Elemental Holdings, Inc. A South Florida Graphic Design Firm
  • ENGAGE
  • CULTURE
  • CASE STUDIES
  • SOLUTIONS
  • COMMUNICATE
  • DISCOVER
  • Menu Menu

Dropbox hack leads to dumping of 68m user passwords on the internet

2016/08/31/0 Comments/in Frontpage Article, Internet News, Security/by Bruce Quiroz

Data stolen in 2012 breach, containing encrypted passwords and details of around two-thirds of cloud firm’s customers, has been leaked

dropbox on an iPhone
The Dropbox data breach has highlighted the problem of password reuse. Photograph: Alamy

Samuel Gibbs

Wednesday 31 August 2016 06.43 EDTLast modified on Wednesday 31 August 201611.11 EDT

  • Share on LinkedIn
  • Share on Google+

Shares

2,203
Save for later

Popular cloud storage firm Dropbox has been hacked, with over 68m users’ email addresses and passwords dumped on to the internet.

The attack took place during 2012. At the time Dropbox reported a collection of user’s email addresses had been stolen. It did not report that passwords had been stolen as well.

The dump of passwords came to light when the database was picked up by security notification service Leakbase, which sent it to Motherboard.

The independent security researcher and operator of the Have I been pwned? data leak database, Troy Hunt, verified the data discovering both his account details and that of his wife.

Hunt said: “There is no doubt whatsoever that the data breach contains legitimate Dropbox passwords, you simply can’t fabricate this sort of thing.”

Dropbox sent out notifications last week to all users who had not changed their passwords since 2012. The company had around 100m customers at the time, meaning the data dump represents over two-thirds of its user accounts. At the time Dropbox practiced good user data security practice, encrypting the passwords and appears to have been in the process of upgrading the encryption from the SHA1 standard to a more secure standard called bcrypt.

Half the passwords were still encrypted with SHA1 at the time of the theft.

“The bcrypt hashing algorithm protecting [the passwords] is very resilient to cracking and frankly, all but the worst possible password choices are going to remain secure even with the breach now out in the public,” said Hunt. “Definitely still change your password if you’re in any doubt whatsoever and make sure youenable Dropbox’s two-step verification while you’re there if it’s not on already.”

Advertisement

The original breach appears to be the result of the reuse of a password a Dropbox employee had previously used on LinkedIn, the professional social network that suffered a breach that revealed the password and allowed the hackers to enter Dropbox’s corporate network. From there they gained access to the user database with passwords that were encrypted and “salted” – the latter a practice of adding a random string of characters during encryption to make it even harder to decrypt.

Dropbox reset a number of users’ passwords at the time, but the company has not said precisely how many.

The hack highlights the need for tight security, both at the user end – the use of strong passwords, two-step authentication and no reuse of passwords – and for the companies storing user data. Even with solid encryption practices for securing users’ passwords, Dropbox fell foul of password reuse and entry into its company network.

Leading security experts recommend the use of a password manager to secure the scores of unique and complex passwords needed to properly secure the various login details needed for daily life. But recent attacks on companies includingbrowser maker Opera, which stores and syncs user passwords, and password manager OneLogin, have exposed the dangers of using the tool.

Picking the right password manager is just as crucial and using one in the first place.

A Dropbox spokesperson said: “There is no indication that Dropbox user accounts have been improperly accessed. Our analysis confirms that the credentials are user email addresses with hashed and salted passwords that were obtained prior to mid-2012. We can confirm that the scope of the password reset we completed last week did protect all impacted users.”

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://elementalstudios.us/wp-content/uploads/2016/08/3003.jpg 372 620 Bruce Quiroz https://elementalstudios.us/wp-content/uploads/2016/09/logo_es_nav-1.png Bruce Quiroz2016-08-31 13:21:082016-08-31 13:21:08Dropbox hack leads to dumping of 68m user passwords on the internet
0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search Search

Recent Posts

  • Wordfence 7.8.0 Is Out! Here Is What Is Included
  • Patch Now: The WordPress 6.0.3 Security Update Contains Important Fixes
  • Wordfence 7.7
  • You Don’t Need to Be a Magician to Optimize SEO
  • Meta is building VR gloves for the metaverse

Categories

  • Apps
  • Business
  • Colors
  • E-Commerce
  • Frontpage Article
  • Graphic Design
  • Graphic Design Firm
  • Internet News
  • Internet Speed
  • Marketing
  • News
  • Printing
  • Privacy
  • Psychology
  • Security
  • SEO
  • Social Media
  • Technology
  • Typography
  • WordPress

Recent Comments

    Archives

    • November 2022
    • October 2022
    • January 2022
    • November 2021
    • October 2021
    • August 2021
    • April 2021
    • June 2020
    • May 2020
    • March 2020
    • February 2020
    • October 2019
    • September 2019
    • July 2019
    • May 2019
    • April 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • September 2018
    • July 2018
    • June 2018
    • May 2018
    • March 2018
    • October 2017
    • November 2016
    • October 2016
    • September 2016
    • August 2016
    • April 2016
    • March 2016
    • February 2016
    • January 2016
    • August 2015
    • June 2015
    • May 2015
    • April 2015
    • March 2015
    • November 2014
    • October 2014
    • July 2014
    • April 2014
    • March 2014
    • February 2014
    • December 2013
    © Copyright - Elemental Holdings, Inc. A South Florida Graphic Design Firm || "We Share your Dreams with the World" || Contact us today via phone or e-mail || info@elementalstudios.us || T. 954.586.4410
    • Link to Facebook
    • Link to Behance
    • Link to X
    • Link to Instagram
    • Link to Youtube
    • Link to Rss this site
    • Link to Mail
    • Link to 500px
    Link to: Why it matters what PHP version you are using. Link to: Why it matters what PHP version you are using. Why it matters what PHP version you are using. Link to: 6 ESSENTIAL WAYS TO IMPROVE YOUR WEBSITE SECURITY Link to: 6 ESSENTIAL WAYS TO IMPROVE YOUR WEBSITE SECURITY 6 ESSENTIAL WAYS TO IMPROVE YOUR WEBSITE SECURITY
    Scroll to top Scroll to top Scroll to top