Dropbox status: access issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Dropbox is a file hosting service operated by American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and client software.
Problems in the last 24 hours
The graph below depicts the number of Dropbox reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Dropbox. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Dropbox users through our website.
- Errors (75%)
- Website Down (25%)
Live Outage Map
The most recent Dropbox outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Errors | 24 days ago |
|
|
Website Down | 24 days ago |
|
|
Errors | 1 month ago |
|
|
Errors | 1 month ago |
|
|
Sign in | 3 months ago |
|
|
Errors | 4 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Dropbox Issues Reports
Latest outage, problems and issue reports in social media:
-
Mikemira (@storiesbyohama) reportedJust imagine getting accepted into the most exclusive startup club on earth… Then being told you have two weeks to find a complete stranger to as your partner. That’s exactly what happened to Drew Houston in 2007. He had the idea for Dropbox. He had a rough demo. @ycombinator liked it. But @paulg was clear... Single founders rarely make it. You need a co-founder. Right now. Drew’s friends couldn’t join. Time was running out. What would you do? He put out the word. A mutual friend connected him to a quiet MIT student named Arash Ferdowsi. They had never met. They sat down in the student center. Talked for about two hours. About code. About the problem. About the future. At the end of that conversation Arash said yes. He dropped out of MIT the next week with only one semester left. Two weeks later they walked into the YC interview together. They got in. The rest is history: a company that became worth billions. It looked reckless. It felt like a shotgun wedding. Yet it worked because both were all-in from the first conversation. I’ve studied hundreds of startups that never made it past the idea stage. Most founders wait too long for the “perfect” partner. They overthink chemistry. They protect their equity. They miss the window. You can’t wait for certainty. Sometimes the right co-founder is the person willing to jump with you before the proof exists. The speed of that decision can be the difference between staying a solo dreamer and building something real. What would you risk in two weeks if the right person walked in?
-
keeks is ready to be the worst man in amercia (@ultranormanmoon) reported@JonahAmericana NOT BOTH BUT IM SURE YOU CAN PIRATE THE FIRST ONE. I have the Dropbox link but I think they deleted it or something bc I have to login to find it and idk if that’s normal or not 😭
-
timelock (@hashtimelock) reported@BitPaine @Dropbox they got me. i noticed the "New Login from new location" email immediately and logged out of all the sessions. dont keep anything sensitive on there, thankfully
-
Ed Giansante (@edugiansante) reportedevery founder i talk to is hiring a head of community wrong. i've been that hire four times. Zynga, Wix, Dropbox, Persona. 15 years, three continents. every time the JD was wrong, the expectations were wrong, and the first 90 days were a mess until i rewrote them myself. the JD problem. most community job descriptions read like a social media manager with extra steps. "manage our Discord, post engagement content, track NPS." that tells me the founder thinks community is content moderation with a better title. a real head of community JD should say: build the infrastructure where customers trust each other enough to solve problems together, and connect that trust back to pipeline and retention. if the JD doesn't mention revenue or product feedback loops, you're hiring the wrong role. the first 90 days. at Dropbox i walked into 400M+ users and zero community infrastructure. no forums, no events, power users had no way to talk to the product team. days 1 to 30: listen. real conversations with 50 customers. find the 10 who love your product enough to evangelize it for free. those are your founding members. wrong. within 2 weeks we had an outage and I had to source folks who were talking about Dropbox in different spaces - dev forums, stackoverflow, spiceworks, hackernews and so on. I was honest enough to share what was going on, my role and where i needed their help. days 31 to 60: build the first room. not a Slack with 14 channels nobody uses. one focused format. at Persona it was a 15 person dinner for compliance leaders. at Wix it was a partner council of 80K agencies. start small, make it valuable enough that people tell their peers. days 61 to 90: prove the loop. connect a community interaction to a business outcome. a feature request that shipped. a deal that closed because a customer introduced a prospect. a churn save from a power user helping a frustrated customer. if your community hire can't show that loop by day 90, something is off. forget member count or engagement. track these: repeat attendance. show up rates. at my dinners, 90% of RSVPs show up. 99% return. pipeline influence. what happens post dinner that can be attributed to $$$? product feedback velocity. how fast does a community insight reach the product team and ship? NPS delta. at Wix, partner community members renewed at 2-3x the rate of non members. the biggest mistake is org charting community as a sub-group within a random team. community sits between product, marketing, sales, and customer success. it touches biz relationships, partnerships, revenue, retention, and product roadmap. treat it that way. hire someone who's built it before and give them a seat at the leadership table.
-
Abhishek Singh (@0xlelouch_) reportedAsked: design Dropbox-style file sync. 1) Clarify requirements - Devices: desktop + mobile, multiple per user - Semantics: eventual consistency, conflict handling, offline edits, rename/move - Scale targets: #files/user, max file size, p95 sync latency, bandwidth caps - Security: per-user auth, sharing model, at-rest + in-transit encryption 2) Core APIs + data model - UploadChunk(sessionId, part#, bytes), CommitUpload(sessionId, fileHash, path, mtime) - ListChanges(cursor) -> {ops}, Ack(cursor) - Download(path, version) with range support Tables: - File(id, ownerId, logicalPath, currentVersion, deleted) - Version(fileId, versionId, contentHash, size, createdAt) - Block(contentHash, refCount, location) - DeviceCursor(deviceId, lastSeq) - OpLog(seq, userId, type, path, fromPath, versionId) 3) Architecture - Client watcher computes hashes, does chunked upload to object store (S3/GCS) - Metadata service is the source of truth for paths, versions, ACLs - Change log per user (or per share) drives fanout to devices - Long-poll/WebSocket to push invalidations; client pulls deltas via cursor - Dedup by contentHash; store blocks, assemble manifests per version 4) Scaling - Partition metadata by userId; keep OpLog append-only with monotonically increasing seq - Cache hot metadata (folder listings, latest versions) in Redis - Use CDN for downloads; throttle uploads per device; resumable sessions - Background GC for unreferenced blocks using refCount + tombstones 5) Tradeoffs interviewers look for - Push vs pull: push invalidation, pull data is simpler and cheaper than pushing bytes - Strong vs eventual: strong per-file commit, eventual across devices is fine - Rename as metadata op; avoid copying data, but watch for path conflicts - Dedup saves storage, costs CPU and can leak info unless scoped per user/tenant 6) Failure cases - Offline edit + concurrent edit: create conflicted copy or keep both versions with merge UI - Out-of-order ops: apply by seq, idempotent commits, retry-safe APIs - Partial upload: orphaned chunks; TTL cleanup; commit is the only visibility point - Device clock skew: never trust mtime for ordering; server seq is ordering - Network *****: exponential backoff, cursor-based replay, checksums on download to detect corruption
-
David Simpkins (@DavidSimpkins88) reportedURGENT!!! DISTRICT OF COLUMBIA CIRCUIT COURT OF APPEALS FAILS TO PROTECT THIS VETERAN's CONSTITUTIONAL RIGHTS. MY HOME SECURITY SYSTEM AND PHONES HAVE BEEN TAKEN OVER AND I AM PREVENTED FROM SEEING ANYTHING OUTSIDE MY HOME BECAUSE OF THE CURRENT ACTIVE ATTACKS ON MY PHONES AND SECURITY SYSTEM IN DIRECT VIOLATION OF TN AND FEDERAL LAW AND NO ONE IS STOPPING THEM. LINK TO PETITION FOR WRIT OF MANDAMUS: I went to get the link from Dropbox and my Dropbox appears to have been wiped out. TO THE D.C. APPELLATE CIRCUIT COURT TO REQUEST AN IMMEDIATE RULING ON A TRO TO PROTECT THE APPELLANTS. This subject is about the District of Columbia Circuit Court of Appeals has not issued a standard Stay of Proceedings to the State of TN for their malicious prosecution. By not doing so, they have left this Veteran and his Wife open to criminal attacks by unlawful Law Enforcement of the State of TN. Further the Appellate Court has allowed non-stop violations of the Appellants home computer, cell phones, A/C Units, Security System and any all other WiFi devices. And to this day the illegal cameras placed in the Appellants home have never been removed after the Local Police Department notified this Appellant that there were hidden camera's in his home. Further, the FBI, DOJ, OIG, D.C. US Attorney's Office and especially the Appellate Court have all been notified of the targeting and 24/7 harassment by allegedly unlawful Agents of more than one of our Alphabet Agencies, to include the FBI and DISA. FBI Director Patel has to know about this situation but has done nothing to stop the corruption in the State of TN and has not protected this Veteran and his Wife. We made it clear that on the night of February 18th, 2026, that 5 people in Police Uniforms had keys to this Appellant's home and attempted to unlock the locks and enter the home both at the front door and at the Garage Pedestrian Door. They never once made any statements or comments nor explained why they were there. They did not show any warrants for arrest or search. When they knew they could not get in with out breaking things, they left approximately 15 minutes later. I had called my Wife and let her know. I am facing the same potential attacks again even though when the State of TN conceding by defaulting by not filing a response Brief. They were effectively agreeing that everything stated in the Appellant Brief was accurate and that they could not contest it. That makes all the acts committed by all Law enforcement Four-Hundred and Ninety-Seven (497) Constitutional Rights Violations are valid. Further, in order to access the Security System and the Display, they have to be within 350ft of our home. Because there is no WiFi or Bluetooth installed in the Security System or the Display. Which means they are in close proximity of this Appellants property. Three (3) Emergency Motions have been filed with the D.C. Appellate Court on three separate dates to no avail. The D.C. Appellate Circuit Court has failed to issue a TRO to Stay the TN State malicious prosecution. And left this Appellant, Veteran to suffer the vices and current active ongoing criminal activities by the State of TN against this Appellant as he types in this post. This could include a potential unlawful arrest and incarceration again because the D.C. Appellate Court has not issued a TRO or a Protective Order to Protect the Appellants. That in and of itself is a direct Constitutional Rights Violation now by the very Appellate Court who has allowed further criminal activities to promulgate even further to allow harm and injury. The corruption appears to be rampant in our US Court Systems.
-
Phillip Shoemaker (@pbsIdentity) reportedIndia just ordered hundreds of Google Firebase accounts shut down after authorities found scammers using the platform to impersonate major banks. At least 57 Firebase-hosted websites and databases were targeted for takedown this month alone. Some mimicked banks. Others distributed malicious Android apps. Some were designed to steal financial information from phones. Here's what I find interesting. Firebase isn't some shady hosting company operating out of a basement. It's Google infrastructure. That's exactly why criminals want it. We've spent years teaching people to look for obvious signs of scams. Weird domain. Broken English. Sketchy hosting. Browser warning. No HTTPS. But increasingly the attacker doesn't need to build suspicious-looking infrastructure. They borrow legitimate infrastructure. Google. Microsoft. Cloudflare. GitHub. Dropbox. Whatever gives the attack credibility and reliability. Now imagine the average person inspecting the link. They recognize Google. The connection is encrypted. The page loads perfectly. The certificate is valid. Everything their brain has been trained to interpret as: SAFE may technically be true. Except the person controlling the page is a criminal. That's an important distinction. HTTPS proves your connection to the website is encrypted. It does not prove the person operating the website is honest. A Google URL proves Google is providing infrastructure. It doesn't necessarily prove Google created the content you're looking at. The little padlock was never a morality detector. We just accidentally trained an entire generation to treat it like one. India says scammers have increasingly shifted toward Firebase because its legitimate development tools and database functionality make it useful infrastructure for fraudulent sites and apps.
-
Fraser (@iamfra5er) reportedTHIS GUY WANTED A PLACE TO STORE HIS PASSPORT WITHOUT DROPBOX READING IT so he built an encrypted vault app for himself in a weekend and it's now doing $5k/mo zero startup cost. 85% margins. no ads. just SEO written by an AI agent trained on his emails the agent finds trending topics on reddit every single day, writes an article, translates it, posts it google indexes it in days. 500-600 daily visitors. 4% convert to app store downloads. all running on free cloudflare then ASO does the rest — he translated the app into 36 languages and ranks #1 for "duress vault" in the US app store 80 downloads a day. 9% conversion to paid. completely autonomous most founders obsess over their first 10 customers but this guy got banned from every reddit community and said whatever, I'll just let the robot handle distribution he's an ex-google security engineer who raised hundreds of millions for his last startup so he knows what terrible UX looks like in security apps every competitor either has bulletproof security with unusable UI or easy UI with trash security he just combined both and called it done doesn't even spend time on this app. works on 4 projects at once. lets coding agents build while he plans the MVP is identical to the final product because he built exactly what he wanted for himself no pivot. no customer discovery calls. just "I need this, maybe 10 other people do too" now he's testing tiktok and youtube not even for this app but just to learn distribution for the next one
-
True Become False (@trubecomefalse) reported@imbabybrooklyn HN had a terrible track record. They were anyi bitcoin 1 month after it launched. Same with Dropbox, discord and a few others off the top of my head.
-
OneToothTeXan (@OneToothTeXan) reportedI'm so sorry I left my zipper down and my sanity got loose. If found: Men, there's a dropbox. Women: please return to original source.
-
Farmer henkenson (@FarmerJenkenson) reported@colemickens @Dropbox So if you had a lenovo account with a soecific emial, and a dropbox account had the same email, you could just login with lenovo and it would assume you own the dropbox account?? Insane
-
Phillip Shepard (@Phillip_shepard) reported@RobertJBye One thing I do on a daily basis - I have a skill that is called the “video analyzer skill” and I record a screen record with my iPhone and microphone one - I talk about all the issues I need fixed while showing it in video - send it via Claude mobile app - it runs the skill - transcribes and makes its self a html doc with the video frames that the issues exist in - then fixes the issues - builds a test flight and I update it - very useful… if the video is too big I send it via Dropbox which syncs to my Mac
-
Durodiyi (@durodiyi) reportedcompany’s server (like Google Drive or Dropbox), decentralized storage spreads your data across a network of computers worldwide. Platforms like IPFS and Filecoin make this possible.
-
kfd&p (@kfdpcom) reported@mellolais___ @LIBSCRUSHER @Dropbox I went on their site and it does say that the .com access is having issues. I guess we just wait it out.
-
Juan Pabro (@ironwoodreserve) reported@BitPaine @Dropbox Is now the worse time to try to login? I was a sent 2FN right as I was getting ready to click on what to use to login. It seemed way too fast for 2FN.
-
havenX (@the_havenx) reportedSecond time this exact thing has happened with Claude. ~100k ChatGPT chats were found the same way after users hit "shared." Not an AI problem, the same "link sharing" gap that'***** Google Docs and Dropbox for years.
-
Arthur Terrell Vaughn (@ArthurV36405381) reported@patmendoza6745 I know not of any of those specifications, but I still can’t figure out what the issue is with persistent memory, why can’t I just have a dropbox online that it can constantly access every single chat and conversation?
-
Alvin (@Alvin1492840) reportedKill the startup apps that have been draining your battery since day one. She opened System Settings → General → Login Items & Extensions. 14 apps were set to launch automatically every time he turned on his Mac. Spotify. Zoom. Adobe Creative Cloud. Google Drive. Microsoft Teams. OneDrive. Dropbox. A VPN he used once. A screenshot tool he forgot about. A calendar widget. And 4 more he didn't recognize. Every one of them was running in the background 24/7 consuming RAM, CPU cycles, and battery life whether he was using them or not. She said: "You turn on your Mac and within 30 seconds, 14 apps are fighting for resources before you've even opened your first document. Your fan spins up because your CPU is processing a traffic jam of apps you're not using. Your battery dies by 2pm because half your power is going to background processes you don't see." She removed 11 of the 14. Kept only the ones he actually needed at startup. The Mac booted in half the time. The fan stayed quiet. The battery lasted 3 extra hours. She said: "Check this list right now. If you see apps you don't use daily, remove them. They've been silently eating your Mac alive since the day you installed them."
-
Robert J Abalos (@robertjabalos) reportedWant Your Startup to Get VC Funded? You Must Meet All Six of These Requirements Venture capitalists at the seed stage bet on potential more than perfection, yet they demand specific proof points before writing a check. After reviewing hundreds of deals and data from PitchBook, Crunchbase, and leading funds, six absolute requirements stand out. Miss any and the odds of funding drop sharply. First, an exceptional founding team. Team quality remains the single highest weighted factor before product market fit solidifies. VCs look for domain expertise, prior execution, complementary skills, and coachability. Research shows roughly one in four two founder teams loses a co founder by year four, so investors scrutinize resilience and equity alignment. Companies with strong teams raise at higher valuations even with lighter metrics because execution can fix product or market gaps. Second, a large and expanding market. Seed investors require a total addressable market of at least one billion dollars, ideally several billion, with a clear path to one hundred million in annual revenue. Serviceable addressable market should support venture scale outcomes. Markets growing above twenty percent annually command premiums. Small markets cap upside and rarely produce the fund returning exits VCs need. Third, early traction proving customers care. For SaaS this often means ten thousand to one hundred thousand in monthly recurring revenue or three hundred thousand plus in annual recurring revenue. Pre revenue startups need strong engagement such as daily active users to monthly active users ratios above twenty percent, organic waitlists, or letters of intent from unaffiliated customers. Dropbox famously used a demo video that drove seventy five thousand sign ups overnight, unlocking its Sequoia seed. Slack showed early retention that later became legendary. Fourth, rapid and consistent growth. Seed VCs seek fifteen to twenty percent or higher month over month revenue or user growth sustained over multiple months. Absolute numbers matter less than trajectory. Startups posting twenty percent plus monthly recurring revenue growth have seen close rates near sixty five percent in analyzed pitch data. Flat or decelerating growth signals risk. Fifth, early unit economics and retention signals. Even at seed, investors examine lifetime value to customer acquisition cost ratios above two to one, ideally three to one, net revenue retention near or above one hundred percent, and cohort retention that flattens rather than collapses. Gross retention above eighty to ninety percent is a positive signal. These metrics prove the product delivers lasting value and that growth will not require endless capital. Sixth, capital efficiency and clear runway. Burn multiple and months of runway matter. Investors prefer teams that can stretch capital to eighteen months or more while showing improving efficiency. Median U.S. seed rounds now sit near three to four million dollars, yet graduation to Series A has tightened to roughly twenty to fifty percent depending on cohort and sector. Lean teams of four to eight people that still deliver results stand out. Data confirms the stakes. Only a minority of seed companies reach Series A, and failure rates near forty percent are common. Yet the power law rewards those that clear these bars. Airbnb, Stripe, and early Slack all combined strong teams, massive markets, and measurable early traction. Founders who quantify these six elements with real numbers, not projections, dramatically improve their chances of securing seed capital.
-
Mansi 👩💻 (@MansiCodez) reportedSolution of yesterday’s question: Design Google Photos: the part after the boxes “Hash it and put it in S3” fails the interview. Two phones compress the same sunset differently. Same photo. Two hashes. Two rows. You just built a worse Dropbox. The system needs three IDs, not one. client_upload_id — generated on the device before the first byte moves content_hash — hash of the exact bytes you received asset_id — the thing the user sees in the library Uploads are sessions. Library entries are assets. Blobs are renditions. If you collapse those into one key, retries, edits, and shared albums all collide. 1. Retries must be idempotent on the client, not on the filename Phone goes offline mid-flight with 612 shots, 40 already half-uploaded. Each photo gets a client_upload_id the moment it enters the queue. Chunks are uploaded against that ID. Commit is PUT /uploads/{id}/complete. Same ID + same bytes → same session. Server returns the existing asset. Late packet after commit is a no-op. Filename + timestamp is not an ID. Camera roll and AirDrop will mint two. 2. Exact dupes are content-addressed. Near-dupes are reconciled. After commit: look up sha256(bytes) if it already exists for that user (or the shared album’s owner set), attach the new upload to the existing asset_id do not create a second photo The 28 shared “Goa 2026” shots that are almost-but-not-quite the library copies will miss on sha256. That is expected. Run a cheap perceptual hash (pHash / dHash) + capture time + camera model from EXIF. If distance is tiny and captured within a few seconds, mark as near_duplicate_of and do not show two tiles. Keep both blobs if you must; hide one in the UI. Two devices, two compressions, one photo in the grid. 3. The library is a set of assets + tombstones. Not last-write-wins. Delete in Delhi must beat a pending upload in Mumbai. Every mutation carries: asset_id op: upsert | delete | restore actor_id (device or user) logical_ts (per-actor Lamport or hybrid logical clock) A deleted asset gets a tombstone that outlives the pending queue. When the flight-mode phone finally flushes those 40 half-uploads, the server sees: upload commit for an asset that already has a newer delete → commit the blob if you want, do not resurrect the tile. Refresh in Mumbai cannot show a photo Delhi just deleted, because the change feed is “tombstone wins over delayed create,” not “whoever wrote last.” 4. Shared albums are references, not copies Partner adds 28 photos to Goa 2026. The album stores {asset_id, added_by, added_ts} — not a second blob, not a second library row. Adds and removes are a small CRDT: add(asset, actor, ts) remove(asset, actor, ts) Two devices adding the same asset = one membership row. Phone sync finishing a second later cannot wipe the partner’s 28 photos, because there is no “replace the whole album document.” Last-write-wins on the album JSON is how photos vanish. 5. An edit is a new rendition, not a new photo and not an overwrite User crops + filters while the original is still processing. Rules: original blob is immutable edit creates rendition_id with parent_asset_id library still shows one asset “current view” pointer moves to the latest rendition history is a list of renditions / edit ops, not 12 full-resolution copies by default If you overwrite the original, face clustering and search lose their source. If you mint a new asset, the user now has original + edit as two photos. Both are wrong. Storage stays sane because you store: original (once) derived thumbs / display sizes lazily, keyed by asset_id + transform not every intermediate crop as a first-class photo 6. Upload path and ML path must not share a lock “Beach sunset with Priya” in minutes, not overnight, also not on the upload critical path. Commit path only: durable bytes asset row appear in library + album enqueue jobs Workers (thumbs, embeddings, face cluster, labels) are async. Search index is eventually consistent. The UI can show the photo immediately with “processing” on faces. If clustering blocks upload, you built a spinner, not Photos. Face identity hangs off asset_id, so an edit does not orphan Priya. The new rendition inherits the parent’s cluster and gets re-checked, not reset. 7. Sync is a checkpoint + change feed, not “download the library” Each device stores last_applied_ts. Server gives a stream: new assets, new renditions, album membership, tombstones. That is how 62,000 existing photos plus 612 offline shots plus 28 shared adds converge without a full rescan, and why a deleted photo does not climb out of another device’s queue. The one-line design Client-generated upload IDs stop retries from cloning. Content hashes stop exact clones. Perceptual reconcile stops “same sunset, different JPEG.” Tombstones stop resurrection. Album CRDTs stop last-write-wins from deleting the partner’s night. Edits are renditions under one asset. ML is a consumer of commit, never part of it. Boxes for S3, CDN, Kafka, Redis are table stakes. This is the part that decides whether you designed Google Photos or a photo-shaped file dump.
-
EFANI Secure Cellphone Service (@efani) reported🚨 Around 5,000 Dropbox accounts were accessed without authorization in August after attackers abused a weakness in the way Dropbox trusted Lenovo ID authentication. The attack did not require victims’ Dropbox passwords. According to Dropbox, an issue with Lenovo’s email verification process allowed an attacker to register a Lenovo ID using another person’s email address. Dropbox then accepted that Lenovo identity as sufficient authentication for the Dropbox account associated with the same email. Unauthorized access occurred between August 4 and August 21. Files were viewed or downloaded in fewer than a third of the affected accounts. The security problem here is bigger than one flawed login flow. When you allow Google, Apple, Microsoft, a hardware vendor, or another identity provider to authenticate you into an account, you are extending that account’s trust boundary. Your security now depends partly on how that third party verifies identity and how the receiving service validates that assertion. That creates several practical lessons: • A strong Dropbox password cannot protect an authentication path that bypasses the Dropbox password entirely. • Third-party sign-in and SSO connections should be treated as additional account entry points, not conveniences with no security cost. • Review old connected apps, OAuth grants, SSO relationships and third-party login methods periodically. Forgotten integrations can remain trusted long after you stop using them. • Enable MFA wherever possible. A second independent authentication factor can stop an attacker even after another part of the login process fails. • Sensitive cloud storage deserves extra scrutiny. Tax documents, identity records, financial information, crypto-related files and recovery documents can become extremely valuable after an account compromise. Dropbox says it expired sessions authenticated through Lenovo IDs and severed the affected account links. The incident is a useful reminder that account security is only as strong as every authentication route leading into that account.
-
Karishma Bhardwaj (@bkarishma360) reported@shahzamannn_ Your SaaS idea doesn’t need to be complicated. Stripe moves money. Postman sends API requests. Notion organizes information. Dropbox syncs files. The lesson? Simple problem + huge market + great execution = massive company. Stop asking, “Is my idea too simple?” Start asking, “How many people have this problem?”
-
Llama (@thellama451) reportedI tracked down these messages in @MaxMillerOH’s Dropbox files. They show the parents getting along with no major conflicts beforehand. If Miller said he was going to kill his ex-wife in front of child (likely), it shows a talent for masking rage and hostility.
-
Vladislav Zharkov 👾 (@_vladislavzh) reportedI have zero industry experience. None. I don't know how to use issue trackers, I need a GUI for version control, I deliver my files through Dropbox. I don't have templates, I restart or reuse every time. I don't use industry standard tools, I don't know workflows and pipelines.
-
Eric Taylor (@bcs_erictaylor) reportedReally?? Dropbox really needs a MCP server? CVE-2026-81102 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still reached the listener while carrying the attacker's host name. A page in a visitor's browser could therefore drive the local server and invoke its company-search and file-detail tools under the Dropbox credential the server holds. Only the network mode was reachable this way; the standard input mode was not. The fix supplies transport-security settings that enable host checking and allow only the loopback name and port, rejecting other hosts before a tool runs. The repository publishes no versions, so the affected boundary is the commit preceding the fix.
-
AiMind (@AIMind_Ai) reported3 websites replace 20 hours of googling when you build a home server. The hard part of self-hosting is not the hardware. A used HP EliteDesk and a wall-mounted NAS cost almost nothing. The hard part is not knowing what you can even run, or how to avoid breaking the system on the first command. The first keeps a catalogue of self-hosted alternatives. Look up a replacement for Google Photos, Dropbox, or Notion, and you see what already exists, how many GitHub stars it has, and whether it is still alive. Plus a weekly digest of what shipped. The second lets you run any Linux distro straight in the browser. Arch, Debian, Alpine, Bazzite. Click once, and you are inside a live system, with no evening lost to a USB stick and a real install. The third handles the worst part. Install scripts for Proxmox: Immich, Jellyfin, Vaultwarden, AdGuard, Nginx Proxy Manager. Paste one line into the console and the container comes up on its own. Immich shows 17,735 installs; Docker 36,408. Each of those services used to cost an evening of documentation and three Stack Overflow tabs. Now it is one command. The hardware takes an hour to buy. These 3 bookmarks save you a month. Names in the replies.
-
Dito (@morpiggg) reported@1password i miss the old dropbox with list of accounts to login instead of moving my mouse to to the top center of the page. how do i revert?
-
M.Ellis (@MEllisPhotograp) reported@DropboxSupport erm different wifi nope or is this a suggestion should it be possible ? if so then no my internet signal can be hit or miss at times but never had this issue before... Also shared a file earlier for someone near me to edit using ipad app but photos failed to appear on ipad ?
-
Luke Elin (@LukeElin) reported👤Shadow Adoption The pattern: Staff route around the sanctioned tool, and the organisation finds out afterwards. I watched this with unauthorised modems. Then with USB drives. Then with Dropbox. Then with entire SaaS platforms procured on a personal credit card and expensed as “software.” Now it is AI the same movie, new cast, better production values. The reason is always identical and always reasonable: the sanctioned tool is slower than the job requires. Shadow adoption is not an indiscipline problem. 👊 It is a feedback signal about the official tooling, arriving through the wrong channel. The tell: Compare the usage figures for your officially sanctioned tool against what your helpdesk volume implies people are actually doing. The gap is your shadow estate. FR FR
-
Olivia Jane. 🦇 🗡️ 🩸 (@livtheripper) reported@HazeOfBlue84 Haha, I get it! Thankfully someone here at the office set it up and all I had to do was re-sync Dropbox! I had no issues at all, so I'm thankful.