Ok. Now that Dropbox is shady as well as overpriced, are there any good alternatives?
IPFS
How Dropbox Hacks Your Mac
231–240 of 435 posts
Re: How Dropbox Hacks Your Mac
#232Re: How Dropbox Hacks Your Mac
#233I'm guessing it's not going to be different from what it does on a Mac, but it would be nice to know exactly...
Re: How Dropbox Hacks Your Mac
#234It looks like in 10.12 Apple has added TCC.db to SIP, so this will no longer work — Dropbox will, hopefully, actually be forced to request accessibility access like they're supposed to. I'm sure they'll still demand your admin password via a dialog that tries super hard to look like a system one to use for whatever other more or less nefarious purposes. Would be nice if there was an alternative that actually syncs as…
We use OneDrive at work and it works pretty much exactly as well as I recall Dropbox working back when I used it.
Re: How Dropbox Hacks Your Mac
#235Re: How Dropbox Hacks Your Mac
#236Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…
To clarify for others: In /Library/DropboxHelperTools, you'll find a folder for each user full of setuid tools which run as root and do various privileged things. I assume that the client is presenting the normal OS X "ask for elevated access" UI and then using that elevated access to configure and install these. (I don't work for Dropbox or anything; I've just been poking around.)
> - We use accessibility APIs for the Dropbox badge (Office integrations) and other integrations (finding windows & other UI interactions).
@newhouseb, I don't have Office, so I've turned off the badge. Is Dropbox now going to leave my accessibility permissions the way I set them? Or is it going to reactivate a permission behind my back that it no longer even needs?
I understand the desire to make your features "just work", but circumventing the user's privacy controls to do that is never acceptable. Especially accessibility, which is basically a general warrant to snoop on everything the user does. You wouldn't be on my system anymore if my work didn't require Dropbox. You're going to lose a lot of trust over this, and it won't even be half of what you deserve.
And it's not even in your interest in the long term. This fiasco has probably made it more likely that Apple will further lock down the accessibility APIs, possibly even making them unavailable without an Apple-issued, potentially App Store-only entitlement. Since Dropbox can't really do its job when it's locked in a sandbox, I really don't think that's what you guys want to happen.
Teams like yours are why we can't have nice things.
(P.S. plz respect NSFileCoordinator this isn't Tiger anymore kthxbai)
Re: How Dropbox Hacks Your Mac
#237Earlier quoted context omitted.
Why would you even do that? What nefarious and yet undiscovered things did you think DropBox was likely to do specifically with the accessibility permission? Permission systems in general seem like a solution without a problem to me. Nobody but a minority of people very concerned about theoretical security problems wanted them on platforms that didn't have them, almost nobody cares what permissions programs use on pl…
Right, they have all your files already, so there's clearly some level of trust.
Hell no they don't? They have some shared folders between classmates and a few encrypted archives for personal backups.
Re: How Dropbox Hacks Your Mac
#238Earlier quoted context omitted.
How's that any different compared to Linux? AFAIK apt packages can run arbitrary scripts as root.
It's slightly different, because Dropbox board members support warrantless surveillance: http://www.drop-dropbox.com/
Re: How Dropbox Hacks Your Mac
#239Re: How Dropbox Hacks Your Mac
#240Earlier quoted context omitted.
Why would you even do that? What nefarious and yet undiscovered things did you think DropBox was likely to do specifically with the accessibility permission? Permission systems in general seem like a solution without a problem to me. Nobody but a minority of people very concerned about theoretical security problems wanted them on platforms that didn't have them, almost nobody cares what permissions programs use on pl…
What if Dropbox has an exploit they're unaware of. Someone finds a whole in Dropbox and boom, now they have accessibility access. Even if you trust the software vendor, security concerns can cascade.
What if the hack pushes a rogue client? Or one CDN endpoint serves a malicious update? Or a little bit of code is sneaked into the development process? Or an employee gets sour? Or a million other things that you hope never happen. There is a reason we don't run apache/nginx/any networked service as root. (You don't, right?)