Dropbox notified some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.

 

What happened

An unauthorized party exploited a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs using victims' email addresses. Dropbox uses Lenovo Identity Provider Services as part of its authentication infrastructure, which lets users log into Dropbox with a verified Lenovo ID. The attacker used the fraudulent Lenovo ID to log into the matching Dropbox account without needing the account password. Some affected users never had a Lenovo account at all. Dropbox determined the attacker accessed accounts between August 4 and August 21, and viewed and downloaded content from some of them.

 

Going deeper

Dropbox's identity-linking process trusted Lenovo's assertion that the attacker controlled a given email address, without requiring confirmation through Dropbox's own existing login method. Lenovo attributed the issue to a legacy integration between Lenovo ID and Dropbox, which an attacker could leverage to improperly authenticate certain Dropbox accounts. Some users noticed the Dropbox login page offering a "Continue with SSO" option tied to their email even though they had never created a Lenovo ID.

 

What was said

In its notification to impacted users, Dropbox explained, "While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address."

A Lenovo spokesperson told BleepingComputer, "Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk."

 

Why it matters

This incident shows how a flaw in one company's identity verification can compromise accounts on a separate platform, even for people who never signed up for the first company's service. Since Dropbox's system trusted Lenovo's assertion about who controlled an email address rather than confirming it through Dropbox's own login, the vulnerability bypassed the victim's Dropbox password entirely.

This is not an isolated incident, in 2020, researcher Bhavuk Jain disclosed a flaw in Apple's "Sign in with Apple" service that could have let an attacker forge a token linking any email address to their own login and take over the associated third-party account, regardless of whether the victim actually had an Apple ID. Apple paid Jain a $100,000 bug bounty for the find. That case and the current one share the same weak point, a service trusting an identity provider's claim about an email address instead of verifying it against the account's own credentials. Anyone relying on third-party identity providers for login was exposed through a channel they may not have known existed on their account.

 

The bottom line

Dropbox expired all sessions that were authenticated through Lenovo IDs and now requires users to enter their Dropbox password when attempting to use Lenovo ID authentication. Lenovo said its investigation found that its own customers were not affected, though the investigation into the incident continues.

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is an identity provider (IdP)?

An identity provider is a service that verifies who a user is and vouches for that identity to other apps, so people can log in without creating a separate password for each one.

 

What is a "single sign-on" (SSO)?

SSO lets a person use one set of login credentials to access multiple separate services without signing in to each one individually.

 

Why do companies like Dropbox let you log in through another company's account?

It's more convenient for users, who can reuse an existing login instead of creating and remembering a new password for every service.