Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is no different from password authentication, Kerberos host authentication, or SSH public key authentication, SSL authentication. If an attacker gets access to your secret or private key, your security is compromised until you revoke that credential. There’s nothing Dropbox can to do fix this on the client side, because an attacker can just run a modified version of the software. In order for Dropbox to “fix” this on the server, they’d have to do source address verification, which would break pretty much everyone except people who have static IP addresses. Even then, IP addresses can still be spoofed given a sufficiently sophisticated attacker. The only thing Dropbox could do is to break every device’s authentication whenever a user changes their password. That might be a good idea, or it might just discourage people from changing their passwords.


Well, _my_ ssh and gpg keys are password protected;)

I agree though, there is only so much Dropbox could do. Since you can already deauth a computer, it doesn't need to be done by password resets.

I think if Dropbox detects two host_id's at the same time (not just in the same time, but both after each other in, say, double the sync period) then it should deauth the host and alert the user to what's going on.


It's different in that I don't have any of my passwords or private keys sitting on disk unencrypted.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: