Dropbox isn’t admitting that some researchers gained access to non-anonymous user data.
Let’s look at how it all started:
A study published Friday by researchers at Northwestern University reportedly obtained information from a Dropbox data manager. The study looked at how the collaboration platform is used by different groups of people.
The study says at one point that Dropbox “gave [the researchers] access to folder data” over a two-year period from about 400,000 users across 1,000 universities. The data was “aggregated and anonymized” by the researchers, according to the publication.
The researchers said the data included “total number of folders, the structure of each folder, and access to shared folders.” But according to the researchers, they and Dropbox employees “could not see any personal information.”
However, the researchers claimed to have seen “every folder in Dropbox associated with a particular researcher, who they shared the folder with, how often they accessed the folder, who they were connected to, how long they were on each project, and how users managed their time across projects.”
The reports prompted a flurry of Twitter protests from prominent academics.
Dropbox denied any of the above in an emailed statement to ZDNet:
“The article contained factual errors that we are working to correct,” said Dropbox spokeswoman Elisa Pandolfi.
“To be clear, before we gave Dropbox users’ data to the researchers, Dropbox permanently anonymized it, rendering any identifiable user information unreadable, such as emails and shared folder IDs.”
“This process prevented [the researchers] from seeing any of the personal information, but allowed them to analyze the data anonymously,” the statement said.
It is not known whether explicit permission was sought from those whose data was used. Dropbox has not yet responded. It is also unclear what role or access the company employee had to the data and why Dropbox did not review the results before publishing them.
____________________________
- Deep Web search engines for researchers
- Dark Patterns: How They Mislead You into Wrong Privacy Choices
- ICANN, unprepared for GDPR implementation in WHOIS
- Secure-K Linux OS USB security based on Debian
- Windows Hello scam with a photo
