Live data from Hacker News

How Dropbox Hacks Your Mac

applehelpwriter.com

421–430 of 435 posts

Re: How Dropbox Hacks Your Mac

#422
post #315

Earlier quoted context omitted.

I switched from Dropbox to Mega a few years ago and they now have mobile apps, sync clients for multiple operating systems and decent browser extensions in addition to a more generous storage allowance. There is also the added benefit of encryption. So far I remain impressed with their service.

I switched from Dropbox to Mega Really? FWIW Kim Dotcom, the founder of Mega, has distanced himself from it, saying the company had "suffered from a hostile takeover by a Chinese investor who is wanted in China for fraud" [1] So yeah, don't trust Dropbox. Instead trust some shady Chinese characters. Can you name one of them? In comparison, note that Ben Newhouse, a Dropbox employee, is actually posting in this discus…

> Instead trust some shady Chinese characters.

What does Chinese have to do with this?

Re: How Dropbox Hacks Your Mac

#423
post #326

Earlier quoted context omitted.

> - We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple). To clarify for others: In /Library/DropboxHelperTools, you'll find a folder for each user full of setuid tools which run as root and do various privileged things. I assume that the client is presenting the normal OS X "ask for elevated access" UI and then using that elevated access to configure and install…

> more likely that Apple will further lock down the accessibility APIs, possibly even making them unavailable without an Apple-issued, potentially App Store-only entitlement. Please feel free to duplicate my radar! Accessibility and Productivity/Utility app developers would love a Sandbox entitlement. rdar://13570189 - Sandbox entitlement for Accessibility API to allow apps for the disabled The Accessibility toolkit…

I don't really see the point of taking a sandbox and then explicitly granting an app inside the privilege to step out of it.

Re: How Dropbox Hacks Your Mac

#424
post #312

Earlier quoted context omitted.

Could this be a consequence of the built in FS APIs coming up short, as Ben put it, and forcing DropBox to do things in less efficient ways to work around the limitations?

What do they need different from what time machine uses?

Time Machine needs to be able to ask which files changed when it is preparing to backup. Dropbox needs to be notified when a file changes so it can sync.

Re: How Dropbox Hacks Your Mac

#425

Hi HN — Ben from Dropbox here on the desktop client team. Wanted to clarify a few things — - Clearly we need to do a better job communicating about Dropbox’s OS integration. We ask for permissions once but don’t describe what we’re doing or why. We’ll fix that. - We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like. - We use accessibility APIs for…

> We only ask for privileges we actively use -- but unfortunately some of the permissions aren’t as granular as we would like.

And as for the rest of the privileges, we just take them without asking. Who knows, someone might refuse!

Re: How Dropbox Hacks Your Mac

#426
post #326

Earlier quoted context omitted.

> more likely that Apple will further lock down the accessibility APIs, possibly even making them unavailable without an Apple-issued, potentially App Store-only entitlement. Please feel free to duplicate my radar! Accessibility and Productivity/Utility app developers would love a Sandbox entitlement. rdar://13570189 - Sandbox entitlement for Accessibility API to allow apps for the disabled The Accessibility toolkit…

I don't really see the point of taking a sandbox and then explicitly granting an app inside the privilege to step out of it.

I don't really see the point of banning Accessibility apps that can't be sandboxed but then allowing those same apps to be distributed outside the Mac App Store. Unless you're banning them from macOS entirely, why not allow these potentially "dangerous" apps to operate underneath the additional Reviews and Guidelines of the App Store?

Re: How Dropbox Hacks Your Mac

#427

Earlier quoted context omitted.

I uninstalled the desktop client because of this exact issue. I just drag/drop via the web interface now. Might not work for some people, but it suits me fine.

Just uninstalled too. I was only using it for syncing 1password data and this pushed me to just switch to a 1pass account

1password has had iCloud syncing for a while now, and in my experience, it's been very reliable.

Re: How Dropbox Hacks Your Mac

#428

Earlier quoted context omitted.

I use owncloud (and then dropbox inside it so some files are double backed up). I find it to be just fine. Have you had any problems with it?

Yes, last time I tried it, had a variety of conflict issues plus the client had some problems, performance and otherwise. If you're just using it as a backup solution (does it even keep file history?) from a single machine + mobile/web access, it may well work acceptably.

I had couple conflicts in the few years Ive used it, but they were few and were actual conflicts (a file on a client was updated at the same time the server copy was updated). It does keep a limited file history. I'm not really using it for file history so I'm not sure exactly what the rules are for retaining old versions.

Re: How Dropbox Hacks Your Mac

#429
post #426

Earlier quoted context omitted.

I don't really see the point of taking a sandbox and then explicitly granting an app inside the privilege to step out of it.

I don't really see the point of banning Accessibility apps that can't be sandboxed but then allowing those same apps to be distributed outside the Mac App Store. Unless you're banning them from macOS entirely, why not allow these potentially "dangerous" apps to operate underneath the additional Reviews and Guidelines of the App Store?

Because an app being on the App Store creates an expectation that cannot be met without the sandbox.

Without the source code and large amounts of resources it is not possible to determine whether an app is malicious or not. The only way would be for Apple to trust that developers actually do what they say they do. The unfortunate reality is that they cannot be trusted. I don't blame Apple for not taking that responsibility. Unfortunately that means the responsibility ends up with the user who cannot make the determination either. Such is life.

Post reply on HN