Hacker News new | past | comments | ask | show | jobs | submit login

It's unfortunate when most are so mesmerized by great but incomplete magic that the magic creators are unwilling to conjure something even more magical to include safety like client-side encryption.

Reworded for the downvotes: Don't punish users because most may not even be aware of the lack of security in Dropbox by not using client-side encryption. If it's too difficult to explain, then it's time to go back and address your implementation of the product. Security through simple ignorance of a known deficiency is just disappointing. Maybe it only affects 1 out of 10 users who trust the safety of their stored password lists or similar documents, but businesses hopefully are more demanding.

And just a note...I do like Dropbox and use it everyday(for non-sensitive files).




Client-side encryption severely worsens the economics of Dropbox, and not everyone needs it. If you want that you're perfectly entitled to go build your own competitor, which will have higher costs.


It's already been built such as Spideroak and Wuala. Dropbox could capture more of the market and even concerned businesses if they make this even as much as a simple configurable option. If the data deduplication costs higher because of client-side encryption, then charge me the commodity price of storage for that option. Not everyone needs it but some do...


How do you propose they pay for the development? I personally doubt they will suddenly have businesses with deep pockets knocking on their door with fistfuls of money.



tarsnap is good, but try to teach your [insert] on how to use the tar command and what [sb]crypt means.


I've once or twice mused about building and selling an app that backs onto tarnsap. The service itself is fantastic, but it's not aimed at the mass market.


They could charge for it separately.


Maybe that's what they are going to use the intended 340 new hires to build. I think that a much higher priced enterprise version that included client-side encryption & much more storage than currently available could be a game-changer for the business. Wouldn't be surprised if they were already working on it


Found this through Google. Client Side Encryption for DB http://getsecretsync.com/ss/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: