Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2011 FTC complaint: marketing said staff couldn't read your files; the fine print said otherwise

April–May 2011

HighStatus: HistoricalProduct: Core syncYear: 2011

Security researcher Christopher Soghoian filed an FTC complaint alleging Dropbox had told users their files were inaccessible even to Dropbox employees, while its actual architecture — and a quietly revised Terms of Service — made clear the company could decrypt and hand over files.

What happened

For years Dropbox's marketing reassured users that their data was safe from prying eyes. Its help pages had stated that Dropbox employees were not able to access user files, and that all files were encrypted and inaccessible without the user's password. In April 2011 Dropbox quietly revised its Terms of Service and security language to clarify that it could, and would, remove its encryption from files to comply with law enforcement requests — language that flatly contradicted the earlier 'employees can't see your files' framing.

On 11 May 2011, Christopher Soghoian — a privacy researcher and former FTC technologist — filed a complaint with the Federal Trade Commission. He argued that Dropbox had engaged in deceptive trade practices by misrepresenting how its encryption worked. The technical heart of the complaint was deduplication: Dropbox compares uploaded files against everything already on its servers and stores just one copy of identical files, which is only possible if Dropbox holds the keys and can read file contents. Because Dropbox — not the user — controlled the encryption keys, the company could access plaintext, meaning the earlier privacy assurances were, at best, misleading.

Soghoian laid out the argument publicly in a post titled 'How Dropbox sacrifices user privacy for cost savings.' The complaint also alleged that Dropbox had overstated the encryption of its mobile apps. The episode reframed Dropbox not as a vault the company couldn't open, but as a service whose convenience depended on the company being able to.

Impact

The complaint permanently changed how Dropbox could describe its own security and seeded years of skepticism among privacy-conscious users. It established the central, recurring critique of the company — that Dropbox holds the keys — and helped create the market for 'zero-knowledge' rivals such as SpiderOak. Coming just weeks before the June 2011 authentication bug that left accounts open to any password, it made Dropbox a standing example in academic and journalistic discussions of cloud-storage privacy.

Dropbox's Response / Official Position

Dropbox said it believed the complaint was without merit, that millions of people relied on the service, and that it worked hard to keep data safe, secure, and private. It revised its help-center and security wording to more accurately describe that files are encrypted with keys Dropbox controls and that it can decrypt files when legally compelled.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation
3 sources
HighHundreds of thousands (Sign-breach class, now in arbitration)

2025: Dropbox forces the Sign-breach class action into private arbitration

A federal judge compelled the users suing over the 2024 Dropbox Sign breach into individual arbitration — finding that by clicking 'I agree' to sign a document they had accepted Dropbox's terms — and then denied reconsideration, effectively shutting the class action out of court.

Legal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

A consumer law firm opened an investigation into Dropbox Plus auto-renewals in 2025, as strengthened automatic-renewal laws in California and New York raised the bar for consent, reminders, and easy cancellation.

Legal Actions & LawsuitsPricing & Business PracticesAccount Lockouts & Support Failures
Read documentation