← Back to context

Comment by ThePhysicist

4 days ago

Damn, big security fuckup by Dropbox, how can they portray that as an issue with Lenovo's e-mail verification process? You should never allow linking of an existing account with a new login method without first confirming that the user is able to sign in with an existing method first! Everyone knows this allows easy account takeovers otherwise, that's such a trivial attack vector, truly a scenario you could pose to a junior security engineer in an interview.