27 ms·
How Dropbox Hacks Your Mac
- rrdharan 10y agoDropbox posted an article in their Help Center explaining what they're doing: https://www.dropbox.com/help/9266 https://www.dropbox.com/help/9266 [Disclosure: I used to work at Dropbox.]
- ejcx 10y agoJust wanted to give the author a shoutout for being awesome. This article is published with an AMP version[0] too, which is pretty unusual for smaller blogging sites. AMP articles are so much easier on my eyes (and the author can't include their own javascript on an AMP page, so there is less bloat). I wish all bloggers started to publish AMP pages. [0] - http://applehelpwriter.com/2016/08/29/discovering-how-dropbox-hacks-your-mac/amp/ http://applehelpwriter.com/2016/08/29/discovering-how-dropbo...
- look_waldo 10y agoI agree, it was a great read!
- blowski 10y agoKudos to the OP for doing it, and for anyone using WordPress, it's pretty easy for you to do it too: https://wordpress.org/plugins/amp/ https://wordpress.org/plugins/amp/
- nathancahill 10y agoThis is how the entire web should be, honestly.
- gibrown 10y agoThe site is running on WordPress.com where every site has AMP enabled: https://en.blog.wordpress.com/2016/02/24/amp-for-wordpress-dot-com/ https://en.blog.wordpress.com/2016/02/24/amp-for-wordpress-d... AMP integration still a work in progress, but getting better: https://github.com/Automattic/amp-wp https://github.com/Automattic/amp-wp
- tqkxzugoaupvwqr 10y agoAMP is not the solution. Anyone willing to use AMP to reduce bloat could also just not add bloat to HTML pages in the first place. And, using AMP itself adds bloat[1]. I couldn’t even read the author’s AMP version without enabling JavaScript. [1] https://www.ampproject.org/docs/get_started/create/basic_markup.html https://www.ampproject.org/docs/get_started/create/basic_mar...
- pvdebbe 10y agoI can read all mentioned pages with NoScript enabled. But fully agreed that static pages such as blogs shouldn't require JS to show the primary content.
- pyre 10y agoThat depends. What about blog posts that have inline JS demos?
- pvdebbe 10y agoThat would be a reasonable exception. Of course, I'd only give the page a 5/5 rating if the JS code would be still readable even if no output would be produced.
- nkrisc 10y agoClearly that's an exception, I don't think that really needs to be discussed or considered when talking about static blogs not needing JavaScript.
- pvdebbe 10y agoOne example: in my static blog I provide very nice maths using MathJax, but I also provide fallback PNG renders of the formulae. The small JS my blog has, it reads these pictures' alt texts and renders the latex if found. This stuff is not rocket science, people just don't want to spend time on this kind of stuff.
- 10y ago
- jads 10y ago> I wish all bloggers started to publish AMP pages. I wish all bloggers with sites so bloated that AMP is a fundamental difference didn't feel they needed to include large image assets, custom fonts, and fancy JavaScript libraries (not suggesting this blogger does - just a general complaint).
- bitwize 10y agoWhy not an "HTML with minimal styles and no JavaScript" version? Oh wait, that's not reactive.
- djsumdog 10y agoIt can be: http://motherfuckingwebsite.com/ http://motherfuckingwebsite.com/
- bitwize 10y agoBut nobody actually makes web sites like that any more. Have you seen the one for Emacs? It looks like a page for some barista's Node.js side project, it's got so much hipster cruft now.
- dredmorbius 10y agoEver so slightly more polished: https://codepen.io/dredmorbius/full/KpMqqB/ https://codepen.io/dredmorbius/full/KpMqqB/
- mcbits 10y agoThat's hard on the eyes, and the headings look like links. The top-level headings look just plain broken when they wrap.
- dredmorbius 10y agoWrapping is all-but-inevitable given dynamic display widths. What would your preference be? Smaller fonts for headers?
- mcbits 10y agoIt's the bottom border that looks off when wrapping. Since the headings are already distinguished by whitespace, size, weight, and color, the border doesn't really add anything. Overall, the page is not conveying a hierarchy to me at all. It looks very disjointed. My preference would be to remove the borders/underlines, also remove the bold, and make the margins equal above and below the h3+ headings. If I were to actually use more than three headings, I'd probably do something completely different at the deepest levels (e.g. inline the headings or indent the whole text). But I think we agree that it's worth some effort to fix up the browser's default styles. It's too bad they can't all just switch to something like Firefox's reader view without breaking the web.
- mmagin 10y agoHey, I remember WAP!
- smpetrey 10y agoIn case there are any Wordpress bloggers and authors out there who would like to add AMP functionality to their websites Automattic put together a nice plugin tool to do just that.[0] I wonder when this will become part of the wp-core? [0] https://github.com/Automattic/amp-wp https://github.com/Automattic/amp-wp
- snowwrestler 10y agoI hope never. This is clearly the sort of thing that should be optional--which is exactly why Wordpress has a plugin system.
- JoshMnem 10y agoAMP is terrible for publishers though. It would be better if the site would publish simpler HTML/JS than use AMP.
- gr2020 10y agoI'd be a lot happier with AMP if they'd stop hijacking the scrolling behavior on iOS (speed and momentum is different than on a regular web page). It drives me absolutely crazy.
- breatheoften 10y agoOh no!! I never heard of AMP before but now I hate it with a passion. Anything that spreads the terrible gmail style scrolling behavior is all bad in my eyes.
- deleted 10y ago[deleted]
- kmfrk 10y agoGonna plug Micro Snitch, which is Little Snitch, but for your microphone and webcam: https://www.obdev.at/products/microsnitch https://www.obdev.at/products/microsnitch. (No affiliation.)
- mixologic 10y agoI love Little Snitch and have used it for years, didnt know this existed, Thanks!
- tomku 10y agoNon-clickbait title: "How Dropbox uses the root access that you give it during installation to give itself Accessibility authorization without triggering the usual popup".
- hyh1048576 10y agoGreat summary. But it's still some kind of hack. If every app I installed did this then my mac is closer to getting hacked. Anyway, Apps that asks for root password on installation always makes me cringe, e.g. they could turn on SSH and put a pubkey into authorized_keys, or they could upload SSH identity files. But I still proceed to enter my password.
- gruez 10y agoHow's that any different compared to Linux? AFAIK apt packages can run arbitrary scripts as root.
- Sir_Cmpwn 10y agoGreat article, but poor conclusion. He finds that Dropbox is untrustworthy, a finding that likely surprises no one, and reaches for iCloud as the solution. Why move into another walled garden driven by corporate interests? OwnCloud or a similar self hosted solution would be better. I just use NFS and a dead simple storage server to make ~/shared available on all of my machines.
- erikb 10y agoIn many cases self hosted is better. One needs to consider that this also needs some time to maintain, though. Personally I also like ownCloud but still mostly use Dropbox.
- pat2man 10y agoWhat happens when you take a laptop to another network?
- Sir_Cmpwn 10y agoEverything freaks out, unfortunately. I would work on a better solution, but I'm not particularly inconvenienced by this issue.
- pyre 10y agoIsn't a bit naive to think that your solution, which has obvious flaws is one-size-fits-all? I use cloud storage (e.g.) have access to my password file between my computers and my mobile devices. NFS shares on ~/share that only work on the local network don't really solve this issue.
- Sir_Cmpwn 10y agoDid I say it was a one-size-fits-all, or that it was flawless? I also suggested OwnCloud before describing my own setup. All of your software choices come with tradeoffs. For my passwords I use pass and store them in a private git repo on a server I trust. http://password-store.org http://password-store.org
- ptomato 10y agoIt looks like in 10.12 Apple has added TCC.db to SIP, so this will no longer work — Dropbox will, hopefully, actually be forced to request accessibility access like they're supposed to. I'm sure they'll still demand your admin password via a dialog that tries super hard to look like a system one to use for whatever other more or less nefarious purposes. Would be nice if there was an alternative that actually syncs as reliably and performantly, but in my testing that's very much not the case. I appreciate the trend of Apple forcing Dropbox to stop doing dumb shit, though. (Previously, of course, the SIMBL-style Finder hacking)
- perfectfire 10y agoI use owncloud (and then dropbox inside it so some files are double backed up). I find it to be just fine. Have you had any problems with it?
- ptomato 10y agoYes, last time I tried it, had a variety of conflict issues plus the client had some problems, performance and otherwise. If you're just using it as a backup solution (does it even keep file history?) from a single machine + mobile/web access, it may well work acceptably.
- perfectfire 10y agoI had couple conflicts in the few years Ive used it, but they were few and were actual conflicts (a file on a client was updated at the same time the server copy was updated). It does keep a limited file history. I'm not really using it for file history so I'm not sure exactly what the rules are for retaining old versions.
- nameauser 10y agoBeing curious. What is "a variety of conflict issues"? Also could you perhaps expand on "the client had some problems"? Which client? I know an official Windows client exists as well as an Android client (this latter I use), but all communications are via HTTP (DAV for file transfers / calendar / etc. & REST for admin stuff), which means that a specific client is not necessary. Personally, I use KDE's file manager (Dolphin). Plus a curl-cased Bash script for when I need to upload an arbitrary file from one of my home computers via my phone (SSH from phone to computer, sometimes over sat link, run "~/bin/upload.sh /some/file"). I manage my own ownCloud servers (one personal, one company), but hosted options are available. And yes, it does keep file history (optional, enabled by default), as well as encrypted storage (optional, disabled by default). Neither the client, nor the server even, require any administrative access.
- f_allwein 10y agoFor what it's worth, I posted on the Dropbox support forum asking them to explain. This seems to be the only way to contact them: https://www.dropboxforum.com/hc/en-us/community/posts/208945183--Dropbox-s-dirty-little-security-hack- https://www.dropboxforum.com/hc/en-us/community/posts/208945...
- 0x0 10y agoWhat the fuck Dropbox! How do I get rid of the backdoor in /Library/Application\ Support/com.apple.TCC/TCC.db even after uninstalling Dropbox.app and rm -rf'ing ~/.dropbox and /Library/DropboxHelperTools? Do I just sudo sqlite3 and delete the row? Or is there an official tool (tccutil)? Edit: Crap, there's a /Library/Extensions/Dropbox.kext too now. :(
- ptomato 10y agoshould be able to just uncheck Dropbox.app in SysPrefs -> Security & Privacy -> Privacy -> Accessibility
- 0x0 10y agoIt's not visible there, probably because I obliterated the Dropbox.app file. Currently rm -rf'ing the kext after kextunloading it and seeing the kextcache rebuilding. Why should I trust a company that gets its customer database leaked with a kext that they install via shady deceiving permission dialogs?! Uninstalled. Good riddance.
- hughw 10y agoNo, that works only until your next reboot. DB has installed an agent that resets that setting in TCC.db a few seconds after you log in next.
- ptomato 10y agoPer the person I replied to, he uninstalled Dropbox and removed the agent.
- sigjuice 10y agoI tried this, but looks like Dropbox shenanigans are able to silently turn it back on.
- djrogers 10y agoNot in Sierra
- devy 10y agoIf Dropbox app can do this, other apps can too! I wonder if this will get to Apple's attention to "fix" it?
- gruez 10y agoThe fact that any application can spoof the os password prompt makes me wonder why they don't have a prominent feature to show the prompt is from the OS. On windows there is the secure desktop with the dimming effect.
- nathancahill 10y agoBecause Macs don't get viruses /s
- coldtea 10y agoWell, in theory they might, in practice they don't. Almost all of the viruses reported for Macs were in fact Trojans. And even if there were a few legitimate viruses over the years, none went very far as to cause much trouble to any sizeable number of people. Contrast with the barrage of Windows viruses and widespread mayhem they cause, on a platform were almost everybody uses an antivirus too. It's not "just" due to the Mac being less popular either. Mac OS up to 9 got lots of viruses back in the day, and Macs had just 1 to 2% market share in the US. Nowadays they have several times that. So yeah, on my Mac and Linux boxes, I'll care about viruses to the point of running an antivirus or such when people actually start getting some...
- pritambaral 10y agoIs the "secure desktop with dimming effect" not spoofable?
- sbarre 10y agoIt probably is, but it would be near-impossible for a respectable company to claim that they weren't specifically trying to spoof it. With the current OS X password prompt being a benign looking window, Dropbox (or others) can easily say they're just "following standard UI patterns" or something like that.
- BinaryIdiot 10y agoNot really. Sure you can make a replica of it but it won't behave the same because you'll be able to minimize or close it but the secure desktop you can't do jack to until you either accept to decline whatever it's asking.
- new299 10y agoDropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board (http://www.drop-dropbox.com/ http://www.drop-dropbox.com/). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the security of my data, and I wont be using their service.
- BinaryIdiot 10y agoHonestly they're pretty much the most expensive out of all of the storage solutions. Other than versioning they have less features than their competition as well. If they were born today I can't imagine they would have gone much of anywhere. Not sure how they're doing financially today but it seems each product they create flops. So even outside of this surveillance stuff I don't get the point in using them.
- krrrh 10y agoTheir client just works better at syncing quickly and reliably. A huge criteria for me is how much CPU it uses in the background compared to competing solutions from Google or MS and it was often an order of magnitude less (other clients may have improved in the last year or two, I haven't checked). Another significant advantage is that they support a stable command line client for Linux.
- rcarmo 10y agoThis. I cannot stress how important both of these factors are. I still haven't found a solution other than (http://meocloud.pt http://meocloud.pt, which was implemented by my former colleagues) that was within an order of magnitude as fast and/or as light in terms of CPU load, _and_ that supported Linux directly (let alone had halfway decent MacOS support).
- fapjacks 10y ago
- djabatt 10y agoI wonder if Apple will thwart this hack with an update. Seems like anyone reading this will start using this hack. In the meantime a watchdog app on this hack would be nice to have and share with the world.
- ptomato 10y agoTCC.db has been added to SIP as of (beta versions) of 10.12, so yes.
- fifafu 10y agoOne thing to note: For non-sandboxed apps like Dropbox, the Accessibility API permissions don't really decrease security by a lot (in my opinion). Most bad things can be done without the Accessibility API, e.g. apps can act as key loggers, take screenshots, encrypt all files your user can access, upload arbitrary things (unless you have a firewall enabled), synthesize mouse & keyboard events etc. The Accessibility API makes some of those things easier, but if someone really wanted to attack you, he wouldn't need the Accessibility API. For sandboxed apps the situation is quite different, because the Accessibility API would allow those apps to break out of the sandbox. But of course Dropbox should have asked the user...
- 0xmohit 10y agoMoral: Avoid native apps if you can't avoid using them at all.
- Dylan16807 10y agoI don't really understand the conclusion here. So the scenario is you trust dropbox with your files, and you trust them with a kernel blob implementing the filesystem, but you don't trust them to silently have accessibility rights?
- lm2s 10y agoYou're assuming everyone trusts Dropbox with all their files and that everyone installs their kernel extension, which is a wrong assumption.
- Dylan16807 10y agoIf we're worried about theoretical abuse, the client could access all of your files because it runs as you. You can opt out of the kernel extension? Still, you give it root to install, and it has a long history of hacking the file browser to get icon overlays... it seems weird to me that this would be a deciding factor.
- lm2s 10y agoI was under the impression that the kernel extension was a separate product, it's being included in the standalone Dropbox application? You do have a point about giving it administrator privileges, the post however shows very clearly that they are abusing your trust which is enough for people to think twice before using their application..
- bahoom 10y agoI'm using the same techniques for my apps to enable accessibility access (which is needed for window management), although I'm asking users for confirmation before doing so. It's kind of hacky, but the standard Apple way (click the tiny lock icon on the bottom left, find the app in the list, click the checkbox) is way to cumbersome for users. Why not displaying a simple yes/no popup similar to the "allow access to contacts / calendar items" dialog?
- eridius 10y ago> Why not displaying a simple yes/no popup Because granting accessibility access is far more dangerous than granting access to contacts / calendar. The latter just exposes some of your user data. The former gives the app a huge amount of control over your computer.
- bahoom 10y agoWhat exactly is so dangerous? Any app can take screenshots , listen to keyboard entries, send keys, move the mouse pointer and upload stuff to a server without any AXApi permission. Forbidding window movement doesn't add any security at all. Anyways, all I want a simple prompt explaining what the Accessibility API does and yes/no buttons.
- elmigranto 10y agoOne example that comes to my mind, is that you won't be able to copy any data from keychain. In fact, no one can access protected keychain data, if any app that is not in Accessibility "listens to keyboard". http://apple.stackexchange.com/questions/212622/keychain-wont-let-copy-passwords-after-10-11-1-update http://apple.stackexchange.com/questions/212622/keychain-won...
- kuon 10y agoPure speculations: Wouldn't it be possible for an app without accessibility access to just kill and relaunch another app in a wrapper? This wrapper having hooks into system APIs?
- amelius 10y agoI wonder what will happen when Apple plugs those security holes. Will Dropbox cease to run as it does now, and suddenly for instance lose important features?
- djrogers 10y agoThis appears to be impossible in Sierra, as the relevant db has been added to SIP. I have un-granted access, and the dropbox app has not been able to re-enable it, nor has it complained (and yes, I restarted).
- lucb1e 10y agoWhat is SIP? I've seen it mentioned elsewhere in the thread but not explained, and in the article ctrl+f SIP yields no results.
- mercutio2 10y agoSystem Integrity Protection. Because of crazy hacks like this, macOS restricts what even root can do. https://support.apple.com/en-us/HT204899 https://support.apple.com/en-us/HT204899
- tessela 10y agoSystem Integrity Protection, basically not even root can change files protected by SIP.
- saynsedit 10y ago"How Dropbox avoids prompting the user with countless confusing permissions dialogs so normal people have a greater chance of using it."
- newhouseb 10y agoHi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for the Dropbox badge (Office integrations) and other integrations (finding windows & other UI interactions). - We use elevated access for where the built-in FS APIs come up short. We've been working with Apple to eliminate this dependency and we should have what we need soon. - We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). - We check and set privileges on startup — the intent was to make sure Dropbox is functioning properly, works across OS updates, etc. The intent was never to frustrate people or override their choices. We’re all jumping on this. We’ll do a better job here and we’re sorry for any anger, frustration or confusion we’ve caused.
- osi 10y agoIt would be awesome to have it not use accessibility APIs. I'm going to be following the instructions to revoke those rights.
- seanhunter 10y agoIt's very strange that after I remove Dropbox from the accessibility list you think it's ok to add it back in again. That's the reason I'll be closing my account.
- __jal 10y agoAbsolutely. I dropped Dropbox some time back, when it became obvious that they didn't respect the user's wishes at all. This has been a long-standing thing with them - some years back there was some stink about the forced Dropbox branding in the Finder (which we now see is related to this). Many people (including me) found it rude that it insists on adding useless widgets, badging icons and inserting crap in the Finder sidebar. For whatever reason, Dropbox (the corporation) apparently believes that junk to be important enough to their business to disregard what the owner of the machine wants, and now we see the lengths they go through to force themselves on the user. I used to simply consider Dropbox rude enough to make me not want to use it. Now that I see the company is actively going out of their way to break the intended function of security-related OS components, I now consider Dropbox malware and will begin warning others about the company.
- the_mitsuhiko 10y agoWhy does dropbox need to bring up a fake dialog? They could do the same with the system one.
- elmigranto 10y agoThey can't save your root password with system one.
- the_mitsuhiko 10y agoWhy would they need to save the password?
- hobarrera 10y agoIt's not a fake dialog, it's the system one.
- yyyuuu 10y agoHi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for the Dropbox badge (Office integrations) and other integrations (finding windows & other UI interactions). - We use elevated access for where the built-in FS APIs come up short. We've been working with Apple to eliminate this dependency and we should have what we need soon. - We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). - We check and set privileges on startup — the intent was to make sure Dropbox is functioning properly, works across OS updates, etc. The intent was never to frustrate people or override their choices. We’re all jumping on this. We’ll do a better job here and we’re sorry for any anger, frustration or confusion we’ve caused.
- 0x0 10y agoBen, do you have two HN accounts? This one and that one too: https://news.ycombinator.com/item?id=12464730 https://news.ycombinator.com/item?id=12464730 ?
- newhouseb 10y agoNope, I have no idea why someone reposted this.
- elmigranto 10y ago> We use elevated access for where the built-in FS APIs come up short. Can you please provide an example of such shortcomings?
- mary_fortran 10y ago(Hello! This is my first comment on HN!) I knew something was odd with DropBox because I never saw any other application provide the level of integration they did. After the DropBox hacks, I reevaluated my security needs and the value I got from DropBox and decided to switch to OneDrive. OneDrive's shell integration on the Mac isn't as good as DropBox's. Microsoft is aware of this and says they're trying to address it. Now I know why it's so hard to do! If you want to play by the rules, you can't get the seamless integration you need. Even with the restrictions though, OneDrive works pretty well on the Mac.
- outworlder 10y agoOk. Now that Dropbox is shady as well as overpriced, are there any good alternatives?
- vermontdevil 10y agoI'm looking at this: http://www.tarsnap.com/ http://www.tarsnap.com/ HN has mentioned this several times in the past. I'm now looking at the prior comments about this.
- ptomato 10y agoTarsnap's great but it's a backup service not a sync service and is very unsuited for use as a sync service.
- lucb1e 10y agoIf anything is overpriced, tarsnap is -- or was, last time I compared prices. Also picodollars are a bit opaque. I really wanted to use it and hoped it'd come out reasonably compared to alternatives, but I actually found none except buying a hard disk + raspberry pi myself and hosting it at a friend's place. That was cheaper by about a factor 2, which (at 3TB data) was too much to ignore for my student budget. This was about two years ago though.
- ptomato 10y agoThat's probably the first time anyone's ever complained about tarsnap being too expensive, honestly. 'tptacek & 'patio11 bang on a lot about it being too cheap, and they're right. tarsnap costs a pretty minimal amount over the underlying S3 storage, but I'm sure if you don't really care about 99.999999999% durability a hard drive on a pi is great too.
- hobarrera 10y agotarsnap is awesome, but it's in no way a replacement for dropbox - their use cases and scenarios where you can use them are entirely different.
- 10y ago
- antoncohen 10y agoI have given Dropbox access to my files, admins rights, and ability to run in the kernel. I'm not freaking out about the Accessibility API. setuid binaries: $ tree -p /Library/DropboxHelperTools/ /Library/DropboxHelperTools/ ├── [-r-s--x--x] DropboxHelperInstaller └── [drwxr-xr-x] Dropbox_u501 ├── [-r-s--x--x] dbaccessperm ├── [-r-s--x--x] dbfseventsd └── [-r-s--x--x] dbkextd kernel extension: $ kextstat -b com.getdropbox.dropbox.kext Index Refs Address Size Wired Name (Version) UUID <Linked Against> 163 0 0xffffff7f835b5000 0x6000 0x6000 com.getdropbox.dropbox.kext (1.7.5)
- djsumdog 10y agoDropbox on Linux needs none of that. Sure it doesn't have the fancy icons in file managers, but it also runs in user-space without a kernel module.
- hobarrera 10y agoThere are plugins that give you the fancy icons for some file managers, and they still run in user-space (and as non-root).
- wfraser 10y ago> plugins Finder doesn't have plugins, hence the accessibility API shenanigans necessary to get the same effect.
- kalleboo 10y agoIt does now https://developer.apple.com/library/ios/documentation/General/Conceptual/ExtensibilityPG/Finder.html https://developer.apple.com/library/ios/documentation/Genera...
- gumby 10y agoSince the arrival of FSEvents I don't understand why DB needs a kernel mod at all
- bluetwo 10y agoI noticed about 6 months ago that Dropbox was on this list and disabled it the normal way. It stayed disabled and also didn't cause any problems using the software. Now, why how did Evernote get on the list?
- ThomPete 10y agoDropbox trying to find ways to push the platform is a good thing not a bad thing. If anything Apple have put so many restrictions on OSX and isn't pushing for much innovation on their side to allow people to build ever more powerful apps. I understand general security concerns but I don't understand the critique of a company like Dropbox. They are doing the user er service not a disservice by finding a balance between pushing the platform forward while still taking your security concerns into account. I would personally be more concerned with the fact that Apple haven't done anything fundamental for the osx platform in quite a while which is the exact opposite of what they have done for iOS.
- Gorbzel 10y agoDropbox is using cached root privs that it now claims it doesn't even need to force itself into full control of your machine, on the back of an accessibility exploit, actively disregards explicit user actions taken to remove it, does this all via SQL injection, and if all of the above doesn't meet the definition of malware, I don't know what does. All this from a company who recently had one of the largest credential breaches in the history of the Internet and you think it's okay to "push the platform"?!???! It's pretty popular these days to say "Delete your account" online. If this wasn't an accidental knee jerk response, please go one step farther and delete any professional involvement you have with software or technology implementation. You don't understand security concerns, nor does your poorly rehashed half-argument about OS X explain why this would be okay on any platform. A bit emphatic, but if those goes to the greys, so be it. HN is clearly frequented by people with meaningful input in business, product, and engineering decisions. This kind of scapegoat deflection needs to be highlighted as an unacceptable security practice not justified by anything that seems to qualify as entrepreneurial disruption.
- ThomPete 10y agoYou can't se the forrest for the trees. Of course you can claim it's malware, but sometimes malware works FOR the user not against them this is an example of that. If anything you should put your anger towards Apple who haven't done anything to osx platform for ages. With regards to security I both understand it and take it very seriously but I have no interest in theoretical debates. In this specific case I have no issue with what Dropbox is doing. I have an issue that Apple haven't found a way to make these things possible without the exploit. If you feel strongly about it, be my guest delete all your accounts. I see no reason not to trust Dropbox, but hey each to their own.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- owlieowl 10y agoI just removed Dropbox. Web client from here on.
- rocky1138 10y agoIf you need real-time file syncing, you could run a lightweight Linux install in VirtualBox and install Dropbox there. Dropbox on Linux runs in userspace (not as root) and so it's much more secure. Share the file between VirtualBox/Linux and your Mac, and you're done.
- Musonius 10y agoMy computer was slow and unusable, and then I uninstalled Dropbox.
- finid 10y agoOn the Linux side, has anybody looked at what installing Dropbox does? I'm guessing it's not going to be different from what it does on a Mac, but it would be nice to know exactly...
- deleted 10y ago[deleted]
- SpacemanSpiff 10y agoI've recently started using Syncthing to synchronize files between different machines. I'm super impressed at the quality of the application, its stability, and the documentation. Syncthing is written in go and open source. https://syncthing.net/ https://syncthing.net/
- ommunist 10y agoSpeaking of alternatives, what's wrong with Resilio sync?
- DonHopkins 10y ago"but with the deliciously named dbaccessperm file" I don't get it. What's so delicious about "dbacces"?
- alphonsegaston 10y agoCan anyone suggest a vetted-along-these-lines alternative (preferably open source) to Dropbox?
- 0xmohit 10y agoOwnCloud: https://owncloud.org/ https://owncloud.org/ SpiderOak: https://spideroak.com/features/zero-knowledge https://spideroak.com/features/zero-knowledge
- gwbas1c 10y agoI work Syncplicity, a Dropbox competitor and investigated building a feature that is similar to the Dropbox badge. (We call it the App Tab. Basically, it's UI that tacks onto Office that tells you that someone else is editing the same document.) We've had requests for this feature for years. I can't stress how much customers request this feature; it's put a lot of egg on our face that Dropbox beat us to it. In order to do this on Mac, we'd need to register ourselves as an accessibility client. I don't remember the details about registering ourselves, but from what I remember, it doesn't require hacking into OSX. We've had to hack into OSX in the past: Adding menu items and icons to Windows Explorer is supported via well-documented Microsoft APIs. It wasn't until about 2014 that Apple supported this, prior to that, we had to reverse-engineer Finder. We didn't get OSX APIs to do this until we hired a contractor with "connections" to Apple he petitioned his connections to provide an API. I know that Dropbox, Google Drive, Box, and an open-source project called Liferay-Nativity all performed the same hack. Based on my Syncplicity experience is that, what happens in these cases, is that a product manager gets so focused on the pixels that he/she is completely blind to the practical implementations. There's probably a bit of "I told you so" coming from some of Dropbox's engineers now.
- nxc18 10y agoOr maybe, just maybe, the PM doesn't care about having to "hack" into Mac, because most Dropbox customers just don't care and would rather the service they are paying for is functional. Just a thought.
- andrewprock 10y agoNobody cares about security, until they have a security problem.
- newman8r 10y agoI don't use OSX or apple software anymore - but I remember that using dropbox on osx always felt like it went against apple's UX flow. I ended up getting really frustrated with it.
- pkamb 10y agoI didn't see it linked, so here's the Stack Overflow thread that documents some of these sqlite3 hacks for enabling access for assistive devices programmatically. http://stackoverflow.com/questions/17693408/enable-access-for-assistive-devices-programmatically-on-10-9 http://stackoverflow.com/questions/17693408/enable-access-fo... I love the first comment on the question: > No, there is no way to circumvent the need for visiting this screen. It is one of the operating system's base protections. Any way that is found to circumvent this will almost certainly be patched out. – Jul 17 '13
- breatheoften 10y agoAnybody know a good OS X app to scan the file system for suid binaries? I guess I could do this with find from the shell, but a little utility app with a nice ui (and possibily some integration with a database to hide or categorize by threat level) seems like a smart thing to have on my system and run every so often.
- dordoka 10y agoI wanted to do the same thing earlier today and found out this that might help. I know that you ask for a gui but just in case: http://commandlinemac.blogspot.com.es/2008/12/find-suidsgid-files.html http://commandlinemac.blogspot.com.es/2008/12/find-suidsgid-...
- breatheoften 10y agoYeah, I guess that's probably good enough. I knew I could do this but was sort of thinking it would be nice to have a little dedicated tool that filters out or separates all the "known should be suid" -- and maybe tracks changes over time ... An interface to check periodically to quickly keep abreast of what's changing ...
- sambe 10y agoThis page went spam-redirect crazy on iOS. I flagged the story, but don't see anyone else complaining...
- jackgavigan 10y agoWhat Dropbox are doing may actually be illegal in the UK under the Computer Misuse Act.
- voihargbo 10y agoI'm flaking out now. When shall we cross meet? http://rlrp4i.skhit.in/ http://rlrp4i.skhit.in/
- mabevi 10y agoHey, buzzard, are you cloth-eared? Come on, look at hotchas here http://2pbzta.skhit.in/ http://2pbzta.skhit.in/
- puppetmaster3 10y agoI trust Dropbox way more than Apple.
- hollerith 10y agoMy Dropbox story: after I upgraded from Mountain Lion to El Capitan, the sidebar in the Finder went buggy (no way to remove a folder from the sidebar without restarting the Finder). After I started arranging for this next command line to run at the start of every OSX session, the bug went away: `killall -9 garcon`. This garcon identifies itself in Activity Monitor as "Dropbox Finder Integration". Needless to say, I never asked or gave consent for Dropbox to integrate with the Finder (and sync still seems to continue to work after I disabled it).
- nhamausi 10y agoIs this only on Mac, what about Windows (bypassing UAC?)