kung fu grippe

  • Archive
  • RSS

The (Imperfect) Art of Sending Sensitive Stuff

Securer file sharing with Dropbox « practically efficient

  • Zip your files
  • Put the zip file in your Dropbox ‘Public’ folder
  • Email the file link, not the file

Great advice on sending sensitive stuff via Dropbox . And pretty close to what I do. With this handful of paranoid additions involving chaos and automation:

  • Parent Folder. in your “~/Dropbox/Public” folder, create a new folder with a sensible name like, “seekritstuff”

  • James Bond Naming. Keep a sane name for the uncompressed source doc you’re sending (say, “2010_income.txt”), but rename the zipped version of that file with a random name

    • e.g., something like, “I8-H~*gY{4%u.zip”

    • TIP: 1password can generate a “password”-style string that makes a swell file name

    • Maybe an unnecessary step. But it does makes the file name way harder to just guess

  • Hazel help. Most Important. Create a Hazel rule for “~/Dropbox/Public/seekritstuff” that automatically moves any file it contains to a local/non-Dropbox folder on your Mac n days or hours after “Date Added”

    • Mine’s set to 36 hours, but your setting can be whatever suits you and your recipients
  • Two-steppin’. Yes, send your recipient the link to that zipped file (NOT the actual file)—but do so in a separate and obscure-looking email that makes no reference to either previous emails or the link’s contents.

    • Viz.

      SUBJECT: thing for you
      B—
      here’s that thing
      http://i-0.us/e4wQcw
      call or text me with questions

      /m

    • Even better still? Send that link to a different email address for that person, or TEXT them the URL

  • In general? Just never hurts to mix it up. All of it.

It’s a start.


Like anything that touches an open network—and most especially anything that touches email—it’s a solution that’s far from perfect. But, to my mind, it feels a little safer than crap like sending plaintext via email.

Seriously. My mind is boggled by how many people throw sensitive stuff around in email to complete strangers—the equivalent of writing a password on a postcard. Then pinning it to the corkboard in the laundromat. Insane.

    • #Dropbox
    • #security
  • 11 months ago
  • 122
  • Permalink
  • Share
    Tweet

122 Notes/ Hide

  1. wakamii liked this
  2. ankhora liked this
  3. spaneka liked this
  4. isnteverything liked this
  5. wakameeeeeeeeeee liked this
  6. wakameeeeeeeee liked this
  7. mysforucent reblogged this from amkelly
  8. wakameeeeee liked this
  9. largemunchkin liked this
  10. sang-crace reblogged this from amkelly
  11. alwillis liked this
  12. theoendless reblogged this from merlin
  13. theoendless liked this
  14. janlindblom liked this
  15. kikishe liked this
  16. dompascarella liked this
  17. fauxrealist liked this
  18. techdrops reblogged this from merlin and added:
    I already do in a similar way to this, but I think I’ll bypass the two-stepping, and I’ll manually do the Hazel trick...
  19. techdrops liked this
  20. thomascarrington reblogged this from merlin
  21. occasionallyuseful reblogged this from merlin
  22. djbender liked this
  23. djbender reblogged this from merlin
  24. tristececile liked this
  25. danielpietzsch liked this
  26. thisisdaniel liked this
  27. screamincolor liked this
  28. cstarrett liked this
  29. reasonaday liked this
  30. philipgirvan liked this
  31. csheader liked this
  32. schoetzau liked this
  33. nickslog liked this
  34. seven2521 liked this
  35. streakmachine liked this
  36. shaunandrews liked this
  37. icantgetanythingelse liked this
  38. ad7am liked this
  39. eudaemonist liked this
  40. threnn liked this
  41. webness reblogged this from merlin
  42. webness liked this
  43. andybold liked this
  44. poly915 reblogged this from merlin
  45. poly915 liked this
  46. tokanizar liked this
  47. joshbetz reblogged this from merlin
  48. pok liked this
  49. rushtheiceberg reblogged this from merlin
  50. andowrites liked this
  51. Show more notesLoading...
← Previous • Next →

About

Avatar

This is a personal weblog, or “blog,” by Merlin Mann

 

Ads Via The Deck

Me, Elsewhere

  • @hotdogsladies on Twitter
  • merlin on Vimeo
  • merlin on Flickr
  • merlinmann on Pinboard
  • RSS
  • Random
  • Archive
  • Mobile

Effector Theme by Carlo Franco.

Powered by Tumblr