Dropbox does encrypt your files, it's just that, naturally, they hold the key.
Even if dropbox's claim was technically correct, it was absolutely misleading. When you say "this data is encrypted" people assume that you mean "... in a way which adds security"; if the same people who have access to the encrypted data also have access to the decryption keys, you might as well be using ROT-13.
If I ask Dropbox for another users files, guess what? They don't hand them over.
Modulo the recently-fixed vulnerability which allowed you to download data if you knew some hashes, that is.
I wouldn't call it a vulnerability. The only way it could be abused would be tricking someone with the file into calculating very specific hashes and giving them to you.
Comments
Dropbox does encrypt your files, it's just that, naturally, they hold the key.
Even if dropbox's claim was technically correct, it was absolutely misleading. When you say "this data is encrypted" people assume that you mean "... in a way which adds security"; if the same people who have access to the encrypted data also have access to the decryption keys, you might as well be using ROT-13.
If I ask Dropbox for another users files, guess what? They don't hand them over.
Modulo the recently-fixed vulnerability which allowed you to download data if you knew some hashes, that is.
I wouldn't call it a vulnerability. The only way it could be abused would be tricking someone with the file into calculating very specific hashes and giving them to you.
I've issued security advisories for FreeBSD for far more obscure contexts than that. :-)