Live data from Hacker News

The Dropbox hack is real

troyhunt.com

551–557 of 557 posts

Re: The Dropbox hack is real

#551

Earlier quoted context omitted.

You don't give your passwords to LastPass either, you give them encrypted random noise they can't do anything with.

Which does not change the parent post's point, that with LastPass you're still giving it to a 3rd party who could leak that information for brute forcing.

If someone could brute force my LastPass password I'd be impressed.

Re: The Dropbox hack is real

#552
post #530

Earlier quoted context omitted.

That's a really unhelpful comment. Please specify what encryption you think Dropbox is doing on the passwords and what knowledge you have on the topic. I'm pretty sure you're going to say "they do TLS" and then the person you're talking to can go ahead and explain that the encryption LastPass/1Password does protects an entirely different threat model, but unless you have a conversation here no one is going to be able…

To be clear, I don't owe you or anyone anything with regards to this conversation. I am not obligated to conform to any particular conversational strategy, and if my intention was to simply claim something was incorrect without elaborating, I am entitled to do so. That said, I was wrong. I recalled what bcrypt does incorrectly.

[deleted]

Re: The Dropbox hack is real

#553
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

Ironically, https://haveibeenpwned.com certificate is signed by StarCom, which is the same as WoSign https://news.ycombinator.com/item?id=12411870 which means it basically trusts a known scammer to provide its security and one should not be giving this site any information you don't want to see in public.

Re: The Dropbox hack is real

#554
post #529

Earlier quoted context omitted.

Who wrote the standalone native application? To be more direct, I'm suggesting the standalone native application may not completely correctly implement the encryption algorithms. I have no evidence of this, but the concept still concerns me.

That's not what you said. You said that if someone owned up 1Password, the whole Internet would be in trouble. But that's like saying that if someone owned up one of the OpenSSH developers, the Internet would be instantly vulnerable. A false statement.

It's a true statement, not a false one. If someone was able to release an intentionally vulnerable version of OpenSSH/1Password, people who updated would be "instantly* (your word) vulnerable.

Re: The Dropbox hack is real

#556
OK. Thank you, HN. I just discovered that I've been pwned on Dropbox breach. If that happened in 2012, and I am using 1Password sync over Dropbox, does that mean that all my passwords stored in 1Password.pif in 2012 were compromised too? Probably yes.
Post reply on HN