Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

121–130 of 435 posts

Re: How Dropbox Hacks Your Mac

#121
Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things —

- Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that.

- We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like.

- We use accessibility APIs for the Dropbox badge (Office integrations) and other integrations (finding windows & other UI interactions).

- We use elevated access for where the built-in FS APIs come up short. We've been working with Apple to eliminate this dependency and we should have what we need soon.

- We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple).

- We check and set privileges on startup — the intent was to make sure Dropbox is functioning properly, works across OS updates, etc. The intent was never to frustrate people or override their choices.

We’re all jumping on this. We’ll do a better job here and we’re sorry for any anger, frustration or confusion we’ve caused.

Re: How Dropbox Hacks Your Mac

#122

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

It would be awesome to have it not use accessibility APIs. I'm going to be following the instructions to revoke those rights.

Re: How Dropbox Hacks Your Mac

#123
post #29

Dropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board ( http://www.drop-dropbox.com/ ). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the securi…

Got a good alt suggestion?

The German branch of Seafile: https://seafile.de/en/products/

I switched all my data (about 250Gb) to them from Dropbox a couple of months ago and it has worked out well enough.

Features:

- servers not based in the US

- encryption

- privacy

- open source (thanks lima)

- multiple libraries (like multiple separate Dropbox folders)

- nice file manager for unsynced (parts of) libraries

- price

- payment options (Bitcoin)

- supports more OSes

- one can run one's own server

Cons vs Dropbox:

- syncing problems not always obvious

- some UX issues

- photo support

- selective sync cumbersome (if not using libraries)

- no LAN sync

Re: How Dropbox Hacks Your Mac

#124

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

It's very strange that after I remove Dropbox from the accessibility list you think it's ok to add it back in again. That's the reason I'll be closing my account.

Re: How Dropbox Hacks Your Mac

#125

Earlier quoted context omitted.

Because Apple doesn't have a mechanism to access files on your Mac, while they do have a mechanism to access files on iCloud. This means someone guessing your security questions, or somebody with a warrant, or somebody abusing their access rights can get to your files.

They do provide the OS, so they implicitly have access to all your files at a level that dropbox would have a hard time achieving.

> so they implicitly have access to all your files

If you can demonstrate how Apple has access to my files on an OS X installation with no iCloud configured, I will round up a massive bounty.

Re: How Dropbox Hacks Your Mac

#126

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

[deleted]

Re: How Dropbox Hacks Your Mac

#127
post #99
post #84

Earlier quoted context omitted.

What kernel extension? Dropbox has a Finder plugin for badges, but what would they need a kernel extension for?

This kernel extension: /Library/Extensions/Dropbox.kext And good question.

The kernel extension implements Dropbox Infinite.

Re: How Dropbox Hacks Your Mac

#128

Earlier quoted context omitted.

Got a good alt suggestion?

The German branch of Seafile: https://seafile.de/en/products/ I switched all my data (about 250Gb) to them from Dropbox a couple of months ago and it has worked out well enough. Features: - servers not based in the US - encryption - privacy - open source (thanks lima) - multiple libraries (like multiple separate Dropbox folders) - nice file manager for unsynced (parts of) libraries - price - payment options (Bitcoin)…

And Seafile is open source, too.

Re: How Dropbox Hacks Your Mac

#130
post #26

Earlier quoted context omitted.

And if you're using Ubuntu, you're trusting package managers, and if you're using Gentoo, you're trusting original developers (how often do you audit source code?)

>And if you're using Ubuntu, you're trusting package managers, and if you're using Gentoo, you're trusting original developers This is correct. Consider, however, the motivations of the people involved. Apple's motivations are to make money from you. Debian's motiviations (intentionally avoiding Ubuntu here) are to make a good user-centric system. Packages are signed by named individuals that I can personally get to…

>>how often do you audit source code?

>You would be surprised!

It doesn't really matter if you do. OpenSSL is one example showing there are critical mistakes of grand level everywhere, same as there might be cleverly hidden backdoor in that multi-100k source tree (or any of the myriad of dependencies) you "audited".

Post reply on HN