Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

'Insecure by design': the 2011 host_id flaw that let a copied config file hijack any account

April 2011

HighStatus: ResolvedProduct: Desktop clientYear: 2011

Researcher Derek Newton showed that Dropbox's desktop client stored an unencrypted authentication token (host_id) in a local config.db file — copy that one value to another machine and you owned the victim's account, with no password and no notification.

What happened

In April 2011 security researcher Derek Newton published 'Dropbox authentication: insecure by design,' revealing that the Windows client kept its login state in a local SQLite file, config.db, in the %APPDATA%\Dropbox directory. Of its fields, only host_id actually governed authentication — and that token was stored in plaintext, was not tied to the machine that generated it, and did not contain the user's password. Anyone who could read that single value could paste it into a fresh Dropbox install on another computer and begin silently syncing the victim's entire account.

Crucially, the stolen token stayed valid until the victim manually unlinked the device from the Dropbox website; changing the password did not invalidate it, and the legitimate user received no alert about the new device. Dropbox argued this was not a flaw because an attacker with local file access had already won, but in October 2011 it shipped client version 1.2.48 that encrypted the local database and added safeguards against credential theft.

Impact

The disclosure became a foundational entry in the long-running case that Dropbox's security model traded safety for convenience, and it directly anticipated the 2015 Man-in-the-Cloud token-theft research. It taught a generation of malware authors that a sync client's local token was a portable skeleton key, and it pushed Dropbox toward encrypted local storage and clearer device-management controls.

Dropbox's Response / Official Position

Dropbox initially disputed that this constituted a vulnerability, saying that once an attacker has physical access to a computer 'the security battle is already lost.' It nonetheless released client 1.2.48 in October 2011 with an encrypted local database and additional protections intended to prevent theft of the machine credentials.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation