Flaw In Dropbox SDK For Android Lets Attackers Steal Data Sent To Users' Account 23
An anonymous reader writes: Researchers from IBM's security team have discovered an authentication flaw in the Dropbox Software Development Kit (SDK) for Android that can be exploited to capture new data a user saves to its Dropbox account. The flaw has been extensively documented by the researchers in a blog post, but the things you initially need to know are these: the vulnerability can be exploited if you use an app that uses a Dropbox SDK Version 1.5.4 through 1.6.1 (the latest one is v1.6.3), or if you visit a specially-crafted malicious page with your Android web browser targeting that app, and that's only if you don't have the Dropbox for Android app installed. Also, an attacker can't access the data you have previously stored in your Dropbox account.
Dropbox going to cut-off insecure apps? (Score:1)
Is there a way for Dropbox to block log-in access from apps that have not been updated to the latest SDK?
This would keep the users safe and put pressure on the app developers to update.
dropbox is run by retards (Score:1)
just like all other 3rd party cloud solutions.
you're all idiots.
Dropbox (Score:1)
They offer something Google Drive doesn't? I only ask because I wonder why anybody would clutter up their phones and tablets with duplicate programs.
Re: (Score:3, Insightful)
They offer something Google Drive doesn't?
Linux support.
Block the flaw (Score:4, Informative)
funny (Score:2, Insightful)
I discontinued the use of Dropbox right after they announced Condi Rice was joining their board. Someone who rampantly supported the domestic spying initiatives sitting for a company that claims to value user privacy sounds like the punchline of a joke. Now we see stories about the NSA repeatedly trying to insert and exploit vulnerabilities into software and products... suspect? yes.
So what online storage is safe? (Score:2)
None of them in my opinion based on what I've read.
Re: (Score:2)
If you' are not encrypting the stuff before they get it. You're a fool.
I don't see the point when my NAS is available, I use Openvpn and it's trivial to setup securely. Changes are encrypted and stored on that miraculous thing called a server I own that is co-located on a remote island. It is cheap and I only store encrypted backups on it.
I am taking notes on what else I should do to protect that stuff further. ;)
Condolezza Rice is on the Dropbox board (Score:2, Informative)
That's all you need to know. [dropbox.com]
Don't use Dropbox.
Users' Account (Score:2)