Live data from Hacker News

Dropbox opening my docs?

wncinfosec.com

121–130 of 136 posts

Re: Dropbox opening my docs?

#121

Earlier quoted context omitted.

That's pretty much exactly what is happening. DropBox converts documents into HTML for easy viewing on the web interface.

You seem pretty confident! Is your source you? A DropBox employee?

abortz from DropBox has stated just this, in this thread, 4hrs before your post

Re: Dropbox opening my docs?

#122
When you click on a .doc file in the Dropbox web interface, you get a preview of the file in PDF format. To do this, Dropbox must open and convert the file. LibreOffice is popular for this, as it can be run in a headless API mode, reads a wide range of files and can output PDF format. So this is what happens here.

The wisdom of executing "active" content embedded in such files is of course doubtful and something Dropbox should investigate. But if you want your files to be safe, you should instead use a service that encrypts them client side, which has the downside of losing the web interface that Dropbox offers (as this requires it to be able to access the decrypted files in order to serve them to you).

Re: Dropbox opening my docs?

#123
post #100

Earlier quoted context omitted.

There are lots of services that generate traffic on your behalf. A very general rule is that you should have to send at least as many bytes as the service does, lest you become a DDOS multiplier. I don't see a .doc file getting small enough to outsize a HTTP request inside of it, even if you used some funky compression, but I'm willing to hear otherwise. One question would be if you could upload the document once and…

Hi everyone, this is Andrew from Dropbox. We do use LibreOffice to render previews of Office documents for viewing in a browser, and have permitted external resource loading to make those previews as accurate as possible. While this could theoretically be used for DDoS, we haven’t seen any such behavior. However, just to be extra cautious we’ve temporarily disabled external resource loading while we explore alternati…

Hi Andrew, thanks for the explanation.

Could Dropbox perhaps let me disable this feature? I almost never use the web interface so I wouldn't miss it and I prefer that my documents are not opened after being synched.

Re: Dropbox opening my docs?

#124
post #100

Earlier quoted context omitted.

There are lots of services that generate traffic on your behalf. A very general rule is that you should have to send at least as many bytes as the service does, lest you become a DDOS multiplier. I don't see a .doc file getting small enough to outsize a HTTP request inside of it, even if you used some funky compression, but I'm willing to hear otherwise. One question would be if you could upload the document once and…

Hi everyone, this is Andrew from Dropbox. We do use LibreOffice to render previews of Office documents for viewing in a browser, and have permitted external resource loading to make those previews as accurate as possible. While this could theoretically be used for DDoS, we haven’t seen any such behavior. However, just to be extra cautious we’ve temporarily disabled external resource loading while we explore alternati…

As one part of your solution, I recommend restricting the machines that can make outbound requests to a certain pool, and then limit that pool's total bandwidth, throwing an alarm whenever the limit is hit.

It may be that you are big enough that even the limited bandwidth you need for normal operations is enough to take out smaller hosts, so you'd need to measure and monitor to see how well this works.

Re: Dropbox opening my docs?

#125
post #58
post #35

Earlier quoted context omitted.

I hate it whenever an article mentions a service or drops an affiliate link and someone's verdict is that the article looks like advertising. Do you prefer your reading content to be devoid of mentioning any products or brands? Should bloggers never make a dime off affiliate links? Be concerned with the content and only the content. If the article has it, it's legit.

> Be concerned with the content and only the content. If the article has it, it's legit. Wrong. Context is everything. You cannot look at data in a vacuum. You need to look at where, why, when and how - especially when it's sensational; i.e. something that may cause someone to take action.

[deleted]

Re: Dropbox opening my docs?

#126
post #78
post #35

Earlier quoted context omitted.

I hate it whenever an article mentions a service or drops an affiliate link and someone's verdict is that the article looks like advertising. Do you prefer your reading content to be devoid of mentioning any products or brands? Should bloggers never make a dime off affiliate links? Be concerned with the content and only the content. If the article has it, it's legit.

I translated your comment to Galician: Eu odio iso, cada vez que un artigo menciona un servizo ou cae dun enlace de afiliado e veredicto de alguén é que o artigo parece publicidade. Prefire o seu contido de lectura a ser desprovisto de mencionar os produtos ou marcas? Se bloggers nunca facer un centavo off ligazóns afiliados? Estar preocupado co contido e só o contido. O artigo ten iso, é lexítimo. If you are curious…

That's spam, not useful data. No one upvoted that hypothetical offering of data. People did find this article interesting.

And hey, maybe I am interested in learning that language. Assuming your forum was appropriate (say, at a Galician convention), that could be a useful thing.

Re: Dropbox opening my docs?

#127
post #58
post #35

Earlier quoted context omitted.

I hate it whenever an article mentions a service or drops an affiliate link and someone's verdict is that the article looks like advertising. Do you prefer your reading content to be devoid of mentioning any products or brands? Should bloggers never make a dime off affiliate links? Be concerned with the content and only the content. If the article has it, it's legit.

> Be concerned with the content and only the content. If the article has it, it's legit. Wrong. Context is everything. You cannot look at data in a vacuum. You need to look at where, why, when and how - especially when it's sensational; i.e. something that may cause someone to take action.

> You cannot look at data in a vacuum.

I never said you could. We're not discussing the philosophy of objective statements that don't require context, we're discussing whether true facts are tainted by subjective elements around them. By definition, they can't be.

If the content is good, it doesn't really matter why it's there. But if you believe the context implies that the data is incomplete (aka, biased) or actually wrong, that's obviously relevant.

Especially if something was an ad, who cares? The data speaks for itself. You just need to verify the ad is correct and isn't mis-representing itself. In this case, the data is fairly objective, they aren't comparing their product to someone else's, just pointing out an action that a product was able to help perform, and that action produced interesting data about another service.

The article didn't come off as an ad, either. My main gripe was that some people complain over any mention of affiliated services. (People also gripe about non-labeled affiliate links by independent-millionaire, popular, respected bloggers.)

Re: Dropbox opening my docs?

#128
post #126
post #78

Earlier quoted context omitted.

I translated your comment to Galician: Eu odio iso, cada vez que un artigo menciona un servizo ou cae dun enlace de afiliado e veredicto de alguén é que o artigo parece publicidade. Prefire o seu contido de lectura a ser desprovisto de mencionar os produtos ou marcas? Se bloggers nunca facer un centavo off ligazóns afiliados? Estar preocupado co contido e só o contido. O artigo ten iso, é lexítimo. If you are curious…

That's spam, not useful data. No one upvoted that hypothetical offering of data. People did find this article interesting. And hey, maybe I am interested in learning that language. Assuming your forum was appropriate (say, at a Galician convention), that could be a useful thing.

With apologies to Arthur C. Clarke: Sufficiently advanced spam is indistinguishable from useful content.

Re: Dropbox opening my docs?

#129
post #100

Earlier quoted context omitted.

There are lots of services that generate traffic on your behalf. A very general rule is that you should have to send at least as many bytes as the service does, lest you become a DDOS multiplier. I don't see a .doc file getting small enough to outsize a HTTP request inside of it, even if you used some funky compression, but I'm willing to hear otherwise. One question would be if you could upload the document once and…

Hi everyone, this is Andrew from Dropbox. We do use LibreOffice to render previews of Office documents for viewing in a browser, and have permitted external resource loading to make those previews as accurate as possible. While this could theoretically be used for DDoS, we haven’t seen any such behavior. However, just to be extra cautious we’ve temporarily disabled external resource loading while we explore alternati…

[deleted]

Re: Dropbox opening my docs?

#130
post #100

Earlier quoted context omitted.

There are lots of services that generate traffic on your behalf. A very general rule is that you should have to send at least as many bytes as the service does, lest you become a DDOS multiplier. I don't see a .doc file getting small enough to outsize a HTTP request inside of it, even if you used some funky compression, but I'm willing to hear otherwise. One question would be if you could upload the document once and…

Hi everyone, this is Andrew from Dropbox. We do use LibreOffice to render previews of Office documents for viewing in a browser, and have permitted external resource loading to make those previews as accurate as possible. While this could theoretically be used for DDoS, we haven’t seen any such behavior. However, just to be extra cautious we’ve temporarily disabled external resource loading while we explore alternati…

@helium: don't trust online storage. Simply encrypt your files with tools like boxcryptor to be sure dropbox (=the NSA) cannot read your files that easy.
Post reply on HN