back

by yen223·14y ago·view on hn ↗
In this case it wouldn't have helped, because the intruder apparently had access to a Dropbox employee's email account.

EDIT: Disregard what I said, apparently the attacker had access to the Dropbox employee's Dropbox account.

3 comments
To be honest I was mostly using the comments section for this link as a soapbox, I realize the idea isn't too relevant to this particular case with Dropbox, as no passwords are known to have been revealed. Sorry.

Though, I do think it would often mitigate the damage from this type of security breach that it seems like we've seen so much of from big name tech companies lately. I'd guess that a majority of accounts created on the internet are pretty unimportant to the account creator, and with how often passwords are reused indiscriminately, the worst effect of these password leaks is often not the unauthorized access to all those accounts on the hacked site but rather the usernames and passwords themselves - which are very often reused for bank, email, etc. accounts. With my proposal, anyone who opted not to have a password wouldn't be vulnerable to that.

Where do you see anything about the Dropbox employee's email account being compromised?
You are right, I misread. Thanks for pointing that out :)
If somebody managed to get read access to my email account, they still wouldn't be able to read any email sent to it - https://grepular.com/Automatically_Encrypting_all_Incoming_E...