Page 1 of 4 1234 LastLast
Results 1 to 16 of 51

Thread: Please, Stop using DropBox

  1. #1
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Please, Stop using DropBox

    http://codeinsecurity.wordpress.com/...-to-lose-aslr/

    DropBox has shown time and time again that they don't get the concepts of security... at all.

    This latest one is very worrying for windows users who don't use IE.

    There are many other cloud data space providers, use them instead.
    throw new ArgumentException (String, String, Exception)

  2. Received thanks from:

    ik9000 (10-09-2013),Marenghi (10-09-2013),Platinum (11-09-2013),stilkun (10-09-2013),watercooled (10-09-2013)

  3. #2
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,036
    Thanks
    1,877
    Thanked
    3,378 times in 2,715 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Please, Stop using DropBox

    Ew. Isn't there a way of using dropbox without installing anything, like good old fashioned uploading/sftp or something?

  4. #3
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Please, Stop using DropBox

    This is more about their security principles.

    They've had bugs which allowed other users to read your files. Not massively complex my god that was a clever hack. A bloody bug shipped to production which didn't provide isolation.
    throw new ArgumentException (String, String, Exception)

  5. #4
    Senior Member
    Join Date
    Dec 2008
    Posts
    977
    Thanks
    5
    Thanked
    48 times in 39 posts
    • GeorgeStorm's system
      • Motherboard:
      • MSI Z77IA-E53
      • CPU:
      • i5 3450
      • Memory:
      • 8gb DDR3 1866mhz C10
      • Storage:
      • 256gb SSD
      • Graphics card(s):
      • GTX780
      • PSU:
      • Silverstone 450W SFX
      • Case:
      • Parvum mitx
      • Operating System:
      • W10
      • Monitor(s):
      • U2711 + U2311H

    Re: Please, Stop using DropBox

    I don't use it for anything important, just handy to move things from place to place/make them available to others every now and again, but if it opens up general security holes then I'll look into others in more detail.

  6. #5
    HEXUS.social member finlay666's Avatar
    Join Date
    Aug 2006
    Location
    Newcastle
    Posts
    8,546
    Thanks
    297
    Thanked
    894 times in 535 posts
    • finlay666's system
      • CPU:
      • 3570k
      • Memory:
      • 16gb
      • Graphics card(s):
      • 6950 2gb
      • Case:
      • Fractal R3
      • Operating System:
      • Windows 8
      • Monitor(s):
      • U2713HM and V222H
      • Internet:
      • cable

    Re: Please, Stop using DropBox

    Mine is generally used for syncing settings and transferring bits, anything secure goes directly to my server
    H3XU5 Social FAQ
    Quote Originally Posted by tiggerai View Post
    I do like a bit of hot crumpet

  7. #6
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Please, Stop using DropBox

    It's not just a case of your files being at risk. It is more a case as a company they don't give a hoot about safety.

    If you are writing some software that is a 'shell extension' something like putting their logo on any folder which is sync'd. That means the code to put that logo on has to be loaded into every process that uses a file dialog. Which is pretty much every interactive program.

    If you are doing that, the code has to be really, really top grade.

    By disabling ASLR they have removed a rather handy security feature. ASLR isn't a perfect defence, but it is more a sign that they are very rooky. Like taxying an airplane with your flaps down, it makes you look like a rooky and people will question if you are safe.
    throw new ArgumentException (String, String, Exception)

  8. #7
    Bah Humbug. Dooms's Avatar
    Join Date
    Jan 2005
    Location
    Stockholm
    Posts
    3,325
    Thanks
    94
    Thanked
    183 times in 141 posts
    • Dooms's system
      • Motherboard:
      • Gigabyte X570 I AORUS PRO WIFI
      • CPU:
      • 3700X
      • Memory:
      • G.SKILL TridentZ Series 32GB (2 x 16GB)
      • Storage:
      • Samsung 970 1TB
      • Graphics card(s):
      • EVGA 2080 Super
      • PSU:
      • 750W Corsair Pro
      • Case:
      • Ncase M1 6.1
      • Operating System:
      • Windows 11 Pro
      • Monitor(s):
      • LG 34UC88 34-Inch 21:9
      • Internet:
      • 1GB Telenor

    Re: Please, Stop using DropBox

    It's a shame its not perfect but I'll continue using it as I have 54Gb of space and nothing I keep on there really matters if its public knowledge.

  9. #8
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Please, Stop using DropBox

    Quote Originally Posted by Dooms View Post
    It's a shame its not perfect but I'll continue using it as I have 54Gb of space and nothing I keep on there really matters if its public knowledge.
    Do you understand that it is making any windows machine that you have the client installed on unsafe?

    And that they've sat on a responsible disclosure, that should cost very little dev time to rectify for ages.
    throw new ArgumentException (String, String, Exception)

  10. #9
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: Please, Stop using DropBox

    I did give Spideroak a try a while back, but the client just wasn't stable enough IMO; it crashed fairly frequently, eating a CPU core until you noticed via task manager and terminated it. It might have improved recently, and they do seem to get security a heck of a lot better than Dropbox.

    Not only do Dropbox not get it, they've essentially lied in the past about how your data is secured, claiming it would not be possible for employees to access it.

    And remember the time where they messed up accounts and people were seeing documents belonging to other accounts etc?

    They're just disastrously bad at security, and even if they patched everything, it would be hard to have any confidence in them considering the lack of competence they've already demonstrated.

  11. #10
    Does he need a reason? Funkstar's Avatar
    Join Date
    Aug 2005
    Location
    Aberdeen
    Posts
    19,874
    Thanks
    629
    Thanked
    962 times in 813 posts
    • Funkstar's system
      • Motherboard:
      • Gigabyte EG45M-DS2H
      • CPU:
      • Intel Core2Quad Q9550 (2.83GHz)
      • Memory:
      • 8GB OCZ PC2-6400C5 800MHz Quad Channel
      • Storage:
      • 650GB Western Digital Caviar Blue
      • Graphics card(s):
      • 512MB ATI Radeon HD4550
      • PSU:
      • Antec 350W 80+ Efficient PSU
      • Case:
      • Antec NSK1480 Slim Mini Desktop Case
      • Operating System:
      • Vista Ultimate 64bit
      • Monitor(s):
      • Dell 2407 + 2408 monitors
      • Internet:
      • Zen 8mb

    Re: Please, Stop using DropBox

    I moved away from DB, but thanks for giving me a reason to uninstall the client

  12. #11
    Senior Member
    Join Date
    Feb 2004
    Posts
    403
    Thanks
    58
    Thanked
    79 times in 68 posts
    • Firejack's system
      • Motherboard:
      • Asus PRIME X470-Pro
      • CPU:
      • AMD Ryzen 7 2700X
      • Memory:
      • TG Dark Pro "8pack Edition"
      • Storage:
      • Crucial 250GB SSD, Sandisk 128GB SSD, Samsung 1TB HDD
      • Graphics card(s):
      • Sapphire RX VEGA 56 8GB Pulse
      • PSU:
      • SeaSonic Focus Plus 650 Gold
      • Case:
      • Fractal Design Define S
      • Operating System:
      • Windows 10 Pro 64bit
      • Monitor(s):
      • Dell S2719DGF
      • Internet:
      • BT Infinity 2

    Re: Please, Stop using DropBox

    I'm still using Dropbox. Don't run it on my server or any privileged accounts. The convenience of it still outweighs the security issues ever so slightly for me.

    Tried all kinds of alternatives from Cubby, Ubuntu One, SkyDrive, Google Drive, Box but I've had problems with each.

    At the moment I'm following the development of BTsync as maybe the long term solution

  13. #12
    Registered+
    Join Date
    Aug 2013
    Location
    Siliguri, WB
    Posts
    25
    Thanks
    9
    Thanked
    0 times in 0 posts
    • machkris's system
      • Motherboard:
      • ASUS P8Z77V-Deluxe
      • CPU:
      • Intel i7-3770
      • Memory:
      • Corsair Dominator 1600
      • Storage:
      • Corsair Fore 3
      • Graphics card(s):
      • XFX nVidia GeForce GTX 295
      • PSU:
      • Cooler Master Silent Pro Hybrid 1050W
      • Case:
      • Cooler Master Cosmos II
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Samsung LED 27"
      • Internet:
      • SiNet

    Re: Please, Stop using DropBox

    I agree. I don't prefer Dropbox personally. Google Drive is way better.

  14. #13
    Treasure Hunter extraordinaire herulach's Avatar
    Join Date
    Apr 2005
    Location
    Bolton
    Posts
    5,618
    Thanks
    18
    Thanked
    172 times in 159 posts
    • herulach's system
      • Motherboard:
      • MSI Z97 MPower
      • CPU:
      • i7 4790K
      • Memory:
      • 8GB Vengeance LP
      • Storage:
      • 1TB WD Blue + 250GB 840 EVo
      • Graphics card(s):
      • 2* Palit GTX 970 Jetstream
      • PSU:
      • EVGA Supernova G2 850W
      • Case:
      • CM HAF Stacker 935, 2*360 Rad WC Loop w/EK blocks.
      • Operating System:
      • Windows 8.1
      • Monitor(s):
      • Crossover 290HD & LG L1980Q
      • Internet:
      • 120mb Virgin Media

    Re: Please, Stop using DropBox

    Does anyone have any experience with the self hosted solutions?

  15. #14
    Registered User
    Join Date
    Aug 2013
    Posts
    5
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Please, Stop using DropBox

    You can use Google Drive instead and if it is personal info which should be shared with rather narrow group of people you can use something like RetroShare.

  16. #15
    Technojunkie
    Join Date
    May 2004
    Location
    Up North
    Posts
    2,580
    Thanks
    239
    Thanked
    213 times in 138 posts

    Re: Please, Stop using DropBox

    Quote Originally Posted by Firejack View Post
    The convenience of it still outweighs the security issues ever so slightly for me.
    Indeed, I haven't found a cross platform (windows/mac) replacement that sits there working and never bothers you.
    Chrome & Firefox addons for BBC News
    Follow me @twitter

  17. #16
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Please, Stop using DropBox

    Quote Originally Posted by mikerr View Post
    Indeed, I haven't found a cross platform (windows/mac) replacement that sits there working and never bothers you.
    It's cross platform convenience (includes *nix) is a big plus - anything sensitive I store there is encrypted by me before it goes there. Otherwise I accept that that cloud storage is inherently insecure.

    Anyone storing stuff on the cloud in clear should accept that it may be compromised, and I'd no more trust Google with the privacy of my data than any other cloud provider.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

Page 1 of 4 1234 LastLast

Thread Information

Users Browsing this Thread

There are currently 2 users browsing this thread. (0 members and 2 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •