7 ms·
Dropbox's website was vulnerable to passive session hijacking until they took note of Firesheep and fixed it. Both this and the mobile issues would have been i
by EricButler 16y ago
Dropbox's website was vulnerable to passive session hijacking until they took note of Firesheep and fixed it.
Both this and the mobile issues would have been identified on the first day of a security audit by even someone with little experience. Dropbox has continued to demonstrate that they do not take security seriously, which is confusing and unacceptable considering the entire company is built on the idea that people will trust them with their data.
Dropbox's claim that the lack of SSL is a speed issue sounds like total nonsense. I'll again reference Adam Langley's work at Google:
"In January this year (2010), Gmail switched to using HTTPS for everything by default. [...] In order to do this we had to deploy no additional machines and no special hardware. On our production frontend machines, SSL/TLS accounts for less than 1% of the CPU load, less than 10KB of memory per connection and less than 2% of network overhead."
http://www.imperialviolet.org/2010/06/25/overclocking-ssl.html http://www.imperialviolet.org/2010/06/25/overclocking-ssl.ht...