"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)" Commonly used? What do they mean by that? Aren't they supposed not to know my password?
Dropbox: Security update & new features
61–69 of 69 posts
Re: Dropbox: Security update & new features
#62"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)" Commonly used? What do they mean by that? Aren't they supposed not to know my password?
Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".
Re: Dropbox: Security update & new features
#63Earlier quoted context omitted.
It's a UI issue. Where would an arbitrary directory show up on other devices? How could you tell quickly which files on your device are being shared?
SugarSync handles it just fine: http://d.pr/i/hluY
Re: Dropbox: Security update & new features
#64Re: Dropbox: Security update & new features
#65Earlier quoted context omitted.
Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".
In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.
Re: Dropbox: Security update & new features
#66Earlier quoted context omitted.
Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".
In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.
What they can't do is randomly salt each stored password.
Re: Dropbox: Security update & new features
#67"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses." I see two ways to read this. a) An employee happened to have a personal Dropbox account, and it was that personal account that was hacked, in exactly the same manner as the other accounts referenced. The employee probably used a different password on Dropbox's internal systems, and as a res…
Why would an employee have work-related data in a personal dropbox account?
Re: Dropbox: Security update & new features
#68Re: Dropbox: Security update & new features
#69Earlier quoted context omitted.
A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.) I looked into this rec…
Someone would need to not only have possession of your phone, but your password as well. So for a hacker to work this: First, get your password. Second, find your location. Third, steal your phone, which for most people, is almost always on their person. Finally, crack whatever security mechanism you have on your phone. For someone to go through all that trouble ... you must be storing some very valuable info. If tha…