Dropbox Got Hacked

(twitter.com)

31 points | by yonilevy 8 hours ago ago

11 comments

  • paxys 5 hours ago ago

    Trusting Lenovo as an auth provider is certainly a decision..

    Handling SSO related security-holes in SaaS apps has made up a major chunk of my career at this point.

    The most common one – app adds SAML-based login and treats the returned email from the SSO provider as authoritative. What the developers don’t realize is that you can set up your own tenant with most major SSO providers and assign users any arbitrary email – no verification needed.

    And if an account with the same email address already exists in your system – congrats, you have just granted full access to it to basically anyone.

  • curuinor 8 hours ago ago

    Any serious career programmer knows in their bones that it's a miracle that anything works at all. Now the general public is getting to learn that fact, by everything systematically breaking. Or getting hacked, in this case.

    • hoppp 8 hours ago ago

      Its just gonna get worse over time.

      • 8 hours ago ago
        [deleted]
  • kevinfiol 3 hours ago ago

    I replaced Dropbox and other cloud storage providers with Syncthing on all of my machines. It's not the equivalent, but I was surprised by how little I missed the cloud storage itself -- in the end, I just needed a way to have my files synced between devices automatically.

  • 5 hours ago ago
    [deleted]
  • k310 8 hours ago ago

    It seems that hacks are only a matter of "when" and not "if"

    I have two credit cards (paid up monthly) for just such a reason and may get a third.

    • gonzalohm 6 hours ago ago

      You mean as a way of protecting against fraudulent charges? If so, there are services that give you single use card numbers and you can set up spending limits.

      • k310 5 hours ago ago

        Just so if one gets hacked, I have a working on in the interim, as new one is issued.

  • 3 hours ago ago
    [deleted]
  • 8 hours ago ago
    [deleted]