Rendered at 23:51:30 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
xaphod 1 days ago [-]
I got this same email about an hour ago.
About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
ThePhysicist 18 hours ago [-]
Damn, big security fuckup by Dropbox, how can they portray that as an issue with Lenovo's e-mail verification process? You should never allow linking of an existing account with a new login method without first confirming that the user is able to sign in with an existing method first! Everyone knows this allows easy account takeovers otherwise, that's such a trivial attack vector, truly a scenario you could pose to a junior security engineer in an interview.
aitchnyu 17 hours ago [-]
What is Lenovo doing here? Were they bundling Dropbox with their devices?
latexr 1 days ago [-]
> Has anyone else received the same notice, or seen any public information about this vulnerability?
This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.
djanogo 13 hours ago [-]
Agree, after over a decade I am about to delete all my files and close the account.
The culture in the company would have to be fu*ked to allow this type of breach. There is no official Dropbox public letter or CEO apology post yet, seems like problem starts at the top with new CEO.
haute_cuisine 12 hours ago [-]
Hardware shops can't do software, software shops can't do hardware. Just never put any hardware company in secure sensitive software related flows.
About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
Another submission on HN (to Twitter).
https://news.ycombinator.com/item?id=49514471
The culture in the company would have to be fu*ked to allow this type of breach. There is no official Dropbox public letter or CEO apology post yet, seems like problem starts at the top with new CEO.