I use dropbox and I appreciate it, but I find communications from you and Arash to be strangely borderline ... off.
A discussion from three weeks ago is not "an old issue." That these issues made it to the FTC in three weeks is probably a remarkable benchmark.
As Arash did several weeks ago, wrt to the password and key issue, you seem to miss the point and almost intentionally dismiss the issue by detailing it as "old issues."
These issues are anything but old, even in internet time.
I would value Dropbox much more than I do if I found that you and Arash could speak with the integrity I find from so many other entrepreneurs.
I know this comment could be dismissed as tin-foiley, but spending a week here reading stories on FBI wire taps or bills passing through congress and I don't think this is much of a stretch by any means.
I imagine this is a (necessity?) of modern day, massive-scale online services like this... or at least it becomes one once they hit critical mass.
For example, I would expect Facebook has a back-channel for law enforcement to view profiles unfettered by privacy settings. I'm not saying I have proof they do, but would anyone really be surprised if a service with 700 million users globally was in-bed with security agencies?
I suppose I just expect that now.
1. Can Dropbox access user files? (already answered, yes)
2. Did you ever claim otherwise?
3. If so, why? And how will you appease any users that were misled? If not, where is the flaw in this complaint and various others?
The kind of vague PR-speak in that blog post will only irritate this crowd and drag the whole thing out. IMHO, the fastest way to make this go away is to take a firm position and state it clearly. And if you don't want to do that then it's probably best to say nothing at all.
Accessing files from the website and file previews can use a key that I give you when I login. The only one where you need to have a key is if I share the file with someone. Can't you throw up a prompt when I elect to share a file that says, "This file will now be accessible to person XYZ. In order to do this DropBox will re-encrypt with our own private key"?
I suspect a lot of people don't share most/all of their files with anyone. It would be nice to have privacy by default and then opt-out when they decide to share it.
Dropbox advocates TrueCrypt in one breath, but refuses to integrate client-only encryption keys in the client with the next breath. Obviously they know what we all know: TrueCrypt presents a poor UX for non-technical users, and so most people won't use it even if it's recommended. Then DropBox gets to be the hero for advocating TrueCrypt while they get de-dup efficiency because they know few people actually bother using TrueCrypt.
Any transfer of keys to dropbox, even temporally, means your data on dropbox should be considered insecure. You have no way to know what's going on on the dropbox side. The same issue arises for CAs that let customers generate SSL keys within a web interface, to avoid the nuisance of having to generate a key/cert/csr themselves and uploading that. It doesn't matter if the CA promises never to store the private key. It's insecure and it's bad practice.
If they can't decrypt it, they can't deduplicate it.
If they couldn't deduplicate it, the costs would be higher.
Higher costs => higher prices
The encryption process doesn't result in one giant blob of data. It results in N blobs, where N is the number of files you store in Dropbox.
EDIT: I misread "deduplicate" as "duplicate". You're correct.
The second method would require identical files from different users to encrypt to the same form, meaning the encryption is not key dependent and thus can also be decrypted without your key.
There may be some other method I'm missing but I don't see how they could de-duplicate with key-dependent encryption when their users hold their own keys.
Still need a lot of improvement but It's good. Built on different philosophy, so the workflow is slightly different, however in some areas (what to backup, what to sync and how) has more flexibility.
One missing feature is syncing directories with others. Probably the architecture that gives the security makes this a difficult task.
To compensate for that, there's a pretty good feature of web-share. Can share anything you backed up, with a separate password that you can revoke any time.
So in the end: I keep Dropbox but removed most of my files from there, started with SpiderOak, and playing with AeroFS (similar functionality on peer-to-peer architecture).