Dropbox has deceived users about the security?

On Sun, May 15, 2011, in the cloud , Privacy , Reporting , by Ernesto Belisario

The cloud computing is the technology of the moment: businesses, governments and simple users are increasingly becoming aware of its benefits and the fact that, in the near future, will revolutionize the world of IT as we know it.
At the same time, just as everyone is talking about the benefits of cloud computing, there is a growing awareness of the critical nature of this technology, mainly due to the loss of control over the data (with the obvious implications in terms of the contract but also security and privacy). This awareness is also accelerated by a series of problems that, in recent weeks, involving some of the leading cloud service providers like Amazon , Microsoft , Aruba and Sony .

These days to be at the center of the cyclone is Dropbox , one of the most popular services for sharing and saving files, accused in a complaint lodged with the Federal Trade Commission , having lied about data security of its members.

Dropbox 错误 页面

The author is dell'esposto Christopher Soghoian , a Ph.D. student at Indiana University, who argues that - contrary to what was stated by Dropbox - it would not be true that the archived files are encrypted and accessible only by the user, since that Dropbox employees could view it at any time . The company, with a post on his blog, has dismissed the allegations but - in fact - recently changed the terms and conditions of service; in particular, whereas before it was provided that:

All files stored on Dropbox servers are encrypted (AES - 256) and are inaccessible without your account password.

Now it is written simply

All files stored on Dropbox servers are encrypted (AES - 256).

But there's more! While up to 13 April 2011, the conditions of use envisaged that

Dropbox employees are not able to access user files

now predict that

Dropbox employees are forbidden to display the contents of files stored in user accounts

It 'obvious that it is not only an ethical question: if Dropbox has really lied, it could be held accountable not only to its users (for example, those who have purchased a pro account may claim reimbursement of the sums paid) but also in relation to other cloud service providers that - those actually providing security guarantees (including encryption) - have been victims of unfair competition: as noted, the coast and the implementation of safety precautions declared would put them unable to adopt policies of price competitive with those of Dropbox.

While waiting for the FTC to rule on complaints and hope that Dropbox has not betrayed the trust of their users, I can not help but point out that - actually - the modification of the conditions is at least unfortunate in terms of its formulation. At a time in which people, organizations and companies need to be able to count on the reliability of cloud providers, they must pay particular attention to the content of the terms of service, writing - with clarity - just what they are capable of assuring and informing users - in a transparent manner - when changing the initial conditions.

Tagged with:

3 Responses to Dropbox misled users about security?

  1. Max-B writes:

    I have developed a small alternative to DropBox that allows me to do more or less the same things as DropBox on a self-managed server.
    The program I wrote is called OurBox and is released under the GPL license, runs on GNU / Linux and requires a server SSH / rsync.

    Here you will find more info and links to the project:

  2. [...] These days, as reported on Law 2.0, the team DropBox has suddenly changed the conditions of use of the service. According to [...]

  3. [...] Quite a stir "the affair Dropbox" (admirably summed up by Ernesto in this post). Assuming that storing in the cloud (the much-discussed "Cloud") file [...]

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>