TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dropbox: Security update & new features

95 pointsby marklabedzalmost 13 years ago

15 comments

parfealmost 13 years ago
I hope Dropbox uses google's authenticator. It supports multiple accounts and won't clutter up my phone.<p><a href="http://code.google.com/p/google-authenticator/" rel="nofollow">http://code.google.com/p/google-authenticator/</a><p>Their "Such as" example makes it seem they only decided to use 2-factor but haven't chosen an implementation yet.
评论 #4321178 未加载
评论 #4321685 未加载
评论 #4321170 未加载
评论 #4320939 未加载
eoghanalmost 13 years ago
The email they sent was unfortunate. It's from no-reply@dropboxmail.com. I presumed it was a phishing attempt.
评论 #4320655 未加载
评论 #4321285 未加载
ghshephardalmost 13 years ago
Good, solid response to the intrusion. I'm particularly happy about the two-factor opportunity. I have no problem re-authenticating every 60-90 days with an SMS sent to my phone, and _definitely_ want any new system to be two-factored before having access to my Dropbox.
评论 #4320692 未加载
eslaughtalmost 13 years ago
"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses."<p>I see two ways to read this.<p>a) An employee happened to have a personal Dropbox account, and it was that personal account that was hacked, in exactly the same manner as the other accounts referenced. The employee probably used a different password on Dropbox's internal systems, and as a result there was no internal breach.<p>b) An employee account for an internal Dropbox system was hacked, and this internal account allowed the attacker to access the project file. In this scenario, even though Dropbox made no specific comments to this effect, we can assume that the attacker may have obtained access to Dropbox's internal networks, so who knows what they could have made off with.<p>It makes a huge amount of difference to me which of those two readings actually took place. In scenario (a), this all boils down to users (including one particular employee) using the same password on too many sites. In scenario (b), Dropbox could be hiding a much larger breach.
评论 #4321674 未加载
merittalmost 13 years ago
Every time I see a Dropbox update I hope it is:<p>* Added ability to sync arbitrary directories<p>And I'm let down. Every single time.
评论 #4320761 未加载
评论 #4321005 未加载
评论 #4320801 未加载
评论 #4321190 未加载
rdlalmost 13 years ago
I really hope they don't make 2fa mandatory. I hate most 2fa systems I've seen (I use Google Authenticator for one gmail account I have, and it makes life even more of a pain than it needs to, even just on Google properties). Having to reauth ~6 devices every month is obnoxious, and I already have a perfectly good password manager with long random per-site passphrases, plus secure storage of my key file and a strong memorized passphrase for it, unlocking sets of passwords only on certain machines. 2fa, particularly a naive version involving SMS or telcos, would make my security worse.
mattlongalmost 13 years ago
&#62; In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)<p>This is ambiguous...by "commonly used" do they mean 1) I'm logging in with my password frequently or 2) my password itself is a commonly used password? I'm assuming (and praying!) they mean the former since the latter would mean they're storing my password in plaintext.<p>UPDATE: Dropbox doesn't store in plaintext. I was incorrect to assume these were the only two possibilities. Confer child comments.
评论 #4320595 未加载
评论 #4320560 未加载
评论 #4320576 未加载
评论 #4320551 未加载
drusenkoalmost 13 years ago
I'm curious who all received this email? Was it sent to the entire user base? If not, what selection criteria did they use?<p>Everyone I've talked to seems to have received the "reset your password" email. I'm quite curious because I'm certain (up until now) that the password I used for Dropbox was both (a) not commonly used and (b) had been changed recently and (c) not leaked anywhere else (to the best of my knowledge).
评论 #4320619 未加载
评论 #4320621 未加载
评论 #4320938 未加载
评论 #4320833 未加载
评论 #4320951 未加载
wamattalmost 13 years ago
One of the more glaring security issues with Dropbox, is the way they are handling 3rd party integration.<p>Giving full access to some random new startup or app is NOT cool. Sure I don't <i>have</i> to, but people also like to try new stuff, and the integration is half the reason for using cloud services in the first place.<p>In fact this really applies to all 'platform' plays facebook, linkedin etc. Rather request minimum priviledges to inter-operate or authenticate, rather than sweeping authorizations.
bierkoalmost 13 years ago
I love the art at the top. Go Jon!
MrEnigmaalmost 13 years ago
When are email addresses going to be considered something that should be protected as well. Obviously you can't one-way hash these, but you can secure them, and definitely not leave them in project documents.
davidcollantesalmost 13 years ago
"In some cases, we may require you to change your password. (For example, if it’s commonly used or hasn’t been changed in a long time)"<p>Commonly used? What do they mean by that? Aren't they supposed not to know my password?
评论 #4322398 未加载
bambaxalmost 13 years ago
This remark may be OT but why use a grey font on a white background?!? This makes the blog very difficult to read. Please don't do that.
cottonseedalmost 13 years ago
What's the best password manager?
five_staralmost 13 years ago
I didn't receive a reset password email. Good thing that I don't store important files in it.