TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dropbox users' email addresses targeted by spam?

71 pointsby Xymak1yalmost 13 years ago
edit: I updated the title to more specifically address the issue.

10 comments

floatingatollalmost 13 years ago
If the user's computer is compromised, a simple SQLite query run against the Dropbox configuration database would reveal all Dropbox email addresses in use by that user.<p>If the user's email is compromised, the Dropbox confirmation email would be easy to locate and harvest, either from their mailbox, or their mail hosting provider's delivery logs.<p>(Usually, however, malware simply scans for <i>all</i> incoming email addresses, and then reports them to a central authority for later spamming.)<p>EDIT: As pointed out elsewhere in this thread, the email address &#60;dropbox@yourdomain&#62; is trivially guessable by dictionary spam attacks.<p>There are many routes to this information leaking. It is not at all apparent whether it's Dropbox yet.<p>Given that Dropbox security is actively responding in the linked forum, it seems as though this HN post - submitted by one of the users posting in that thread as "affected" - is solely to create "buzz", rather than to share news with Hacker News.
评论 #4256687 未加载
评论 #4256378 未加载
dr_faustusalmost 13 years ago
Just searched in my Spam folder for the email address I only use for Dropbox et voilà: I got the spam messages mentioned. After the password-gate last year (<a href="http://blog.dropbox.com/index.php/yesterdays-authentication-bug/" rel="nofollow">http://blog.dropbox.com/index.php/yesterdays-authentication-...</a>) this is the second major security breach by a company I (and many people I know) have a lot of data entrusted to... This really sucks!<p>Whats even worse: The first reports came in (from users!) over one day ago and the forum thread seems to indicate that they still have no clue what happend!<p>[Update] One possibility might be, that dropbox is not the culprit after all but that the spammers started to realize that people use those service-specific addresses more and more and they just send out emails to [some-service-name]@[some-domain]. At least my address is dropbox@[mydomain].<p>So lets hope for that...
评论 #4256240 未加载
bradleylandalmost 13 years ago
While it appears plausible (likely, even) that Dropbox is the source of the disclosure, it's not verifiable as fact until someone identifies the method used to obtain the email addresses. This makes the title inappropriate.<p>Malware frequently targets address books and browser forms as a means of harvesting email addresses. Not saying that it can't be Dropbox, and I'm not saying that it's even unlikely, but years of troubleshooting have taught me not to name the root cause until I can verify it myself. This is even more true when you're putting someone else's reputation on the line.
评论 #4256522 未加载
joealbaalmost 13 years ago
A quick browse through my domain's catchall spam folder shows an e-mail addressed to techdirt@mypersonaldomain. I don't have a techdirt account -- nor have ever used this e-mail address anywhere. Yes, spam bots make guesses, folks.<p>The Internet would be a better place if people would stop, take a deep breath and think before they type.<p>Good idea: Let the dropbox folks know that you received spam to a custom address tied to their service and let them look into it, whether it be a directed spam campaign or a possible leak.<p>Bad idea: "OMG!!1! Dropbox is pwn3d! Admit it! Apologize for your wrongs!"
ecaronalmost 13 years ago
I don't see any confirmation in the forum that the "e-mail addresses of users" was leaked by Dropbox. It also appears to be mainly Euro-centric accounts. So while there is certainly a problem and it is very likely originating with Dropbox, the title is quite misleading and overly condemning given the known facts.
评论 #4256249 未加载
adanto6840almost 13 years ago
I use a specific "MYNAME-dropbox@MYDOMAIN.com" email address for Dropbox and I can confirm that my Dropbox-specific address has NOT received any SPAM messages.<p>The only messages that have ever been sent to that specific address are from Dropbox themselves...
评论 #4256969 未加载
gingerlimealmost 13 years ago
I've had the same issue with box.net a few weeks/months ago. I only signed up for their service and never really used it, and I used a one-off email address that is randomly generated and used only for the service. I do this regularly now. With each service I subscribe to, I first of generate a unique random email address, so if I start to get spam, I can either block this address only, or at least know where it was leaked...
dhyasamaalmost 13 years ago
My favorite part of the support forum is the suggestion to submit a ticket and it will "usually" be addressed in 1-3 days.
评论 #4256279 未加载
TomGullenalmost 13 years ago
Here's one way to get people's email addresses. For what it's worth, I emailed DropBox about this a long time ago (months ago) and didn't even get a reply to my email!<p>If you use your DropBox referal code, on this page:<p><a href="https://www.dropbox.com/account/bonus" rel="nofollow">https://www.dropbox.com/account/bonus</a><p>You will see a list of peoples email addresses that clicked the link and signed up. Unbeknownst to them you have their email addresses.<p>We have hundreds of these email addresses in our account as we have been promoting DropBox on our website for a long time. The referral status page also shows information about how far through the install they are, when they signed up etc.<p>This is bad because it makes phishing quite easy.<p>Perhaps not the source of the spam, but nonetheless still a bad execution in my opinion.
评论 #4257635 未加载
justauseralmost 13 years ago
But this doesn't mean anything though right since all encryption happens clientside right? Oh...wrong service. This is Dropbox so they have the key on their end.
评论 #4256304 未加载