3 ms·
Callas tweeted on April 19: “I deleted my Dropbox account. It turns out that they lied and don’t actually encrypt your files and will hand them over to anyone w
by armored 15y ago
Callas tweeted on April 19: “I deleted my Dropbox account. It turns out that they lied and don’t actually encrypt your files and will hand them over to anyone who asks.”
That's actually a lie too. Dropbox does encrypt your files, it's just that, naturally, they hold the key. If I ask Dropbox for another users files, guess what? They don't hand them over.
If your info is really that sensitive then for heavens sake don't outsource encryption and key management to a third party you have no supervision over. Encrypt your super sensitive files with Truecrypt and then share/sync them with Dropbox.
- MarketingMuppet 15y agoI don't consider it 'natural that any provider of supposedly secure storage would hold the account owners encryption key. It's not hard (as proven by SpiderOak and Wuala) to implement client side encryption. It does however make it impossible (hard) to cross-account deduplicate which makes storage costs higher for the operator. I think the issue here is that dropbox tried to position themselves as 'as secure as everyone else' while actually holding the encryption keys and deduplicating across accounts, something that is not true for their competition.
- cperciva 15y agoDropbox does encrypt your files, it's just that, naturally, they hold the key. Even if dropbox's claim was technically correct, it was absolutely misleading. When you say "this data is encrypted" people assume that you mean "... in a way which adds security"; if the same people who have access to the encrypted data also have access to the decryption keys, you might as well be using ROT-13. If I ask Dropbox for another users files, guess what? They don't hand them over. Modulo the recently-fixed vulnerability which allowed you to download data if you knew some hashes, that is.
- Dylan16807 15y agoI wouldn't call it a vulnerability. The only way it could be abused would be tricking someone with the file into calculating very specific hashes and giving them to you.
- cperciva 15y agoI've issued security advisories for FreeBSD for far more obscure contexts than that. :-)
- deleted 15y ago[deleted]