Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

271–280 of 435 posts

Re: How Dropbox Hacks Your Mac

#272
post #252

Earlier quoted context omitted.

This appears to be impossible in Sierra, as the relevant db has been added to SIP. I have un-granted access, and the dropbox app has not been able to re-enable it, nor has it complained (and yes, I restarted).

What is SIP? I've seen it mentioned elsewhere in the thread but not explained, and in the article ctrl+f SIP yields no results.

System Integrity Protection. Because of crazy hacks like this, macOS restricts what even root can do.

https://support.apple.com/en-us/HT204899

Re: How Dropbox Hacks Your Mac

#273
post #125

Earlier quoted context omitted.

> so they implicitly have access to all your files If you can demonstrate how Apple has access to my files on an OS X installation with no iCloud configured, I will round up a massive bounty.

Open your finder. Every file that you see has just been touched by apples code. Your OS does have access to all files that you have on your computer. It manages all network connections. It exposes all information that tools such as little snitch display to you. Apple signs and provides all software updates to you. They control SPI and app sandboxing. I'm not saying that Apple does access your files. I do trust them n…

burn.

Re: How Dropbox Hacks Your Mac

#275

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

"We use elevated access for where the built-in FS APIs come up short."

One wonders what Dropbox would say if someone decided to obtain elevated access on their servers by surreptitious means because Dropbox's API "came up short".[1]

[1] https://www.dropboxforum.com/hc/en-us/community/posts/204550...

Re: How Dropbox Hacks Your Mac

#276
post #252

Earlier quoted context omitted.

This appears to be impossible in Sierra, as the relevant db has been added to SIP. I have un-granted access, and the dropbox app has not been able to re-enable it, nor has it complained (and yes, I restarted).

What is SIP? I've seen it mentioned elsewhere in the thread but not explained, and in the article ctrl+f SIP yields no results.

System Integrity Protection, basically not even root can change files protected by SIP.

Re: How Dropbox Hacks Your Mac

#277

Earlier quoted context omitted.

It's very strange that after I remove Dropbox from the accessibility list you think it's ok to add it back in again. That's the reason I'll be closing my account.

Why would you even do that? What nefarious and yet undiscovered things did you think DropBox was likely to do specifically with the accessibility permission? Permission systems in general seem like a solution without a problem to me. Nobody but a minority of people very concerned about theoretical security problems wanted them on platforms that didn't have them, almost nobody cares what permissions programs use on pl…

I prefer to know what the apps I install are going to be doing. To this end, OS-enforced permissions for using various services are a godsend. No program should need "admin" rights. And I should be able to know and control what each app I run can and cannot do. This seems utterly obvious to me. Even if most people dont' care, the tools should be there. There've been more than enough cases where apps have collected information they shouldn't have, whether intentionally or lazily. It baffles me that anyone could seriously make the argument you seem to be making.

Re: How Dropbox Hacks Your Mac

#278

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

> - We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). To clarify for others: In /Library/DropboxHelperTools, you'll find a folder for each user full of setuid tools which run as root and do various privileged things. I assume that the client is presenting the normal OS X "ask for elevated access" UI and then using that elevated access to configure and install…

Wow, it's stunning that an app would install anything suid root.

Admittedly I'm not a Mac guy, but that can't be common practice.

And then the response isn't "we're going to stop endangering our users with this dangerous practice", it's "we're going to stop doing this one particular thing that happened to be called out this time".

Re: How Dropbox Hacks Your Mac

#280

Earlier quoted context omitted.

> - We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). To clarify for others: In /Library/DropboxHelperTools, you'll find a folder for each user full of setuid tools which run as root and do various privileged things. I assume that the client is presenting the normal OS X "ask for elevated access" UI and then using that elevated access to configure and install…

Wow, it's stunning that an app would install anything suid root. Admittedly I'm not a Mac guy, but that can't be common practice. And then the response isn't "we're going to stop endangering our users with this dangerous practice", it's "we're going to stop doing this one particular thing that happened to be called out this time".

> that can't be common practice.

It's not. It's very unusual.

Post reply on HN