Dropbox Accused of Lying About Security
lee1 writes "Dropbox faces a possible FTC investigation because of misleading statements it has made about the privacy and security of its 25 million users' files. The cloud storage company previously claimed that it was impossible for its employees to access file contents, but in fact, as the encryption keys are in their possession, this is false. The complaint (PDF) points out that their false security claims gave Dropbox a competitive advantage over other firms offering similar services who actually did provide secure encryption."
One reason is that the person making the complaint is Christopher Soghoian, a heavyweight when it comes to computer security.
Spideroak is a better choice. All data is encrypted on the client side and sent to the server. The Spideroak servers do not store your passphrase, thus it is impossible for them to access your data . The obvious downside is you can't afford to forget your password as you cannot reset it.
Did they ever say that though? If you RTF complaint, the closest they ever came to making that claim was this line:
"Dropbox employees aren't able to access user files, and when troubleshooting an account they only have access to file metadata (filenames, file sizes, etc, not the file contents)"
I suppose if you tilt your head and squint, that could mean they don't keep a copy of the keys. I read it as the guys on the floor can't log into your account and snoop around.
Because it's not a little generic info about their lives. It's a small leak here a small leak there, pretty soon they've got all of it, and you don't have any privacy. You'd be shocked at how much information about you is likely out there. Even those of us that are exceedingly careful are constantly spied on by ad networks.
It might not be a big deal to you, but once that information is out there, it's out there, and there's no telling what will become of that information in the future. That there is the problem, there's no control over it and we've no idea what somebody else is going to do with it.
O rly?
AT&T seeks more phone deregulation in Alabama
AT&T and Deutsche Telekom push for deregulation of wireless markets
Time Warner seeks Manhattan deregulation
It's trivially easy to find other examples.