Feeds

Security researcher warns over Dropbox authentication security flaw

Knitted in insecurity

The essential guide to IT transformation

Attackers able to get their hands on a Dropbox configuration file would be able to access and download any files a user synchronises through the service without betraying any signs of compromise, a security researcher has discovered.

Derek Newton discovered that a Dropbox authentication token, stored in a config file of the Dropbox directory of a Windows PC, allows access to an associated account with the file-synchronisation service – even if a user changes his password. Dropbox allows the automatic synchronisation of files between multiple computers and mobile devices. The freemium-based service works on multiple operating system platforms and mobile devices. It also offer a web-based interface to data held through an account; these are free to consumers for storage synchronisation volumes of up to 2GB.

The Windows config file might be lifted after a machine becomes compromised via a Trojan, the most obvious attack scenario. If stolen, the host_id config file can used on any other system and the breach can only be resolved by logging into an account and revoking this credential rather than simply changing passwords. Users will not be informed if a new computer is added to a synchronisation list.

Newton blames designs flaws in the Windows version of Dropbox for what he argues is a security weakness. It is unclear whether or not Linux, Mac OS X or mobile Dropbox authentication tokens might lend themselves to similar attacks.

Arash Ferdowsi, Dropbox's CTO, contested this assessment, arguing that if an attacker succeeded in either planting a Trojan on a PC or otherwise hacking into a machine, then all the files on the system are up for grabs anyway. Nonetheless, Ferdowsi said that the design of the Dropbox client may be improved in the light of Newton's research. Possible ideas include making sure that Dropbox authentication tokens are tied to a particular system and not portable, H Security reports. ®

Boost IT visibility and business value

More from The Register

next story
Pay to play: The hidden cost of software defined everything
Enter credit card details if you want that system you bought to actually be useful
Shoot-em-up: Sony Online Entertainment hit by 'large scale DDoS attack'
Games disrupted as firm struggles to control network
HP busts out new ProLiant Gen9 servers
Think those are cool? Wait till you get a load of our racks
Silicon Valley jolted by magnitude 6.1 quake – its biggest in 25 years
Did the earth move for you at VMworld – oh, OK. It just did. A lot
VMware's high-wire balancing act: EVO might drag us ALL down
Get it right, EMC, or there'll be STORAGE CIVIL WAR. Mark my words
Forrester says it's time to give up on physical storage arrays
The physical/virtual storage tipping point may just have arrived
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.