. One scenario is traveling abroad and having my phone stolen/lost.

For an iPhone, a full backup via iTunes will include the authenticator app data, won't it? And you'll be printing out emergency passwords when you set up two-factor either way.

It doesn't look like this works with the google authenticator app when restoring to a different device.

For emergency passwords, does that mean you're keeping a printed out copy with you when you travel?

Re: The Dropbox hack is real

#457

Earlier quoted context omitted.

I tried lastpass and it's been nothing but a pain in the arse. I still use it but I frickin' hate it.

If you're on a Mac, 1Password is a monumentally better experience.

Works great until it doesn't (multiple user profiles in your browser, HTTP auth, non-browser based stuff like VPNs).

Re: The Dropbox hack is real

#458

Earlier quoted context omitted.

Except the one to your password manager :)

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

It's really not so bad. I was reluctant to use 1password until being forced to by work, and discovered how wonderful having a password manager is.

First off, your passphrase should only be used for the password manager itself. So if you accidentally paste it on twitter, you just change your passphrase.

Secondly, you're way more easily fooled than a password manager. I don't know my passwords (they're generated), so to phish me you have to convince 1password as well. That means e.g the google open redirect bug on HN yesterday can't trick me with a fake password page on a different domain.

Third, it makes your passwords way easier to use on mobile. Most of the managers support whatever biometric integration your phone has nowadays, so rather than trying to type your 24 character alphanumeric symbol crap (or worse, a crappy password because you didn't want to make a good one on mobile) by hand you can just paste it in.

Lastly, it encourages you to actually use separate passwords for all your accounts. And when passwords get leaked, your manager can tell you which sites need new passwords.

In conclusion, password managers improve your internet security and experience immeasurably. Go buy 1password!

- satisfied 1password customer

Re: The Dropbox hack is real

#459
post #392
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Anyway, tech-savvy folk are more likely to setup their own file-sync server. It is the non-tech-savvy people who are the primary users of dropbox.

Re: The Dropbox hack is real

#460

Earlier quoted context omitted.

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

Make sure you turn on 2FA on your password manager. That should allay most of those fears. (Of course you would still change the password if it was leaked somehow.)

1Password doesn't have 2FA because it needs to decrypt your data. It does have a long "secret account" key that you need along with your password.
Post reply on HN