DropBox Lied About User Privacy, Could View Uploaded Files
Allows employees access to unencrypted data.


Peeping Tom
According to Christopher Soghoian, a PhD student at the School of Informatics and Computing at Indiana University, “Dropbox de-duplicates the files that its users have stored online. This means that if two different users store the same file in their respective accounts, Dropbox will only actually store a single copy of the file on its servers.
The service tells users that it uses the same secure methods as banks and the military to send and store your data and that all files stored on Dropbox servers are encrypted (AES-256) and are inaccessible without your account password. However, the company does in fact have access to the unencrypted data (if it didn't, it wouldn't be able to detect duplicate data across different accounts)."
The de-duplication was tested by uploading new randomly generated 6.8MB file to dropbox which lead to 7.4MB of network traffic, while a 6.4MB file that had been previously uploaded to a different dropbox account lead to just 16KB in network traffic. That means that Dropbox was able to detect the contents of the uploaded files and make changes to the one which had similar content by adding the bits that it had missing. Soghoian also states that the AES-256 used by Dropbox is useless against attacks if the encryption key isn't kept private.
The US Federal Trade Commission (FTC) has received a complaint about the deceptive trade practices by Dropbox and is currently looking into the matter.

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
