Technology content trusted by users in Australia and around the world.
4,967 Articles | 29,991 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

AU EditionYou are located: Home > All News > Cloud Computing News > Dropbox admits user accounts were hijacked, adds new security

Dropbox admits user accounts were hijacked, adds new security

By: (more) | Cloud Computing News | Posted: Aug 1, 2012 3:28 pm

A few weeks ago, there were reports of Dropbox users started to receive spam on the e-mails tied to Dropbox. The major problem with this was that some of these user's e-mails were only tied to their Dropbox account which meant that the spam or address leak was coming from Dropbox itself as there would be no other way for the e-mail to be released.

 

dropbox_admits_user_accounts_were_hijacked_adds_new_security

 

Dropbox enlisted the help of "an outside team of experts" to aid their own security team and law enforcement. Dropbox's VP of Engineering, Aditya Agarwal, said in a blog post that a number of usernames and passwords were stolen from third party websites. These combos were then used to sign into "a small number of Dropbox accounts."

 

One of those stolen password combos belonged to an employee. The employee's Dropbox contained a project file which had a list of e-mails. The company believes "this improper access is what led to the spam." Dropbox is taking several steps to prevent something like this from happening in the future. These are laid out below:

 

  • Two-factor authentication, a way to optionally require a unique code in addition to your password when signing in. (Coming in a few weeks)
  • New automated mechanisms to help identify suspicious activity. We'll continue to add more of these over time.
  • A new page that lets you examine all active logins to your account.
  • In some cases, we may require you to change your password. (For example, if it's commonly used or hasn't been changed in a while)

 

There's still plenty to be learned as the investigation is on-going. Currently, it would appear that both Dropbox and its users share the responsibility for this hack. Dropbox is doing its part and suggests that its users do the same. They point out that "though it's easy to reuse the same password on different websites, this means if any one site is compromised, all your accounts are at risk."


SOURCE #1

Related Tags



Further Reading: Read and find more Cloud Computing news at our Cloud Computing news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Western Digital Scorpio Blue (WD5000LPVT) 500GB HDD Review
  • Upcoming Content: Scythe Mugen 4 Tower CPU Cooler Review
  • Upcoming Content: NZXT Grid 10 Port Fan Hub Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Cloud Computing News Posts

View More Cloud Computing News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Cloud Computing Press Releases

View More Cloud Computing Press Releases