A CRITICAL ANALYSIS OF DROPBOX SOFTWARE SECURITY

No ratings

Presented at Hack.Lu 2012 by

Dropbox is an online file storage service with at least 50 million users as of October 2011 (source: Forbes). Company market value is estimated over $4 billion. Dropbox is now widely used by mobile workforces for sharing corporate data, as Dropbox started to provide a commercial "team" edition for storing up to 1TB of data "in the Cloud". Dropbox is a mash-up of several Cloud services (including Amazon Storage), therefore Dropbox "externals" are relatively well-known. In this paper, we plan to expose Dropbox software internals, protocols, and even worse: security issues. Several alerts were raised in year 2011 (as related on Bruce Schneier\'s blog), but nobody really took care to look "under the hood" as deep as we did. Dropbox users, as well as the forensics community, will benefit from this analysis.