← Back to context

Comment by Dylan16807

10 years ago

I don't really understand the conclusion here. So the scenario is you trust dropbox with your files, and you trust them with a kernel blob implementing the filesystem, but you don't trust them to silently have accessibility rights?

You're assuming everyone trusts Dropbox with all their files and that everyone installs their kernel extension, which is a wrong assumption.

  • If we're worried about theoretical abuse, the client could access all of your files because it runs as you.

    You can opt out of the kernel extension? Still, you give it root to install, and it has a long history of hacking the file browser to get icon overlays... it seems weird to me that this would be a deciding factor.

    • I was under the impression that the kernel extension was a separate product, it's being included in the standalone Dropbox application? You do have a point about giving it administrator privileges, the post however shows very clearly that they are abusing your trust which is enough for people to think twice before using their application..

      4 replies →

>you trust dropbox with your files, and you trust them with a kernel blob implementing the filesystem, but you don't trust them to silently have accessibility rights?

The problem here isn't that you don't trust them to have accessibility rights, it's that Dropbox has phished your root password, stored it, and will continue to modify your system to meet it's desired operating criteria.

  • >- We never see or store your admin password. The dialog box you see is a native OS X API (i.e. made by Apple).

    Direct from the DB engineer at top of thread.

Trusting them with some files that you knowingly add vs giving them root permissions and password are two totally different things.