3 ms·
I'm surprised there is no mention of security or privacy. I'd have thought that's one of the reasons for controlling your own edge network.
by meteor333 8y ago
I'm surprised there is no mention of security or privacy. I'd have thought that's one of the reasons for controlling your own edge network.
- anonacct37 8y agoIf I had to guess the people who wrote this are just assuming tls on top.
- zimbatm 8y agoThat's an interesting implication. If they distribute the same cert so widely geographically, any host country could technically request it for "lawful intercepts".
- dsl 8y agoYou don't have to keep keys on boxes in random countries if you use a TLS oracle [1]. Another option is deploying the keys onto an HSM and pointing your frontends at that. 1. Here is CloudFlare's implementation (and pats themselves on the back for "inventing" it): https://blog.cloudflare.com/keyless-ssl-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/keyless-ssl-the-nitty-gritty-tec...
- romed 8y agoA host country can request a lawful intercept regardless of whatever technical conditions exist on your network.
- deleted 8y ago[deleted]
- blub 8y agoDropbox doesn't offer privacy. Anything done on the service is visible to them and whoever else convinces them to hand over the data. They're exactly the type of cloud service that shouldn't be used by businesses or privacy-conscious individuals. Security's also questionable. They had an incident where one could log into any account a long time ago. More recently they were presenting a fake admin dialog to syphon the admin password on macOS and perform some admin tasks on the machine.
- jesseendahl 8y agoTheir security is very good nowadays. I suggest reading their security whitepaper and their blog posts on various security topics: https://www.dropbox.com/static/business/resources/Security_Whitepaper.pdf https://www.dropbox.com/static/business/resources/Security_W... https://blogs.dropbox.com/tech/tag/security-2/ https://blogs.dropbox.com/tech/tag/security-2/ Disclaimer: I used to work there on the Security Engineering team.