Skip to content

Comment on Dropbox Lied to Users about Data Security, Complaint to FTC Alleges

Comments

OK, so I am a fan of dropbox and I use it across many machines, (better than those on Richess) -- and, as I understand the overall issue to be, the concern is that DropBox may at some point "hand over your files" to (I assume) The Feds -- should they come knocking?

Now, I expect that for all intents and purposes the encryption/security employed by Dropbox is 'good-enough' that I dont have to worry about random-internet-user gaining access to my docs, yet I have absolutely NO illusions that ANY company will refuse to hand over my data to the feds should the feds be seeking it.

Further, I would suggest that anyone with anything they dont want the feds to know about/get their mitts on not be stupid enough to store said sensitive secrets IN THE FUCKING CLOUD

Additionally, I can understand that Drew may not be the most savvy in navigating such issues given him being a young CEO and all - and I can understand that he would want all the DropBoxians to feel comfortable with the safety and security of their data in his hands - but I would like to see a frank, real-world answer to any security claims which delineate in no-uncertain-terms exactly what level of data safety, security and encryption one may expect.

Drew may even do well as to explicitly say "We shall not refuse to hand over any of your data (and its revision history) to the Feds should they come seeking it with legal merit."

If, after such a statement people are concerned about their data going anywhere -- they should get off dropbox / implement truecrypt as stated.

Finally, a question for Drew: given this craptastic event; would Drop Box be open to much more robust file encryption tools being developed as an addon to DropBox; e.g. a third party wrapper application that allows end-to-end encryption while still allowing the web UI etc to work?

(If I misread the circumstances of the whole issue - forgive my little rant)

and, as I understand the overall issue to be, the concern is that DropBox may at some point "hand over your files" to (I assume) The Feds -- should they come knocking?

No, the concern is that Dropbox led people to believe that by use of encryption, Dropbox was preventing user files from being accessible to anyone except that user, which isn't actually true, and that Dropbox gained unearned competitive advantage because of that untruth.

Technically-savvy users who know (or more to the point, care) how Dropbox works behind the scenes may be able to figure out that user files had to be accessible to Dropbox (the "but how could they de-dupe files?" argument). Bully for them, but the fact that some people understand why an advertising claim is misleading doesn't make it okay for that claim to be misleading in the first place.

They can dedupe without needing to decrypt. Tarsnap does this. The issue is with features like being able to reset your password, downloading and sharing files via the web interface, etc.

Yes, but Tarsnap (as far as I know) only dedupes your data i.e., if I upload the same file twice it will be stored once. This is easy, because two identical files encrypted by the same key (i.e., mine) are still identical.

Dropbox dedupes across users, if Alice and Bob both upload foo.txt with identical contents (but encrypted with their own keys) the encrypted result will not be identical even though the files are. Right now Dropbox does dedupe in this situation, which obviously required unencrypted access to both files.

They actually say that they will hand over anything to the feds:

"New TOS:

Compliance with Laws and Law Enforcement Requests; Protection of Dropbox’s Rights. We may disclose to parties outside Dropbox files stored in your Dropbox and information about you that we collect when we have a good faith belief that disclosure is reasonably necessary to (a) comply with a law, regulation or compulsory legal request; (b) protect the safety of any person from death or serious bodily injury; (c) prevent fraud or abuse of Dropbox or its users; or (d) to protect Dropbox’s property rights. If we provide your Dropbox files to a law enforcement agency as set forth above, we will remove Dropbox’s encryption from the files before providing them to law enforcement. However, Dropbox will not be able to decrypt any files that you encrypted prior to storing them on Dropbox."

http://blog.dropbox.com/?p=735

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.