{"id":244638,"date":"2016-08-31T15:49:17","date_gmt":"2016-08-31T15:49:17","guid":{"rendered":"http:\/\/citifmonline.com\/?p=244638"},"modified":"2016-08-31T15:49:17","modified_gmt":"2016-08-31T15:49:17","slug":"dropbox-hack-affected-68-million-users","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=244638","title":{"rendered":"Dropbox hack &#8216;affected 68 million users&#8217;"},"content":{"rendered":"<p class=\"story-body__introduction\">A Dropbox security breach in 2012 has affected more than 68 million account holders, according to security experts<\/p>\n<p>Last week, Dropbox reset all passwords that had remained unchanged since mid-2012 &#8220;as a preventive measure&#8221;.<\/p>\n<p>In 2012, Dropbox had said hacks on &#8220;other websites&#8221; had affected customers who used their Dropbox password on other sites too.<\/p>\n<p>But now what purports to be the details of 68.6 million Dropbox accounts have emerged on hacker trading sites.<\/p>\n<p>The 5GB document has been acquired by a Motherboard reporter, who also said it had been verified as genuine by a &#8220;senior Dropbox employee&#8221; speaking on the condition of anonymity.<\/p>\n<p>The data includes email addresses and hashed passwords.<\/p>\n<p>But security researcher Troy Hunt, who has also seen the document, said the hashing algorithm that obscured the passwords was &#8220;very resilient to cracking&#8221;.<\/p>\n<p>&#8220;Frankly, all but the worst possible password choices are going to remain secure even with the breach now out in the public,&#8221; he said.<\/p>\n<p>Mr Hunt said he had managed to independently verify the hack by finding the password of his wife within the cache.<\/p>\n<p>He told BBC News the document contained a &#8220;very unique, 20-character, completely random password&#8221; used by his wife to login to Dropbox.<\/p>\n<p>It had been created by a password manager, he said, making the chance of it having been correctly guessed &#8220;infinitely small&#8221;.<\/p>\n<p>Mr Hunt wrote his blog: &#8220;There is no doubt whatsoever that the data breach contains legitimate Dropbox passwords &#8211; you simply can&#8217;t fabricate this sort of thing.&#8221;<\/p>\n<p>Security researcher Ken Munro also said the hack appeared to be genuine and to have &#8220;taken place in 2012&#8221;.<\/p>\n<p>In a statement sent to the BBC, Dropbox said: &#8220;This is not a new security incident.&#8221;<\/p>\n<p>And there was &#8220;no indication&#8221; Dropbox user accounts had been improperly accessed.<\/p>\n<p>&#8220;Our analysis confirms that the credentials are user email addresses with hashed and salted passwords that were obtained prior to mid-2012,&#8221; said the statement.<\/p>\n<p>&#8220;We can confirm that the scope of the password reset we completed last week did protect all impacted users.<\/p>\n<p>&#8220;Even if these passwords are cracked, the password reset means they can&#8217;t be used to access Dropbox accounts.&#8221;<\/p>\n<p>Meanwhile, on Tuesday the password management service OneLogin &#8211; of which Dropbox is a client &#8211; revealed that a user gained access to one of its systems used for log storage and analytics.<\/p>\n<p>Alvaro Hoyos, chief information security officer at OneLogin, has said that this incident is not connected to the Dropbox hack.<\/p>\n<p>&#8220;We have no indication that OneLogin&#8217;s August 2016 incident is connected to any further incidents currently in the news,&#8221; Mr Hoyos told the BBC.<\/p>\n<p>&#8220;To reiterate what our recent blog post stated, the impacted system is a standalone system and there are no signs of suspicious activity in any of our other systems.<\/p>\n<p>&#8220;The security of our customers is of the utmost importance and we are carrying out an extensive investigation in partnership with a third-party cybersecurity firm. We are advising impacted customers as soon as any additional information becomes available as a result of the investigation.&#8221;<\/p>\n<p>&#8211;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Dropbox security breach in 2012 has affected more than 68 million account holders, according to security experts Last week, Dropbox reset all passwords that had remained unchanged since mid-2012 &#8220;as a preventive measure&#8221;. In 2012, Dropbox had said hacks on &#8220;other websites&#8221; had affected customers who used their Dropbox password on other sites too. [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":244639,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[106],"tags":[],"class_list":["post-244638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/244638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=244638"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/244638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/media\/244639"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=244638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=244638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=244638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}