How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

If you ever linked your Dropbox account to a Lenovo ID – perhaps to make life easier when logging in via a Lenovo laptop – you might want to take heed.

How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

If you ever linked your Dropbox account to a Lenovo ID – perhaps to make life easier when logging in via a Lenovo laptop – you might want to take heed.

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo’s own identity system, Lenovo ID.

Dropbox sent a warning to affected users about what it described as “an issue with Lenovo’s email verification process,” which saw attackers registering a brand new Lenovo ID with someone else’s email address but never verified that the user registering the ID had ownership of the email inbox.

That clearly is sloppy, but what made things much worse was that due to a legacy integration between Lenovo and Dropbox, a Lenovo ID registered against your email address could then be used to log straight into your Dropbox account – no questions asked, no Dropbox password requested.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Lenovo told Bleeping Computer that its own customers and systems were unaffected, and that “upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk.”

Dropbox attempted to put a good spin on things, telling Reuters that less than a third of affected accounts had had their files accessed in the breach.

Frankly, that would be cold comfort to me if I owned one of the Dropbox accounts that was compromised, and I would also feel disappointed that it had taken weeks to receive warning of the security breach (which was not apparently caught by monitoring at the time, but only spotted during a later investigation).

Dropbox says it has terminated all sessions authenticated through a Lenovo ID, and now requires a user’s actual Dropbox password to be entered – even when signing in through Lenovo ID, which should close the loophole.

Affected users have also been told to reset their Dropbox and email passwords, and enable two-factor authentication (2FA).

Regardless of whether you have received a warning from Dropbox or not, it only takes a few minutes to enable 2FA. Don’t just turn it on for your Dropbox account, enable it everywhere it is made available. It isn’t a 100% solution, but it can provide a higher level of protection that will defeat many attempts to compromise accounts.

This hack of 5000 Dropbox accounts was not sophisticated. It did not rely upon advanced malware, or exploit a complex zero-day vulnerability. This was simply the case of an attacker finding a glaring loophole in the security of one company’s identity system, and that it was being implicitly trusted by another’s.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed. Things could have been much much worse.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.