About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
Damn, big security fuckup by Dropbox, how can they portray that as an issue with Lenovo's e-mail verification process? You should never allow linking of an existing account with a new login method without first confirming that the user is able to sign in with an existing method first! Everyone knows this allows easy account takeovers otherwise, that's such a trivial attack vector, truly a scenario you could pose to a junior security engineer in an interview.
This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.
Agree, after over a decade I am about to delete all my files and close the account.
The culture in the company would have to be fu*ked to allow this type of breach. There is no official Dropbox public letter or CEO apology post yet, seems like problem starts at the top with new CEO.
I got this same email about an hour ago.
About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
Damn, big security fuckup by Dropbox, how can they portray that as an issue with Lenovo's e-mail verification process? You should never allow linking of an existing account with a new login method without first confirming that the user is able to sign in with an existing method first! Everyone knows this allows easy account takeovers otherwise, that's such a trivial attack vector, truly a scenario you could pose to a junior security engineer in an interview.
What is Lenovo doing here? Were they bundling Dropbox with their devices?
> Has anyone else received the same notice, or seen any public information about this vulnerability?
Another submission on HN (to Twitter).
https://news.ycombinator.com/item?id=49514471
This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.
Agree, after over a decade I am about to delete all my files and close the account.
The culture in the company would have to be fu*ked to allow this type of breach. There is no official Dropbox public letter or CEO apology post yet, seems like problem starts at the top with new CEO.
Hardware shops can't do software, software shops can't do hardware. Just never put any hardware company in secure sensitive software related flows.