Earlier quoted context omitted.
Very yes (we don't allow Dropbox† on our machines, but we know of companies that rely on it). Grandalf's point is extremely well taken. It's actually true. Not only that, but regulated companies (in health care and finance) that have a reasonable belief that any of their systems might have had Dropbox on them technically need to audit now. I point this out not to bag on Dropbox, but as an illustration of how sane som…
Why not Tarsnap?
Dropbox passwords optional for four hours
41–48 of 48 posts
Re: Dropbox passwords optional for four hours
#42Re: Dropbox passwords optional for four hours
#43Earlier quoted context omitted.
I like Tarsnap. If I had to recommend a 3rd party storage vendor, it would be Tarsnap.
I know, but that doesn't answer my question. Why is it banned at your shop?
Re: Dropbox passwords optional for four hours
#44I hope they add login activity to their "Recent Events" feed ASAP.
Re: Dropbox passwords optional for four hours
#45Earlier quoted context omitted.
I didn't say they do, but they should hire people competent to make educated decisions in the regulatory environment they're in. That's why they pay bofhs -- not because they like our views, but because we _read_ the specs. EDIT: To phrase less hostilely -- HIPAA and various finance laws consist of thousands of pages of what to do and what not to do. Dropbox is a shiney webpage that isn't PCI certified or HIPAA certi…
HIPAA does not have thousands of pages on what and what not to do. It's actually quite vague, and mostly comes down to fines after the fact. There's also no such thing as a government sanctioned HIPAA certification. There's just random people willing to 'certify' you.
Still, complying with HIPAA does make one point _very_ clear -- audit controls - Dropbox has none exposed to you, and thus it simply does not comply unless you have your own layer of controls (encryption) on top.
It also seems to fall down under 'Standard: Person or entity authentication' as well, but that's just me being snarky.
Health-care and finance are places with legal (or contractual) obligations -- and that was my main point: if you have a set of rules (or even best practices), and you fall afowl of them, don't go screaming that someone else is to blame.
Re: Dropbox passwords optional for four hours
#46Earlier quoted context omitted.
The thing is that you can't do email then. You can say that google might leak your emails, but the same is true if you use your private email server.
The security of my private mailserver is nearly the same as the security of my laptop. For security reasons I don't use a VPS for email, but a small server that sits in my basement: There are some security measures that will lead to an automatic shutdown in case someone tries to physically access the server and the whole harddisk is encrypted. (Yes - you can call me paranoid.)
Re: Dropbox passwords optional for four hours
#47Earlier quoted context omitted.
The security of my private mailserver is nearly the same as the security of my laptop. For security reasons I don't use a VPS for email, but a small server that sits in my basement: There are some security measures that will lead to an automatic shutdown in case someone tries to physically access the server and the whole harddisk is encrypted. (Yes - you can call me paranoid.)
You go through a lot of trouble to try to secure an inherently insecure protocol (email). Or do you mainly use on-the-wire encrypted mail as well?
Re: Dropbox passwords optional for four hours
#48I use any online service with the assumption that the things I put up there could likely become public, no longer anonymous, or what have you. I don't think this is overly paranoid, given how difficult computer security is. To me; it would make sense if Dropbox stored everything encrypted (as in, encrypted pre-transfer), and you needed the private key to decrypt stuff, unless you specifically state that it is to be p…
Depends on the online-service. E.g., I trust tarsnap (client-side encryption, not under an open-source license but you can compile it yourself) with very sensitive data. I also trust Wuala (also client-side encryption) with semi-sensitive data, although it somewhat worries me that Wuala's source is not publicly available for reviews. I don't trust Dropbox due to the lack of encryption - that's why I don't really use…