<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dropbox Security Issues&#8211;IT has itself to Blame</title>
	<atom:link href="http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/feed/" rel="self" type="application/rss+xml" />
	<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/</link>
	<description>Thoughts on the Future of Business and User-Centered Technology</description>
	<lastBuildDate>Tue, 18 Jun 2013 06:31:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Keeping Safe In The Cloud &#124; WikiCloud</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-131817</link>
		<dc:creator>Keeping Safe In The Cloud &#124; WikiCloud</dc:creator>
		<pubDate>Mon, 03 Sep 2012 09:49:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-131817</guid>
		<description><![CDATA[[...] which reported a breach of its systems that could have compromised users passwords. As I said in a post reflecting on the Dropbox issue: “…amazing functionality doesn’t mean that the product is [...]]]></description>
		<content:encoded><![CDATA[<p>[...] which reported a breach of its systems that could have compromised users passwords. As I said in a post reflecting on the Dropbox issue: “…amazing functionality doesn’t mean that the product is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dropbox Security Issues–IT has itself to Blame &#124; WikiCloud</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-130747</link>
		<dc:creator>Dropbox Security Issues–IT has itself to Blame &#124; WikiCloud</dc:creator>
		<pubDate>Mon, 27 Aug 2012 09:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-130747</guid>
		<description><![CDATA[[...] (Cross-posted @ The Diversity Blog &#8211; SaaS, Cloud &amp; Business Strategy) [...]]]></description>
		<content:encoded><![CDATA[<p>[...] (Cross-posted @ The Diversity Blog &#8211; SaaS, Cloud &amp; Business Strategy) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 123 Tax</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-128522</link>
		<dc:creator>123 Tax</dc:creator>
		<pubDate>Sat, 11 Aug 2012 20:27:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-128522</guid>
		<description><![CDATA[Any corporate worries could be avoided by locking down profiles. It is shocking how often the basics aren&#039;t covered!]]></description>
		<content:encoded><![CDATA[<p>Any corporate worries could be avoided by locking down profiles. It is shocking how often the basics aren&#8217;t covered!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Official Rackspace Blog - Keeping Safe In The Cloud</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-128129</link>
		<dc:creator>The Official Rackspace Blog - Keeping Safe In The Cloud</dc:creator>
		<pubDate>Tue, 07 Aug 2012 20:32:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-128129</guid>
		<description><![CDATA[[...] which reported a breach of its systems that could have compromised users passwords. As I said in a post reflecting on the Dropbox issue: &#8220;…amazing functionality doesn’t mean that the product is [...]]]></description>
		<content:encoded><![CDATA[<p>[...] which reported a breach of its systems that could have compromised users passwords. As I said in a post reflecting on the Dropbox issue: &#8220;…amazing functionality doesn’t mean that the product is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roy</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127434</link>
		<dc:creator>Roy</dc:creator>
		<pubDate>Wed, 01 Aug 2012 08:30:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127434</guid>
		<description><![CDATA[No there aren&#039;t. There are lots of &quot;Dropbox-like&quot; services that advertise encryption, but dig a bit deeper and you&#039;ll find it is only encryption of the files in transit. Similarly, most allow data to be moved to any mobile device without restriction.

A corporate dropbox requires:
1. Data at rest encryption, with the key controlled by the data owner
2. Data in transit encryption
3. Strong authentication
4. Controls over which end-devices can be used.
5. End-device encryption
6. Control over the sharing of data
7. Remote data wipe.
8. (For European companies) Adherence to data protection regulations
9. SAS70/ISO standards certifying compliance with security controls]]></description>
		<content:encoded><![CDATA[<p>No there aren&#8217;t. There are lots of &#8220;Dropbox-like&#8221; services that advertise encryption, but dig a bit deeper and you&#8217;ll find it is only encryption of the files in transit. Similarly, most allow data to be moved to any mobile device without restriction.</p>
<p>A corporate dropbox requires:<br />
1. Data at rest encryption, with the key controlled by the data owner<br />
2. Data in transit encryption<br />
3. Strong authentication<br />
4. Controls over which end-devices can be used.<br />
5. End-device encryption<br />
6. Control over the sharing of data<br />
7. Remote data wipe.<br />
8. (For European companies) Adherence to data protection regulations<br />
9. SAS70/ISO standards certifying compliance with security controls</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Kepes</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127409</link>
		<dc:creator>Ben Kepes</dc:creator>
		<pubDate>Wed, 01 Aug 2012 00:05:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127409</guid>
		<description><![CDATA[Jon - fair comment. I guess my perception comes from having dealt with all of those companies and seeing the degree of seriousness with which they look at their businesses. There is no functional issue I can point to that increases risk, it&#039;s a gut feeling based on spending time with all of these players and watching them develop over the past few years.]]></description>
		<content:encoded><![CDATA[<p>Jon &#8211; fair comment. I guess my perception comes from having dealt with all of those companies and seeing the degree of seriousness with which they look at their businesses. There is no functional issue I can point to that increases risk, it&#8217;s a gut feeling based on spending time with all of these players and watching them develop over the past few years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Brewer</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127403</link>
		<dc:creator>Jonathan Brewer</dc:creator>
		<pubDate>Tue, 31 Jul 2012 23:15:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127403</guid>
		<description><![CDATA[Hi Ben,

I see two issues here:

1.) Sync files to the laptop of an employee who leaves the company, and they go with him - but how is this different from the same employee connecting a USB drive and doing the same?

2.) A potential spam issue which at this point is just FUD. 

I still don&#039;t see how or why Syncplicity, Microsoft SkyDrive, SugarSync etc. are any different or better than DropBox. How about a benefit/risk matrix?]]></description>
		<content:encoded><![CDATA[<p>Hi Ben,</p>
<p>I see two issues here:</p>
<p>1.) Sync files to the laptop of an employee who leaves the company, and they go with him &#8211; but how is this different from the same employee connecting a USB drive and doing the same?</p>
<p>2.) A potential spam issue which at this point is just FUD. </p>
<p>I still don&#8217;t see how or why Syncplicity, Microsoft SkyDrive, SugarSync etc. are any different or better than DropBox. How about a benefit/risk matrix?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Kepes</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127393</link>
		<dc:creator>Ben Kepes</dc:creator>
		<pubDate>Tue, 31 Jul 2012 21:15:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127393</guid>
		<description><![CDATA[Multiple encryption, remote wipe... yeah, there are solutions IMHO]]></description>
		<content:encoded><![CDATA[<p>Multiple encryption, remote wipe&#8230; yeah, there are solutions IMHO</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rocio Ramos</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127392</link>
		<dc:creator>Rocio Ramos</dc:creator>
		<pubDate>Tue, 31 Jul 2012 21:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127392</guid>
		<description><![CDATA[I, and my coworkers, have always used dropbox as more of a leisure cloud app than business. We have never stored any important business or personal documents in our dropbox accounts. Nothing to do with the company really, just our own personal reasons. But security issues likes these do raise a flag.]]></description>
		<content:encoded><![CDATA[<p>I, and my coworkers, have always used dropbox as more of a leisure cloud app than business. We have never stored any important business or personal documents in our dropbox accounts. Nothing to do with the company really, just our own personal reasons. But security issues likes these do raise a flag.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Pushor</title>
		<link>http://diversity.net.nz/dropbox-security-issuesit-has-itself-to-blame/2012/07/31/comment-page-1/#comment-127381</link>
		<dc:creator>Patrick Pushor</dc:creator>
		<pubDate>Tue, 31 Jul 2012 19:44:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.diversity.net.nz/?p=8812#comment-127381</guid>
		<description><![CDATA[Do they really though?  No doubt on paper they have the features to satisfy the C** , but in reality there are very few services (not products) that will be effective in eliminating employees walking off with important information.]]></description>
		<content:encoded><![CDATA[<p>Do they really though?  No doubt on paper they have the features to satisfy the C** , but in reality there are very few services (not products) that will be effective in eliminating employees walking off with important information.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
