The 2011 authentication bug: any password unlocked any account
June 2011
For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.
What happened
On 19 June 2011 Dropbox pushed a code change that broke its authentication system. In a post titled 'Yesterday's Authentication Bug,' published the next day, Dropbox co-founder Arash Ferdowsi wrote: 'Hi Dropboxers, Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm.' For close to four hours — from 1:54pm to 5:46pm Pacific time (PDT) — the password check on Dropbox's servers was broken, so some accounts could be opened without the correct password.
TechCrunch reported on the bug that same afternoon, in a piece by Jason Kincaid titled 'Dropbox Security Bug Made Passwords Optional For Four Hours.' It quoted an affected user who wrote: 'I found I was able to log into my account using an incorrect password.' TechCrunch published a reply it said came from Dropbox CTO Arash Ferdowsi ('according to the Pastebin post,' as the outlet put it) reading: 'there was a very brief glitch and this should never happen/be possible again.'n Dropbox's own figures on the scale narrowed as its investigation continued. The original post said: 'A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.' Four days later, in an update appended to the same post, Dropbox gave a far more precise final count, telling users: 'According to our records, there were fewer than a hundred affected users and neither account settings nor files were modified in any of these accounts.'
Dropbox said it emailed everyone who had logged in during the window with details of the activity on their account and closed its original post with: 'This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.'
Impact
The bug became a reference point in the debate over Dropbox's security architecture. Weeks earlier, researcher Christopher Soghoian had filed an FTC complaint accusing Dropbox of misleading users about how its encryption worked; the authentication bug appeared to validate the underlying concern that Dropbox could access user files and that its server-side model created a single point of catastrophic failure. It durably damaged trust among privacy-conscious users and fueled the market for 'zero-knowledge' competitors.