Securing the Cloud

Cloud-vault-image-from-shutterstockSecuring the cloud: a reader asks…

I use Dropbox for storing files online as a backup to my computer. I’ve been reading about cloud-based storage and hacking, and I’m a little worried about the safety of my files. I know that the files are encrypted during the upload and download process (from Dropbox servers to my computer), but what about the security of those files while they’re on Dropbox servers? I’m looking at a third party encryption tool: Boxcryptor. Do you think I should use something like this?

Well, first I should tell you that Dropbox servers keep your files secure on their server in several ways. First, they use 256-bit AES encryption while the files are stored, as well as using 128-bit or higher AES encryption and SSL/TLS when the files are being transferred from and to your computer. Dropbox also is very aggressive in monitoring and protecting their servers from hackers. See their security page for more info. With all that, it’s my belief that your files are as safe as they can be in the cloud, and as safe or safer than the files on your computer.

After all, personal computers get hacked all the time. That’s because we humans aren’t very good at adequately securing our own computers. We use crappy passwords (or skip passwords entirely), install dodgy programs and apps on our computer without even thinking, click on popups, ads and hyperlinks without considering the safety of doing so, open email file attachments automatically, and other unsafe behavior.

boxcryptor-logoAdding a third party encryption tool will add a very tiny additional measure of security (if any at all compared to all the other threats) and will cost you quite a bit. Not money, since using Boxcryptor is free for personal use (with limitations), but in terms of time and effort you have to go through to download and install the program and use it from day to day. Don’t get me wrong, I think Boxcryptor is a great tool and even at $48/year for the unlimited personal use option it’s a good value. But the truth is that most or all of your personal files aren’t worth adding that additional security layer.

Advertisement

Your better option is to make sure you’ve done the following:

Dropbox-LogoWith your Dropbox account:

  1. use a strong (13+ characters) and unique password
  2. enable 2-step verification (aka 2-factor authentication)
  3. turn on recommended security features
  4. monitor your account activity (from the events page) and turn on notifications in Profile > Preferences

microsoft-windows-logosOn your Microsoft Windows computer:

  1. use a good antivirus program (such as Bitdefender Internet Security)
  2. use a good anti-malware program (such as Malwarebytes Anti-Malware Premium)
  3. use a good anti-exploit program (such as Malwarebytes Anti-Exploit Premium)
  4. Learn and follow safe computing practices (see our handy guide)

apple-iphone6-vs-samsung-galaxy-s6Mac users should still follow #4 above.

On your Smartphone/Tablet:

  1. Use a strong passcode for every time you use your device (unique six digit code for iOS, unique pattern for Android)
  2. Never let someone else borrow your device without you watching exactly what they’re doing
  3. Set your device so it will be automatically wiped if lost or stolen (usually after 10 bad attempts to guess your passcode)

Of course if you are storing the equivalent of national secrets in your Dropbox account, I’d recommend you use something like Boxcryptor. After all, every online entity has either already been or is going to be hacked at some point, and for really sensitive information, you don’t wan to take a chance.


This website runs on a patronage model. If you find my answers of value, please consider supporting me by sending any dollar amount via Click or tap to open a new browser tab or your Venmo app and send money via Venmo to @positek (send to @PosiTek), Click or tap to open a new browser tab or your Paypal app to send money via your Paypal account to support@positek.net (send to Support@PosiTek.net), Click or tap to open a new browser tab or your Paypal app to send money using your credit card to support@positek.net (no Paypal account required) using any credit card (no Paypal account required), using Zelle, Apple Pay or Google Pay, or by mailing a check or cash to PosiTek.net LLC 1934 Old Gallows Road, Suite 350, Tysons Corner VA 22182. I am not a non-profit, but your support helps me to continue delivering advice and consumer technology support to the public. Thank you!

Go to Top of Page

One Comment

  1. Nice post. I learn something new and challenging on sites I StumbleUpon every
    day. It’s always useful to read content from other writers and use something from other web sites.

Leave a Comment

Your email address will not be published. Required fields are marked *

For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

This site uses Akismet to reduce spam. Learn how your comment data is processed.