Skip to main content

Dropbox authentication gaffe exposes users’ files

dropbox-logo-large
Image used with permission by copyright holder

Online storage service Dropbox—popular for its seamless mobile and desktop client software—accidentally disabled password authentication on its service for four hours yesterday. Although Dropbox says less than one percent of its 25 million accounts were accessed during that time, the gaffe does mean that all users’ content—potentially including email, documents, photos, videos, passwords, and more—were exposed to the whole Internet until Dropbox corrected the issue.

According to Dropbox CEO Arash Ferdowsi, Dropbox began rolling out a code change just before 2PM PDT on June 20 that exposed an issue in Dropbox’s authentication system that would enable logins without a correct password. Dropbox found the problem four hours later and severed all active connections to the service, re-instating normal authentication.

Recommended Videos

“We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed,” Ferdowsi wrote. “If we identify any specific instances of unusual activity, we’ll immediately notify the account owner.” The company says that all accounts logged in during the period should now have received an email message with additional security information.

The gaffe follows controversial changes to Dropbox’s privacy policy and re-statement of its content encryption process, which have sparked a complaint to the Federal Trade Commission. Dropbox has characterized the complaint as meritless.

Dropbox’s authentication failure highlights some of the risks of cloud-based storage: while users appreciate the convenience and elegance of Dropbox storage and being able to access it cleanly from a number of devices and services, the bottom line is that users are trusting their data to third parties, and operational glitches seem all too common the burgeoning cloud world.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
How to store files on OneDrive on Windows 10
windows search down fix 10 cortana laptop 768x768

OneDrive is Microsoft's cloud storage platform, and it's fully integrated into Windows 10, making it a great choice for file sharing and cloud backups among your devices. You can move files and folders to and from your OneDrive in a few different ways, but none of them are complicated, and all of them are quick. Here's how to store files on OneDrive on Windows 10.

Interested in other cloud storage options? Check out our guide to the best cloud backup clients.
Step 1: Open the OneDrive folder

Read more
The best cloud storage options to support your small business

If you've got limited physical hard drive space or you simply want to keep your files safely backed up elsewhere, cloud storage is a huge help. When it comes to small business, such data and files is even more valuable. After all, it's bad enough if you lose personal photos or information, but losing vital data in your business could cost you a lot of time and money, as well as potentially your reputation.

We've checked out the best cloud storage services for your small business, looking at what's best depending on the size of your company, as well as any potential requirements you might have for how your data is accessed such as end-to-end encryption or two-factor authentication. We've also looked at some cloud services which offer free storage for a limited time, or up to a certain amount of space. Products like Apple's iCloud service, OneDrive, and Google Drive often provide some free cloud storage to get you started with their services.

Read more
Nvidia celebrates Trump, slams Biden for putting AI in jeopardy
The Nvidia RTX 5090 GPU.

In response to new export restrictions placed on AI GPUs, Nvidia posted a scathing blog criticizing the outgoing Biden-Harris administration. The administration's Interim Final Rule on Artificial Intelligence Diffusion largely targets China with restrictions on AI GPUs, according to Newsweek.

Nvidia disagrees. "While cloaked in the guise of an 'anti-China' measure, these rules would do nothing to enhance U.S. security. The new rules would control technology worldwide, including technology that is already widely available in mainstream gaming PCs and consumer hardware. Rather than mitigate any threat, the new Biden rules would only weaken America’s global competitiveness, undermining the innovation that has kept the U.S. ahead," wrote Nvidia's vice president of government of affairs Ned Finkle.

Read more