Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

101–110 of 435 posts

Re: How Dropbox Hacks Your Mac

#101

Earlier quoted context omitted.

Got a good alt suggestion?

Has anyone tried sync.com? From their website they claim end to end encryption and seem to take privacy ands security seriously.

As long as the client is proprietary, how can one know that they are any better than Dropbox?

Feature-wise sync.com looks interesting, but there seem to be very few users out there. I would be worried that they disappear when they run out of VC money.

Re: How Dropbox Hacks Your Mac

#102
post #12
post #11

What the fuck Dropbox! How do I get rid of the backdoor in /Library/Application\ Support/com.apple.TCC/TCC.db even after uninstalling Dropbox.app and rm -rf'ing ~/.dropbox and /Library/DropboxHelperTools? Do I just sudo sqlite3 and delete the row? Or is there an official tool (tccutil)? Edit: Crap, there's a /Library/Extensions/Dropbox.kext too now. :(

should be able to just uncheck Dropbox.app in SysPrefs -> Security & Privacy -> Privacy -> Accessibility

No, that works only until your next reboot. DB has installed an agent that resets that setting in TCC.db a few seconds after you log in next.

Re: How Dropbox Hacks Your Mac

#103
post #64

Earlier quoted context omitted.

Honestly they're pretty much the most expensive out of all of the storage solutions. Other than versioning they have less features than their competition as well. If they were born today I can't imagine they would have gone much of anywhere. Not sure how they're doing financially today but it seems each product they create flops. So even outside of this surveillance stuff I don't get the point in using them.

Their client just works better at syncing quickly and reliably. A huge criteria for me is how much CPU it uses in the background compared to competing solutions from Google or MS and it was often an order of magnitude less (other clients may have improved in the last year or two, I haven't checked). Another significant advantage is that they support a stable command line client for Linux.

I've had significant issues attempting to run dropbox headless on the server for file syncing. We needed to include files from another group that was used to primarily working in Dropbox in a daily report build, and so our first go at it was to just run dropbox on that machine and pull the files directly from there. Long story short, the Dropbox client crashed periodically and would stop syncing due to issues with its local state.

After setting up monitoring around the client to keep it running we wound up switching to a different, more reliable solution.

Dropbox works ok on the server but I wouldn't rely on it as a step in any important workflows unless the client has improved significantly in the past year.

Re: How Dropbox Hacks Your Mac

#104
post #6

Non-clickbait title: "How Dropbox uses the root access that you give it during installation to give itself Accessibility authorization without triggering the usual popup".

Corrected proposed non-clickbait title: "How Dropbox fakes an authorization prompt to trick you into entering credentials that it then caches in order to bypass restrictions on what root is able to do so that it can persist a security bypass mechanism."

The first bit, for me, is key.

Re: How Dropbox Hacks Your Mac

#105

Earlier quoted context omitted.

Is the "secure desktop with dimming effect" not spoofable?

Not really. Sure you can make a replica of it but it won't behave the same because you'll be able to minimize or close it but the secure desktop you can't do jack to until you either accept to decline whatever it's asking.

Disable the minimize button? Hook into alt tab? There's endless opportunities!

Re: How Dropbox Hacks Your Mac

#106
post #12
post #11

What the fuck Dropbox! How do I get rid of the backdoor in /Library/Application\ Support/com.apple.TCC/TCC.db even after uninstalling Dropbox.app and rm -rf'ing ~/.dropbox and /Library/DropboxHelperTools? Do I just sudo sqlite3 and delete the row? Or is there an official tool (tccutil)? Edit: Crap, there's a /Library/Extensions/Dropbox.kext too now. :(

should be able to just uncheck Dropbox.app in SysPrefs -> Security & Privacy -> Privacy -> Accessibility

I tried this, but looks like Dropbox shenanigans are able to silently turn it back on.

Re: How Dropbox Hacks Your Mac

#107
post #99
post #84

Earlier quoted context omitted.

What kernel extension? Dropbox has a Finder plugin for badges, but what would they need a kernel extension for?

This kernel extension: /Library/Extensions/Dropbox.kext And good question.

I don't see that on my Mac, probably a different client version. I guess it's related to Project Infinite:

https://blogs.dropbox.com/tech/2016/05/going-deeper-with-pro...

Re: How Dropbox Hacks Your Mac

#108
post #40

I wonder if Apple will thwart this hack with an update. Seems like anyone reading this will start using this hack. In the meantime a watchdog app on this hack would be nice to have and share with the world.

TCC.db has been added to SIP as of (beta versions) of 10.12, so yes.

Re: How Dropbox Hacks Your Mac

#110
post #102
post #12

Earlier quoted context omitted.

should be able to just uncheck Dropbox.app in SysPrefs -> Security & Privacy -> Privacy -> Accessibility

No, that works only until your next reboot. DB has installed an agent that resets that setting in TCC.db a few seconds after you log in next.

Per the person I replied to, he uninstalled Dropbox and removed the agent.
Post reply on HN