Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

211–220 of 435 posts

Re: How Dropbox Hacks Your Mac

#211
post #199

Earlier quoted context omitted.

>We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). If that's the case, How is it that the accessibility preferences are changed without root authorization?

Once you type your password into the Apple dialog, you grant Dropbox root access. That's the purpose of this dialog in all cases.

Per the original article, even root doesn't automatically have permission to modify the system.preferences.accessibility list.

Re: How Dropbox Hacks Your Mac

#212
post #2

Just wanted to give the author a shoutout for being awesome. This article is published with an AMP version[0] too, which is pretty unusual for smaller blogging sites. AMP articles are so much easier on my eyes (and the author can't include their own javascript on an AMP page, so there is less bloat). I wish all bloggers started to publish AMP pages. [0] - http://applehelpwriter.com/2016/08/29/discovering-how-dropbo..…

In case there are any Wordpress bloggers and authors out there who would like to add AMP functionality to their websites Automattic put together a nice plugin tool to do just that.[0] I wonder when this will become part of the wp-core? [0] https://github.com/Automattic/amp-wp

I hope never. This is clearly the sort of thing that should be optional--which is exactly why Wordpress has a plugin system.

Re: How Dropbox Hacks Your Mac

#213
post #9

It looks like in 10.12 Apple has added TCC.db to SIP, so this will no longer work — Dropbox will, hopefully, actually be forced to request accessibility access like they're supposed to. I'm sure they'll still demand your admin password via a dialog that tries super hard to look like a system one to use for whatever other more or less nefarious purposes. Would be nice if there was an alternative that actually syncs as…

I use owncloud (and then dropbox inside it so some files are double backed up). I find it to be just fine. Have you had any problems with it?

Yes, last time I tried it, had a variety of conflict issues plus the client had some problems, performance and otherwise. If you're just using it as a backup solution (does it even keep file history?) from a single machine + mobile/web access, it may well work acceptably.

Re: How Dropbox Hacks Your Mac

#214

Earlier quoted context omitted.

Honestly they're pretty much the most expensive out of all of the storage solutions. Other than versioning they have less features than their competition as well. If they were born today I can't imagine they would have gone much of anywhere. Not sure how they're doing financially today but it seems each product they create flops. So even outside of this surveillance stuff I don't get the point in using them.

Out of the mainstream ones, they are the only ones supporting Linux.

How so? Seafile and SpiderOak both thrive on their excellent Linux support, and Mega also supports Linux with an official client. They are, if not in the top five, at least in the top ten of popular consumer cloud storage solutions.

Re: How Dropbox Hacks Your Mac

#215

Earlier quoted context omitted.

It's very strange that after I remove Dropbox from the accessibility list you think it's ok to add it back in again. That's the reason I'll be closing my account.

Why would you even do that? What nefarious and yet undiscovered things did you think DropBox was likely to do specifically with the accessibility permission? Permission systems in general seem like a solution without a problem to me. Nobody but a minority of people very concerned about theoretical security problems wanted them on platforms that didn't have them, almost nobody cares what permissions programs use on pl…

What if Dropbox has an exploit they're unaware of. Someone finds a whole in Dropbox and boom, now they have accessibility access.

Even if you trust the software vendor, security concerns can cascade.

Re: How Dropbox Hacks Your Mac

#216

Earlier quoted context omitted.

Can you also tell us why Dropbox eats lots of CPU cycles anytime there is any filesystem activity? If I unzip a large archive in /tmp, Dropbox is eating 60% of my CPU. If I open the new Xcode for the first time (and the system verifies all the signatures) Dropbox is eating 100% of one CPU. It really seems like the Dropbox client is monitoring the entire filesystem (all FSEvents) instead of just the dropbox syncing fo…

Could this be a consequence of the built in FS APIs coming up short, as Ben put it, and forcing DropBox to do things in less efficient ways to work around the limitations?

[deleted]

Re: How Dropbox Hacks Your Mac

#218

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

> The intent was never to frustrate people or override their choices

When you designed an agent that specifically overrides the user's choice to turn off Accessibility rights for Dropbox, frustrating that attempt, I suspect that was intentional.

Re: How Dropbox Hacks Your Mac

#220
post #9

It looks like in 10.12 Apple has added TCC.db to SIP, so this will no longer work — Dropbox will, hopefully, actually be forced to request accessibility access like they're supposed to. I'm sure they'll still demand your admin password via a dialog that tries super hard to look like a system one to use for whatever other more or less nefarious purposes. Would be nice if there was an alternative that actually syncs as…

We use OneDrive at work and it works pretty much exactly as well as I recall Dropbox working back when I used it.
Post reply on HN