Dropbox 数据泄露

8 分•作者: hmate9•27 天前•原帖
我今天收到了来自Dropbox的安全通知,称我的账户在2026年8月4日至8月21日期间被未经授权访问,Dropbox认为账户中的文件可能已被查看或下载。 根据邮件内容,Dropbox使用联想作为身份提供者,允许用户通过经过验证的联想ID进行身份验证。 Dropbox表示: 联想的电子邮件验证过程存在问题,导致未经授权的人员使用我的电子邮件地址注册了一个联想ID,并利用该联想ID登录到与该电子邮件地址关联的Dropbox账户。 因此,我理解攻击路径大致如下: 1. 攻击者使用受害者的电子邮件地址注册一个联想ID。 2. 联想错误地将该电子邮件地址视为已验证。 3. Dropbox信任联想身份。 4. 攻击者获得对与该电子邮件地址关联的Dropbox账户的访问权限。 Dropbox表示,它已使所有通过联想ID进行身份验证的会话失效,并从我的账户中移除了联想链接。它还表示,未经输入Dropbox密码,账户无法再使用联想身份验证。 我搜索了Dropbox或联想的公开披露信息,但尚未找到。 有没有其他人收到相同的通知,或者看到关于此漏洞的任何公开信息? 我特别想知道联想ID登录机制的可用范围有多广,以及可能有多少个Dropbox账户受到影响。
查看原文
I received a security notice from Dropbox today saying that my account was accessed without authorization between August 4 and August 21, 2026, and that Dropbox believes files in the account were viewed or downloaded.<p>According to the email, Dropbox uses Lenovo as an identity provider, allowing users to authenticate to Dropbox with a verified Lenovo ID.<p>Dropbox says:<p>an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.<p>So, as I understand it, the attack path was roughly:<p>1. Attacker registers a Lenovo ID using the victim’s email address. 2. Lenovo incorrectly treats the email address as verified. 3. Dropbox trusts the Lenovo identity. 4. Attacker gets access to the Dropbox account associated with that email address.<p>Dropbox says it has since expired all sessions authenticated through Lenovo ID and removed the Lenovo link from my account. It also says Lenovo authentication can no longer be used for the account without first entering the Dropbox password.<p>I’ve searched for a public disclosure from Dropbox or Lenovo and haven’t found one yet.<p>Has anyone else received the same notice, or seen any public information about this vulnerability?<p>I’m particularly interested in knowing how broadly the Lenovo ID login mechanism was available and how many Dropbox accounts may have been affected.