Attackers allegedly registered Lenovo IDs using victims’ email addresses, then used Dropbox SSO / OIDC federation to authenticate as those users. The key failure was email-based account matching across a federated trust boundary. In other words: Email address ≠ proof of account ownership. Dropbox knew it since the first week of August yet notification emails were sent to all customers today

  • Nate@piefed.alphapuggle.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 days ago

    Slop writeup, but from what I’ve gathered is Dropbox wasn’t checking email_verified: true and lenovo would let you otherwise have a fully functional account without a verified email