4 ms·
Nice article. However: > It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people. I'd sugg
by comstock 9y ago
Nice article. However:
> It's alarming not just because the number is so low, but because Dropbox holds such valuable information for so many people.
I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability.
Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). And they have proponents of warrantless surveillance on their board:
http://www.drop-dropbox.com http://www.drop-dropbox.com
- dx034 9y ago> I'd suggest that Dropbox users somewhat self select for those not as concerned about security as others. And more concerned about availability. I would rather say that Dropbox is being used by many people without tech knowledge. And while they might be concerned about security, they often just don't know how improtant 2 factor authentication is. At least that's what I can see for some friends & family.
- y4mi 9y agoeeh, since when does u2a protect against back-end breaches? thats just a security layer against phishing or password leaks... don't get me wrong, i'd advice everyone to use it for anything remotely critical, because its pretty easy to setup and live with, but it really doesnt help against state actors or hackers that compromised the data servers.
- hellofunk 9y ago> since when does u2a protect against back-end breaches? Because if someone steals your DB password, they still won't be able to login to your account. Maybe they won't have to, if they also stole your data and found a way to decrypt it, but since those are different things, it is plausible that there could be a leak of login information without a leak of data, in which case your two-factor authentication would keep the attackers out of your data.
- ProblemFactory 9y ago> since when does u2a protect against back-end breaches? It doesn't have to. For 99.999% people, the two most realistic threats are: * There is a keylogger on some computer where you access your Dropbox, for example at a print shop, * You use the same password on many sites, one gets compromised, and automated bots try to access your Dropbox account.
- dx034 9y agoA Dropbox hack is nothing most users have to protect themselves against. Same as with a google breach where GMail data gets leaked. As a personal user of no special interest, no one would use a potential Dropbox vulnerability to just get your data. If you secure your end you'll be fine. That's different for big corporations or people with a public profile (e.g. politicians). In this case you have to ensure that malicious actors with a lot of money and knowledge cannot gain access. But then again, self hosting is likely less secure than Dropbox or Google.
- Angostura 9y agoI have tech knowledge, but I had absolutely no knowledge that Dropbox offered 2-factor. I don't keep confidential stuff in DB because, I know that the company effectively has access to everything. Nonetheless, 2 factor sounds interesting. So I look at this: https://www.dropbox.com/help/security/enable-two-step-verification https://www.dropbox.com/help/security/enable-two-step-verifi... Right. Now I understand why so few people have it enabled.
- hellofunk 9y agoExplain? You read a page about two-step and say that explains why no one has enabled it? You claim to have tech knowledge, but are not able to turn on this simple security setting (or even know it exists, despite that it's listed very clearly in your Dropbox settings page)? I use two-factor/two-step verification on every single service I have, including all social media accounts, email accounts, etc. Most major services/sites these days provide it. The way Dropbox does it is no different than any others; it takes 2 minutes to set it up. What did you find difficult about it?
- woogley 9y ago> You claim to have tech knowledge, but are not able to turn on this simple security setting GP didn't say _they_ can't enable it after reading the help page. I think they are implying that the very detailed help page looks long and complicated to a non-techie (who might not even understand the benefit of going through such a hurdle in the first place).
- Angostura 9y ago> Before enabling two-step verification, you'll receive ten 8-digit backup codes. It is very important that you write these codes down and store them somewhere safe. Do any of your other systems handle recovery like that?
- msl09 9y agoMy problem with dropbox alternatives is that they are either far more expensive or don't run on linux (with syncing).
- hipitihop 9y agohttps://spideroak.com/one/ https://spideroak.com/one/ runs on Linux. I have not checked how it compares to DropBox pricing wise, but ticks all my security/privacy boxes
- hellofunk 9y ago> Dropbox does not encrypt your data server side (or at the very least, can easily decrypt it). I think claims like this need to be backed up. Now, obviously a biased source, but Dropbox itself says this: "Each file is split into discrete blocks, which are encrypted using a strong cipher. Only blocks that have been modified are synced. Each individual encrypted file block is retrieved based on its hash value, and an additional layer of encryption is provided for all file blocks at rest using a strong cipher. Both dedicated internal security teams and third-party security specialists protect these services through the identification and mitigation of risks and vulnerabilities. These groups conduct regular application, network, and other security testing and auditing to ensure the security of our back-end network. In addition, our responsible disclosure policy promotes the discovery and reporting of security vulnerabilities." [0] So we have files that are broken apart, each part encrypted, then the whole combination encrypted again, then lots of security auditing in-house and outside, and with incentives for people that discover flaws to report them. That seems pretty industry-standard to me, but I'd like to know more. I really have some difficulty imagining a company like Dropbox, which knows how important the documents it stores are, being careless with security. Not saying they may not be, but it's going to take more than an HN comment that includes some politicized perspective about the Bush administration to convince me. Furthermore, this article [1] claims that Dropbox encrypts files on the server even stronger than Google does. It also points out that user behavior is usually the main security hole, which will always be true with any service. [0] https://www.dropbox.com/security https://www.dropbox.com/security [1] https://www.virtru.com/blog/dropbox-encryption/ https://www.virtru.com/blog/dropbox-encryption/
- GranPC 9y agoIt does sound like they can easily decrypt the data, since they have the keys.
- jasonsync 9y agoYes, Dropbox uses encryption in transit and at rest, and security would certainly a top priority for any custodian of that much data. Dropbox is an industry leader, and in many ways sets the course for the entire industry to follow in this regard. The issue with Dropbox is that they also have access to your encryption keys, which means they can easily decrypt and access your files, at their discretion. According to Drew Houston (Dropbox CEO), they need access to your files to offer features like search, to be able to better understand how you're using the service, ability to integrate with third-parties, and for law enforcement. Some of these "trade-offs" are mentioned by Mr. Houston himself in this interview when responding to criticism from Edward Snowden a few years ago: https://techcrunch.com/2014/11/04/dropboxs-drew-houston-responds-to-snowdens-privacy-criticism-its-a-trade-off/ https://techcrunch.com/2014/11/04/dropboxs-drew-houston-resp... More to the point, giving Dropbox (and their affiliates and trusted third-parties) permission to access to your files is a key provision of the Dropbox terms of service: Our Services also provide you with features like photo thumbnails, document previews, commenting, easy sorting, editing, sharing and searching. These and other features may require our systems to access, store and scan Your Stuff. You give us permission to do those things, and this permission extends to our affiliates and trusted third parties we work with. https://www.dropbox.com/terms https://www.dropbox.com/terms As Mr. Houston said in the article referenced above, if you want better encryption there are alternatives. Disclaimer: I work at Sync.com
- jpalomaki 9y agoConfidentiality, Integrity and Availability (CIA). Those are all part of information security. This is actually quite interesting, since it is a bit like CAP theorem. When you increase confidentiality and integrity, you might be affecting availability in a negative way. Take Dropbox as an example. Since they don't have efficient end-to-end encryption offering, they can offer you password resets (=availability of data is good). Add in secure end-to-end encryption and password resets won't be enough, you need to have in addition good backups for the encryption keys to ensure access to the data.