Or does Dropbox have the power to pilfer through my data, along with official snoopers and hackers?
Or does Dropbox have the power to pilfer through my data, along with official snoopers and hackers?
Alternatives would be Spideroak and Wuala or addon software like Boxcryptor. They work but not as flawlessly and user-friendly as Dropbox usually does …
In particular, an attacker having access to the ciphertext at two or more different times violates EncFS's security assumptions; undetected malicious modification of files is also feasible in this scenario.
Many encrypted filesystems do not include such a property in their design criteria - for example, XTS mode as-is is not suitable for use in this scenario either, so please also try to avoid putting TrueCrypt (et al) on Dropbox!
For a broad general example of what a system would look like which tries to address this use case more naturally and effectively (although, caveat: I have not reviewed it in great detail myself), please see Tahoe-LAFS.
Would you recommend something other than Dropbox + EncFS as the best compromise for a file-sync solution that has reasonable security, a non-buggy client, supports block-level sync, is reasonably priced and "just works"? BitTorrent Sync + EncFS?
If you want to have security against the cloud storage provider, it is better to use some other encryption solution.
In CrashPlan, you can at least set your own private key if you like. You still need to trust the provider/vendor, however, the software is at least built to do local encryption. Dropbox does not work that way.