Уровень 0 · материалов: 3
В этот кластер входят документы, касающиеся технических уязвимостей и недостоверности заявлений Dropbox о защите данных, но не входят документы о функциональных возможностях сервиса или его рыночной стратегии.
Общие признаки: уязвимости безопасности Dropbox, вводящие в заблуждение заявления о шифровании, доступ к пользовательским данным
Группа выше: Риски и критика облачных сервисов
Смысл: The main idea is that Dropbox's security claims are misleading because the company retains the decryption keys, allowing them to provide plaintext data to the government and meaning employees are only policy-restricted, not technically barred, from accessing user files.
Dropbox's encryption does not prevent the company from decrypting and handing over user files to government authorities upon request.
Смысл: The text describes a legal dispute where Dropbox is accused of misleading users about its encryption practices to gain a market advantage, highlighting the difference between 'administrative prohibition' of access and 'technical impossibility' of access.
Dropbox faces an FTC complaint for falsely claiming that employees could not access encrypted user files, a practice that gave them a competitive edge over truly secure cloud storage providers.
Смысл: The main idea is that Dropbox's reliance on a static, portable host_id stored in a local SQLite database creates a security loophole where account access can be stolen via a simple file copy, bypassing password changes.
Dropbox's use of a static, portable host_id in its local configuration file allows attackers to gain full account access by simply copying that ID to another machine.