1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Other Drop Box Security Flaw

Discussion in 'Tech Support' started by Pookie, 16 Jul 2013.

  1. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,566
    Likes Received:
    176
    Well I just changed my Drop Box password and unbelievably all the client machines are still happily syncing away! I imagined as soon as I changed the password via the website it would break all the client machines untill the password was updated.

    Also on the client machine if i clink on the link to go to dropbox.com it auto logs in just fine with the old password! Has this alway's been the case? Has anyone else seen this?
     
    andrew8200m likes this.
  2. Atomic

    Atomic Gerwaff

    Joined:
    6 May 2002
    Posts:
    9,646
    Likes Received:
    94
    When you enter the username/password on a client it is just to link it to your dropbox account. Once linked you can change the password as the client has already authenticated and will keep the authentication token until it's unlinked manually.

    To stop a client syncing you have to do it in the client settings or via the account section on the dropbox website devices section.
     
    andrew8200m and Pookie like this.
  3. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,566
    Likes Received:
    176
    Thanks Atomic

    I did just as you said and unlinked all machines via the website. Crazy that changing the password still allows syncing but that's just my opinion. Thanks for the help again buddy :thumb: + Rep
     
  4. sparkyboy22

    sparkyboy22 Web Tinkerer

    Joined:
    3 May 2010
    Posts:
    738
    Likes Received:
    35
    This is a feature that is used by most sites/applications with shared log ins.
    I know its a different platform but facebook is another that uses the same / very similar system.
    When you use the sign in with facebook option on a site or app changing your facebook password will not prevent the others from accessing your account. This means that you dont have to go round and change the password on all the sites that you use the facebook log in for.

    Its the same with drop box so you dont have to reconfigure every client when you change your password and the ability to remotely close the link to any client on your account and delete all content means that you can easily manage those that you no longer use.
     
    andrew8200m likes this.
  5. faugusztin

    faugusztin I *am* the guy with two left hands

    Joined:
    11 Aug 2008
    Posts:
    6,953
    Likes Received:
    270
    Authorizing via username and password gives the client an access to your dropbox account, where it can request an access token via API. After that it never uses your username and password again, it authorizes via access token.

    It is called OAuth and it is used widely all over the net. Apps accessing Google Accounts ? They use it (did you notice the window where it asks you if you grant access rights to the app) ? Facebook ? They use it. Twitter ? The actually came up with the idea.

    http://en.wikipedia.org/wiki/OAuth
    https://www.dropbox.com/developers/blog/45/using-oauth-20-with-the-core-api
     
    andrew8200m likes this.
  6. mike_dowler

    mike_dowler What's a Dremel?

    Joined:
    17 Mar 2006
    Posts:
    99
    Likes Received:
    4
    Don't forget that removing Dropbox access doesn't remove the files from that device. I had a laptop stolen 3 days after it arrived - just enough time to install Dropbox and sync up. They hadn't tried to sync, so I'm hopeful that the thief simply wiped the drive. No way to stop someone accessing those files though.

    On the replacement, I installed Prey and Truecrypt straight off.
     
  7. wolfticket

    wolfticket Downwind from the bloodhounds

    Joined:
    19 Apr 2008
    Posts:
    3,556
    Likes Received:
    646
    I tried Boxcryptor a while back. Seemed to work fine, albeit without filename encryption and device limitations on the free version. Gives you that warm feeling that even Dropbox themselves can't access your files :)
     
  8. Big_malc

    Big_malc Minimodder

    Joined:
    7 Sep 2010
    Posts:
    1,627
    Likes Received:
    83
    thanks wolfticket :clap:
     

Share This Page