Live data from Hacker News

Dropbox Lack of Security

tirania.org

131–140 of 193 posts

Re: Dropbox Lack of Security

#131
post #6

truecrypt ftw If you're uncomfortable with dropbox, put a truecrypt partition right inside your dropbox folder.

If you do this, make sure you disable the TrueCrypt option which preserves the original modification time of the encrypted volume when you modify the container, otherwise Dropbox may not notice when you make changes.

The "preserve modification timestamp" option is part of TC's plausible deniability feature.

Re: Dropbox Lack of Security

#132
post #32

This is the first time I've heard someone on HN actually ask for more security theatre. Sure, Dropbox could spend seven figures to get a ISOxxxx whatever consultancy to draw up a 125 page document describing their internal checks, do the obligatory all-hands yearly mandatory training where you have to get 10/10 questions right and question 1 is "A user has uploaded naked pictures of themselves to their account. True…

As others said, #1 is false. You can look at your data whenever you want without letting others do the same, even if they have access to the data. That's what asymmetric (or even symmetric) cryptography does. Apart from that, did anyone ever think Dropbox was completely secure? The mere fact that they perform deduplication, which is not possible if they can't read your data, should have tipped people off to it. Not t…

I don't use Dropbox so I recently learned that they performed data deduplication. For me this is still a breaking story.

Re: Dropbox Lack of Security

#133

Dropbox didn't lie. This is simply a misinterpretation (or misunderstanding) of what's meant by the phrase "Dropbox employees aren't able to access user files". It's not the same as saying "It's impossible." The fact is, if you send a company your unencrypted data, it's obviously possible for them to view it at some point. Otherwise they could never encrypt it in the first place. So when they say that employees aren'…

The plain English meaning of the words "aren't able to access user files" is not the same as "choose not to access user files".

Dropbox could just keep keys in a store where only automated user accounts can get to them -- ones where only the founders have passwords, or they are in escrow. I think there are ways to restrict the access to founders and a fail-safe, without opening them up to anyone who works at Dropbox.

Re: Dropbox Lack of Security

#134
post #32

This is the first time I've heard someone on HN actually ask for more security theatre. Sure, Dropbox could spend seven figures to get a ISOxxxx whatever consultancy to draw up a 125 page document describing their internal checks, do the obligatory all-hands yearly mandatory training where you have to get 10/10 questions right and question 1 is "A user has uploaded naked pictures of themselves to their account. True…

All he's really asking for is for Dropbox to explain their security in ways that don't overpromise what they actually deliver. If they want to live up to their promise, then he's suggesting a way to do that.

Re: Dropbox Lack of Security

#135
post #32

This is the first time I've heard someone on HN actually ask for more security theatre. Sure, Dropbox could spend seven figures to get a ISOxxxx whatever consultancy to draw up a 125 page document describing their internal checks, do the obligatory all-hands yearly mandatory training where you have to get 10/10 questions right and question 1 is "A user has uploaded naked pictures of themselves to their account. True…

#1 is not true. SpiderOak and Wuala both have products in the marketplace today that demonstrate the effective use of encryption in a backup and sync app. SpiderOak has no ability to examine or to give the plaintext of a user's data to a government or anyone else - not filenames, folder names, etc. On the servers, we just see sequentially numbered encrypted containers. We are incapable of betraying our customers in t…

I'd never heard of SpiderOak before. Reading some info on their site here is how they explain how they allow access to your files from a browser.

"When you access your data via the website, in order for the SpiderOak server to send you your folder and filenames, and send your browser the plain text versions of your data, you must type in your password, which exists in the SpiderOak server's memory for the duration of your browsing session. Your password is only stored only in encrypted memory (and never written to an unencrypted disk) and is destroyed when your browsing session ends."

Seems pretty cool. I might have to check them out.

Re: Dropbox Lack of Security

#137
post #82

Earlier quoted context omitted.

Everything on your website that in any way addresses "Dropbox's security" should make absolutely clear the extent to which users can expect their data to be "secure". In Dropbox's case, users can expect the following: - Data is probably secure from sniffers That's it. It matters little whether "Drew has physical access to our storage servers anymore". Your code obviously has easy access to the keys used to encrypt an…

you're right in that all these things are theoretically possible in a system where the encryption key is not stored client-side. I don't know of many services that advertise every way in which their systems could be compromised. I think you'd be hard pressed to find a company doing this. in the case of google - is there a document explaining all the places your email could end up? we believe that what we advertise is…

This is a discussion of the consistency of advertised security claims with disclosures about availability of data to government subpoena.

In that context, statements like "we believe that what we advertise is in our userbase's best interest" make my ears prick up. I'm not a crypto expert, but this sort of thing does not seem like a straightforward response to the OP.

Re: Dropbox Lack of Security

#138
post #82

Earlier quoted context omitted.

Everything on your website that in any way addresses "Dropbox's security" should make absolutely clear the extent to which users can expect their data to be "secure". In Dropbox's case, users can expect the following: - Data is probably secure from sniffers That's it. It matters little whether "Drew has physical access to our storage servers anymore". Your code obviously has easy access to the keys used to encrypt an…

you're right in that all these things are theoretically possible in a system where the encryption key is not stored client-side. I don't know of many services that advertise every way in which their systems could be compromised. I think you'd be hard pressed to find a company doing this. in the case of google - is there a document explaining all the places your email could end up? we believe that what we advertise is…

"Our reputation would be permanently damaged if dropbox is compromised."

This is why I trust DropBox with my data: because I'm a paying customer. That means our goals are aligned.

Re: Dropbox Lack of Security

#139
post #124
post #53

Three points: 1. Sensationalism aside, Dropbox should review questionable security claims to reduce false sense of security if any. With millions of users, careless words formed out of marketing needs are no longer needed. What Dropbox users need now is more clear picture of what they are giving up to gain Dropbox's services. 2. The weakest security link is the user and their computer, not Dropbox which has enough fi…

Agreed. Except a lot of companies have a lot of " financial incentives at stake to be diligent security wise" but aren't. Something I very recently heard: "World of Warcraft has had RSA-style two-factor token authentication for years, and my bank still doesn't"

Some thoughts re WoW vs banks:

WoW Authenticator is optional, costs $30~40, and intended for serious WoW players in a community with very strong peer support. Banks can do first two but don't have a community of tech savvy users to reduce cost of support manageable.

So Blizzard could but banks couldn't. Will this change? I think so but it'll have to be opt-in and paid for by customers, likely through third-party services first.

Re: Dropbox Lack of Security

#140

Earlier quoted context omitted.

The difference being that you can change your facebook password. It's not that easy with dropbox.

It's just as easy to de-authorize devices (and hence invalidate host IDs) on Dropbox as is is to change your Facebook password.

If you dupe someone's Dropbox host ID, they'll only see the one entry on their page, so it's quite likely they would not be aware that they've been "duped".
Post reply on HN