Dropbox breach Alert: How a Lenovo ID flaw turned federated login into an account-takeover path

https://wp.me/pfPk8e-6nb

Attackers allegedly registered Lenovo IDs using victims' email addresses, then used Dropbox SSO / OIDC federation to authenticate as those users. The key failure was email-based account matching across a federated trust boundary. In other words: Email address ≠ proof of account ownership. Dropbox knew it since the first week of August yet notification emails were sent to all customers today

22 points · 3 comments · view on lemmy.world

3 Comments

bamboo@lemmy.blahaj.zone · 2 pts · 9d (1 reply)

Not sure what wp.me is but seems like a tracking redirect. This is the link to the actual article without the redirect tracking: https://thecybersecguru.com/news/dropbox-breach-lenovo-id-account-takeover/

UnLocoPoco@lemmy.world · 1 pts · 9d

Nah. Just that its the sharing url mechanism of jetpack

nathan@piefed.alphapuggle.dev · 1 pts · 9d

Slop writeup, but from what I've gathered is Dropbox wasn't checking email_verified: true and lenovo would let you otherwise have a fully functional account without a verified email