Live data from Hacker News

Dropbox: Security update & new features

blog.dropbox.com

61–69 of 69 posts

Re: Dropbox: Security update & new features

#61

"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)" Commonly used? What do they mean by that? Aren't they supposed not to know my password?

Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".

Re: Dropbox: Security update & new features

#62

"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)" Commonly used? What do they mean by that? Aren't they supposed not to know my password?

Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".

In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.

Re: Dropbox: Security update & new features

#63
post #46
post #39

Earlier quoted context omitted.

It's a UI issue. Where would an arbitrary directory show up on other devices? How could you tell quickly which files on your device are being shared?

SugarSync handles it just fine: http://d.pr/i/hluY

That looks complicated. Dropbox targets itself at people who just want it to work without having to think about it.

Re: Dropbox: Security update & new features

#65
post #62

Earlier quoted context omitted.

Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".

In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.

[deleted]

Re: Dropbox: Security update & new features

#66
post #62

Earlier quoted context omitted.

Good question, but perhaps it's shorthand for "your password generates a hash matching that generated by passwords found in various stolen password lists in circulation".

In which case they're not hashing the password properly, they're likely checking the plaintext password as it's sent over HTTPS.

They do not need to transmit plaintext passwords, they merely need to pick when and how to salt each password carefully.

What they can't do is randomly salt each stored password.

Re: Dropbox: Security update & new features

#67
post #52

"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses." I see two ways to read this. a) An employee happened to have a personal Dropbox account, and it was that personal account that was hacked, in exactly the same manner as the other accounts referenced. The employee probably used a different password on Dropbox's internal systems, and as a res…

Why would an employee have work-related data in a personal dropbox account?

Presumably because they dogfood their own product to their employees. I don't actually know if they do that, but I do know a lot of other companies that do. And it makes sense--if your employees don't use your product on a regular basis, then you're in trouble. But apparently keeping company data in a Dropbox account (personal or otherwise) also has potential security implications.

Re: Dropbox: Security update & new features

#68
post #28
post #25

Every time I see a Dropbox update I hope it is: * Added ability to sync arbitrary directories And I'm let down. Every single time.

https://www.dropbox.com/help/175/en and a symlink?

Symlinks are not synced automatically, only when restarting Dropbox, or pause/resume syncing.

Re: Dropbox: Security update & new features

#69
post #42
post #34

Earlier quoted context omitted.

A password as secure as my phone is not promising; T-Mobible was recently happy to reset my lost PIN by having me give the last four digits of any phone number I'd dialled in the last 23 hours. I don't really think it's as useful two-factor because the token is only as secure as another company's password system. (Aside from the problems that you have to have a Google Account and a smartphone.) I looked into this rec…

Someone would need to not only have possession of your phone, but your password as well. So for a hacker to work this: First, get your password. Second, find your location. Third, steal your phone, which for most people, is almost always on their person. Finally, crack whatever security mechanism you have on your phone. For someone to go through all that trouble ... you must be storing some very valuable info. If tha…

No. First, get password. Second, get phone number. Third, pretext to gain control of the account and forward/copy texts, view them via web interface, or replace the phone.
Post reply on HN