Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I love Dropbox and use it every day. But this article says the data is encrypted before being sent to the cloud, and that is not true. Because of that, it's not a good idea to put sensitive stuff on Dropbox, like "accounting" stuff or stock agreements.

For everything else, it is totally amazing.



Update: http://www.getdropbox.com/faq#security-and-privacy Here it says it does encrypt (256bit AES over SSL) the files before sending them to the cloud.

I agree with you on the matter that you don't place sensitive stuff on it. But my 'accounting' stuff isn't that interesting for 3rd parties; as I also said in the comments on my blog: "I get your concerns and need for a private key. Also a key based on a combination of username and password would be the simplest solution to this problem. For me the encryption isn’t that of a big issue since 3rd parties viewing my files aren’t going to get anything out of it that should do damage to me. Of course, when you store sensitive data on it, you should also invest in some security on your part (like the mentioned TrueCrypt)."


Regarding your update: that's saying they encrypt the pipe between your computer and their servers using SSL. The files are still stored without encryption on their servers (as far as I can tell).


Their FAQ item says the data is stored encrypted.


Accounting stuff could be VERY interesting for 3rd parties if they're your competitors


Competitors hacking into my dropbox account?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: