Live data from Hacker News

Dropbox passwords optional for four hours

techcrunch.com

21–30 of 48 posts

Re: Dropbox passwords optional for four hours

#21

Anyone using SpiderOak? They're the only other versioning diff-based backup service I know of that supports Linux (with a free tier; there's also Tarsnap). They also claim 'zero-knowledge' encryption. Anyone have any opinions?

There's also ownCloud (http://owncloud.org/index.php/Main_Page), if you're into that whole home server thing. It definitely supports Linux.

Re: Dropbox passwords optional for four hours

#22
post #18
post #11

Earlier quoted context omitted.

And anyone who stored that sort of data in dropbox more or less had it coming. HIPAA & finance laws are very clear about the security they require -- dropbox has always been hand-wavey in their explanation of their security.

What's your point? The IT guys can't catch a break, can they? If they say "no you can't install stuff on your machine", message board geeks are up in arms. But when normal people, for whom these computer systems are designed in the first place, make (layperson-) reasonable decisions about what folders to put files in, there's the message board geek again, harassing them for not understanding how transparent cloud fil…

If you're a 'normal person', you shouldn't be making decisions about the security of my health-care or financial data; If you're in the position to make that decision, you should have been aware that dropbox was not a "safe" third party;

On the part of the _users_ of dropbox, I have empathy; In part of those running their medical/finance business on assumptions of dropboxes security, I have nothing but emnity.

Re: Dropbox passwords optional for four hours

#23
post #22
post #18

Earlier quoted context omitted.

What's your point? The IT guys can't catch a break, can they? If they say "no you can't install stuff on your machine", message board geeks are up in arms. But when normal people, for whom these computer systems are designed in the first place, make (layperson-) reasonable decisions about what folders to put files in, there's the message board geek again, harassing them for not understanding how transparent cloud fil…

If you're a 'normal person', you shouldn't be making decisions about the security of my health-care or financial data; If you're in the position to make that decision, you should have been aware that dropbox was not a "safe" third party; On the part of the _users_ of dropbox, I have empathy; In part of those running their medical/finance business on assumptions of dropboxes security, I have nothing but emnity.

I hate to be the one to break this to you†, but normal people make up almost the entire chain of custody for regulated data. Normal people write your health records. Normal people check them out of databases and read them. Normal people load them into spreadsheets. Normal people generate reports. Businesses do not exist to support super-savvy BOFH's. It is rather the other way around.

Ok, no I don't

Re: Dropbox passwords optional for four hours

#24
post #23
post #22

Earlier quoted context omitted.

If you're a 'normal person', you shouldn't be making decisions about the security of my health-care or financial data; If you're in the position to make that decision, you should have been aware that dropbox was not a "safe" third party; On the part of the _users_ of dropbox, I have empathy; In part of those running their medical/finance business on assumptions of dropboxes security, I have nothing but emnity.

I hate to be the one to break this to you†, but normal people make up almost the entire chain of custody for regulated data. Normal people write your health records. Normal people check them out of databases and read them. Normal people load them into spreadsheets. Normal people generate reports. Businesses do not exist to support super-savvy BOFH's. It is rather the other way around. † Ok, no I don't

I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs.

EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certified. If you chose to operate in a business that requires HIPAA/PCI, and used dropbox for that data, _you_ are at fault, not dropbox, not the bofhs, and not the coder. In the case of HIPAA - you would be the criminal.

Re: Dropbox passwords optional for four hours

#25
post #3

I use any online service with the assumption that the things I put up there could likely become public, no longer anonymous, or what have you. I don't think this is overly paranoid, given how difficult computer security is. To me; it would make sense if Dropbox stored everything encrypted (as in, encrypted pre-transfer), and you needed the private key to decrypt stuff, unless you specifically state that it is to be p…

Depends on the online-service. E.g., I trust tarsnap (client-side encryption, not under an open-source license but you can compile it yourself) with very sensitive data. I also trust Wuala (also client-side encryption) with semi-sensitive data, although it somewhat worries me that Wuala's source is not publicly available for reviews. I don't trust Dropbox due to the lack of encryption - that's why I don't really use it, even though I currently have a free account with 20 GB available.

Re: Dropbox passwords optional for four hours

#26
post #4
post #3

I use any online service with the assumption that the things I put up there could likely become public, no longer anonymous, or what have you. I don't think this is overly paranoid, given how difficult computer security is. To me; it would make sense if Dropbox stored everything encrypted (as in, encrypted pre-transfer), and you needed the private key to decrypt stuff, unless you specifically state that it is to be p…

The thing is that you can't do email then. You can say that google might leak your emails, but the same is true if you use your private email server.

The security of my private mailserver is nearly the same as the security of my laptop. For security reasons I don't use a VPS for email, but a small server that sits in my basement: There are some security measures that will lead to an automatic shutdown in case someone tries to physically access the server and the whole harddisk is encrypted. (Yes - you can call me paranoid.)

Re: Dropbox passwords optional for four hours

#29

Earlier quoted context omitted.

That's not exactly true. You just need to be super-paranoid and make sure that everything of importance is sent (on both ends) encrypted. That's still wholly untenable for the real world, but not all paranoid people live in the real world per se.

It's unfortunate that simple public key encryption, which has been easily available for many years, is still seen as untenable and "super-paranoid." Any email client, or better yet Gmail, could easily implement it and make it virtually transparent to the user (when both ends of the email are using such a client, obviously).

I apologise if you have mistaken my meaning! I certainly hope we don't take wider scale encryption to be untenable, but it is very certainly untenable for a single person to use the web in a meaningful way with normal people while maintaining that every single email needs to be encrypted.

Re: Dropbox passwords optional for four hours

#30
post #10
post #7

Earlier quoted context omitted.

I can smell all the journalists down voting

hilarious, but you all know that journalists in the tech world are seen as the "I-dont-know-nothing-but-I'll-just-pretend__with-a-smile-like-if-i-understood."

make me the worst HN user and go blog about it :)
Post reply on HN