Skip to main content

Dropbox security woes are back, FTC complaint filed

dropbox-logo-largeLess than a month ago, we questioned whether Dropbox’s privacy changes warranted concern of PlayStation proportions. The phrase that piqued users’ interest had to do with sharing information with outside entities, namely the government and law authorities. “We may disclose to parties outside Dropbox files stored in your Dropbox and information about you that we collect when we have a good faith to believe that disclosure is reasonably necessary,” the statement reads, and lists various legal, security, and safety situations in which it may have to do this.

Dropbox also clarified the state of security of your stored documents. Namely, its encryption process wasn’t quite what users believed it to be, and while Dropbox assured everyone its system is adequately safe, nerves were rattled to say the least. And now, it looks like users aren’t the only ones calling foul, as a complaint against the company has been filed with the Federal Trade Commission.

Recommended Videos

The site previously claimed that “all files stored on Dropbox servers are encrypted (AES-256) and are inaccessible without your account password” (AES-256 is the highest strength of Advanced Encryption Standard ciphers used to encrypt data). Instead, Dropbox has been using file dedpulication when it’s initially uploading a document in order to determine if that file has already been uploaded by someone else (and if it has, it then links to the formerly uploaded one). This process means Dropbox can save ample storage space and bandwidth, but by means of a less secure system.

Ph.D. candidate and graduate fellow at Indiana University Christopher Soghoian filed the complaint, and explained in his blog his reasons for questioning Dropbox’s policies. He argues that if Dropbox is using a deduplication system, it definitely is able to see unencrypted version of your files in order to determine if there are duplicates. And as Soghoian explains, these measures are “useless against many attacks if the encryption key isn’t kept private,” which he’s uncertain of. The complaint states that “Dropbox does not employ industry best practices regarding the use of encryption technology. Specifically, Dropbox’s employees have the ability to access its customers’ unencrypted files.” The statement goes on to say that the encryption keys are stored on company servers.

For anyone storing particularly sensitive information on the site, this news if cause for concern. But there are also users who believe cloud-based storage can only be so safe, and you’re taking a leap of faith by using them altogether. But what does Dropbox have to say about it? “We believe this complaint is without merit, and raises issues that were addressed in our blog post on April 21, 2011 .  Millions of people depend on our service every day and we work hard to keep their data safe, secure, and private,” says company spokesperson Julie Supan.

Adding a strange twist to the whole thing is the fact that Soghoian broke the Facebook PR scandal story. Busy guy.

Molly McHugh
Former Digital Trends Contributor
Before coming to Digital Trends, Molly worked as a freelance writer, occasional photographer, and general technical lackey…
OpenAI showing a ‘very dangerous mentality’ regarding safety, expert warns
ChatGPT and OpenAI logos.

An AI expert has accused OpenAI of rewriting its history and being overly dismissive of safety concerns.

Former OpenAI policy researcher Miles Brundage criticized the company's recent safety and alignment document published this week. The document describes OpenAI as striving for artificial general intelligence (AGI) in many small steps, rather than making "one giant leap," saying that the process of iterative deployment will allow it to catch safety issues and examine the potential for misuse of AI at each stage.

Read more
M3 Ultra vs. M4 Max: Which is better? Benchmarks can’t tell either
2025 Mac Studio

Apple surprised us with its announcement of the new Mac Studio this week, and confused us with its chip choices -- the M4 Max and the M3 Ultra. It's hard enough to tell which chip is more powerful just from their names, but according to early benchmarks, it's also hard to tell from their CPU performance.

https://x.com/VadimYuryev/status/1897849477706481701?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1897849477706481701%7Ctwgr%5E8073e41e643559d3c995c3a698fc2b5523a61222%7Ctwcon%5Es1_&ref_url=https%3A%2F%2F9to5mac.com%2F2025%2F03%2F06%2Fm3-ultra-m4-max-chip-benchmark%2F

Read more
AMD’s RX 9070 XT could soon cost a lot more than it does now
An Asus RX 9070 XT TUF GPU.

After the way Nvidia's RTX 50-series ended up being called a "paper launch," many breathed a sigh of relief when AMD's RX 9000 series appeared on the shelves in much larger quantities. However, once this initial shipment is sold, AMD could face the same problem as the rest of the best graphics cards: Price hikes, price hikes everywhere.

The cards officially hit the shelves yesterday, and many were spotted far above the recommended list price (MSRP), with some overclocked models priced at up to $250 more than the $600 starting price. However, AMD spoke several times about working with its partners to ensure wide availability at MSRP, and indeed, many retailers had some models up for sale. Those MSRP cards were only around for a short time, though, and they might never come back, according to retailers.

Read more