Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

171–180 of 435 posts

Re: How Dropbox Hacks Your Mac

#171

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

It's very strange that after I remove Dropbox from the accessibility list you think it's ok to add it back in again. That's the reason I'll be closing my account.

Most programs don't consider that you might try to explicitly revoke permissions. It's a very understandable bug/behavior. I think it's worth giving them a chance to amend that code.

Re: How Dropbox Hacks Your Mac

#172
post #9

It looks like in 10.12 Apple has added TCC.db to SIP, so this will no longer work — Dropbox will, hopefully, actually be forced to request accessibility access like they're supposed to. I'm sure they'll still demand your admin password via a dialog that tries super hard to look like a system one to use for whatever other more or less nefarious purposes. Would be nice if there was an alternative that actually syncs as…

I use owncloud (and then dropbox inside it so some files are double backed up). I find it to be just fine. Have you had any problems with it?

Re: How Dropbox Hacks Your Mac

#173
post #68
post #64

Earlier quoted context omitted.

Their client just works better at syncing quickly and reliably. A huge criteria for me is how much CPU it uses in the background compared to competing solutions from Google or MS and it was often an order of magnitude less (other clients may have improved in the last year or two, I haven't checked). Another significant advantage is that they support a stable command line client for Linux.

This. I cannot stress how important both of these factors are. I still haven't found a solution other than ( http://meocloud.pt , which was implemented by my former colleagues) that was within an order of magnitude as fast and/or as light in terms of CPU load, _and_ that supported Linux directly (let alone had halfway decent MacOS support).

If you're up for a self-hosted option, Seafile is great. The server and the client are both pretty lightweight. You should create and store encrypted volumes yourself and not trust its encryption mechanism, but it handles delta sync very well, which means it's only sending the pieces that change (and e.g. a Veracrypt/Truecrypt volume doesn't change a lot when adding/removing data from a volume, so you won't sync a lot for example with OwnCloud, which also has the nasty habit of eating your files).

Re: How Dropbox Hacks Your Mac

#174

Earlier quoted context omitted.

Honestly they're pretty much the most expensive out of all of the storage solutions. Other than versioning they have less features than their competition as well. If they were born today I can't imagine they would have gone much of anywhere. Not sure how they're doing financially today but it seems each product they create flops. So even outside of this surveillance stuff I don't get the point in using them.

As far as I know, DropBox is the only service that does delta block uploads correctly and switches to LAN transfer when two synced computers are in the same network. I know it's CS 101, but neither Google Drive, iCloud, or OneDrive do this. Not to mention the other services have bizarre naming limits (e.g., dotfiles are forbidden on OneDrive). Also, DropBox supports Linux officially.

Seafile does, too. OwnCloud definitely does not. Actually OwnCloud's Github issue for delta sync is a great read, if you're up for some humor.

Re: How Dropbox Hacks Your Mac

#175
post #161

Earlier quoted context omitted.

>you trust dropbox with your files, and you trust them with a kernel blob implementing the filesystem, but you don't trust them to silently have accessibility rights? The problem here isn't that you don't trust them to have accessibility rights, it's that Dropbox has phished your root password, stored it, and will continue to modify your system to meet it's desired operating criteria.

>- We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). Direct from the DB engineer at top of thread.

If that's the case, How is it that the accessibility preferences are changed without root authorization?

Re: How Dropbox Hacks Your Mac

#176
post #2

Just wanted to give the author a shoutout for being awesome. This article is published with an AMP version[0] too, which is pretty unusual for smaller blogging sites. AMP articles are so much easier on my eyes (and the author can't include their own javascript on an AMP page, so there is less bloat). I wish all bloggers started to publish AMP pages. [0] - http://applehelpwriter.com/2016/08/29/discovering-how-dropbo..…

AMP is not the solution. Anyone willing to use AMP to reduce bloat could also just not add bloat to HTML pages in the first place. And, using AMP itself adds bloat[1]. I couldn’t even read the author’s AMP version without enabling JavaScript. [1] https://www.ampproject.org/docs/get_started/create/basic_mar...

> just not add bloat to HTML pages

This isn't really a solution when many authors use a CMS, like WordPress and others, where the bloat is built-in. Sure you can write a custom theme etc, but not everyone (1) has the ability to do that, and (2) wants to dedicate the time to do that.

Re: How Dropbox Hacks Your Mac

#177

Ok. Now that Dropbox is shady as well as overpriced, are there any good alternatives?

I'm looking at this: http://www.tarsnap.com/ HN has mentioned this several times in the past. I'm now looking at the prior comments about this.

Tarsnap's great but it's a backup service not a sync service and is very unsuited for use as a sync service.

Re: How Dropbox Hacks Your Mac

#178
post #29

Dropbox circumventing security restrictions (albeit for legit reasons) is particularly worrying because they have board members who support warrentless surveillance. In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board ( http://www.drop-dropbox.com/ ). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the securi…

Got a good alt suggestion?

OwnCloud https://owncloud.org

Re: How Dropbox Hacks Your Mac

#179
post #11

What the fuck Dropbox! How do I get rid of the backdoor in /Library/Application\ Support/com.apple.TCC/TCC.db even after uninstalling Dropbox.app and rm -rf'ing ~/.dropbox and /Library/DropboxHelperTools? Do I just sudo sqlite3 and delete the row? Or is there an official tool (tccutil)? Edit: Crap, there's a /Library/Extensions/Dropbox.kext too now. :(

> Crap, there's a /Library/Extensions/Dropbox.kext too Now I'm getting paranoid. My /Library/Extensions/ directory contains the following kernel extensions. I purchased Little Snitch so I knew about theirs. Anyone have any comments on the rest of them? ACS6x.kext ATTOCelerityFC8.kext ATTOExpressSASHBA2.kext ATTOExpressSASRAID2.kext ArcMSR.kext BJUSBLoad.kext CIJUSBLoad.kext CalDigitHDProDrv.kext HighPointIOP.kext Hig…

I've got all of them except for

  BJUSBLoad.kext
  CIJUSBLoad.kext
  LittleSnitch.kext
From some online searching, it looks like

    BJUSBLoad.kext
and

    CIJUSBLoad.kext
are related to Canon printers.

Re: How Dropbox Hacks Your Mac

#180
post #96
post #18

Earlier quoted context omitted.

How's that any different compared to Linux? AFAIK apt packages can run arbitrary scripts as root.

No respectable package would put up a fake sudo prompt only to stash away your password for later use.

It's a good thing Dropbox isn't doing that, then.
Post reply on HN