Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2011 authentication bug: any password unlocked any account

June 2011

CriticalStatus: Resolved fewer than a hundred, per Dropbox's final count (initially described as 'much less than 1 percent' of accounts that logged in during the window) affectedProduct: Core syncYear: 2011

For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.

What happened

On 19 June 2011 Dropbox pushed a code change that broke its authentication system. In a post titled 'Yesterday's Authentication Bug,' published the next day, Dropbox co-founder Arash Ferdowsi wrote: 'Hi Dropboxers, Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm.' For close to four hours — from 1:54pm to 5:46pm Pacific time (PDT) — the password check on Dropbox's servers was broken, so some accounts could be opened without the correct password.

TechCrunch reported on the bug that same afternoon, in a piece by Jason Kincaid titled 'Dropbox Security Bug Made Passwords Optional For Four Hours.' It quoted an affected user who wrote: 'I found I was able to log into my account using an incorrect password.' TechCrunch published a reply it said came from Dropbox CTO Arash Ferdowsi ('according to the Pastebin post,' as the outlet put it) reading: 'there was a very brief glitch and this should never happen/be possible again.'n Dropbox's own figures on the scale narrowed as its investigation continued. The original post said: 'A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.' Four days later, in an update appended to the same post, Dropbox gave a far more precise final count, telling users: 'According to our records, there were fewer than a hundred affected users and neither account settings nor files were modified in any of these accounts.'

Dropbox said it emailed everyone who had logged in during the window with details of the activity on their account and closed its original post with: 'This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.'

Impact

The bug became a reference point in the debate over Dropbox's security architecture. Weeks earlier, researcher Christopher Soghoian had filed an FTC complaint accusing Dropbox of misleading users about how its encryption worked; the authentication bug appeared to validate the underlying concern that Dropbox could access user files and that its server-side model created a single point of catastrophic failure. It durably damaged trust among privacy-conscious users and fueled the market for 'zero-knowledge' competitors.

Dropbox's Response / Official Position

Dropbox disclosed the bug publicly the next day in a post titled 'Yesterday's Authentication Bug,' signed by co-founder Arash Ferdowsi, apologized, and said it had ended all logged-in sessions as a precaution. Over the following days it posted three further updates, ultimately telling affected users: 'According to our records, there were fewer than a hundred affected users and neither account settings nor files were modified in any of these accounts.' It said it was scrutinizing its controls and adding safeguards to prevent a recurrence.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation