Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Expert comment - Dropbox resetting old passwords

August 2016 by Charles Read, Regional Director of UK, Ireland and Benelux at OneLogin

With the recent news that Dropbox is resetting passwords that haven’t been changed since 2012, please find below comment from Charles Read, Regional Director – UK, Ireland and Benelux at OneLogin around the topic.

The comment looks at how, despite it being a positive move to come from a vendor as large as Dropbox, for a truly secure environment, the implementation of a single sign-on platform with SAML based authentication services is recommended.

The recent announcement that Dropbox is to force password resets on accounts that haven’t been reset since 2012 is a really positive move to come from a vendor as large as Dropbox. For consumers, it’s very common to see the same password being used for multiple services, despite contrary advice from multiple vendors. As such, the compromised LinkedIn credentials from 2012 could well be the same credentials that users still have for their Dropbox account, putting both themselves and DropBox at risk.

In the corporate world, utilising a password as the only form of authentication for multiple accounts is already considered as weak security, however we are yet to see consumers apply this approach to the protection of their personal credentials. By adopting two factor authentication on top of regular passwords it’s possible to significantly reduce the risk coming from compromised credentials. However, for a truly secure environment I would always advocate the implementation of a single sign on platform with SAML based authentication services, something that Dropbox has supported in its product for many years. Two factor authentication can then be layered on top of this technology to entirely eliminate the risk associated with stolen credentials.


See previous articles

    

See next articles












Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts