Posted September 1, 2016 Who remembers this? It turns out hackers got some passwords too.. Quote Hackers have stolen over 60 million account details for online cloud storage platform Dropbox. Although the accounts were stolen during a previously disclosed breach, and Dropbox says it has already forced password resets, it was not known how many users had been affected, and only now is the true extent of the hack coming to light. Quote Earlier this week, Dropbox announced it was forcing password resets for a number of users after discovering a set of account details linked to a 2012 breach. Quote “We've confirmed that the proactive password reset we completed last week covered all potentially impacted users," said Patrick Heim, Head of Trust and Security for Dropbox. "We initiated this reset as a precautionary measure, so that the old passwords from prior to mid-2012 can’t be used to improperly access Dropbox accounts. We still encourage users to reset passwords on other services if they suspect they may have reused their Dropbox password.” Source: http://motherboard.vice.com/read/hackers-stole-over-60-million-dropbox-accounts Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/ Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 2 factor auth Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383617 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 59 minutes ago, zMeul said: 2 factor auth Not phone 2 factor auth, email is best imo (e.g. steam code when using new browser) hello! is it me you're looking for? ᴾC SᴾeCS ᴰoWᴺ ᴮEᴸoW Spoiler Desktop: X99-PC CPU: i7 5820k Mobo: X99 Deluxe Cooler: Dark Rock Pro 3 RAM: 32GB DDR4 GPU: GTX 1080 Storage: 1TB 850 Evo, 1TB HDD, bunch of external hard drives PSU: EVGA G2 750w Peripherals: Logitech G502, Ducky One 711 Audio: Xonar U7, O2 amplifier (RIP), HD6XX Monitors: 4k 24" Dell monitor, 1080p 24" Asus monitor Laptop: -Overkill Dell XPS Fully maxed out early 2017 Dell XPS 15, GTX 1050 4GB, 7700HQ, 1TB nvme SSD, 32GB RAM, 4k display. 97Whr battery Dell was having a $600 off sale for the fully specced out model, so I decided to get it -Crapbook Fully specced out early 2013 Macbook "pro" with gt 650m and constant 105c temperature on the CPU (GPU is 80-90C) when doing anything intensive... A 2013 laptop with a regular sized battery still has better battery life than a 2017 laptop with a massive battery! I think this is a testament to apple's ability at making laptops, or maybe how little CPU technology has improved even 4+ years later (at least, until the recent introduction of 15W 4 core CPUs). Anyway, I'm never going to get a 35W CPU laptop again unless battery technology becomes ~5x better than as it is in 2018. Apple knows how to make proper consumer-grade laptops (they don't know how to make pro laptops though). I guess this mostly software power efficiency related, but getting a mac makes perfect sense if you want a portable/powerful laptop that can do anything you want it to with great battery life. Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383781 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 2 minutes ago, rattacko123 said: Not phone 2 factor auth, email is best imo i've been using the google auth app for couple of years, I prefer it to mail or SMS auth - I have a dedicated phone just for 2 factor problem with your logic is that you need to protect your mail too, and how are you gonna do that if not with a phone (SMS or 2 factor app) ?? Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383787 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 (edited) Using two-factor-authentication as well, with my phone via SMS. I do not like the way Dropbox handles this. I received an email telling me that all passwords from 2012 an earlier were going to be reset. No mention of the hack as a reason. Plus if I used a very secure password* before, the chances that someone retrieves my new password using a man-in-the-middle-attack are higher than the chances that my old password will be breached. *) My Dropbox password was generated by KeePass using an algorithm that puts out stuff like n@fY^`Ö{{w'ZE&<oQNOSÖ](r|däwzBKd, which I would call pretty secure. Edited September 1, 2016 by Tataffe THIS SIGNATURE INTENTIONALLY LEFT BLANK Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383857 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 Yay! For dropbox not having the ability to use a YubiKey. I paid $40 USD for it Western Sydney University - 4th year BCompSc student Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383877 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 46 minutes ago, zMeul said: i've been using the google auth app for couple of years, I prefer it to mail or SMS auth - I have a dedicated phone just for 2 factor problem with your logic is that you need to protect your mail too, and how are you gonna do that if not with a phone (SMS or 2 factor app) ?? But what if phon get hack? Well, you could use a really strong password for your email, or use another email as a backup email for 2-factor auth hello! is it me you're looking for? ᴾC SᴾeCS ᴰoWᴺ ᴮEᴸoW Spoiler Desktop: X99-PC CPU: i7 5820k Mobo: X99 Deluxe Cooler: Dark Rock Pro 3 RAM: 32GB DDR4 GPU: GTX 1080 Storage: 1TB 850 Evo, 1TB HDD, bunch of external hard drives PSU: EVGA G2 750w Peripherals: Logitech G502, Ducky One 711 Audio: Xonar U7, O2 amplifier (RIP), HD6XX Monitors: 4k 24" Dell monitor, 1080p 24" Asus monitor Laptop: -Overkill Dell XPS Fully maxed out early 2017 Dell XPS 15, GTX 1050 4GB, 7700HQ, 1TB nvme SSD, 32GB RAM, 4k display. 97Whr battery Dell was having a $600 off sale for the fully specced out model, so I decided to get it -Crapbook Fully specced out early 2013 Macbook "pro" with gt 650m and constant 105c temperature on the CPU (GPU is 80-90C) when doing anything intensive... A 2013 laptop with a regular sized battery still has better battery life than a 2017 laptop with a massive battery! I think this is a testament to apple's ability at making laptops, or maybe how little CPU technology has improved even 4+ years later (at least, until the recent introduction of 15W 4 core CPUs). Anyway, I'm never going to get a 35W CPU laptop again unless battery technology becomes ~5x better than as it is in 2018. Apple knows how to make proper consumer-grade laptops (they don't know how to make pro laptops though). I guess this mostly software power efficiency related, but getting a mac makes perfect sense if you want a portable/powerful laptop that can do anything you want it to with great battery life. Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383911 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 1 minute ago, rattacko123 said: But what if phon get hack? Well, you could use a really strong password for your email, or use another email as a backup email for 2-factor auth my phone doesn't get hacked because I only use it 2 factor, I don't even go on line with it and again that logic ... you need a 2nd email for backup and 3rd email for backup of the 2nd ... and so on Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383918 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 Or you could forget about both a backup email and a phone by having a YubiKey that you carry with you in your lanyard or in your wallet. Western Sydney University - 4th year BCompSc student Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8383940 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 1 hour ago, kiska3 said: Yay! For dropbox not having the ability to use a YubiKey. I paid $40 USD for it You can definitely use your YubiKey. They implemented the FIDO U2F standard last year (almost one year exactly) for two factor authentication. Spoiler Main rig specs: i5-6500 (3.2 GHz), Cryorig H5 Universal, EVGA GTX 970 FTW+, 16GB Corsair Vengeance DDR4 (2133MHz), Asus Z170i Pro Gaming, Samsung 950 PRO 256GB, Phanteks Enthoo Evolv ITX, LG 3440x1440 Ultrawide. Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8384055 Share on other sites More sharing options... Link to post Share on other sites More sharing options...
Posted September 1, 2016 I like how they silently sent out mails last week where the just said that everyone that had passwords from before the mid of 2012 would need to change them. I just thought it was some kind of new policy that they wouldn't allow passwords older than 4 years, but hey, this is the actual reason : D Ryzen 7 5800X Corsair H115i Platinum ASUS ROG Crosshair VIII Hero (Wi-Fi) G.Skill Trident Z 3600CL16 (@3800MHzCL16 and other tweaked timings) MSI RTX 3080 Gaming X Trio Corsair HX850 WD Black SN850 1TB Samsung 970 EVO Plus 1TB Samsung 840 EVO 500GB Acer XB271HU 27" 1440p 165hz G-Sync ASUS ProArt PA278QV LG C8 55" Phanteks Enthoo Evolv X Glass Logitech G915 Logitech MX Vertical Steelseries Arctis 7 Wireless 2019 Windows 10 Pro x64 Link to comment https://linustechtips.com/topic/652874-dropbox-hack-2012/#findComment-8384182 Share on other sites More sharing options... Link to post Share on other sites More sharing options...