[ISN] Dropbox confirms it got hacked, will offer two-factor authentication

From: InfoSec News <alerts_at_private>
Date: Wed, 1 Aug 2012 04:15:53 -0500 (CDT)
http://arstechnica.com/security/2012/07/dropbox-confirms-it-got-hacked-will-offer-two-factor-authentication/

By Jon Brodkin
Ars Technica
July 31, 2012

A couple of weeks ago Dropbox hired some "outside experts" to 
investigate why a bunch of users were getting spam at e-mail addresses 
used only for Dropbox storage accounts. The results of the investigation 
are in, and it turns out a Dropbox employee’s account was hacked, 
allowing access to user e-mail addresses.

In an explanatory blog post, Dropbox today said a stolen password was 
"used to access an employee Dropbox account containing a project 
document with user email addresses." Hackers apparently started spamming 
those addresses, although there’s no indication that user passwords were 
revealed as well. Some Dropbox customer accounts were hacked too, but 
this was apparently an unrelated matter. "Our investigation found that 
usernames and passwords recently stolen from other websites were used to 
sign in to a small number of Dropbox accounts," the company said.

Dropbox noted that users should set up different passwords for different 
sites. The site is also upping its own security measures. In a few 
weeks, Dropbox said it will start offering an optional two-factor 
authentication service. This could involve users logging in with a 
password as well as a temporary code sent to their phones.

[...]


--
Learn how to be a Pen Tester, CISSP, ISSMP, or ISSAP with Expanding Security online.
Come to a free class and see how good and fun the program really is.
http://www.expandingsecurity.com/PainPill
Received on Wed Aug 01 2012 - 02:15:53 PDT

This archive was generated by hypermail 2.2.0 : Wed Aug 01 2012 - 02:51:16 PDT