5 ms·
Couple of reasons why this might be news. 1. Under /features check out the 'Certification and Compliance section'. >> Dropbox's storage is SSAE16/SOC1, SOC2,
by ayanb 13y ago
Couple of reasons why this might be news.
1. Under /features check out the 'Certification and Compliance section'.
>> Dropbox's storage is SSAE16/SOC1, SOC2, ISAE 3402 and ISO 27001 certified on Amazon S3 and may provide data mirroring across other secure data centers
SSAE16/SOC1 compliances were not present in the earlier versions and this is a decent step forward for adoption of dropbox in larg(ish) IT departments. This will imply "firewalls are in place at all externally facing access points".
2. From a usability point of view, the promise of a seamless way to integrate both your personal and work accounts from the same device.
3. "Seamlessly upgrade existing Dropbox accounts to Dropbox for Business and transfer files to a co-worker when someone leaves", although this is in Beta currently, this reduces a lot of headache for IT departments during employee exits.
Seems like most of the other features remain the same, though.
- zwily 13y agoI suspect they're just piggy-backing on Amazon's certifications. Notice how they say "Dropbox storage", not the entire service.
- skue 13y ago> 2. From a usability point of view, the promise of a seamless way to integrate both your personal and work accounts from the same device. [emphasis mine] It wasn't clear from the announcement that Dropbox for Business will support multiple work accounts on the same device. The marketing content appeared to be written to appeal for enterprise IT managers, who obviously wouldn't be worried about this. For IT-managed devices that's fine, but there sure are a lot of people nowadays with side businesses or who consult with multiple organizations that all want to share files. And currently it's easier to use Box (or Google Docs) than sharing folders via Dropbox and worrying about busting each sharee's Personal storage quotas.[1] [1] https://www.dropbox.com/help/59/en https://www.dropbox.com/help/59/en
- nvk 13y agoUntil they implement client side encryption I cannot use this service. Forget about NSA, what about rogue admins, or just plain bugs. Dropbox = Your-Unencrypted-Files-Here.com
- Spooky23 13y agoClient side encryption defeats the purpose of most of the value-add features of Dropbox. I'd actually argue that it would make the service more dangerous, as once you decrypt a file outside of the context of your desktop, the Dropbox service has the key. How do you share a file on the web or via mobile client with low friction without rendering that client-side encryption useless? (A: You don't.) IMO, if you have data security needs that necessitate client-side encryption, and you use a public service to store that information, you need to give up whiz-bang features or reduce your security requirement.
- mynegation 13y ago> How do you share a file on the web or via mobile client with low friction without rendering that client-side encryption useless? (A: You don't.) Exactly. Not all of us _need_ to share files, I just need a secure backup. And it is technically possible to access files on various clients using only client-side encryption and separate encrypted files from plain-text should you need to.
- Spooky23 13y agoFrom a compliance standpoint, these are pretty meaningless. Sounds like Dropbox marketing isn't taking security and compliance very seriously. Actually, it really bothers me that Dropbox touts these things as compliance factors (vs. features of the underlying storage system). Dropbox is the user-facing service, not Amazon S3. If I put a bunch of money in some super-duper safe, chain it to a flatbed truck, and then leave the truck unlocked with the engine running, the safe doesn't make that money secure.
- Khaine 13y agoYou can't make any assumption based on SSAE16/SOC1 compliance, without looking at the statement of applicable controls. You can take more comfort from the ISO 27001 compliance