TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Dropbox investigating possible security breach

34 点作者 mjfern将近 13 年前

3 条评论

incongruity将近 13 年前
What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send <i>spam</i>. So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.)<p>Otherwise, it just doesn't make sense that <i>spam</i> is the first sign we'd see of problems.<p>So, my fellow HN readers, what's the explanation for this?
评论 #4264733 未加载
评论 #4264531 未加载
评论 #4265336 未加载
评论 #4264908 未加载
评论 #4264631 未加载
pedrobelo将近 13 年前
Kind of a long shot, but their "forgot password" flow allows for username enumeration attacks:<p><a href="https://www.dropbox.com/forgot" rel="nofollow">https://www.dropbox.com/forgot</a>
nohat将近 13 年前
I recommend encfs.
评论 #4264602 未加载