The interesting part is that it came through a legacy Lenovo ID authentication flow, not some crazy “encryption got broken” scenario.

Makes you wonder where the real weak point in cloud storage usually is — encryption, login, or third-party integrations?

  • urushitan 漆たん@kakera.kintsugi.moe
    link
    fedilink
    arrow-up
    5
    ·
    12 days ago

    Their defaults are AES256 at rest

    https://www.dropbox.com/features/security

    That being said, that’s not end to end encrypted because they have the keys, so if someone breaks into their infrastructure, they break into the files. It moreso prevents the datacenter owner/someone acquiring drives from getting in.

    They do have support for end to end encryption, but that’s not included on their standard plans, you need to pay for the “Advanced” plan for that feature