Dropbox accounts left open for 4 hours due to programming bug

Wired News: "Dropbox, one of the most popular ways to share and sync files online, says the accounts became unlocked at 1:54pm Pacific time Sunday when a programming change introduced a bug." Four hours later, the hole was closed. Security researcher Christopher Soghoian was the first to notice the (um, gaping) security hole.

13

  1. It’s a good thing all those files were encrypted so not even dropbox could read them.

  2. So no one did any regression testing or even any roll out “smoke testing”. Pathetic.
    The perils of doing all your corporate programming for free by teenagers living in their mom’s basement.

  3. I must admit, I’m as surprised as anybody to find myself in possession of the secret formula for Coca Cola. I would have never guessed the castor oil and clam juice parts.

  4. How is this even possible? Isn’t there any encryption on the files, meaning it shouldn’t be possible accessing files without password decrypting them?

    1. There is no encryption, this was already known. From the dropbox website:

      Dropbox employees are prohibited from viewing the content of files you store in your Dropbox account, and are only permitted to view file metadata (e.g., file names and locations). Like most online services, we have a small number of employees who must be able to access user data for the reasons stated in our privacy policy (e.g., when legally required to do so). But that’s the rare exception, not the rule. We have strict policy and technical access controls that prohibit employee access except in these rare circumstances.

  5. As a (former) Dropbox user I’d like to recommend SugarSync as an alternative way to backup and sync your data in the cloud. Free accounts provide 5GB of disk space and you can choose which folders to sync in your hard drive, not only one single dropbox.
    If anyone wants to register for an account, feel free to use my referral link that will add 500 MB further bonus to both mine and your account :)
    https://www.sugarsync.com/referral?rf=do5qm2rpjareh
    Thanks!

  6. Spideroak have a zero-knowledge privacy policy. I’d say it’s not quite as polished a product as dropbox, but everything is encrypted before it leaves my computer (come on spideroak open source your client so we can check!) and stored encrypted, so NO ONE can read it. I have access to files from android to. (I am not affiliated with Spideroak in away way.)

    Join via this link and we both get an extra 1GB (I believe you start with 2GB free):

    https://spideroak.com/download/referral/dd998cb68d2fba5eb916a000411c2263

  7. Good article – here is another Cloud Storage solution that lets your computer to fully encrypt your files before sending out:
    With SugarSync, you get 5GB of cloud storage space with the FREE version, but now there is no restriction to the number of computers you can sync/backup (up from 2).
    It gives you the ability to upload and sync any folder on your computer.
    It is the only service that offers such a broad device and OS support with apps for BlackBerry, Android, iPhone/iPad, Symbian, not to mention your computer!
    You can also stream MP3 music files to your smartphone or computer.

    Also if you use the below referral code you get a bonus 500MB extra on top of your Free 5GB!

    https://www.sugarsync.com/referral?rf=tbtp0asbw9pt

    Hope this helps someone!

Comments are closed.