Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Dropbox security bug


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion

Dropbox security bug
Reply
 
Thread Tools
Old 21-06-2011, 19:52   #1
Matt D
Cable Forum Team
 
Matt D's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Services: Freeview, Sky+HD, Sky Broadband Unlimited, BT phone
Posts: 15,035
Matt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny stars
Matt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny starsMatt D has a pair of shiny stars
Dropbox security bug

"Dropbox Security Bug Made Passwords Optional For Four Hours"

Quote:
Originally Posted by TechCrunch
This morning a post on Pastebin outlined a serious security issue that was spotted at Dropbox: for a brief period of time, the service allowed users to log into accounts using any password. In other words, you could log into someone’s account simply by typing in their email address. Given that many people entrust Dropbox with important data (one of the service’s selling points is its security), that’s a really big deal.

We’ve now confirmed with Dropbox that the service did have this issue yesterday — Dropbox says that it began after a code push at 1:54 PM PDT and was fixed at 5:46 PM PDT (they had the fix live five minutes after they discovered it). So, in total, the bug was live for around four hours.

The question now is how many people were affected. The company will be announcing that “much less than 1 percent” of users logged in during this time, and that all sessions have now been logged out as a security precaution. The team is now investigating if any accounts were improperly accessed, and says that anyone who was impacted will be notified.

Update: Here’s the company’s blog post, which just went live:
"Yesterday’s Authentication Bug"

Quote:
Originally Posted by Arash Ferdowsi on the Dropbox blog
Hi Dropboxers,

Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.

We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner. If you’re concerned about any activity that has occurred in your account, you can contact us at support@dropbox.com.

This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.

-Arash

[Update - 10:46pm] – We’re working around the clock to gather additional data and continue to review logs for potentially unauthorized activity. We aim to notify users who had login activity during the period within the next few hours.

We are sorry for this and regardless of how many people were ultimately affected, any exposure at all is unacceptable to us. We will continue to provide regular updates.

[Update - 2:49am] – At this point, the accounts that logged in during the period have been emailed with additional activity-related details for review. If you have any questions or concerns, please contact us at support@dropbox.com.

Oops...
Matt D is offline   Reply With Quote
Advertisement
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 12:49.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2