2 ms·
Yes, systems can definitely fake any ID you attempt to use: MAC addresses, machine IDs, hostnames, etc. Attackers can intercept rekey attempts and clone the new
by mryall 16y ago
Yes, systems can definitely fake any ID you attempt to use: MAC addresses, machine IDs, hostnames, etc. Attackers can intercept rekey attempts and clone the new key on their systems. But arguing that these improvements shouldn't be done because they don't totally close every security vulnerability in a system is an example of Perfect Solution fallacy [1]. Just because security cannot be perfect doesn't mean that steps to improve it shouldn't be taken.
The advantage of rekeying or secondary verification of the client is that it addresses the kind of attack where you can simply copy this metadata and have enough information to remotely compromise the Dropbox data later. As you say, whether that is worth fixing is up to Dropbox to do a cost-benefit analysis. But I hope they wouldn't discard the chance to improve their security simply because a perfectly secure system isn't possible.
[1] http://en.wikipedia.org/wiki/Nirvana_fallacy#Perfect_Solution_Fallacy http://en.wikipedia.org/wiki/Nirvana_fallacy#Perfect_Solutio...