3 ms·
The features page of your website says this about security: >All transmission of file data and metadata occurs over an encrypted channel (SSL). >All files sto
by blakeweb 16y ago
The features page of your website says this about security:
>All transmission of file data and metadata occurs over an encrypted channel (SSL).
>All files stored on Dropbox servers are encrypted (AES-256).
And yet I hear people here saying that Dropbox is "missing encryption." What's the real story? Are there more technical details on your encryption posted somewhere on your site?
I'd really like to know, as I actually have a good deal of semi-sensitive information stored in my account right now--a decision I made based on the wording I copied in above and on my trust in the Dropbox folks so far.
- ivankirigin 16y agoWhen people say Dropbox is missing encryption, they mean encrypting files before they are uploaded so not even Dropbox could look at the files - end to end, so to speak. They do not mean that Dropbox is insecure. Dropbox is secure. The problem with end to end is that it makes sharing or public files unfeasible, and those are important parts of Dropbox.
- zcid 16y agoHave you considered making encryption available on a per-folder basis? The encryption would be done on the client side so it wouldn't incur any additional computational expense for your servers, but would still provide the peace of mind that many look for with TrueCrypt containers. This could be even be done in a way to allow the user to choose his implementation.
- poi98u7y6tryuio 16y agoIf you want to do that then encrypt the files with truecrypt or something you trust and let DB sync the truecrypt container file. But everytime you slightly change the contents, Dropbox will have to resend the entire container - thats one of the features of good encryption
- zcid 16y agoI do this currently, but I wish there was a more elegant solution. As far as I can tell from my own usage, the only portion that is uploaded is the changed portion. I have a 1GB container currently synced and when I change files in that container, I can assure you that it doesn't upload 1GB of information. It appears to only transfer the delta.
- jodrellblank 16y agoOne of the properties of a good hash algorithm is that a small change in the input makes a big change in the output, and one of the properties of a good encryption algorithm is that the output looks random. I don't know how the two are supposed to combine, but the prediction is that for a truecrypt disk image, any change in the contents produces a very different disk image all over - so transferring "the delta" is still a much larger amount than you'd expect. Although, if this were the case it would also have to rewrite the disk image a lot and that might be quite bad for just local use.
- Dylan16807 16y agoThe encryption is block based. Change a bit and you're completely scramble the block, but no more.
- zcid 16y agoI think that the biggest concern is that Dropbox has access to your files. The files might be encrypted from the point of view of the physical location, but they are still accessible to Dropbox employees, feds, or anyone that manages to breach their servers. The most common solution to this is to use TrueCrypt containers for any particularly sensitive files.