Most Popular Stories
- A 'mobile help desk' in every pocket, from Salesforce.com
- How hackers can eavesdrop on prevalent videoconferencing systems
- Survey finds many users blow by SharePoint security
- Risk certification answers a clear demand
- What happens when the CIO is also the CFO
- Researchers expose security holes in SCADA systems
Events
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - BlackBerry World – Register Now & Save!
May 1-3, 2012 — Orlando, FL - DrupalCon Denver: Drupal Means Business
March 20 - 23, 2012 — Denver, CO - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Results of a Survey on DevOpsTrends
- Security Intelligence: Enabling Security Monitoring for Landscapes
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- Cloud Computing: How To Make Your Own Silver Lining
Dropbox accounts left completely unprotected for four hours
A flawed code update over the weekend botched the password authentication component of Dropbox on Sunday, leaving the popular cloud storage service essentially unprotected for four hours. As reported by PC Magazine, users logging onto Dropbox between 1:54 pm and 5:45 pm on Sunday would have been able to access all the files stored in any of the 25 million accounts on Dropbox--even without typing in a password or with the wrong password.
According to InformationWeek, the flaw was made public by security researcher Christopher Soghoian after receiving a tip from a unidentified Dropbox user who found himself able to log into his account in spite of obvious typos when keying in his password. The error was fixed about five minutes after Dropbox was notified.
In an update posted on the company's blog, Dropbox founder Arash Ferdowsi admitted that the error "should never have happened." He wrote: "We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again." This fiasco is certainly a heavy blow to the reputation of the company, which is still recovering from allegations in an FTC complaint just last month that it lied to users about its data security.
For more on this story:
- check out this article at InformationWeek
- check out this article at PC Magazine
- check out this article at Examiner.com
Related Articles:
Dropbox faces FTC complaint that it lied to users about data security
Security researcher questions design of Dropbox authentication
Dropbox hits version 1.0
Fuze Box Brings Complete Webinar Support and Enhanced Dropbox
Related Stories
- Dropbox's multiple security problems
- Dropbox terms of service tweak triggers privacy scare
- Dropbox faces FTC complaint that it lied to users about data security
- Security researcher questions design of Dropbox authentication
- Dropbox hits version 1.0
- The growing problem of banking Trojans
- Floating data centers on the horizon?
- How to prep laptops for airport security
- Eventually, all data will be compromised
- Personal data on millions of veterans stolen
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |




