Hacker News new | ask | show | jobs
by progval 3036 days ago
Decryption keys are stored on Dropbox's servers, which makes this encryption pointless if the company turns evil.
1 comments

Not all decryption needs to be end to end encryption. I’m not sure when this idea developed, but it’s silly.

If your threat model mandates that you use end to end encryption, go for it, and choose something other than Dropbox. But saying the encryption is pointless just because the organization that manages the keys could become “evil” is hyperbole.

Dropbox deduplicates files across user accounts to minimize storage. Effectively, this means all accounts share one private key for encryption...

Edit: to be clear, I believe it is an option on enterprise accounts to use your own key.