My company uses Dropbox extensively for storing documents with sensitive information.
My company uses Dropbox extensively for storing documents with sensitive information.
Dropbox has been in the news for scanning user files for years (eg, [1][2][3]). Note that the third link dates back to 2011; not a new issue.
If you do want to keep your data secure from the cloud provider, encrypt it yourself, or use a service that encrypts it before uploading using a key you provide (and with a client you trust not to be compromised). Spideroak makes a big play for this market[4], but I can't vouch for them.
[1]: http://www.pcworld.com/article/2048680/dropbox-takes-a-peek-...
[2]: https://www.extremetech.com/computing/179495-how-dropbox-kno...
[3]: https://readwrite.com/2011/04/20/how-to-keep-dropbox-employe...
I don't mean to nitpick and it's been a while, but Dropbox used to claim that "even our employees can't access your files". People called them out on the misleading language and they changed it.
https://www.cbsnews.com/news/at-dropbox-even-we-cant-see-you...
If Dropbox did that, you wouldn't be able to reset your password (since they do not store your password, just a salted hash, I hope).
Dropbox does plenty of interesting things with its users' files to optimize storage. I know they dedupe files, probably using a file hash. Perhaps they optimize even further.
Right, or course. I'm thick today.
Although there is a database of hashes and whatnot for child porn that service providers can access, so they don't necessarily need unencrypted access to the files, since they can hash locally and send that to their servers.
Specifically I recall a story that pirates were using their api to just upload the hash and basically use it as a file transfer service. They had to start requesting random chunks of files to make sure you actually had the file you were trying to sync.
Edit - I found a link: http://www.wired.co.uk/article/dropbox-dmca-position
The file uploaded in an instant, lending a lot of credibility to the theory that the software hashes a file and looks for the same hash in a central database, and if there's a match doesn't bother to upload the file but simply adds a pointer to it.
Not really surprising
I have no knowledge of Dropbox' internals, but I've been involved with several cloud backups solutions that "fully encrypt your data". Only to have a hard time convincing people that "Full Disk Encryption on a server" will do little to prevent an employee of that company accessing data.