This might be the first time a large company has actually apologised and admitted some fault. Colour me shocked.
A recent security incident involving Dropbox Sign
31–40 of 76 posts
Re: A recent security incident involving Dropbox Sign
#32Earlier quoted context omitted.
Dropbox offers end-to-end encryption now (for business teams): https://blog.dropbox.com/topics/company/new-solutions-to-sec...
I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.
Re: A recent security incident involving Dropbox Sign
#33I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…
Re: A recent security incident involving Dropbox Sign
#34Dropbox was breached also around 2012.
That was when i stopped using the cloud for storing personal stuff. Fast forward a decade and i've more than had my fill of self hosting stuff, so a couple of years ago i went all in on the cloud again, though with a bit of a different approach. Stuff that is not really sensitive is uploaded "as is". Yes, that includes our photos. While i don't want our photo library to be "public domain", there is nothing there of p…
Re: A recent security incident involving Dropbox Sign
#35Earlier quoted context omitted.
That was when i stopped using the cloud for storing personal stuff. Fast forward a decade and i've more than had my fill of self hosting stuff, so a couple of years ago i went all in on the cloud again, though with a bit of a different approach. Stuff that is not really sensitive is uploaded "as is". Yes, that includes our photos. While i don't want our photo library to be "public domain", there is nothing there of p…
For this reason, I enabled E2E encryption for iCloud. Sure, if you are very paranoid, you can choose not to trust Apple, but E2E encryption on iCloud is seamless, and I haven't noticed a difference since enabling it.
iCloud works great, and even if you trust Apple (which i do to some extent), your data is still only safe as long as nobody gains access to your devices. Once somebody has access to your devices, files are no longer encrypted.
The choice of Cryptomator was a convenience choice. I could have just as easliy encrypted files using GPG, LUKS, encrypted disk images or similar, but i would not have been able to access those directly from my phone/tablet in their cloud location, which is something i can do with Cryptomator.
For reference, i have about 4TB data in the cloud (~3.5TB photo library), and a 2GB Cryptomator vault, so it's not exactly the main driver of the operation :)
Re: A recent security incident involving Dropbox Sign
#36Earlier quoted context omitted.
Dropbox offers end-to-end encryption now (for business teams): https://blog.dropbox.com/topics/company/new-solutions-to-sec...
I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.
Re: A recent security incident involving Dropbox Sign
#37> Based on our investigation, a third party gained access to a Dropbox Sign automated system configuration tool. The actor compromised a service account that was part of Sign’s back-end, which is a type of non-human account used to execute applications and run automated services. As such, this account had privileges to take a variety of actions within Sign’s production environment. The threat actor then used this acc…
A service account is used to give limited permissions on one system to another system. Normally only that system would need access to them, not any human.
Their main benefit is that, since no person is trying to do their day job here, the account can be locked down to precisely the permissions it needs. The reality is that service accounts are usually given extremely permissive access initially and then forgotten about. This makes them juicy targets for attackers.
Re: A recent security incident involving Dropbox Sign
#38Earlier quoted context omitted.
Of course there isn't, but it limits efficiency and features. For example, you will miss all the fancy features Google Images does in cloud and user experience might be slower, since everything must be processed and downloaded on client side. Some level of metadata is always unencrypted.
That's trading one feature for a bunch of others. Users should have the choice of what features they think are important.
Re: A recent security incident involving Dropbox Sign
#39Earlier quoted context omitted.
I use Proton Drive [1], they offer e2ee but I agree with you: the Dropbox app experience is probably still the best. [1] https://proton.me/drive
OK, so there is no fundamental obstacle for providing true e2ee.
Re: A recent security incident involving Dropbox Sign
#40Earlier quoted context omitted.
For this reason, I enabled E2E encryption for iCloud. Sure, if you are very paranoid, you can choose not to trust Apple, but E2E encryption on iCloud is seamless, and I haven't noticed a difference since enabling it.
I did the same, but i still use Cryptomator for stuff like sensitive documents and the sorts, much like i would have used an encrypted image before using cryptomator. iCloud works great, and even if you trust Apple (which i do to some extent), your data is still only safe as long as nobody gains access to your devices. Once somebody has access to your devices, files are no longer encrypted. The choice of Cryptomator…