Total Visits: 4272250 | Uniques today: 241

Dropbox leaves user accounts unlocked for 4 hours


Posted by viktoriadicheva on 21 Jun 2011 - 17:22 (0 comments)
At a time when hackers are on a tear looting information willy-nilly from insecure sites on the Web, Dropbox did the unthinkable Sunday -- it allowed anyone in the world to access any one of its 25 million customers' online storage lockers -- simply by typing in any password.

Dropbox, one of the most popular ways to share and sync files online, says the accounts became unlocked at 1:54pm Pacific time Sunday when a programming change introduced a bug.

The company closed the hole a little less than 4 hours later. The bug was reported on Dropbox forums and on Pastebin (via security researcher Christopher Soghoian).
The company gave more specifics in a blog post Monday afternoon:

"We're conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we'll immediately notify the account owner.
"If you're concerned about any activity that has occurred in your account, you can contact us at security@dropbox.com.This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again."

However, Christopher Soghoian argues that Dropbox's model introduces too many security vulnerabilities and that Dropbox overstated how secure file storage was, leading him to file an FTC complaint against the company.

News source: cnn


Print Send to a friend Post a comment

Share |

Add a new comment
Sorry, this news post has been closed and you cannot post any comments to it.
New Files
Most Downloaded

RSS Facebook Twitter