Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

81–90 of 435 posts

Re: How Dropbox Hacks Your Mac

#81
post #29

Dropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board ( http://www.drop-dropbox.com/ ). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the securi…

Got a good alt suggestion?

Re: How Dropbox Hacks Your Mac

#82
post #41

One thing to note: For non-sandboxed apps like Dropbox, the Accessibility API permissions don't really decrease security by a lot (in my opinion). Most bad things can be done without the Accessibility API, e.g. apps can act as key loggers, take screenshots, encrypt all files your user can access, upload arbitrary things (unless you have a firewall enabled), synthesize mouse & keyboard events etc. The Accessibility AP…

> apps can act as key loggers

I thought that required accessibility access?

Re: How Dropbox Hacks Your Mac

#83
post #75
post #21

The fact that any application can spoof the os password prompt makes me wonder why they don't have a prominent feature to show the prompt is from the OS. On windows there is the secure desktop with the dimming effect.

That reminds of how Windows asks you to press "ctrl+alt+del" before typing your account password in some situations, because other software cannot intercept ctrl+ald+del so you know the login prompt is legit.

That was actually designed to avoid typing credentials into "faked" password dialogs. The above mentioned "Secure Desktop" with dimming is not designed for that, but for the, rather hilarious, fact that it is trivial for a Windows program to hit any button on the screen it wants to. Having the permission requests pop up on a "Secure Desktop" prevents a malicious program from hitting the "Allow" button for it's own permission request. The funny part is that this is the exact kind of functionality dropbox is "hacking" itself access to.

Re: How Dropbox Hacks Your Mac

#84
post #77

Earlier quoted context omitted.

If we're worried about theoretical abuse, the client could access all of your files because it runs as you. You can opt out of the kernel extension? Still, you give it root to install, and it has a long history of hacking the file browser to get icon overlays... it seems weird to me that this would be a deciding factor.

I was under the impression that the kernel extension was a separate product, it's being included in the standalone Dropbox application? You do have a point about giving it administrator privileges, the post however shows very clearly that they are abusing your trust which is enough for people to think twice before using their application..

What kernel extension? Dropbox has a Finder plugin for badges, but what would they need a kernel extension for?

Re: How Dropbox Hacks Your Mac

#85
post #29

Dropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board ( http://www.drop-dropbox.com/ ). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the securi…

Got a good alt suggestion?

Spideroak, if your reason for switching is privacy.

Re: How Dropbox Hacks Your Mac

#86
post #21

The fact that any application can spoof the os password prompt makes me wonder why they don't have a prominent feature to show the prompt is from the OS. On windows there is the secure desktop with the dimming effect.

Because Macs don't get viruses /s

Well, in theory they might, in practice they don't.

Almost all of the viruses reported for Macs were in fact Trojans.

And even if there were a few legitimate viruses over the years, none went very far as to cause much trouble to any sizeable number of people. Contrast with the barrage of Windows viruses and widespread mayhem they cause, on a platform were almost everybody uses an antivirus too.

It's not "just" due to the Mac being less popular either. Mac OS up to 9 got lots of viruses back in the day, and Macs had just 1 to 2% market share in the US. Nowadays they have several times that.

So yeah, on my Mac and Linux boxes, I'll care about viruses to the point of running an antivirus or such when people actually start getting some...

Re: How Dropbox Hacks Your Mac

#87

Great article, but poor conclusion. He finds that Dropbox is untrustworthy, a finding that likely surprises no one, and reaches for iCloud as the solution. Why move into another walled garden driven by corporate interests? OwnCloud or a similar self hosted solution would be better. I just use NFS and a dead simple storage server to make ~/shared available on all of my machines.

"OwnCloud or a similar self hosted solution would be better."

Perhaps better for limited use cases that don't really apply to the vast majority of Dropbox's user base.

You start off comparing apples to oranges, and with your latter solution, you aren't even comparing to fruit anymore.

Re: How Dropbox Hacks Your Mac

#88
post #82
post #41

One thing to note: For non-sandboxed apps like Dropbox, the Accessibility API permissions don't really decrease security by a lot (in my opinion). Most bad things can be done without the Accessibility API, e.g. apps can act as key loggers, take screenshots, encrypt all files your user can access, upload arbitrary things (unless you have a firewall enabled), synthesize mouse & keyboard events etc. The Accessibility AP…

> apps can act as key loggers I thought that required accessibility access?

no, only if you use the cocoa/carbon apis. Using IOKit it doesn't need access to the Accessibility API. However IOKit is blocked for sandboxed applications.

Re: How Dropbox Hacks Your Mac

#89
post #64

Earlier quoted context omitted.

Honestly they're pretty much the most expensive out of all of the storage solutions. Other than versioning they have less features than their competition as well. If they were born today I can't imagine they would have gone much of anywhere. Not sure how they're doing financially today but it seems each product they create flops. So even outside of this surveillance stuff I don't get the point in using them.

Their client just works better at syncing quickly and reliably. A huge criteria for me is how much CPU it uses in the background compared to competing solutions from Google or MS and it was often an order of magnitude less (other clients may have improved in the last year or two, I haven't checked). Another significant advantage is that they support a stable command line client for Linux.

I'd rather pay for privacy and security with compute cycles. To whom else do you give your root password and hope that nothing bad happens?

Re: How Dropbox Hacks Your Mac

#90
post #29

Dropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board ( http://www.drop-dropbox.com/ ). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the securi…

Got a good alt suggestion?

Has anyone tried sync.com? From their website they claim end to end encryption and seem to take privacy ands security seriously.
Post reply on HN