Dropbox Sign (formerly HelloSign) data breach

by jackconsidineon 5/1/2024, 11:19 PMwith 3 comments

by tyrelbon 5/2/2024, 4:23 AM

I use Dropbox Sign API, so a little fearful our private data was accessed.

API keys were leaked as part of this hack. It's unclear from press release if hackers used the API keys to access data/documents of customers.

April 24th they became aware of issue, reporting it over a week later. I'd also be curious on how long this problem went on before being detected on April 24?

I suppose more will come out in the coming days...

by richijon 5/2/2024, 11:19 AM

[dupe] https://news.ycombinator.com/item?id=40233746

(this item was first, but the other has more traction)

by patrickbolleon 5/2/2024, 12:29 AM

Brutal.