The Dropbox hack is real(troyhunt.com)
troyhunt.com
The Dropbox hack is real
https://www.troyhunt.com/the-dropbox-hack-is-real
539 コメント
Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.
Dropbox should absolutely be held to the flame for trying to downplay the severity of this. Their communication says 'This is purely a preventative measure', but if you had/have reused this password on any other sites (let's face it a huge proportion of non tech savvy people do this) then your entire online presence may be exposed.
It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could see your pattern and start spamming by guessing popular services.
On a side note, don't forget the time dropbox accepted ANY password during logins - http://www.cnet.com/news/dropbox-confirms-security-glitch-no...
On a side note, don't forget the time dropbox accepted ANY password during logins - http://www.cnet.com/news/dropbox-confirms-security-glitch-no...
50% of the leaked hashes were bcrypt and the other 50% were salted sha1.
So, asking the HNers who crack passwords or follow the tech closely and have a good feel:
Salted sha1 can be brute forced much quicker, but in practical terms what kind of complexity of password is vulnerable today if it was stored salted sha1 vs bcrypt?
And how can this be projected to change in the next couple of years?
So, asking the HNers who crack passwords or follow the tech closely and have a good feel:
Salted sha1 can be brute forced much quicker, but in practical terms what kind of complexity of password is vulnerable today if it was stored salted sha1 vs bcrypt?
And how can this be projected to change in the next couple of years?
Repeating from the other thread:
I highly recommend Troy's HIBP service, hiding your e-mail from showing up in public searches (important for opsec), and donating whatever you can to Troy. He's doing excellent work. This is the first time it's notified me and it was great, because I completely forgot I signed up. I appreciate a service that low maintenance.
HIBP is a truly essential service and I'd be happy to pay more. Even with good password discipline it's useful knowledge on your exposure and I cannot recommend it enough. He mentions it near the end but this is one of those no brainers that should be repeated very loudly.
https://haveibeenpwned.com
I highly recommend Troy's HIBP service, hiding your e-mail from showing up in public searches (important for opsec), and donating whatever you can to Troy. He's doing excellent work. This is the first time it's notified me and it was great, because I completely forgot I signed up. I appreciate a service that low maintenance.
HIBP is a truly essential service and I'd be happy to pay more. Even with good password discipline it's useful knowledge on your exposure and I cannot recommend it enough. He mentions it near the end but this is one of those no brainers that should be repeated very loudly.
https://haveibeenpwned.com
Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well.
I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices.
For your critical services, keeping encrypted copies of your backup codes is a must.
I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices.
For your critical services, keeping encrypted copies of your backup codes is a must.
> 1Password now has a subscription service for $3 a month and you get the first 6 months for free.
Don't pay for this people. Use the open source password manager Keepass http://keepass.info/
Don't pay for this people. Use the open source password manager Keepass http://keepass.info/
> As for Dropbox, they seem to have handled this really well.
I'm biased, but I can't agree with this. From what I can tell, there are two communications from Dropbox -- one in 2012 [1] and one last week [2].
In 2012 they did not disclose that hashes were stolen, so I don't see how it's really relevant. In the latest communication, they don't actually explain the risk to the user. They say it is "purely as a preventative measure" but if salts and hashes were accessed, then that is not the case.
Just because Troy doesn't have access to some of the salts, doesn't mean the attacker doesn't have access. We don't know how many iterations of SHA-1, but SHA-1 can be run by a single GPU on the order of billions of times per second. So unless Dropbox is coming out and saying they know for certain that random 128-bit salts were definitely not accessed by the attacker, almost all of the SHA1 hashed passwords are getting cracked. Users need to know their passwords are exposed, and must be reset not as a preventative measure, but because they are almost certain to be compromised.
As for the salted/bcrypt passwords, we can see from Troy's hash they used $2a$08$ which is bcrypt with a cost factor of 8 -- 2^8 iterations. Gosney's latest rig [3] could crack these bcrypt hashes at about 105,700 / 8 = 13,212 per second. That's not terrible, but that's still 416 billion tries in a year for a modest investment.
[1] - https://blogs.dropbox.com/dropbox/2012/07/security-update-ne... [2] - https://blogs.dropbox.com/dropbox/2016/08/resetting-password... [3] - https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
I'm biased, but I can't agree with this. From what I can tell, there are two communications from Dropbox -- one in 2012 [1] and one last week [2].
In 2012 they did not disclose that hashes were stolen, so I don't see how it's really relevant. In the latest communication, they don't actually explain the risk to the user. They say it is "purely as a preventative measure" but if salts and hashes were accessed, then that is not the case.
Just because Troy doesn't have access to some of the salts, doesn't mean the attacker doesn't have access. We don't know how many iterations of SHA-1, but SHA-1 can be run by a single GPU on the order of billions of times per second. So unless Dropbox is coming out and saying they know for certain that random 128-bit salts were definitely not accessed by the attacker, almost all of the SHA1 hashed passwords are getting cracked. Users need to know their passwords are exposed, and must be reset not as a preventative measure, but because they are almost certain to be compromised.
As for the salted/bcrypt passwords, we can see from Troy's hash they used $2a$08$ which is bcrypt with a cost factor of 8 -- 2^8 iterations. Gosney's latest rig [3] could crack these bcrypt hashes at about 105,700 / 8 = 13,212 per second. That's not terrible, but that's still 416 billion tries in a year for a modest investment.
[1] - https://blogs.dropbox.com/dropbox/2012/07/security-update-ne... [2] - https://blogs.dropbox.com/dropbox/2016/08/resetting-password... [3] - https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?
Can someone in the know indicate how to BEST manage passwords for different services in a secure way in 2016? Should I be using password managers (à la 1Password, LastPassword and others), or use something like Keychain Access on Mac OS X (what are the Windows equivalents?), anything else? It's important to note that not everyone is well-educated on the matter, despite the fact that most people on HN are technical people.
EDIT: Thanks everyone for your answers, this is a good example of the power of communities.
EDIT: Thanks everyone for your answers, this is a good example of the power of communities.
What really bothers be about this is that Dropbox hasn't bothered to reset the sessions. Even after I manually reset my password (which I wasn't prompted or forced to do btw), all my apps (iPhone, desktop etc) that have existing sessions wasn't expired. So for all I know, a hacker might already have an open session to my Dropbox and changing the password will not fix that
Clarification edit: I did receive the e-mail from Dropbox letting me know that I should change my password, but when visiting dropbox.com I was already logged in and wasn't prompted to perform the pw reset
Clarification edit: I did receive the e-mail from Dropbox letting me know that I should change my password, but when visiting dropbox.com I was already logged in and wasn't prompted to perform the pw reset
How is it possible for Hashcat to crack a 20 character long random password in 6ms? That is mind boggling.
I thought he was just going to hash the password and see if it fit the leaked hash, but no, it looks like he actually did the reverse and cracked the hash to see if it fit the password, right?
Edit: oh it looks like he provided the password to hashcat in the form of a psudo 'dictionary' to use. So Hashcat was not really cracking it - just iterating through a 1 word dictionary - like he said.
I thought he was just going to hash the password and see if it fit the leaked hash, but no, it looks like he actually did the reverse and cracked the hash to see if it fit the password, right?
Edit: oh it looks like he provided the password to hashcat in the form of a psudo 'dictionary' to use. So Hashcat was not really cracking it - just iterating through a 1 word dictionary - like he said.
So we finally get validation of https://news.ycombinator.com/item?id=5300492
Self hosting is my way to go. Had enough of this.
> My wife uses a password manager. If your significant other doesn't (and I'm assuming you do by virtue of being here and being interested in security), go and get them one now! 1Password now has a subscription service for $3 a month and you get the first 6 months for free.
How about...not? There are tiny open source tools for every OS. You can do it locally, save it on a stick or on your damn phone...why taking more risks especially facing this massive fail here?
> My wife uses a password manager. If your significant other doesn't (and I'm assuming you do by virtue of being here and being interested in security), go and get them one now! 1Password now has a subscription service for $3 a month and you get the first 6 months for free.
How about...not? There are tiny open source tools for every OS. You can do it locally, save it on a stick or on your damn phone...why taking more risks especially facing this massive fail here?
What sites does everyone have two step verification on? I'm trying to figure out where I need to setup two step verification that also accounts for a phone being stolen/lost.
Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...
Between gmail, dropbox (1password is synced here), and apple, I'm not sure where I should be enabling it. It seems like everywhere but gmail and apple is probably the right move...
I wonder if they got the seeds ('secret key' in [1]) for the 2FA as well.
[1] https://en.wikipedia.org/wiki/HMAC-based_One-time_Password_A...
[1] https://en.wikipedia.org/wiki/HMAC-based_One-time_Password_A...
Great read.
He goes on to say that 1Password has a subscription now and that you should signup for it.
No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time.
Am I alone with this view?
He goes on to say that 1Password has a subscription now and that you should signup for it.
No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time.
Am I alone with this view?
I wonder why the SHA1s don't have the salt. Were they removed so that only the original owners have it so it's easier to crack?
Oh well, another HIBP entry with my email address...
Oh well, another HIBP entry with my email address...
Funny, I just got an email a week ago saying they had noticed my password hadn't been changed in awhile (2012, which was interesting based on the article). Sounds like they knew about this and beefed up security.Or, they beefed up security on newer passwords but didn't cut over the old ones? The email did not mention any data theft, kinda wish it did. Too little, too late.
I'm surprised no one has mentioned Dropbox's bug bounty program: https://hackerone.com/dropbox
You have to wonder if all those grumbling whitehats were on to something when they said bug bounties should pay a lot more than what they do and that there IS a black market interest for them.
You have to wonder if all those grumbling whitehats were on to something when they said bug bounties should pay a lot more than what they do and that there IS a black market interest for them.
I suppose this is off topic, but I checked one of my email addresses on https://haveibeenpwned.com/ and found a LinkedIn hack from May 2016.
Thing is I've deleted my LinkedIn account thrice in 2013. They have no right to stop have my email after that long.
Thing is I've deleted my LinkedIn account thrice in 2013. They have no right to stop have my email after that long.
OK. Thank you, HN. I just discovered that I've been pwned on Dropbox breach. If that happened in 2012, and I am using 1Password sync over Dropbox, does that mean that all my passwords stored in 1Password.pif in 2012 were compromised too? Probably yes.
Why isn't Dropbox reporting this? I'd have more respect for them if they were more honest about this.
Well, thank goodness I got robbed after 2012, which caused me to change all my passwords everywhere. Else I don't think I would've ever gotten around to changing my Dropbox password, as it's just a long string of randomness.
So besides resetting the password, should one also unlink devices and apps?
I've never trusted dropbox, cloud etc. They drive me paranoia. :/
If find this just interesting that just last week my steam account was successfully logged in from Russia (I'm in the UK). Looks like I forgot about Steam to make my passwords stronger.
How can I tell if someone has accessed my account / files?
Hmm, my account appears on HIBP, but Dropbox haven't asked me to change my password on login... Who to believe? (probably not Dropbox)
Recently I had received an email from Dropbox asking me to change my password and now I read about the hack , I wonder if there is any correlation here.