Dropbox for Business
dropbox.com
dropbox.com
1. Under /features check out the 'Certification and Compliance section'.
>> Dropbox's storage is SSAE16/SOC1, SOC2, ISAE 3402 and ISO 27001 certified on Amazon S3 and may provide data mirroring across other secure data centers
SSAE16/SOC1 compliances were not present in the earlier versions and this is a decent step forward for adoption of dropbox in larg(ish) IT departments. This will imply "firewalls are in place at all externally facing access points".
2. From a usability point of view, the promise of a seamless way to integrate both your personal and work accounts from the same device.
3. "Seamlessly upgrade existing Dropbox accounts to Dropbox for Business and transfer files to a co-worker when someone leaves", although this is in Beta currently, this reduces a lot of headache for IT departments during employee exits.
Seems like most of the other features remain the same, though.
It wasn't clear from the announcement that Dropbox for Business will support multiple work accounts on the same device. The marketing content appeared to be written to appeal for enterprise IT managers, who obviously wouldn't be worried about this.
For IT-managed devices that's fine, but there sure are a lot of people nowadays with side businesses or who consult with multiple organizations that all want to share files. And currently it's easier to use Box (or Google Docs) than sharing folders via Dropbox and worrying about busting each sharee's Personal storage quotas.[1]
Dropbox = Your-Unencrypted-Files-Here.com
I'd actually argue that it would make the service more dangerous, as once you decrypt a file outside of the context of your desktop, the Dropbox service has the key. How do you share a file on the web or via mobile client with low friction without rendering that client-side encryption useless? (A: You don't.)
IMO, if you have data security needs that necessitate client-side encryption, and you use a public service to store that information, you need to give up whiz-bang features or reduce your security requirement.
Exactly. Not all of us _need_ to share files, I just need a secure backup. And it is technically possible to access files on various clients using only client-side encryption and separate encrypted files from plain-text should you need to.
Actually, it really bothers me that Dropbox touts these things as compliance factors (vs. features of the underlying storage system). Dropbox is the user-facing service, not Amazon S3.
If I put a bunch of money in some super-duper safe, chain it to a flatbed truck, and then leave the truck unlocked with the engine running, the safe doesn't make that money secure.
You can take more comfort from the ISO 27001 compliance
For us this means one thing: There is a well-supported and maintained Linux client that just works.
I've no doubt we'll be giving Dropbox for Business a try, but it's pretty much because of the ubiquity rather than anything else.
Do you know for a fact that this won’t be possible?
All in all, the whole process needs some revision on their part.
This isn't the same way I did it, but here is an article on it.
http://lifehacker.com/5971204/run-multiple-dropbox-accounts-...
Dropbox is a great Tool, no question, but if you're a company (outside of the US) you should think about what you store where.
I'm fine with Dropbox, but there's my Boss, you know.
But if your data never crosses a US border (E.g. a Norwegian person using jottacloud), then the NSA cable taps have no effect. If your server is not in a US server farm or in a US Company, then it can't be subverted at destination the way that lavabit was going to go (and the other major companies have already gone).
I'm really suspicious of this "safer in the USA" stuff right now.
Perhaps, as pertains to the taps we were warned about by Mark Klein, Snowden, et al. But if you think that's the full extent of US intelligence taps, Angela Merkel's cell phone rather disagrees. (And the notion that they'd tap a half dozen foreign leaders before they tapped a trunk line or five is pretty laughable.)
That taps at borders which NSA / GCHQ have legal access to are well documented: http://www.independent.co.uk/news/uk/politics/operation-temp...
Other borders ... not so much.
> With the NSA's money and engineering resources, I don't really think any data is safe anywhere.
The NSA are legally constrained. They can't walk into a data center in Germany waving a court order and insist on a tap and no publicity. This is essentially what happened to lavabit because their data center was in the US. Yeah, a data center in Europe could be hacked. but:
1) Any bad actor could try to do this
2) Trying to do this in a notionally friendly country is not the most diplomatic thing. Not saying it can't happen but it would be arrogant and risky. Consider the fallout if some disgruntled sysadmin drops dox on it. http://www.cbc.ca/news/world/nsa-s-alleged-spying-on-merkel-...
There are laws in the US that they attempt to abide by that make this more difficult domestically, but not as difficult on foreign soil.
I wonder if that means one could sign up for 5 accounts and pay $75/month for unlimited space for personal use. (You could just use one account and never sync the other four.)
I did it in 2011 as well for my own account and still have the extra storage. I've since upgraded though. Even 15GB is peanuts today...
Now, why was your comment even made again?