We are aware of the issue with the badge emails resending to everyone, we apologise for the inconvenience - learn more here.

Forum Discussion

PierreLeBear's avatar
PierreLeBear
Helpful | Level 5
5 years ago

Zero Knowledge Encryption

I find that many Cloud services offer encryption during transfer to the service and encryption at the destination.   Dropbox does this too.   Unfortunately, the keys used at the destination are available to Dropbox.   What would make Dropbox unique is if it would offer Zero Knowledge encryption at the client.   That way all files are encrypted at the client with the customer retaining the keys.   Why is this important?  There can be bugs during transfer even if encryption is used (remember the famous OOPS with caches on internet servers offering up unencrypted data?). Also, the government can force Dropbox to deliver user data (or it may be compromised by hackers).

Dropbox with Zero Knowledge Encryption would be a market leading solution that would drive a great preference over OneDrive, Google Drive and others.  It would be the only way I would be comfortable putting my files on the cloud.

  • apfund's avatar
    apfund
    7 months ago

    I wanted to share a quick update with you: 

    We have launched our end-to-end encryption in April. More details can be found here and here
    High level overview: 
    You can now add end-to-end encryption to team folders. The functionality is available for our Advanced, Business Plus and Enterprise customers at no additional costs. 

    If there are any questions, please let me know!

  • OurClemonsFamily's avatar
    OurClemonsFamily
    New member | Level 2

    I'm currently using Dropbox for non-private items.  I'm using iDrive at additional cost to have a private encrypted backup that only I have the encryption key for.  It's on me to know where the key is and have multiple backups in various places.  I have an encrypted copy of the key on Dropbox.

     

    You should offer self-control of the encryption key as a user option (all their decision and responsibility) with a list of any services that could be a problem that you use.

  • Dropitinthebox's avatar
    Dropitinthebox
    Collaborator | Level 8

    boxcryptor.com works with Dropbox and can do this for you I believe, which might be a good solution for some?

     

    Still, I'm also totally in favor of adding this to Dropbox natively instead of having to rely on a 3rd party solution. And totally agree with the comment made by some of the others that it's an essential option that you'd expect to see in a mature product like Dropbox.

  • foxclout's avatar
    foxclout
    New member | Level 2

    https://help.dropbox.com/accounts-billing/security/how-security-works

    Dropbox doesn't provide for client-side encryption. Dropbox also doesn't support the creation of your own private keys. However, Dropbox users are free to add their own encryption.

     

    I'm using Cryptomator, so I lost a few features from Dropbox to gain my privacy. Dropbox Vault is just a folder with an extra password, not encrypted, just password / pin to access it.

     

    I tried to create a secret.txt file, write something on it,  "Copy Dropbox Link", and lock my vault, then, I tried to open this copied link to Private Browsing mode, and I can see what is inside secret.txt file without login to any account, such a privacy, right?

     

    I still using Dropbox because it can run on multiple OS, I'm using Linux, MacOS, and sometimes Windows, but I consider to move to another provider which have e2e encryption.

  • Dropitinthebox's avatar
    Dropitinthebox
    Collaborator | Level 8

    "Status: Needs more votes" ???

     

    I thought 166 votes is a LOT comparing to the number of people who are active in this section of the forum?

    How many votes are required?

  • Whatever2018's avatar
    Whatever2018
    New member | Level 2

    The number of votes is irrelevant. Companies like Dropbox do not implement features based on user suggestions. They do so via bean counting.

     

    Dropbox has over 15 million users that pay a subscription fee and nearly $2 BILLION in revenue.  That subscription payment is a "vote" for the policy of "whatever you do is fine by me."

     

    They would need to lose around 1 million subscriptions explicitly due to lack of zero-knowledge encryption before they even considered implementing the idea.

     

    Synopsis: If you are paying a fee now, you have already voted that everything is absolutely great and in no need of change.

    • foxclout's avatar
      foxclout
      New member | Level 2

      Cryptomator and Veracrypt. I'm using Cryptomator, but it's not free on Android and Apple device.

      Anyway, I'm free Dropbox user right now, I don't have any plan to back to be paid customer anymore.

      • MrSquish's avatar
        MrSquish
        New member | Level 2

        You can add me to the "Down vote" for not having this option.  They bought out boxcryptor, which many of us used to add the extra layer of encryption, while still being able to use the history and version features within dropbox.  I've been a paid subscriber for years, but without this feature, it's time to move on. 

  • GottZ's avatar
    GottZ
    New member | Level 2

    I just run through the rclone crypt layer before I mount my cloud providers.
    I still think it's horrible, privacy is locked behind a paywall.

About Security and Permissions

Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.

Need more support

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!