Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From their FAQ: https://www.dropbox.com/help/27

  "We have strict policy and technical access controls that
   prohibit employee access except in these rare circumstances."
Perhaps they accidentally published an internal version of their authentication code which allows a Dropbox employee to view files for any account?


If such code even exists why would it require them to enter a password?


You're assuming their internal tools have the same fields and field validation requirements as public-facing login mechanisms, while is likely not the case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: