Dropbox Breach: Fewer Than 100 Accounts Affected, One Person Actively Exploited(techcrunch.com)
techcrunch.com
Dropbox Breach: Fewer Than 100 Accounts Affected, One Person Actively Exploited
http://techcrunch.com/2011/06/24/dropbox-breach-fewer-than-100-accounts-affected-but-one-person-actively-exploited-it/
10 comments
The part of one individual doing all the accessing can't be right. The dude who reported it (on hn or reddit not sure) said he had his friend double check it.
They may just be counting those who were actively exploited, and excluded the cases where the guy and his friend were checking a few accounts. Since they reported it, it would be fairly easy to isolate their activities from other accesses.
Still, they should be more precise in their language.
I still maintain they should send an "all clear" email to people that weren't accessed, just for peace of mind.
I haven't even received my notice that there was a security breach to begin with.
I wonder if Dropbox lists on its balance sheet a teflon shield, or jobsian field of distortion generator....
I wonder if Dropbox lists on its balance sheet a teflon shield, or jobsian field of distortion generator....
Apple's been disclosing theirs for years -- required to by GAAP -- but the thing prevents people from noticing it.
These only appear when notice of them is helpful, say in court cases and such. Sort of like using an eclipse to see a star through a gravitational lens. And even then you can't remember the case, or its role in the reasoning, just that Apple was totally not at fault.
These only appear when notice of them is helpful, say in court cases and such. Sort of like using an eclipse to see a star through a gravitational lens. And even then you can't remember the case, or its role in the reasoning, just that Apple was totally not at fault.
This was a great letter, and Drew handled this perfectly. I am impressed.
[deleted]
[deleted]
Yes it was a nicely worded email but without a file-level log of what was accessed and when it's hard to know if you need to worry about this or not.
They really should have referenced in the email, but Dropbox does already have a file-level timestamped activity log that you can access for your account anytime:
https://www.dropbox.com/events
EDIT: Oops, my bad: this log only tracks add, edit, move, delete. It doesn't show what files have been viewed/downloaded. Sorry for the noise.
https://www.dropbox.com/events
EDIT: Oops, my bad: this log only tracks add, edit, move, delete. It doesn't show what files have been viewed/downloaded. Sorry for the noise.
True however this doesn't appear to track "reads" (unless I'm overlooking something?).
Note that the email mentions that some users (well, at least the user who disclosed the email) did not have any of their files accessed: "our records do not indicate that any files were viewed or downloaded." Presumably, they're doing something different for users who did have their files accessed, or at least if one of those users specifically requested that information they would disclose it.
If you're saying that Dropbox should include an access log for their web interface, then I fully agree (even if it's buried in the interface, with a giant "experimental" warning, it would still be useful).
If you're saying that Dropbox should include an access log for their web interface, then I fully agree (even if it's buried in the interface, with a giant "experimental" warning, it would still be useful).
[deleted]