Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Identity & Access

Dropbox Enhances Authentication Security With USB Second Factor

Dropbox customers can now protect their accounts by using a USB device as the second factor in the two-step authentication (2FA) process.

Dropbox customers can now protect their accounts by using a USB device as the second factor in the two-step authentication (2FA) process.

2FA can be a highly efficient mechanism for protecting online accounts because it prevents unauthorized access even if the username and password have been compromised. The second authentication factor is usually provided via text messages or a special application, but physical USB security keys are also becoming increasingly popular.

U2F security Key

With the addition of support for Universal 2nd Factor (U2F) security keys, Dropbox wants to enhance security while making it easy for customers to access their 2FA-protected accounts. When logging in to their account, after entering their password, users have to insert the security key into the computer’s USB port instead of typing in a 6-digit code received via SMS or an authentication app.

Dropbox has pointed out that two-step verification systems that rely on one-time passwords can be defeated by attackers who can trick victims into entering both their password and the verification code on a phishing website. Security keys are much more efficient because they use cryptographic communications to ensure that they can only be used on the legitimate Dropbox website.

Users who want to leverage the new feature must acquire a USB device compliant with FIDO U2F and add the security key to their account from the settings menu.

The new security feature currently only works on Google Chrome. Dropbox noted that customers who want to use the feature can continue to log in to their accounts by using the one-time passwords received via SMS or an authentication app when logging in from platforms or devices that don’t support U2F, or if they don’t have the security key on hand.

Advertisement. Scroll to continue reading.

The U2F keys acquired by users for their Dropbox accounts can also be used for other services, such as Google. The search giant announced the introduction of USB security keys in October 2014.

The Linux Foundation also introduced a similar 2FA authentication feature last year for developers working on the Linux kernel.

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.

AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.