Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you have 2FA enabled on your Dropbox (and probably your email too), then taking just your credentials won't give the attacker access.

Also, an attacker logging in to your Dropbox would leave a trace in your activity log.



You could still be compromised in this situation if you use 1Password to store your 2FA codes.


Sure, there are scenarios where limited permissions won't make a difference, but there are also scenarios where it will make a difference, and that's what matters.

Of course, it's up to 1Password to decide whether those scenarios are a high priority or not.

edit: 1Password, not Dropbox




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: