Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Straight from Drew himeself:

   data's stored on s3, and encrypted before storage -- there'll be another 
   option to enter in an additional passphrase (or private key) when installing 
   in order to encrypt your data before it leaves your computer (kind of like 
   what mozy does.)
It is sad to me that this never came to pass. I guess the desire to offer a web interface overrode the idea of encrypting the files before they left your computer. Not that you can't use your own encryption, but having it built in would have been great.


It's possible that encryption would have caused problems with their deduplication code since a single file is deduped across multiple accounts.


Didn't they nix dedupe across accounts, as people realised they could "transfer" files that way, and DropBox didn't want to deal with DMCA issues?


No, they never nixed them. Everyone has to deal with DMCA issues—Dropbox does a pretty proactive job of it (http://www.quora.com/Dropbox/What-are-some-methods-to-evade-...)


How exactly could you "transfer" files that way? You could just upload something to Dropbox and share your logon credentials and any form of dedup or DMCA won't help.


See the StakOverflow question for more details but the basics of it is that in order to optimize uploads the DB client calculates the hash of a file before uploading it and if the hash along with other attributes about the file like size etc... match then they assume it is the same. So you used to be able to trick the service into letting you download a file you never actually had if you knew the hash and other attributes.

http://stackoverflow.com/questions/4767505/exploit-dropbox-f... http://en.wikipedia.org/wiki/Dropship_(software)


I'm not sure why you're getting downvoted for asking a question.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: