Earlier quoted context omitted.
A Synology/QNAP/TrueNAS NAS is a far better solution, with no restriction.
You would still need somewhere to do off site backups to. (Edit: changed offline to offsite)
A recent security incident involving Dropbox Sign
61–70 of 76 posts
Re: A recent security incident involving Dropbox Sign
#62Re: A recent security incident involving Dropbox Sign
#63Earlier quoted context omitted.
Dropbox offers end-to-end encryption now (for business teams): https://blog.dropbox.com/topics/company/new-solutions-to-sec...
I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.
Is dropbox advanced a business plan?
Re: A recent security incident involving Dropbox Sign
#64Earlier quoted context omitted.
They were using SHA1, then they migrated. 68 million accounts dumped: https://www.theguardian.com/technology/2016/aug/31/dropbox-h... https://www.troyhunt.com/the-dropbox-hack-is-real/ now they first hash the password using SHA512 (with a per-account salt) then they hash the password with bcrypt (with the default strength) then they encrypt the password with a key that the application server runs with, but that is no…
That… seems excessive. Is it just security theater or actually useful somehow?
Re: A recent security incident involving Dropbox Sign
#65Earlier quoted context omitted.
They were using SHA1, then they migrated. 68 million accounts dumped: https://www.theguardian.com/technology/2016/aug/31/dropbox-h... https://www.troyhunt.com/the-dropbox-hack-is-real/ now they first hash the password using SHA512 (with a per-account salt) then they hash the password with bcrypt (with the default strength) then they encrypt the password with a key that the application server runs with, but that is no…
That… seems excessive. Is it just security theater or actually useful somehow?
Re: A recent security incident involving Dropbox Sign
#66This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them. We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.
We’ve been with hellosign for years and Dropbox has done a great job of stabilizing them. I will tell you that they have put in a ton of ops work to keep the platform up more consistently.
Our implementation of their API was a bit of a mess so it can be hard to see through our own crap sometimes to give credit where its due haha.
Re: A recent security incident involving Dropbox Sign
#67> For those who received or signed a document through Dropbox Sign, but never created an account, email addresses and names were also exposed. So they also leaked data of people who are not their customers, and who never agreed to have their information collected. I doubt that flies under the GDPR.
In the grand scheme of things, expecting your name and email address to really stay private is not all that reasonable. You probably gave them to the person who then used Dropbox Sign to send you a document. If you were really worried you could have used a throwaway account. The old saying is, once you tell someone, it's no longer a secret.
In the grand scheme of things, nothing matters and we’re all going to die. It’s been a while since I read the GDPR, but I don’t remember a section titled “personal data which is OK to leak because it doesn’t matter in the grand scheme of things *shrug emoji*”.
> You probably gave them to the person who then used Dropbox Sign to send you a document. If you were really worried you could have used a throwaway account.
Yes, you probably did. And that’s irrelevant. That data should’ve been deleted once it was no longer relevant. Almost no one goes around giving throwaway email accounts to acquaintances. Do you also suggest people have a throwaway phone number they give to friends and family, for when they upload it to a service like WhatsApp?
Re: A recent security incident involving Dropbox Sign
#68This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them. We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.
Acquired in 2022? IMO that's enough time to bring their service up to the same security standard as the rest of their services, assuming it's a priority. Google and others normally have a 6 month grace period for bug bounty reports in acquisitions.
Re: A recent security incident involving Dropbox Sign
#69This is Dropbox Sign, not Dropbox. It’s a document signing product akin to Docusign, and was called Hellosign before Dropbox acquired them. We are a customer of theirs at my startup, and as far as I can tell Dropbox has made very few changes since the acquisition beyond changing the branding. So I wouldn’t take this incident to be an indicator of much on the cloud-storage side of the company.
Acquired in 2022? IMO that's enough time to bring their service up to the same security standard as the rest of their services, assuming it's a priority. Google and others normally have a 6 month grace period for bug bounty reports in acquisitions.
If you can get competent people to work for you while keeping Wall Street happy, sure, but there are much "cooler" companies across the street that Wall Street is more excited about, are hiring right now, and the competent folk are going there.
At the end of this extreme is Equifax-like companies that have leaks and lots of other issues. Before you ask why Equifax sucks so much, ask yourself: Would you work there? No? That's why they continue to suck.
While Dropbox isn't Equifax, it isn't OpenAI or NVIDIA right now.
Re: A recent security incident involving Dropbox Sign
#70Earlier quoted context omitted.
I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.
Its says: The latest security features will be available to all Dropbox Advanced, Business Plus, and Enterprise customers starting today. Is dropbox advanced a business plan?