Settings

Theme

Security culture, the Dropbox way

blogs.dropbox.com

21 points by apu 8 years ago · 13 comments

Reader

pvg 8 years ago

I'm sure Dropbox takes security seriously and works hard at it but this piece doesn't tell me a lot more than that except in much longer form. You can find/replace 'trust' (and 'security') with 'truck' and come away as informed and potentially slightly more amused.

  • tlb 8 years ago

    Some informative parts that keep their meaning under s/trust/truck/g include:

    "... daylong social engineering workshop designed and led by internal experts that immersed them in a hypothetical scenario involving a malicious insider."

    "... a hands-on workshop where Dropbox employees researched, crafted, and presented their own phishing schemes."

    "... our annual Capture the Flag"

    It's interesting the emphasis on social attacks. You only have to get the cryptography right once, but every employee needs to defend against social engineering.

    • pvg 8 years ago

      You forgot the really important ones, I think. Trucktober and tailgating. It does raise the interesting question of why Dropbox does not celebrate Trarch.

dokem 8 years ago

The harder a company tries to sell their philosophy the less I'm inclined to believe them. Words are cheap.

java-man 8 years ago

a better approach would be implementing a zero-knowledge storage infrastructure, like tarsnap.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection