2 ms·
To be honest I was mostly using the comments section for this link as a soapbox, I realize the idea isn't too relevant to this particular case with Dropbox, as
by FaceKicker 14y ago
To be honest I was mostly using the comments section for this link as a soapbox, I realize the idea isn't too relevant to this particular case with Dropbox, as no passwords are known to have been revealed. Sorry.
Though, I do think it would often mitigate the damage from this type of security breach that it seems like we've seen so much of from big name tech companies lately. I'd guess that a majority of accounts created on the internet are pretty unimportant to the account creator, and with how often passwords are reused indiscriminately, the worst effect of these password leaks is often not the unauthorized access to all those accounts on the hacked site but rather the usernames and passwords themselves - which are very often reused for bank, email, etc. accounts. With my proposal, anyone who opted not to have a password wouldn't be vulnerable to that.