http://www.informationweek.com/news/security/vulnerabilities/231000111

(From the article)

Dropbox on Monday acknowledged that its vast store of files was left open to 
the world on Sunday for four hours as a result of a bug. During this period, 
any account could be accessed using any password.

………

In March, the security of Dropbox's Android mobile client came under fire when 
security researcher Mike Cardwell revealed 
<https://grepular.com/Dropbox_Mobile_Less_Secure_Than_Dropbox_Desktop>  that 
the app was transmitting file metadata without SSL encryption. 

The following month, Ferdowsi and Drew Houston, co-founder and CEO, explained 
that they had decided to favor performance over security because "enabling SSL 
for all metadata transfers made the app several times slower." They also 
acknowledged Cardwell's concerns and said they were working on a way to send 
metadata over SSL more efficiently in their mobile apps. 

 

Reply via email to