Live data from Hacker News

A recent security incident involving Dropbox Sign

sign.dropbox.com

31–40 of 76 posts

Re: A recent security incident involving Dropbox Sign

#32
post #10

Earlier quoted context omitted.

Dropbox offers end-to-end encryption now (for business teams): https://blog.dropbox.com/topics/company/new-solutions-to-sec...

I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.

If you want encryption enough, you can probably pay for a three-person business plan and just not set up the extra users. Looks like it would double your monthly subscription over the most expensive personal plan.

Re: A recent security incident involving Dropbox Sign

#33

I love Dropbox but stuff like this is a good reminder to re-evaluate using any service that store large amount of personal data without e2ee. I understand that partly because of block-level diffing and syncing, it's hard to provide true e2ee for Dropbox, but it's still a big reason why I'm having most of my stuff in iCloud Drive (with Advanced Data Protection), despite liking Dropbox much more. Hope they'll come arou…

[deleted]

Re: A recent security incident involving Dropbox Sign

#34
post #3

Dropbox was breached also around 2012.

That was when i stopped using the cloud for storing personal stuff. Fast forward a decade and i've more than had my fill of self hosting stuff, so a couple of years ago i went all in on the cloud again, though with a bit of a different approach. Stuff that is not really sensitive is uploaded "as is". Yes, that includes our photos. While i don't want our photo library to be "public domain", there is nothing there of p…

For this reason, I enabled E2E encryption for iCloud. Sure, if you are very paranoid, you can choose not to trust Apple, but E2E encryption on iCloud is seamless, and I haven't noticed a difference since enabling it.

Re: A recent security incident involving Dropbox Sign

#35

Earlier quoted context omitted.

That was when i stopped using the cloud for storing personal stuff. Fast forward a decade and i've more than had my fill of self hosting stuff, so a couple of years ago i went all in on the cloud again, though with a bit of a different approach. Stuff that is not really sensitive is uploaded "as is". Yes, that includes our photos. While i don't want our photo library to be "public domain", there is nothing there of p…

For this reason, I enabled E2E encryption for iCloud. Sure, if you are very paranoid, you can choose not to trust Apple, but E2E encryption on iCloud is seamless, and I haven't noticed a difference since enabling it.

I did the same, but i still use Cryptomator for stuff like sensitive documents and the sorts, much like i would have used an encrypted image before using cryptomator.

iCloud works great, and even if you trust Apple (which i do to some extent), your data is still only safe as long as nobody gains access to your devices. Once somebody has access to your devices, files are no longer encrypted.

The choice of Cryptomator was a convenience choice. I could have just as easliy encrypted files using GPG, LUKS, encrypted disk images or similar, but i would not have been able to access those directly from my phone/tablet in their cloud location, which is something i can do with Cryptomator.

For reference, i have about 4TB data in the cloud (~3.5TB photo library), and a 2GB Cryptomator vault, so it's not exactly the main driver of the operation :)

Re: A recent security incident involving Dropbox Sign

#36
post #10

Earlier quoted context omitted.

Dropbox offers end-to-end encryption now (for business teams): https://blog.dropbox.com/topics/company/new-solutions-to-sec...

I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.

A Synology/QNAP/TrueNAS NAS is a far better solution, with no restriction.

Re: A recent security incident involving Dropbox Sign

#37

> Based on our investigation, a third party gained access to a Dropbox Sign automated system configuration tool. The actor compromised a service account that was part of Sign’s back-end, which is a type of non-human account used to execute applications and run automated services. As such, this account had privileges to take a variety of actions within Sign’s production environment. The threat actor then used this acc…

The credentials for service accounts are generally available to a system admin but I think in most cases it would be a strange request to ask for them, so not a strong vector for social engineering.

A service account is used to give limited permissions on one system to another system. Normally only that system would need access to them, not any human.

Their main benefit is that, since no person is trying to do their day job here, the account can be locked down to precisely the permissions it needs. The reality is that service accounts are usually given extremely permissive access initially and then forgotten about. This makes them juicy targets for attackers.

Re: A recent security incident involving Dropbox Sign

#38
post #22
post #15

Earlier quoted context omitted.

Of course there isn't, but it limits efficiency and features. For example, you will miss all the fancy features Google Images does in cloud and user experience might be slower, since everything must be processed and downloaded on client side. Some level of metadata is always unencrypted.

That's trading one feature for a bunch of others. Users should have the choice of what features they think are important.

They typically do, by picking the product they wish to use.

Re: A recent security incident involving Dropbox Sign

#39
post #7
post #4

Earlier quoted context omitted.

I use Proton Drive [1], they offer e2ee but I agree with you: the Dropbox app experience is probably still the best. [1] https://proton.me/drive

OK, so there is no fundamental obstacle for providing true e2ee.

It is very complicated to get this right from development standpoint. In true E2E, client must be "fat", kitchen sink and everything. Pretty sure Dropbox isn't like that right now. E2E is not a "feature", it is like a different paradigm of problem solving.

Re: A recent security incident involving Dropbox Sign

#40

Earlier quoted context omitted.

For this reason, I enabled E2E encryption for iCloud. Sure, if you are very paranoid, you can choose not to trust Apple, but E2E encryption on iCloud is seamless, and I haven't noticed a difference since enabling it.

I did the same, but i still use Cryptomator for stuff like sensitive documents and the sorts, much like i would have used an encrypted image before using cryptomator. iCloud works great, and even if you trust Apple (which i do to some extent), your data is still only safe as long as nobody gains access to your devices. Once somebody has access to your devices, files are no longer encrypted. The choice of Cryptomator…

How do you sync the cryptomator vault safely, properly handling conflicts?
Post reply on HN