Go to Post It's not about which is better, it's about which is better for your team. - Karthik [more]
Home
Go Back   Chief Delphi > Technical > Technical Discussion
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 02-06-2011, 09:25
Ether's Avatar
Ether Ether is offline
systems engineer (retired)
no team
 
Join Date: Nov 2009
Rookie Year: 1969
Location: US
Posts: 7,995
Ether has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond repute
Dropbox security

FWIW, article about Dropbox security:
http://windowssecrets.com/newsletter...-alternatives/


  #2   Spotlight this post!  
Unread 02-06-2011, 10:13
tim-tim's Avatar
tim-tim tim-tim is offline
Simplicity by Design...
AKA: Tim Miedzinski
FRC #0836 (The RoboBees)
Team Role: Mentor
 
Join Date: Feb 2007
Rookie Year: 2004
Location: Hollywood
Posts: 603
tim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond reputetim-tim has a reputation beyond repute
Re: Dropbox security

Thanks for the info.

Good thing I only keep college work on there.
__________________
The RoboBees

Tim's Shortcuts Anderson Powerpoles and Crimper, Star/Tube Nuts
  #3   Spotlight this post!  
Unread 02-06-2011, 10:13
JesseK's Avatar
JesseK JesseK is offline
Expert Flybot Crasher
FRC #1885 (ILITE)
Team Role: Mentor
 
Join Date: Mar 2007
Rookie Year: 2005
Location: Reston, VA
Posts: 3,608
JesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond repute
Re: Dropbox security

Quote:
Originally Posted by Woody Leonhard
He argues with some authority that Dropbox has an unfair advantage over competing cloud file-sharing services by maintaining its own keys (which allows its programs and employees access to your data).
I don't understand how this is an unfair advantage? Is the claim that dropbox security is sub-par simply because employees have a process to go through in order to access the file contents?

Using COTS cloud services, especially free services, to store sensitive proprietary information for a company has been a known no-no in the IT industry since the word "cloud" was even coined. For anything sensitive, the best philosophy isn't centered around if something gets hacked, but rather a matter of when it will become hacked (hi Sony!). Sure, we lose agility by the inability to automatically sync files, or have files available anywhere -- but the tradeoff is well worth it for trade secrets.

For the really paranoid, there's also the good-ol' trusty IronKey USB sticks. 4GB of 256-bit AES on a key chain FTW.
__________________

Drive Coach, 1885 (2007-present)
CAD Library Updated 5/1/16 - 2016 Curie/Carver Industrial Design Winner
GitHub
  #4   Spotlight this post!  
Unread 02-06-2011, 10:42
Ether's Avatar
Ether Ether is offline
systems engineer (retired)
no team
 
Join Date: Nov 2009
Rookie Year: 1969
Location: US
Posts: 7,995
Ether has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond repute
Re: Dropbox security

Quote:
Originally Posted by JesseK View Post
I don't understand how this is an unfair advantage?
Because if they can un-encrypt your data, they can "deduplicate" files and use delta storage for large files, which takes less storage. He mentioned that in the article.


Quote:
Originally Posted by JesseK View Post
Is the claim that dropbox security is sub-par simply because employees have a process to go through in order to access the file contents?
Yes. He mentioned other companies in the article which have no access to decryption.


Please note: I am neither agreeing nor disagreeing with the above, simply explaining what I think he meant.


  #5   Spotlight this post!  
Unread 02-06-2011, 10:59
JesseK's Avatar
JesseK JesseK is offline
Expert Flybot Crasher
FRC #1885 (ILITE)
Team Role: Mentor
 
Join Date: Mar 2007
Rookie Year: 2005
Location: Reston, VA
Posts: 3,608
JesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond reputeJesseK has a reputation beyond repute
Re: Dropbox security

Quote:
Originally Posted by Ether View Post
Because if they can un-encrypt your data, they can "deduplicate" files and use delta storage for large files, which takes less storage. He mentioned that in the article.

Yes. He mentioned other companies in the article which have no access to decryption.

Please note: I am neither agreeing nor disagreeing with the above, simply explaining what I think he meant.
Gotcha. Interestingly, I'd never heard of drop box until I went back to school, and hadn't heard of any of the other sync-services until this article.

TANSTAAFL indeed.
__________________

Drive Coach, 1885 (2007-present)
CAD Library Updated 5/1/16 - 2016 Curie/Carver Industrial Design Winner
GitHub
  #6   Spotlight this post!  
Unread 02-06-2011, 14:03
sanddrag sanddrag is offline
On to my 16th year in FRC
FRC #0696 (Circuit Breakers)
Team Role: Teacher
 
Join Date: Jul 2002
Rookie Year: 2002
Location: Glendale, CA
Posts: 8,499
sanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond repute
Re: Dropbox security

Is there something exactly like dropbox but where you run the server on your own machine somewhere?
__________________
Teacher/Engineer/Machinist - Team 696 Circuit Breakers, 2011 - Present
Mentor/Engineer/Machinist, Team 968 RAWC, 2007-2010
Technical Mentor, Team 696 Circuit Breakers, 2005-2007
Student Mechanical Leader and Driver, Team 696 Circuit Breakers, 2002-2004
  #7   Spotlight this post!  
Unread 02-06-2011, 14:18
Ether's Avatar
Ether Ether is offline
systems engineer (retired)
no team
 
Join Date: Nov 2009
Rookie Year: 1969
Location: US
Posts: 7,995
Ether has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond reputeEther has a reputation beyond repute
Re: Dropbox security

Quote:
Originally Posted by sanddrag View Post
Is there something exactly like dropbox but where you run the server on your own machine somewhere?
In the article the author mentions alternatives to Dropbox. All of them are client applications I think, but at least one of them generates the passwords and encryption locally so that the server has no access to the content of your files.

If you want to run an Apache server on your own machine you could certainly store files there and completely control access to them. I know that's not "like Dropbox", but it would give you access to your files from any internet-connected device.




Last edited by Ether : 02-06-2011 at 14:23.
  #8   Spotlight this post!  
Unread 02-06-2011, 16:17
Alan Anderson's Avatar
Alan Anderson Alan Anderson is offline
Software Architect
FRC #0045 (TechnoKats)
Team Role: Mentor
 
Join Date: Feb 2004
Rookie Year: 2004
Location: Kokomo, Indiana
Posts: 9,112
Alan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond reputeAlan Anderson has a reputation beyond repute
Re: Dropbox security

Quote:
Originally Posted by sanddrag View Post
Is there something exactly like dropbox but where you run the server on your own machine somewhere?
SparkleShare is supposed to do what you're asking. It doesn't look quite ready for regular use yet, though. There's also iFolder, which seems more complete.

Last edited by Alan Anderson : 02-06-2011 at 16:47. Reason: more better URL
  #9   Spotlight this post!  
Unread 02-06-2011, 16:42
Hugh Meyer's Avatar
Hugh Meyer Hugh Meyer is offline
Registered User
FRC #1741 (Red Alert Robotics)
Team Role: Mentor
 
Join Date: Feb 2009
Rookie Year: 2008
Location: Greenwood Indiana
Posts: 158
Hugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud ofHugh Meyer has much to be proud of
Re: Dropbox security

Quote:
Originally Posted by sanddrag View Post
Is there something exactly like dropbox but where you run the server on your own machine somewhere?
Funambol is one that I have been looking at. It has several sync clients that work with several different types of devices.

http://www.funambol.com/

I use Subversion, but it is not "exactly like dropbox" but it is a great way to keep files in sync across many computers.

http://subversion.apache.org/

-Hugh
  #10   Spotlight this post!  
Unread 04-06-2011, 22:40
Stuart's Avatar
Stuart Stuart is offline
#include coffee.h
FRC #1745 (P51- Mustangs)
Team Role: Mentor
 
Join Date: Jan 2006
Rookie Year: 2004
Location: Dallas, TX
Posts: 413
Stuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond reputeStuart has a reputation beyond repute
Send a message via AIM to Stuart
Re: Dropbox security

1745 Still uses Dropbox for its stuff but all of our financials are now in a Truecrypt container.

I found the whole thing stinks. the way they presented it to people is that they encrypted/decrypted it locally then only stored the hash ( without the password) like lastpass. but really the only thing keeping your files safe is a company policy (and disgruntled/blackmailed/hacked employees always follow policy)

as far as alts ( if you dont want to pre encrypt ) Steve Gibson ( from Security Now / Grc.com) uses Jungle disk for all his stuff and if its good enough for Steve it should be good enough for us.
__________________
Proud mentor of Team #1745 the P-51 Mustangs

If at first it doesn't work, use a hammer.
If that doesn't work, use a bigger hammer.
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:39.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi