About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.
I got this same email about an hour ago.
About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.
One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.
This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.
> Has anyone else received the same notice, or seen any public information about this vulnerability?
Another submission on HN (to Twitter).
https://news.ycombinator.com/item?id=49514471