Cloud storage provider Dropbox has implemented two-factor authentication to bolster security after experiencing a breach earlier this year.
The company announced plans July 31 to deploy an authentication approach that would require two forms of identification before users can sign in. The change followed the revelation that usernames and passwords stolen from other sites had been used to sign into a number of Dropbox accounts, including one belonging to a Dropbox employee. The employee’s account contained a “project document” with user email addresses that the company has said were used to launch a spam campaign.
In order to get the improved security, users need to upgrade to version 1.5.12 and turn the feature on. Users can choose to receive a six-digit PIN code that will be text-messaged to their mobile phones when a new device is used to access their account. Users can also utilize several mobile apps that support the Time-based One-time Password algorithm.
The company also said previously that it had added new automated mechanisms to pinpoint suspicious activity as well as a new page that lets users examine all active log-ins to their account and in some cases requires users to change their passwords – for example, if the password is common or hasn’t been changed in a long time.
“At the same time, we strongly recommend you improve your online safety by setting a unique password for each Website you use,” Dropbox engineer Aditya Agarwal blogged in July. “Though it’s easy to reuse the same password on different Websites, this means if any one site is compromised, all your accounts are at risk. Tools like 1Password can help you manage strong passwords across multiple sites.”
More from Brian Prince
- U.S. Healthcare Companies Hardest Hit by ‘Stegoloader’ Malware
- CryptoWall Ransomware Cost Victims More Than $18 Million Since April 2014: FBI
- New Adobe Flash Player Flaw Shares Similarities With Previous Vulnerability: Trend Micro
- Visibility Challenges Industrial Control System Security: Survey
- Adobe Flash Player Zero-Day Exploited in Attack Campaign
- Researchers Demonstrate Stealing Encryption Keys Via Radio
- Researchers Uncover Critical RubyGems Vulnerabilities
- NSA, GCHQ Linked to Efforts to Compromise Antivirus Vendors: Report
Latest News
- Malicious NPM, PyPI Packages Stealing User Information
- VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
- 98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis
- Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
- Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform
- Ransomware Leads to Nantucket Public Schools Shutdown
- Stop, Collaborate and Listen: Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing
- Boxx Insurance Raises $14.4 Million in Series B Funding
