Yeah, that's kind of what I'm curious about: did Dropbox learn about it through that guy's discovery? If so, we're lucky that that guy came across it the very same day the bug was introduced. I'd assume there aren't that many people who would have found the security hole, been nice not to abuse it and cared enough to let Dropbox and the world know…