Live data from Hacker News

A recent security incident involving Dropbox Sign

sign.dropbox.com

1–10 of 76 posts

Re: A recent security incident involving Dropbox Sign

#2
I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more.

Hope they'll come around and add it at some point, and not just for businesses as hinted at when they acquired boxcryptor.

(Cryptomator and encrypted sparsebundles work great on Dropbox. Just annoying to manage)

Re: A recent security incident involving Dropbox Sign

#4

I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…

I use Proton Drive [1], they offer e2ee but I agree with you: the Dropbox app experience is probably still the best.

[1] https://proton.me/drive

Re: A recent security incident involving Dropbox Sign

#5
> Based on our investigation, a third party gained access to a Dropbox Sign automated system configuration tool. The actor compromised a service account that was part of Sign’s back-end, which is a type of non-human account used to execute applications and run automated services. As such, this account had privileges to take a variety of actions within Sign’s production environment. The threat actor then used this access to the production environment to access our customer database.

Not familiar with this area, how usually does it happen? Social engineering or some more "technical" ways?

Also, under normal (not hacked) circumstance, who usually would have access to these service accounts?

Re: A recent security incident involving Dropbox Sign

#6
"Upon further investigation, we discovered that a threat actor had accessed data including Dropbox Sign customer information such as emails, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication."

hashed passwords, API keys, OAuth tokens, MFA...

Oh no.

Re: A recent security incident involving Dropbox Sign

#7
post #4

I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…

I use Proton Drive [1], they offer e2ee but I agree with you: the Dropbox app experience is probably still the best. [1] https://proton.me/drive

OK, so there is no fundamental obstacle for providing true e2ee.

Re: A recent security incident involving Dropbox Sign

#10

I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…

Dropbox offers end-to-end encryption now (for business teams):

https://blog.dropbox.com/topics/company/new-solutions-to-sec...

Post reply on HN