top of page

Dropbox 13.2 (iOS / App Store) on Jul 21, 2016

  • Фото автора: privacymeteronline
    privacymeteronline
  • 23 июл. 2016 г.
  • 6 мин. чтения

Our examination revealed total 16 items, where were 7 DAR items and 9 DIT items. Among DAR items 2 best items found and among DIT items 9 best items found. Also 0 worst DAR items found and 0 worst DIT items found.

This application is available for iOS here. This app was designed to make this service the place for your photos, docs, videos, and other files. The latest build was released on Jul 19, 2016.

Let's cite the description of this application below: ------------------------------------------- Dropbox is the place for your photos, docs, videos, and other files. Files you keep in Dropbox are safely backed up and you can get to them from all your devices. It’s easy to send large files to anyone, even if they don’t have a Dropbox account. Features: • Access your files on any device, even if you’re offline • Create and edit Microsoft Office files from your iPhone or iPad • Share links to your largest files without using email attachments We offer in-app purchases for Dropbox Pro, which includes 1 TB of storage and additional features. The amount will be charged to your iTunes account and will vary by plan and country. You’ll see the total price before completing payment. Dropbox Pro subscriptions purchased in-app renew monthly or yearly depending on your plan. To avoid renewal, you must turn off auto-renew at least 24 hours before your subscription ends. You can turn off auto-renew at any time from your iTunes account settings. Dropbox also offers one-month trials for monthly subscriptions. -------------------------------------------

Protection levels.

Locally stored data (Data-at-Rest, DAR). Locally stored data groups include Media Information, Documents Information, Credentials Information, Application Information, Device Information. The average DAR value is 4.50 points (7.00 points of system protection and 2.00 points of own protection). It is higher than a typical value (3.5 points, where's 7 points of system protection and 0 points of own protection).

Items #1 with average value 7.00 points (7 points of system protection, 7 points of own protection) means data protection levels have following definitions. Frankly talking, complianced but there are publicly known techniques to access the data where system protection case - root/jailbreak is required but not possible without wiping device data, and own protection case - data is not available in backups. - Screen Snapshots ('Media Information' Group) - Screenshots of your device screen running certain apps (by default available for iOS device but happens for any 3rd party apps that have such features). This data item related to mentioned group meant to be lot of data like photo, image, video, audio, - Device Details ('Device Information' Group) - Includes basic device details plus hardware key and fingerprints as well as IMEI. This data item related to mentioned group meant to be details about your device

Items #2 with average value 3.50 points (7 points of system protection, 0 points of own protection) means data protection levels have following definitions. Frankly talking, extra data found that shouldn't be accessed where system protection case - root/jailbreak is required but not possible without wiping device data, and own protection case - stored as is. - Document Details ('Documents Information' Group) - Common info about documents synchronized or stored locally (properties like size, date and time, etc.). This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Document List ('Documents Information' Group) - List of documents stored local or synchronized over Internet. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Local 'n' Network Paths ('Documents Information' Group) - Paths about local or networks directories, folders, files. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Credentials (IDs) ('Credentials Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Application Configs ('Application Information' Group) - Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any kind of info related to app, app settings, incl. installed apps or installers

Also, keep in mind, using jailbroken device means the system protection level is 0 points and you're using out-of-dated iOS < 8.3 the system protection level is 2 points. If some data marked as shareable via iTunes, then the system protection level is 4 points.

Transferred data (Data-in-Transit, DIT). Transferred data groups include Credentials Information, Application Information, Account Information, Documents Information, Media Information. The average DIT value is 5.00 points (4.00 points of system protection and 6.00 points of own protection). It is higher than a typical value (4 points, where's 4 points of system protection and 4 points of own protection).

Items with average value 5.00 points (4 points of system protection, 6 points of own protection) means data protection levels have following definitions. Frankly talking, data is not available all the time or partially accessed where system protection case - informs if fake certificate imported into a device, and own protection case - ssl pinning (can be patched). - Credentials (IDs) ('Credentials Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Credentials (Passwords) ('Credentials Information' Group) - Well known passwords or PINs you're using to get an access to your account (usually worse than tokens because gives a full access to your account). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Application Configs ('Application Information' Group) - Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any kind of info related to app, app settings, incl. installed apps or installers, - Account Settings 'n' Configs ('Account Information' Group) - Information about your account settings and configurations. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Sync Documents ('Documents Information' Group) - Documents synchronized or locally stored on your device as is or converted into another file formats (like.pdf or set of separated jpg file per each .pdf). This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Document Details ('Documents Information' Group) - Common info about documents synchronized or stored locally (properties like size, date and time, etc.). This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Document List ('Documents Information' Group) - List of documents stored local or synchronized over Internet. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Media Data ('Media Information' Group) - Any kind of info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be lot of data like photo, image, video, audio, - Tracked Data 'n' Favourites ('Documents Information' Group) - Any kind of favourites data or tracked data marked as desirable by users and for users (Like is that user is on fb messenger, viber, bank client or favourite hotel, room type, flight route, airline). This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format

Keep in mind if you're using out-of-dated iOS < 9.0, the system level equals 2 points instead of 4. It means your data can be stolen without involving your actions.

Below you find two infographics summarizing what we described above.

First pic includes info about data items combined into groups and best protected items found.

Second pic includes info about data items separately from group and worst protected items found

Privacy Policy Full application privacy policy is available here. You may find privacy policy details proceeding the link above to compare developer's vision on data protection with our results.

Thanks for staying with us, your Privacymeter Team!

Comments


Want more to read?
Tag cloud
Follow us
  • Black Facebook Icon
  • Black Twitter Icon
  • Black Google+ Icon
  • Black LinkedIn Icon
  • Black RSS Icon
  • Black Pinterest Icon
  • blackberry
  • telegram
  • скачанные файлы
  • re.vu

Подпишитесь на рассылку

Будьте в курсе наших новостей

bottom of page