That Dropbox "Hack" Was Just Your Old Passwords Coming Back

That Dropbox "Hack" Was Just Your Old Passwords Coming Back

Tech News 2fa dropbox passwords security

So this happened on Monday: somebody posted what they claimed was a dump of usernames and passwords for something like 7 million Dropbox accounts, first on Pastebin, then on Reddit after the Pastebin links got yanked. The poster wanted Bitcoin donations to keep releasing "batches." Very charming business model.

Dropbox came out fast and said, basically, nope, we weren't breached. Their systems are fine. What actually happened (and this is the part that matters more than the scary headline) is that the passwords came from other sites that got hacked a while back, and people had reused the same email/password combo on Dropbox too. So some bot somewhere just ran the leaked credentials against Dropbox's login form and whatever stuck, stuck. That's it. That's the whole hack. Not clever, not a zero-day, just a spreadsheet and patience.

I bring this up not because I think it's the biggest tech story of the week (it very much is not, there was a giant Apple event today and I'm sure half the internet is already covered in iPad Air 2 and iMac takes by the time anyone reads this) but because the "we weren't hacked, YOU were just careless everywhere else" pattern keeps happening and it never seems to change anyone's behavior. Including mine, if I'm honest. I went and checked my own password situation last night after reading about this and found three different accounts still using a password I definitely used somewhere else, one of which was a forum I haven't logged into since like 2012 and completely forgot existed.

Spent about 40 minutes going through and changing the obvious ones. Turned on two-factor on Dropbox while I was in there, which took maybe ninety seconds and I have no idea why I hadn't already done it. If you use Dropbox and haven't done that, go do it now, it's under Settings > Security, and it's genuinely one of the least annoying 2FA setups I've dealt with — you get the option to use an authenticator app or just SMS codes if you're lazy about it.

What actually annoys me is how few services outside the big names even offer 2FA at all in 2014. I went through my LastPass vault (which, fine, yes, I use a password manager and have for a couple years now, and no I'm not going to stop recommending it to everyone who'll listen) and out of maybe 60 accounts in there, I think six supported any kind of second factor. Six! Your bank, sure. Google, obviously. Dropbox now. And then a long tail of shopping sites and forums where a stolen password is just... game over, forever, until you notice.

The bigger issue nobody wants to say out loud is that "don't reuse passwords" is advice that's been repeated so many times it's basically wallpaper now, everyone nods along and then reuses passwords anyway because remembering forty unique strings is a genuinely miserable task without help. A password manager fixes this almost completely and yet I still talk to people, smart people, people who build software for a living, who just don't use one. I don't fully get it. Maybe it's the setup friction, maybe it's not trusting a third party with the master keys (fair, honestly, that one I get), maybe it's just inertia.

Anyway. Nobody's Dropbox files got exposed here, which is good, and the company's response was fast and clear, which is also good — no corporate mumbling, no "we take security very seriously" nothing-statement, just a direct "here's what happened and it wasn't us." Wish more companies did the post-mortem thing that plainly.

Small thing, but if you're the type who reuses a password across a bunch of random sites (you know who you are), this is as good a nudge as any to go spend the twenty minutes. It's tedious. Do it on a Sunday with a podcast on or something. Future you will not thank you, because future you won't even know it almost happened, which is sort of the whole point.