main topics archive podcast connect
about 13 years ago
SGP has no shortage of cases for iPhone or iPad, and their Linear Mini series, while being their budget line, is far from being comparable to a generic means of protection ...
about 13 years ago
This week we talk some pretty important stuff like Anime Expo 2011, Captain America (is it good, bad, ugly?), MacBook Battery hacking, 3DS price cuts (now just $169), Battlefield 3 Alpha ...
about 13 years ago
This week, we have a special show because we’re giving away a copy of the new Annihilation DLC for Call of Duty Black Ops (Steam, PC). We’ve done Giveaways before, but ...
about 13 years ago
On this week’s show, Connor and Brandon talk Facebook Video chat, cereal and milk, Bioshock Infinite, Quadrotors, the new Youtube, Spotify coming to the US, Connor gets his iPhone hacked and ...
about 13 years ago
Special thanks — to Connor for filling in this episode!!! On this installment of the Okay Geek Show, Ricardo is away at the 2011 Anime Expo spreading the joy of Okay Geek with ...
about 13 years ago
  We have been underground bashing our keyboards and inhaling coffee for the past two weeks covering E3 2011 which has been a blast, but a lot of hard work. ...
about 13 years ago
  This week on the show, Ricardo and Brandon sit down and talk about the widest veryity of topics ever discussed before… we start with Basketball and end up talking ...
about 13 years ago
  This is our first video podcast, and we’re so proud we managed to do it live on Friday, all in one take. This episode, Ricardo and Brandon start the ...
about 13 years ago
  This week, we are talking about a veryity of topics that are strange, just as they are awesome. We’re talkin’ Bear Grylls, Piss, Thor, vocaloid raves, and a bunch ...
about 13 years ago
  You remember the our old podcast right? Well that was somewhat of a test. A test to see if our readers would enjoy hearing us and listening to what ...
  • Have a suggestion?

  • *
  • *
  • *

REQUIRED READING

Notify Ricardo

When you finish something, notify Ricardo (Executive Editor) via a private DM through Twitter.

Okay Geek Traffic Traffic live stats Twitter activity Facebook Page Image compress app Tips & Guidelines Report a problem
← Previous Clean slate Next →
Wednesday
Jun222011

Your Dropbox account was unlocked for 4 hours last weekend, anyone could access it

Dropbox is one of my favorite services, and I am sure many of our readers have been using Dropbox for a very long time. We have managed to trust Dropbox with our files stored on their servers, and for the most part they seemed to have been pretty proficient in keeping them safe. Dropbox was such a wonderful service… until last weekend when their lack of attention to security became blatantly obvious.

Essentially what happened was a “bug” started causing trouble at 1:54pm on Sunday, but the Dropbox team didn’t seem to notice at all. They had recently performed a code update, obviously hadn’t tested a single thing (besides basic functionality), and pushed it live to their 25 million users. It wasn’t until 5:41pm (4 hours later) that the bug was found which comprised all user authentication, and only then the team took action — That means your Dropbox account was completely open and publicly accessible for 4 hours — somebody could have logged into your account using any password.

Quote from Official Dropbox Blog

Hi Dropboxers,

Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.

We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner. If you’re concerned about any activity that has occurred in your account, you can contact us at support@dropbox.com.

This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.

No matter how many people this affected…

Dropbox stresses that “much less than 1 percent” of their users logged in during that period, and that may be true (there isn’t any control number to judge by), but it doesn’t matter if this effected anyone at all — the problem is that Dropbox was careless enough to allow 25 million people’s private data and personal info to be accessible by anyone.

In the end, this event will definitely bring darker times for Dropbox, and it’s going to be extremely hard for them to re-gain the trust of their users. It just seems un-real that a company can leave something like this to go un-noticed for 4 hours, and yet proceed to fix it in 5 minutes.

References (1) Dropbox
Discussion Threads

Follow and Subscribe to Okay Geek - We always send our latest articles to Twitter, RSS, Facebook and more, as well as other awesome content we find interesting.

Related Posts Plugin for WordPress, Blogger...