Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

The archive

Issues Database

Every documented issue, searchable and filterable by category, year, and keyword. Toggle between grid and timeline views, and export the filtered set to CSV.

On 30 August 2015 Dropbox suffered a worldwide outage that locked users out of their files; the company blamed an issue that arose during routine internal maintenance.

Reliability & Data Loss
Read documentation

During the August 2015 global outage, Dropbox's status page reported service restored while many users were still locked out — a documented gap between the company's stated status and the actual experience of its users.

Reliability & Data LossAccount Lockouts & Support Failures
Read documentation

Responding to criticism of Dropbox's lack of zero-knowledge encryption, CEO Drew Houston framed the fact that Dropbox can access users' files as a deliberate 'trade-off between usability/convenience and security.'

Privacy & Encryption Concerns
Read documentation

Dropbox's April 2014 appointment of former Secretary of State Condoleezza Rice — a defender of warrantless wiretapping — to its board triggered the grassroots 'Drop Dropbox' campaign, and months later Edward Snowden publicly branded the service 'hostile to privacy.'

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation
2 sources
MediumUsers in mainland China

Blocked behind the Great Firewall: Dropbox in China since 2014

China's Great Firewall has blocked Dropbox since 2014 — at one point cutting users off from their own files overnight without warning — leaving the service reachable in the country only via VPNs that are themselves restricted.

Product Changes & User BacklashGovernment Access & Surveillance
Read documentation

A viral 2014 incident revealed that Dropbox compares the cryptographic hashes of files users try to share against a blacklist of DMCA-flagged content and blocks matches — surprising users who assumed their files were entirely private.

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation

Because Dropbox mirrors a permissive server namespace onto stricter local filesystems, files with disallowed characters, over-long paths, or trailing periods can fail to sync or be silently renamed — sometimes without any clear warning to the user.

Reliability & Data Loss
Read documentation

Years before the California district attorneys' 2018 settlement, a private plaintiff brought a class action alleging Dropbox enrolled users in automatic subscription renewals without proper consent under California's Automatic Renewal Law; the case was removed to federal court and ended in a stipulated dismissal.

Legal Actions & LawsuitsPricing & Business Practices
Read documentation

After the 2013 PRISM disclosures named major US tech firms, Dropbox spent the following years documenting — through its own reports and advocacy — that it sits inside the same surveillance ecosystem: subject to NSLs, FISA orders and rising law-enforcement demands, with only banded, gagged disclosure permitted.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Because gag orders bar providers from confirming secret national-security demands, some companies post a 'warrant canary' — a standing statement that disappears if such a demand arrives. Dropbox relies on banded transparency reporting rather than a canary, leaving the most sensitive demands invisible to users.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

When Dropbox cannot reconcile two versions of a file, it preserves both — saving the loser as a duplicate stamped 'conflicted copy' — a data-safety mechanism that in practice creates lasting duplication and version confusion that users cannot turn off.

Reliability & Data LossProduct Changes & User Backlash
Read documentation
2 sources
Medium~7 million claimed by the Pastebin poster; Dropbox said the passwords had already been expired

The 2014 'Dropbox hack' that wasn't: leaked credentials and ransom

Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.

Security Incidents & Data Breaches
Read documentation