Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My biggest issue with Dropbox, and I am probably not alone in this, is still security. After the lapses earlier in the year, I still store most files in a TrueCrypt share in my DropBox folders. Since I can't access the TrueCrypt volume from my phone or other mobile devices, it limits the portability of the data.


We've been told they do encrypt files internally. I don't think there is any usable way to have users manage their keys by themselves. Who wants to input large encryption keys to their mobile phone every time they want to use Dropbox? And if the phone remembers the key, then it's not too far from the current situation.


"My phone stores my private key" is very, very far from "Dropbox's servers can see all my data".


Certainly, but the practical privacy implications are probably similar. In case of a stolen phone, the thief has access to all the files in both of these cases. Sure it would be cool if Dropbox wouldn't have any access to our files, but I don't see how it would happen without eroding the usability. It could be an opt-in feature of course.


Dropbox can be subpoena'd.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: