Live data from Hacker News

Dropbox passwords optional for four hours

techcrunch.com

31–40 of 48 posts

Re: Dropbox passwords optional for four hours

#31

Anyone using SpiderOak? They're the only other versioning diff-based backup service I know of that supports Linux (with a free tier; there's also Tarsnap). They also claim 'zero-knowledge' encryption. Anyone have any opinions?

There's also ownCloud ( http://owncloud.org/index.php/Main_Page ), if you're into that whole home server thing. It definitely supports Linux.

It supports Linux poorly, and supports nothing else at all.

(WebDAV isn't "support," when you look at the Dropbox/SpiderOak feature set.)

Re: Dropbox passwords optional for four hours

#33
post #24
post #23

Earlier quoted context omitted.

I hate to be the one to break this to you†, but normal people make up almost the entire chain of custody for regulated data. Normal people write your health records. Normal people check them out of databases and read them. Normal people load them into spreadsheets. Normal people generate reports. Businesses do not exist to support super-savvy BOFH's. It is rather the other way around. † Ok, no I don't

I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs. EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certi…

Friend of mine worked for a drug company, medical data on patients (they were handling the side-effect reports) was just emailed around, and I know they had work documents on their home computer.

Re: Dropbox passwords optional for four hours

#34
post #33
post #24

Earlier quoted context omitted.

I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs. EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certi…

Friend of mine worked for a drug company, medical data on patients (they were handling the side-effect reports) was just emailed around, and I know they had work documents on their home computer.

I would never be foolish enough to say it _doesn't_ happen, simply that the rules say it _mustn't_ happen. Anyone who ends up complaining that they're forced to disclose because they didn't follow best practices, just learned why they're best practices.

I admit readliy it's mostly the problem of bad luck (being targeted) or careless (losing emailed reports w/ identifying data ) - but if and when that drug company gets sued for something like that, guess which side the law will be on?

Re: Dropbox passwords optional for four hours

#35
post #24
post #23

Earlier quoted context omitted.

I hate to be the one to break this to you†, but normal people make up almost the entire chain of custody for regulated data. Normal people write your health records. Normal people check them out of databases and read them. Normal people load them into spreadsheets. Normal people generate reports. Businesses do not exist to support super-savvy BOFH's. It is rather the other way around. † Ok, no I don't

I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs. EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certi…

HIPAA does not have thousands of pages on what and what not to do. It's actually quite vague, and mostly comes down to fines after the fact. There's also no such thing as a government sanctioned HIPAA certification. There's just random people willing to 'certify' you.

Re: Dropbox passwords optional for four hours

#36
post #24

Earlier quoted context omitted.

I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs. EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certi…

HIPAA does not have thousands of pages on what and what not to do. It's actually quite vague, and mostly comes down to fines after the fact. There's also no such thing as a government sanctioned HIPAA certification. There's just random people willing to 'certify' you.

The HIPAA data security requirements are tiny and largely boil down to "data should be encrypted in transit and at rest and require access control".

http://law.justia.com/cfr/title45/45-1.0.1.3.70.3.33.6.html

Re: Dropbox passwords optional for four hours

#37

Earlier quoted context omitted.

It's unfortunate that simple public key encryption, which has been easily available for many years, is still seen as untenable and "super-paranoid." Any email client, or better yet Gmail, could easily implement it and make it virtually transparent to the user (when both ends of the email are using such a client, obviously).

I apologise if you have mistaken my meaning! I certainly hope we don't take wider scale encryption to be untenable, but it is very certainly untenable for a single person to use the web in a meaningful way with normal people while maintaining that every single email needs to be encrypted.

I agree. I didn't mean that your evaluation of the current state of things is wrong, but rather that the current state of things is unfortunate.

Re: Dropbox passwords optional for four hours

#38
post #3

I use any online service with the assumption that the things I put up there could likely become public, no longer anonymous, or what have you. I don't think this is overly paranoid, given how difficult computer security is. To me; it would make sense if Dropbox stored everything encrypted (as in, encrypted pre-transfer), and you needed the private key to decrypt stuff, unless you specifically state that it is to be p…

Why would you assume that things that you store online is 'public'? Do you assume the same with bank information? or do you just not use online banking or bill paying?

Re: Dropbox passwords optional for four hours

#39
post #11
post #9

Anyone who had any confidential data in Dropbox (medical research data, credit card transaction data) must now file a data breach report.

And anyone who stored that sort of data in dropbox more or less had it coming. HIPAA & finance laws are very clear about the security they require -- dropbox has always been hand-wavey in their explanation of their security.

The problem is just that they haven't been! According to their TOS until just over a month they were HIPAA compliant as a secure online service abiding by the set rules.

Re: Dropbox passwords optional for four hours

#40
post #17

Earlier quoted context omitted.

Do people really store confidential business data like that in dropbox?

Very yes (we don't allow Dropbox† on our machines, but we know of companies that rely on it). Grandalf's point is extremely well taken. It's actually true. Not only that, but regulated companies (in health care and finance) that have a reasonable belief that any of their systems might have had Dropbox on them technically need to audit now. I point this out not to bag on Dropbox, but as an illustration of how sane som…

Why not Tarsnap?
Post reply on HN