Live data from Hacker News

The Dropbox hack is real

troyhunt.com

471–480 of 557 posts

Re: The Dropbox hack is real

#471

Earlier quoted context omitted.

I browse with tin foil hat settings so I authenticate multiple times a day.

Then you wouldn't complain about an extra few seconds for 2FA.

I do.

I don't turn on 2FA because it's a pain in the ass. I want to like it but the extra annoyance isn't compelling enough for me.

Re: The Dropbox hack is real

#473
I really don’t know much about this scam thing and at the same time , no one wants to be on the losing side . But i just came across a good hacker who helped me hack my boyfriends text messages, whatsap, Facebook , Instagram messages remotely..You don’t have to touch his phone while you have access to his conversations through the software he bought and install remotely on my phone , i dont know how he did this but i think he's perfect at it.....contact him at jonnycyberghost@gmail.com..Tell him Allinson referred you, then you can thank me later. God Bless.

Re: The Dropbox hack is real

#474

I really don’t know much about this scam thing and at the same time , no one wants to be on the losing side . But i just came across a good hacker who helped me hack my boyfriends text messages, whatsap, Facebook , Instagram messages remotely..You don’t have to touch his phone while you have access to his conversations through the software he bought and install remotely on my phone , i dont know how he did this but i…

maybe he shouldn't be your boyfriend...

Re: The Dropbox hack is real

#475
post #374

Earlier quoted context omitted.

And who, exactly, encrypts them for you? Dropbox was also encrypting your passwords, FWIW.

IIRC encryption and decryption is done on the client side and the server only stores encrypted data. Dropbox was not encrypting passwords they were hashing them. If you stored already encrypted files on Dropbox nobody can decrypt those files provided your encryption key is good.

> Dropbox was not encrypting passwords they were hashing them.

Incorrect.

Re: The Dropbox hack is real

#476
How is it possible for Hashcat to crack a 20 character long random password in 6ms? That is mind boggling.

I thought he was just going to hash the password and see if it fit the leaked hash, but no, it looks like he actually did the reverse and cracked the hash to see if it fit the password, right?

Edit: oh it looks like he provided the password to hashcat in the form of a psudo 'dictionary' to use. So Hashcat was not really cracking it - just iterating through a 1 word dictionary - like he said.

Re: The Dropbox hack is real

#477

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

Oddly enough I have had the opposite experience. I have been running per-service emails for 10 years and wonder to myself if it is worth the bother as I can recall only one ever spreading.

Interesting. The plot thickens.

I don't have any fancy script to check these addresses - I have to go into my spam headers manually, and I've not done that for a long time. Perhaps there was a common issue a while ago that got patched. I'll have to check whether modern addresses are being spammed.

Re: The Dropbox hack is real

#479
post #408
post #358

Earlier quoted context omitted.

Also, LastPass uses a similar site, plus it's specific knowledge of your passwords (last time it was changed), to let you know if a password has been compromised. Not sure if 1Password does as well, but it seems like a fairly obvious feature to add.

1Password has a "Watchtower" feature that "identifies websites that are vulnerable to Heartbleed". Also under Security Audit are sections for Weak Passwords, Duplicate Passwords, and groupings of password ages (3+ years old, 1-3 years old, 6-12 months old for me). It does not appear to keep track of leaks/hacks. https://watchtower.agilebits.com/

The problem with this feature seems to be that it thinks if the site reissues its certificate it means all passwords there were compromised. Which leads it to mark all old passwords as vulnerable, even if no breaches were actually reported for the site.

The certificate/password link is a guess since on their website they say to change the password starting with date that matches the date of certificate reissuance.

This seems to be related to Hearbleed, also it lists a site that didn't reissue certificate after Heartbleed as vulnerable too, and so for passwords there, seems to be regardless of age.

I am a long-time 1password user and have a lot of old passwords, so for me like 90% of passwords are listed as compromised, which I'm pretty sure is not the case.

Re: The Dropbox hack is real

#480
post #372

Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.

Genuinely curious, but what do you think the severity is? Everything I know about it (this article included) places the Dropbox leak very low in my sense of severity.

did dropbox ever write up the details of how they were compromised and what else the attackers may have taken?

If not, there's nothing to suggest they didn't take other things.

Post reply on HN