Skip to content

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

theregister.com
14 points0xmohit4 comments
On HN

Comments

Does anyone have any idea how the hardware key part worked? I was under the impression my yubikey would only send a key for a specific URL so there would be no way to just forward the key to actual github because it would be for the wrong domain.

Should we expect a source code dump soon?

No need

For a Linux user, you can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem. From Windows or Mac, this FTP account could be accessed through built-in software.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.