According to the email, Dropbox uses Lenovo as an identity provider, allowing users to authenticate to Dropbox with a verified Lenovo ID.
Dropbox says:
an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.
So, as I understand it, the attack path was roughly:
1. Attacker registers a Lenovo ID using the victim’s email address. 2. Lenovo incorrectly treats the email address as verified. 3. Dropbox trusts the Lenovo identity. 4. Attacker gets access to the Dropbox account associated with that email address.
Dropbox says it has since expired all sessions authenticated through Lenovo ID and removed the Lenovo link from my account. It also says Lenovo authentication can no longer be used for the account without first entering the Dropbox password.
I’ve searched for a public disclosure from Dropbox or Lenovo and haven’t found one yet.
Has anyone else received the same notice, or seen any public information about this vulnerability?
I’m particularly interested in knowing how broadly the Lenovo ID login mechanism was available and how many Dropbox accounts may have been affected.
About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
Another submission on HN (to Twitter).
https://news.ycombinator.com/item?id=49514471