Dropbox got hacked and there's plenty of blame to go around in this debacle. Dropbox dropped the ball, but users made it worse. Call this a teachable moment. Dropbox, the red-hot cloud storage service admitted on Tuesday that it has been hacked. How many accounts were compromised and what data may have been stolen isn’t known, or if it is, Dropbox isn’t saying. So what’s the lesson here? There are two: No matter what vendors tell you, cloud storage isn’t, and probably never will be, completely secure. Users who still haven’t figured out that using one password on multiple sites isn’t smart are simply asking to be hacked. The Dropbox hack began to surface in mid-July when users of the file storage service noticed that they were getting spam directed to email accounts they only use to access Dropbox. That was an obvious tip-off that the leak was inside Dropbox. Once users began to post complaints about the spam to an online discussion forum, the company investigated. As late as last Friday, the company said it had no evidence of a hack. That story changed radically on Tuesday when the company announced this via a blog post by Aditya Agarwalm, the company’s VP of Engineering: SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe “Our investigation found that usernames and passwords recently stolen from other websites were used to sign in to a small number of Dropbox accounts. We’ve contacted these users and have helped them protect their accounts. “A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses. We believe this improper access is what led to the spam. We’re sorry about this, and have put additional controls in place to help make sure it doesn’t happen again.” Notice what’s going on here. On the one hand, the company is admitting that its security was lax. You know that because further down in the post is a list of four new things the company is doing to plug its leaky defenses. Then there’s this: “At the same time, we strongly recommend you improve your online safety by setting a unique password for each website you use. Though it’s easy to reuse the same password on different websites, this means if any one site is compromised, all your accounts are at risk.” The last point is a good one. I have a friend who stores important documents in Dropbox, uses passwords over and over again, and keeps track of them in an unencrypted text file. Her security strategy: “I don’t name the file ‘passwords,'” she told me. I won’t embarrass my friend by printing her name, but she’s the kind of user who opens the door to hackers. As the company points out, there are a number of tools you can use that will generate strong passwords and make it easy (and quite safe) to keep track of them. I use LastPass; Dropbox recommends iPassword. The bottom line: Dropbox needs to forget that it’s hot and trendy and remember that it won’t stay successful if it doesn’t do a better job of keeping its users safe. And users have to act like responsible adults and take responsibility for their own security. Related content feature The dark arts of digital transformation — and how to master them Sometimes IT leaders need a little magic to push digital initiatives forward. Here are five ways to make transformation obstacles disappear. By Dan Tynan Oct 02, 2023 11 mins Business IT Alignment Business IT Alignment Business IT Alignment feature What is a project management office (PMO)? The key to standardizing project success The ever-increasing pace of change has upped the pressure on companies to deliver new products, services, and capabilities. And they’re relying on PMOs to ensure that work gets done consistently, efficiently, and in line with business objective By Mary K. Pratt Oct 02, 2023 8 mins Digital Transformation Project Management Tools IT Leadership opinion The changing face of cybersecurity threats in 2023 Cybersecurity has always been a cat-and-mouse game, but the mice keep getting bigger and are becoming increasingly harder to hunt. By Dipti Parmar Sep 29, 2023 8 mins Cybercrime Security brandpost Should finance organizations bank on Generative AI? Finance and banking organizations are looking at generative AI to support employees and customers across a range of text and numerically-based use cases. By Jay Limbasiya, Global AI, Analytics, & Data Management Business Development, Unstructured Data Solutions, Dell Technologies Sep 29, 2023 5 mins Artificial Intelligence Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe