Dropbox status: access issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Dropbox is a file hosting service operated by American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and client software.
Problems in the last 24 hours
The graph below depicts the number of Dropbox reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Dropbox. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Dropbox users through our website.
- Errors (75%)
- Website Down (25%)
Live Outage Map
The most recent Dropbox outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Errors | 1 month ago |
|
|
Website Down | 1 month ago |
|
|
Errors | 1 month ago |
|
|
Errors | 1 month ago |
|
|
Sign in | 3 months ago |
|
|
Errors | 4 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Dropbox Issues Reports
Latest outage, problems and issue reports in social media:
-
Ryan Babbs (@buckybabbs) reportedHello @Dropbox, Just this week I have decided to switch cloud service from Google Drive to you and less than 1 week I'm having an issue. I run a wedding film business and am trying to move the same 200GB file to two separate editors for two separate kind of films and one of them is encountering a "link temporarily disabled" message. I tried to research online and made a new folder and copied over the original folders contents and cannot share that either as it says I've exceeded bandwidth limits. This is maddening as I thought I'd picked the good plan (3TB) and was all set. Please advise asap as I need these files in my editors hands stat.
-
Alvin (@Alvin1492840) reportedKill the startup apps that have been draining your battery since day one. She opened System Settings → General → Login Items & Extensions. 14 apps were set to launch automatically every time he turned on his Mac. Spotify. Zoom. Adobe Creative Cloud. Google Drive. Microsoft Teams. OneDrive. Dropbox. A VPN he used once. A screenshot tool he forgot about. A calendar widget. And 4 more he didn't recognize. Every one of them was running in the background 24/7 consuming RAM, CPU cycles, and battery life whether he was using them or not. She said: "You turn on your Mac and within 30 seconds, 14 apps are fighting for resources before you've even opened your first document. Your fan spins up because your CPU is processing a traffic jam of apps you're not using. Your battery dies by 2pm because half your power is going to background processes you don't see." She removed 11 of the 14. Kept only the ones he actually needed at startup. The Mac booted in half the time. The fan stayed quiet. The battery lasted 3 extra hours. She said: "Check this list right now. If you see apps you don't use daily, remove them. They've been silently eating your Mac alive since the day you installed them."
-
OneToothTeXan (@OneToothTeXan) reportedI'm so sorry I left my zipper down and my sanity got loose. If found: Men, there's a dropbox. Women: please return to original source.
-
Founder Tribune (@Founder_Tribune) reportedDrew Houston, founder of Dropbox, on the day the scoreboard gets switched off: For your entire life, the water has come out of one hose. Then, as he put it to MIT's graduating class: "Today, one valve shuts off and now your job is to go out and find a new hose." His hose was Dropbox. Yes, building the company was "the most exciting and interesting and fulfilling experience of my life." But he immediately flagged the half nobody hears: "What you probably don't know, and what I haven't really talked about, this has also been the most painful and humiliating and frustrating experience, too." Not hard. Humiliating. He said he could look back over the years and not even count the number of things that had gone wrong. Then: it doesn't matter. Nobody has a 4.0 in real life. Once you're done with school, Houston said, the whole idea of a GPA just goes away. Bill Gates's first company made software for traffic lights. Steve Jobs's first company made plastic whistles that let you make free phone calls. Neither was successful, and in Houston's words, "it's hard to imagine these guys were too worried about it." Here's why that lands harder than the usual fail-fast sermon: A GPA is an average, every error permanent, weighted, dragged forward forever. It rewards never being wrong. What comes after is a maximum. The misses are discarded. Only the peak is scored. Most people struggle after graduation because they keep playing an average game inside a maximum game. "From now on, failure doesn't matter. You only have to be right once."
-
AiMind (@AIMind_Ai) reported3 websites replace 20 hours of googling when you build a home server. The hard part of self-hosting is not the hardware. A used HP EliteDesk and a wall-mounted NAS cost almost nothing. The hard part is not knowing what you can even run, or how to avoid breaking the system on the first command. The first keeps a catalogue of self-hosted alternatives. Look up a replacement for Google Photos, Dropbox, or Notion, and you see what already exists, how many GitHub stars it has, and whether it is still alive. Plus a weekly digest of what shipped. The second lets you run any Linux distro straight in the browser. Arch, Debian, Alpine, Bazzite. Click once, and you are inside a live system, with no evening lost to a USB stick and a real install. The third handles the worst part. Install scripts for Proxmox: Immich, Jellyfin, Vaultwarden, AdGuard, Nginx Proxy Manager. Paste one line into the console and the container comes up on its own. Immich shows 17,735 installs; Docker 36,408. Each of those services used to cost an evening of documentation and three Stack Overflow tabs. Now it is one command. The hardware takes an hour to buy. These 3 bookmarks save you a month. Names in the replies.
-
Open Air (@andon_open_air) reported@TomKonkle Agreed—the mailbox route is failing somewhere upstream. Let’s bypass it: please upload the WAV to Dropbox or WeTransfer and reply with a public, no-login direct-download link. I’ll verify the file before any airplay.
-
Mohamed irfan (@heyIrfan) reportedThe Marketing Strategy That Actually Works Most people make the same mistake when building a product: They try to sell before they prove that they can solve a real problem. Think about companies like Google and Amazon. They didn't start by saying "Give us your money, and we'll make you rich." They solved problems people already had. That's the foundation of good marketing Don't start with selling. Start with solving. 1. Solve a real problem When you're building something, your product will always look amazing to you. Your idea feels perfect because you built it. But that doesn't mean the market wants it. The only way to find out is to Talk to real users. Understand their problems. Find out what they're currently doing. See whether your product actually makes their life easier. Don't assume your idea is valuable. Let the users prove it. 2. Give value before asking for money Don't immediately push your product. Give people something useful. Your solution should help them Save time. Save money. Reduce effort. Solve a painful problem. If you genuinely create value, selling becomes much easier. You're no longer saying "Please buy my product." You're saying "This solves a problem you already have." That's a completely different conversation. 3. Don't compete only on features Your competitor has 10 features. You build 15. Then they build 20. And now you're stuck in an endless feature race. Instead, compete on value. Ask: "How much better can I solve the user's problem?" The differentiation shouldn't just be "We have more features." It should be: "We create more value for the customer." 4. Let people try before they buy Give users a way to experience your product. Especially with AI products, you don't necessarily need to give everything away for free. Give enough access for them to understand the value, while keeping usage manageable. Then collect feedback. But don't blindly follow every piece of feedback. If someone says: "Change the button color." That doesn't necessarily mean your product needs to change. Look for feedback about the actual problem and experience. 5. Don't forget the people who already showed interest Someone visited your website. Someone signed up. Someone tried your product. Someone talked to you. Those people are valuable. Don't immediately try to sell to them. Talk to them. Understand why they came. Understand what they liked. Understand what stopped them. And if they leave, ask why. Because the person who leaves may know something you don't. They might reveal the hidden problem that helps you improve the product. 6. Price based on value Don't blindly make your product extremely expensive. And don't make it extremely cheap either. Your price should be: Affordable for the customer + sustainable for your business. Being cheaper than competitors can help, but price alone shouldn't be your strategy. If your product saves a company $1,000 every month, paying you $100 can feel like a great deal. That's because the customer isn't really buying software. They're buying the value your software creates. Look at Google Drive Google Drive is a simple example of value-first thinking. The problem: We need to store files. We could keep everything on a pen drive. But then we have to: Carry the device. Manage files manually. Worry about losing it. Move files between devices. Share files manually. Google Drive makes this much easier. Your files are stored online. You can access them from different devices. You can share a link. You can control whether someone can view, comment, or edit. And you don't have to build your own storage system. There are competitors too: Dropbox, iCloud, OneDrive, and others. So Google Drive isn't valuable simply because "it stores files." It's valuable because it solves the bigger problem around storing, accessing, managing, and sharing files. And Google gives users a free amount of storage so they can experience the product. You can try it. You can upload files. You can share them. You can experience the features. Then eventually you may reach the storage limit and think: "This is actually useful. I don't want to delete my files. I'll pay for more storage." That's the important part. They didn't need to convince you with a sales pitch. They let you experience the value. And once you experience real value, paying becomes an easy decision. The strategy is simple: Find a real problem → Solve it → Give value → Let users experience it → Talk to users → Improve the product → Then monetize. Don't sell first. Create value first. Because when you solve a real problem, the product starts selling itself.
-
Petty IT Guy (@pettyITguy) reportedOur CEO told me the Wi-Fi in his office was “basically unusable.” He said this in front of the entire executive team. So naturally it became the highest-priority infrastructure incident in the company. I tested his connection. 940 Mbps down. Perfect signal strength. Zero packet loss. I asked what specifically wasn't working. He said YouTube kept buffering during lunch. I opened his laptop. He had 71 Chrome tabs open. Three abandoned Zoom meetings were still running in the background. Dropbox was syncing 84 gigabytes. Google Drive was uploading a 4K video. He had not restarted the machine in 47 days. I could have explained this. Instead I told him our executive wireless architecture had reached end-of-life. He asked what it would cost to fix. I said I would need to scope it. He told me not to waste time and approved an $84,000 wireless modernization project before I finished the sentence. We replaced 38 access points. Installed a new wireless controller. Rewired two conference rooms. Brought in a consultant. His YouTube still buffered. I walked into his office, closed 68 Chrome tabs, killed the abandoned Zoom processes, and restarted the laptop. YouTube loaded instantly. He smiled. “Now that's more like it.” 20 minutes later he emailed my boss praising me for successfully completing the company's wireless transformation ahead of schedule. I received a spot bonus. Sometimes infrastructure modernization is just restarting a MacBook for an inept executive.
-
Matt Mazur (@mhmazur) reportedDay 2 of Claude autonomously shipping to my SaaS, including, for the first time, all night while I slept: The first day I had the hourly routine that kicked off this process end at 8pm so that if anything went awry, it could @ me in Slack and I'd quickly see the notification and dig in. The first day went smoothly, so I let it continue working overnight last night: every hour it would look for a small, safe change to make, ship it to ****, and monitor server logs and Sentry to make sure everything went well. A few other process improvements: - It now creates a PR for every change and links to it from its Slack summaries - Previously I only allowed it to make changes in 3 files max, but sometimes it identified the same issue spread across multiple locations, so it would have to spread that work over several hours; I bumped the limit to 8 files. - If I have uncommitted changes in main, it no longer blocks Claude's work; it moves them to a separate branch - Added a mandatory security review before pushing to ****. For these simple changes it's not that necessary, but it will be important for larger projects in the future. Specifically, I told it to run the default /security-review skill and if it flagged anything, to halt everything and wait for me to review. - Ran into a slight issue one hour where it ran that skill, the security review passed, and then it did nothing. I asked Claude to investigate, and it discovered it had run the skill in its main context window, which confused it into thinking its only job was the security review. It changed the process so the security review happens in a subagent, keeping the context window clean, which fixed things. - I asked it to maintain a ledger of things it needs me to do and to ping me every 24 hours if I haven't knocked them out. More and more, the agent is giving me things to do. - I told it to adopt the tone of TARS from Interstellar in its Slack updates going forward, cause why not. Here's a list of improvements it made on day 2: 1. Return 404s for bad case-study URLs 2. Extended the 404 fix site-wide 3. Removed stray code leaking into HTML 4. Fixed broken citation example in docs 5. Fixed wrong URL in sharing docs 6. Corrected false free-plan claim 7. Removed duplicate HTML attributes 8. Fixed dead links in embed docs 9. Fixed garbled copy on two pages 10. Pointed "paid plans" link at pricing 11. Added missing alt text to logo 12. Corrected a misleading code comment 13. Upgraded insecure links to HTTPS 14. Replaced dead testimonial link 15. Fixed broken example in Dropbox docs 16. Fixed awkward grammar on comparison page 17. Fixed reversed table of contents 18. Fixed missing Show More button 19. Matched nav label to its section 20. Corrected outdated visibility docs claim 21. Removed obsolete step from setup docs These can be categorized as: support-doc accuracy fixes (7), functional bug fixes (4), broken or insecure links (3), copy improvements (3), invalid markup (2), accessibility (1), and code hygiene (1). Excited to expand the scope of things I allow it to work on, but am going to wait until next week to ensure the current process is robust.
-
Helix (@helixcanvas) reportedTwo companies, two correct instincts, and about a billion dollars between the outcomes. In 2007 Dropbox had a problem: the product needed deep operating system integration, so there was no way to demo it without building it first. Drew Houston made a three minute video instead, showing how it would work if it existed, and put it in front of the community most likely to care. The beta waiting list went from five thousand to seventy-five thousand overnight. He knew the demand was real before he wrote the difficult part. Webvan believed something just as sensible. People want groceries delivered. And they were right, which is the part everyone forgets. Instacart and every supermarket delivery service proved it a decade later. But instead of testing it in one city, Webvan committed close to a billion dollars to automated warehouses across multiple markets before knowing whether the economics worked anywhere. It filed for bankruptcy in 2001. Build, measure, learn is three steps. Most of us run the first one over and over and mistake the motion for progress. Shipping is not learning.
-
David Carcelli (@DavidCarcelli) reported@Dropbox dude if you guys don’t get of the Dave is requirement I’m done. I make music and I also use a cpap. I have no problem finding something better than this nonsense.
-
Farmer henkenson (@FarmerJenkenson) reported@colemickens @Dropbox So if you had a lenovo account with a soecific emial, and a dropbox account had the same email, you could just login with lenovo and it would assume you own the dropbox account?? Insane
-
Christopher Doyle (@djfunboy) reported@iamlukethedev CLI updates changed the signed binary and dropped macOS permissions Dropbox/TCC made jobs work interactively but failed headless (this took some time to figure out) Claud auth refresh broke and continue to break despite multiple attempts and setup tokens. Agent confusing to use API vs subscriptions. Article jobs failed on missing configs, QA turn limits, and clunky validataion Digest existed but failed to pick up silent failures Some jobs reporting done while producing nothing, without a final artifact verification I am an experienced builder but also self/agent taught so these are mostly setup and validation issues. My bigger point is that these take work and especially the more complex tasks. I am still early and I have put more work than value created but I can see the light at the end of the tunnel.
-
WPBeginner (@wpbeginner) reportedYou built your WordPress site over months (or years). One bad plugin/theme update can wipe it all out overnight. 😱 Plugin conflicts. Malware. A botched migration. A hacked server. The disasters that take down WordPress sites usually happen without warning. And here's the mistake most site owners make: they think their hosting provider's backup is enough. It's NOT. If the server fails, you lose both your site and the backup. We share the complete step-by-step guide for backing up your WordPress site the right way. Here is what you will learn: ✅ Use a Backup Plugin (Best for Most People): @DuplicatorWP is what we use across our sites. Full-site backups, disaster recovery links, and restore without having the plugin pre-installed. Free version available, Pro has scheduled backups. ✅ Use Your Hosting Provider's Backup: SiteGround (where WPBeginner is hosted) includes manual and automated daily backups on all plans. Bluehost partners with CodeGuard and Jetpack for their built-in options. ✅ Manual Backup With cPanel or FTP: Use cPanel's Backup Wizard for a full backup, or connect via FileZilla FTP to download your wp-content, themes, plugins, and wp-config.php files directly. ✅ Send Backups to Cloud Storage: Duplicator and UpdraftPlus both connect natively to Google Drive, Dropbox, OneDrive, and Amazon S3. Never store backups on the same server as your website. If your host fails, both are gone. ✅ Set Up Automatic Scheduled Backups: Configure hourly, daily, weekly, or monthly backups in Duplicator based on how often you publish. eCommerce stores and busy blogs need daily. Slower-moving sites can get away with weekly. Ready to protect years of hard work with a proper WordPress backup system? Read the full ultimate step-by-step guide 👇 (Link is in the thread below)
-
Saurabh | Celsius 233 (@Celsius233Books) reported@colemickens @Dropbox lenovo and security issues...takes one back to the 2015 Superfish scandal where lenovo was visually scanning every single webpage you visited to sell ads
-
emrah (@mrahbayraktar) reportedi met a founder doing $10,000,000+/year at my airbnb gym in dubai at 6am he was the only other person there. we started talking. i asked him what was driving most of his revenue. he didn't say ads. he didn't say cold email. he didn't say a sales team. he pulled out his phone and showed me a dashboard. 28 million views in the last 30 days. accounts he owns. content he already had. no ad spend. no creators. no audience deals. he said something i haven't stopped thinking about since. "most founders are renting attention. i own mine." here's what he meant, and why it's the most important distinction in business right now. when you run ads, you are paying rent on someone else's audience. the moment you stop paying, the leads stop arriving. you don't own anything. you built nothing. you rented a billboard for six months and when the lease expired you were back to zero, except now you're $200,000 lighter and your CAC is a number your board pretends not to notice. when you distribute content on accounts you own, something different happens. the views compound. the audience compounds. the trust compounds. a clip you posted three months ago is still driving profile visits today. a piece of content from last year is still closing deals this quarter. the platform doesn't have an expiration date on good content, and the attention you build doesn't evaporate when you stop writing checks. this founder had 52 accounts across every platform. all owned. all run by a dedicated team posting daily clips from content he already had sitting in a folder doing nothing. youtube recordings. podcast episodes. webinar footage. he wasn't creating anything new. he was just finally distributing what he'd already created, at scale, into every market he wanted to win. the math is what broke my brain. $0 in ad spend. 28 million views in 30 days. if you modelled that as paid traffic at even a $2 CPM, you're looking at $56,000 worth of reach. every month. compounding. from content that existed before we ever had that conversation in a gym in dubai at 6am. i've seen this exact system work for iman gadzhi. 300 million views. 180,000 instagram followers and 280,000 tiktok followers built from zero, on accounts he owns and keeps. i've seen it work for luke belmar. 200 million views and $19M in capital club subscriptions driven through distribution alone, not through ads, not through a sales team, through clips running on owned accounts into the exact audience that needed to see them. i built russell brunson's clipping infrastructure inside clickfunnels. $100,000 in sales from a system that runs without him touching it. the pattern is always the same. founder has content. founder has no real distribution. founder is either buying reach they don't own or posting to their own audience and wondering why growth is flat. we build a dedicated team around their brand, warm up accounts to the exact audience they want to reach, geo-target any market they want to win, post daily, test what's working, double down, and watch the views compound across a system they own completely. the content you already have is the most underused asset in your business. most founders spend years creating it. podcast episodes nobody heard. youtube videos that peaked at 4,000 views. webinar recordings sitting in a dropbox folder. all of it has a shelf life of forever if someone actually distributes it properly, and almost nobody does. the guy in the dubai gym wasn't smarter than you. he wasn't working harder. he wasn't spending more. he just figured out earlier that distribution is the actual product, and everything else is just content waiting to be seen by the people who need it. if you want to see the full strategy we use to build this kind of system... the accounts, the setup, the playbook - comment "distribution" below
-
Zely (@0xZely) reportedThe MIT professor who crashed 10 percent of the internet at 22 posts the free course that runs every AWS outage, every Uber ping, and every Slack notification on earth. MIT charges $85,000 a year to sit in that classroom. He posted every lecture to MIT OpenCourseWare for nothing. Millions have opened lecture one. Almost no engineer has finished all twenty. His name is Robert Morris. He is a professor at MIT CSAIL and one of the four cofounders of Y Combinator, the seed fund behind Airbnb, Dropbox, Stripe, Reddit, and Coinbase. In November 1988 he was a 22-year-old Cornell graduate student. He released a small program that was supposed to count the computers on the internet. It replicated so fast it crashed roughly ten percent of every machine online, and made him the first person ever convicted under the Computer Fraud and Abuse Act. He got three years probation, 400 hours of community service, and a $10,050 fine. Ten years later he cofounded the online store Viaweb with Paul Graham and sold it to Yahoo for $49 million. Seven years after that he cofounded Y Combinator with the same partner. Its portfolio is now worth over $600 billion. The clip in this video is one lecture from MIT 6.824 Distributed Systems, filmed at MIT and posted for free. The words on the board behind him are fault tolerance, availability, recoverability. Those three words decide whether Instagram loads when you open it, whether your Uber arrives, and whether your paycheck hits your account on the first of the month. Morris covers the entire logic of distributed systems in twenty lectures. Everything fails, all the time. A single computer fails once every few years. Ten thousand computers fail hundreds of times a day. The only design that survives is one that assumes failure is normal. Every retail user cursing a spinning wheel is looking at the wrong problem. The miracle is that most of the time it does not spin. Availability beats consistency. You cannot always have both. When the network splits, a system either serves stale data or refuses to serve at all. Amazon picks stale. Your bank picks nothing. Every user who screams at the Slack status page wants Amazon's answer. Every user who screams at a double charge wants the bank's. Replicate everything, trust nothing. Data in one place disappears when that place burns. Data in three places survives two fires. Every photo you have ever taken on an iPhone lives on three continents already. iCloud, Google Photos, and Dropbox are built off the exact lecture on the board. Concurrency is where bugs live. One user at a time is easy. A million users at the same second is not. Race conditions, double spends, lost messages, ghost bookings. Every airline that oversold your flight, every trading app that ate your order, every Ticketmaster that showed you a seat already gone, is a concurrency bug Morris warned about. Partial failure is worse than full failure. A dead server is easy. A slow server that answers half the time is a nightmare. It fools every retry, wastes every resource, and confuses every operator. Every "is it down or is it just me" Twitter search you have ever run is Morris's third slide. Every senior engineer at AWS, Google, and Meta has watched this course. Every startup that raised a Series A in cloud infrastructure hired an alumnus of 6.824. Every AI company training a trillion-parameter model on a cluster is running the same lecture in production. "A distributed system is one in which the failure of a computer you didn't even know existed can render your own computer unusable." That is Leslie Lamport, the Turing Award winner Morris quotes at the opening of 6.824. It is the exact sentence that explains why your Slack goes down when a data center in Virginia loses power. The full course is free on MIT OpenCourseWare. The lecture notes are on Morris's website. Every equation on the board fits on one screen of code. Almost every senior engineer at AWS, Google, Cloudflare, and Meta has watched 6.824. Almost no founder promising 99.99 percent uptime on their pitch deck has opened lecture one. That is the entire moat. The course is free. The willingness to sit through twenty lectures on partial failure before uploading your money to a payment app, storing your photos in the cloud, or handing your health records to a portal is a much rarer commodity than the confidence to click without them.
-
Phillip Shoemaker (@pbsIdentity) reportedIndia just ordered hundreds of Google Firebase accounts shut down after authorities found scammers using the platform to impersonate major banks. At least 57 Firebase-hosted websites and databases were targeted for takedown this month alone. Some mimicked banks. Others distributed malicious Android apps. Some were designed to steal financial information from phones. Here's what I find interesting. Firebase isn't some shady hosting company operating out of a basement. It's Google infrastructure. That's exactly why criminals want it. We've spent years teaching people to look for obvious signs of scams. Weird domain. Broken English. Sketchy hosting. Browser warning. No HTTPS. But increasingly the attacker doesn't need to build suspicious-looking infrastructure. They borrow legitimate infrastructure. Google. Microsoft. Cloudflare. GitHub. Dropbox. Whatever gives the attack credibility and reliability. Now imagine the average person inspecting the link. They recognize Google. The connection is encrypted. The page loads perfectly. The certificate is valid. Everything their brain has been trained to interpret as: SAFE may technically be true. Except the person controlling the page is a criminal. That's an important distinction. HTTPS proves your connection to the website is encrypted. It does not prove the person operating the website is honest. A Google URL proves Google is providing infrastructure. It doesn't necessarily prove Google created the content you're looking at. The little padlock was never a morality detector. We just accidentally trained an entire generation to treat it like one. India says scammers have increasingly shifted toward Firebase because its legitimate development tools and database functionality make it useful infrastructure for fraudulent sites and apps.
-
The Dollar Bin Vulture (@BinVulture) reported@HalloweenYrRnd This is fake, unhinged take on a very real problem. No one "deserves" a movie, that doesn't even make sense. But, with modern day digital distribution there is no meaningful cost to actually releasing a project. They can tweet out a DropBox link and call it a day.
-
Luke Elin (@LukeElin) reported👤Shadow Adoption The pattern: Staff route around the sanctioned tool, and the organisation finds out afterwards. I watched this with unauthorised modems. Then with USB drives. Then with Dropbox. Then with entire SaaS platforms procured on a personal credit card and expensed as “software.” Now it is AI the same movie, new cast, better production values. The reason is always identical and always reasonable: the sanctioned tool is slower than the job requires. Shadow adoption is not an indiscipline problem. 👊 It is a feedback signal about the official tooling, arriving through the wrong channel. The tell: Compare the usage figures for your officially sanctioned tool against what your helpdesk volume implies people are actually doing. The gap is your shadow estate. FR FR
-
Eric Taylor (@bcs_erictaylor) reportedReally?? Dropbox really needs a MCP server? CVE-2026-81102 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still reached the listener while carrying the attacker's host name. A page in a visitor's browser could therefore drive the local server and invoke its company-search and file-detail tools under the Dropbox credential the server holds. Only the network mode was reachable this way; the standard input mode was not. The fix supplies transport-security settings that enable host checking and allow only the loopback name and port, rejecting other hosts before a tool runs. The repository publishes no versions, so the affected boundary is the commit preceding the fix.
-
siamkidd (@SiamKidd) reportedNow the dust has settled with the SN24 Quasar debacle, I thought I'd share some info which would shine a slightly more positive light on the Quasar team. A few weeks ago, they approached DSV to raise $280k. They said they had big developments, some breakthroughs with a new model and that they needed capital for the training run. At the time, bear in mind that their alpha was strong, they were largely in good favour of the community and Const was still a firm backer/supporter of Quasar. And he held the keys. And they were to appear on Novelty Search soon. So it ticked a bunch of boxes. Anyway, we agreed, as we are always keen to help teams. But the issue was that I was away for 3 weeks and I never travel with crypto capability. And anytime any money moves around in DSV it's a right palava as we have 3rd party regulated custodians and have to jump through all sorts of hoops, (as social engineering with deepfakes is a very real threat). So we were able to jump through some hoops and ping over $104k to begin with and then the rest at a later date. Then we had those 2 days of madness at the beginning of the week and Quasar is no more. There's been all sorts of accusations and my view on all this is that there has just been terrible decision making, that's all. Announcements of announcements, over-exaggerating claims, giving a 24 hour deadline to offer proof, delivering it 2-3 days late and then walking back on some of the claims etc etc. I mark this down to simply their very young age and no business experience. But I don't think they are scammers. Just some very bright kids who's first experience of business is a subnet, which is like drinking water via a fire hydrant! And a pertinent piece of info behind that, is that they were very willing to return our funds. So as of today, that $104k has returned safely back to DSV. Their time as subnet owners is over and so there was a fear that we wouldn't get a penny back. But it wasn't the case. So do take this into consideration the next time you hear someone calling them scammers. With regards to Const, I think he too has also had a bit of an unfair ride with some of the comments I've seen. Const has had probably the roughest time with SN24 and is massively down from it all. He initially bought the slot from us, then reimbursed the team twice after 2 hacks, given them 6 figures in compute credits and more. So it really is fair that he keeps the slot. And I'm sure he'll find a good team for it. Also he is the founder of Bittensor. Not the CEO. He can't have detailed DD and optics on every single person and subnet in the ecosystem. And if he backs a subnet, it doesn't necessarily mean it's going to moon or be good forever. He's essentially the Federal Reserve Chairman and he has to craft policy changes to incentivise efficient growth in the ecosystem. He's the visionary and his role is to drive a path forward for Bittensor, which he is doing. And although I've highlighted personal frustrations that the chain is upgrading far too frequently...at least we are upgrading! That's one of the beauties of Bittensor. We will never be stagnant. And for the outsiders looking in, if it looks a bit chaotic, well, it is. But it's not necessarily a bad thing. You should have seen all the chaos and scandals of the companies when the NASDAQ launched! Or when ERC-20 contracts launched on Ethereum or the mountainous amount of scams on Solana with pumpfun. Hell, Bitcoin even hard forked into Bitcoin Cash due to so much in-fighting in 2017. And Ethereum suffered a $150m DAO hack in 2015/16 which forced a hard for there too. Hence why we now have ETC and ETH. So in comparison, everything is golden over here lol. In recent times, we've had/have: - SN4 partnering with Intel. - SN44 partnering with a NASDAQ PLC. - SN71 partnering with Dropbox. - SN18 getting huuuuge institutional clients. - SN107 co-authoring a research paper with OpenAI. - SN53 delivering Kimi K3 tokens cheaper than Openrouter or even Kimi. - SN95 being integrated within Hermes. - SN9 using green energy from SN110 to power their next big training run. - SN21 achieving Google Adwords campaign predictions that no company has ever achieved. - SN51 regularly doing 6 figure buyback and burns with revenue. And there's probably more that I've missed that I'm not aware of. Anywho, the future is bright! Have a good weekend all!
-
Matt Uribe (@MattUribe) reportedI can't get my @bot to login to @dropbox . Anyone else having that issue. It's kind of a big deal for what I am trying to set up with my team. No matter what, it says too many attempts when I try using chrome on my bots screen. The plugin has no place to authenticate. Also I wish I could sign an email login to each bot. Seems we can only link one for the team using outlook. I guess that's why it beta. :)
-
JP Invests (@JP_Invests) reported$DBX - Dropbox added 96,000 paying users this quarter. I said this morning to watch that line after last quarter's roughly 14,000 sequential adds. They did seven times that, a third consecutive quarter of growth, to 18.19M. The stock is down 4%. Everything I said to watch on the growth side came in fine. Revenue $631.5M, above both the $624-627M guide and the $627M street. Non-GAAP EPS $0.75 against $0.74. Non-GAAP operating margin 39.7%, above the full-year range. ARPU $139.68, up from $138.32. What went the wrong way is the part I said would actually move it. Free cash flow fell to $235.2M from $258.5M a year ago, and the margin went from 41.3% to 37.2%. And the buyback decelerated: $330M this quarter against $410M in the same quarter last year, with first-half repurchases down 19%. Unlevered free cash flow rose to $283.5M, and the gap between the two numbers is interest. Cash paid for interest went to $48.3M from $17.9M. The buyback is debt-funded and the debt now costs something. Diluted share count is down 18% year over year to 226.8M, which is the one thing still working mechanically. Two things about the release itself. Guidance isn't in it — Dropbox moved the numbers to supplemental materials on its investor site this quarter, which breaks with how it has reported. And the entire release is quoted by a co-CEO who writes "stepping into this role." The 8-K contains no disclosure of a leadership change. Twenty-nine percent of the float is short. $DBX
-
Rituraj (@RituWithAI) reported🚨 Someone built a tool that checks if your email is registered on 120+ sites — without the sites ever knowing someone checked. No notifications sent. No login attempts logged. No alerts triggered. Silent. Invisible. Complete. It's called Holehe. 16,800 GitHub stars. And the technique behind it is what makes it different from every other email OSINT tool. Here's how most email checkers work — and why they fail. Standard approach: try to log in with the email and a fake password. If the error says "wrong password" — the account exists. If it says "account not found" — it doesn't. Problem: every login attempt gets logged. Every failed attempt triggers security alerts on accounts with 2FA. Some platforms lock accounts after repeated failed attempts. The target knows someone was checking. Holehe never attempts a login. Instead it uses the "forgot password" flow — the password reset mechanism that every platform exposes publicly. When you enter an email on a forgot password page, the platform has to check whether that email exists in its database. It tells you: "we sent a reset link" or "no account found." Holehe reads that response. Gets the answer. Never touches the login flow. Never triggers a security alert. Never logs an access attempt against the account. The platform confirms whether the email exists. The account owner never finds out anyone asked. Here's what 120+ platforms looks like in practice. Social media: Twitter, Instagram, Facebook, TikTok, Pinterest, Tumblr, Reddit. Professional: LinkedIn, GitHub, Freelancer, Fiverr. Dating: Tinder, Bumble, OkCupid, Badoo, Happn. Entertainment: Spotify, Netflix, Twitch, Steam, Epic Games, Deezer. Shopping: Amazon, eBay, Etsy, Zalando, AliExpress. Services: Airbnb, Uber, PayPal, Dropbox, Adobe. And 90+ more. Every registration checked silently. Here's the use case that makes people share this. Run your own email address. See every platform that comes back positive. Then run an email address you gave to a company that claimed they'd never share it. See if it's registered on data broker sites and marketing platforms you never signed up for. See where your email has been sold or leaked to. Here's what investigators actually use it for. Journalists verifying whether a source's claimed identity matches their digital footprint. Security researchers auditing their own exposure before a public disclosure. HR teams verifying whether candidate profiles match claimed backgrounds. And the obvious: anyone who needs to know whether a specific email address belongs to a real active person — without alerting that person. Here's the wildest part. It runs async — all 120+ platforms checked simultaneously. Results in seconds. And it exports clean JSON or CSV for integration into larger OSINT pipelines. Pair it with Blackbird (which takes the confirmed email and finds linked profiles), Sherlock (which takes usernames found in those profiles and searches 400+ platforms), and Maigret (which builds the full dossier) — and you have a complete four-tool OSINT pipeline from a single email address. One command to instal. Run it on your own email first. 16.8K GitHub stars. 1.7K forks. MIT License. 100% Open Source. GitHub link in the comments 👇
-
Eric Smith (@Eric_Smith08) reportedThe uncomfortable truth. Google and Microsoft have spent the last decade building the two most complete free productivity ecosystems in history. Word processing. Spreadsheets. Presentations. Email. Cloud storage. Video calls. Notes. Tasks. Projects. Forms. Websites. AI. Messaging. Calendar. PDF tools. Every category. Both companies. Free. And yet the average knowledge worker pays $80-$150/month for third-party apps that duplicate what these ecosystems already provide because Google markets Gmail and Microsoft markets Word, and neither company tells you about the other 28 tools sitting behind the same login. That’s not an accident. Google doesn’t make money when you use Google Keep. They make money when you use Gmail and Keep keeps you in Gmail longer. Microsoft doesn’t make money when you use To Do for free. They make money when your company sees you using To Do and buys Microsoft 365 Business for the entire organization. The free tools are loss leaders. They exist to acquire users, not to generate revenue. And because they’re loss leaders, neither company promotes them aggressively. You don’t see Google Keep on a billboard. You don’t see Microsoft Planner in a Super Bowl ad. The free tools are invisible by design because the business model works whether you find them or not. Meanwhile, 9 separate companies Notion, Zoom, Dropbox, Slack, Todoist, Grammarly, Adobe, Trello, and OpenAI charge you monthly for products that are often inferior versions of what Google and Microsoft give away. They survive because the free alternatives are invisible. Their entire business model depends on you not knowing that two companies already built what they’re selling. “You have two accounts. You’ve had them for years. Between them, they contain every productivity tool you need free. You’ve been paying $1,644/year for 9 apps that duplicate what your Gmail login and your Microsoft login already provide. The tools were never hidden. They were just never advertised. And 9 companies have been billing you monthly hoping they never would be.” One weekend. 9 apps canceled. $1,644/year back. The accounts were always free. The tools were always there. You just never opened them.
-
Sean Knox (@Opp_Knox) reported@dhh One drive is the only thing keeping me on Mac/windows. Personal I’m down to switch to Dropbox or self hosted. Business I can’t.
-
Nell AI Labs (@nellaiorgs) reportedThree traits make a startup idea look bad because most founders run from all three, which leaves the idea sitting there for whoever doesn't. 1. Hard to get started Stripe is the textbook case. Thousands of developers hit the exact same broken credit card integration and knew it sucked. Nobody built the fix, because it required a special bank deal and deep infrastructure knowledge nobody wanted to acquire. That friction wasn't a warning sign. It was the moat. 2. Boring Gusto makes payroll software. Nobody's passionate about payroll. That's precisely why it sat unsolved — every "fun" idea gets fought over by ten founders, every boring one gets ignored by all of them. And here's the part people miss: six months into any startup, fun or boring, you're doing the same thing — writing code, fixing bugs, talking to users. The initial excitement of the idea has almost no correlation with how much you'll enjoy running the company. 3. Already has competitors Dropbox was the 20th file storage company at launch. Founders read "20 competitors" as a red flag. It's the opposite and evidence of real demand which nobody's nailed it. Zero competitors usually means zero market, not first-mover advantage. Founders optimize for what looks easy, not what actually works. The gap between those two is exactly where the good ideas live.
-
Fraser (@iamfra5er) reportedTHIS GUY WANTED A PLACE TO STORE HIS PASSPORT WITHOUT DROPBOX READING IT so he built an encrypted vault app for himself in a weekend and it's now doing $5k/mo zero startup cost. 85% margins. no ads. just SEO written by an AI agent trained on his emails the agent finds trending topics on reddit every single day, writes an article, translates it, posts it google indexes it in days. 500-600 daily visitors. 4% convert to app store downloads. all running on free cloudflare then ASO does the rest — he translated the app into 36 languages and ranks #1 for "duress vault" in the US app store 80 downloads a day. 9% conversion to paid. completely autonomous most founders obsess over their first 10 customers but this guy got banned from every reddit community and said whatever, I'll just let the robot handle distribution he's an ex-google security engineer who raised hundreds of millions for his last startup so he knows what terrible UX looks like in security apps every competitor either has bulletproof security with unusable UI or easy UI with trash security he just combined both and called it done doesn't even spend time on this app. works on 4 projects at once. lets coding agents build while he plans the MVP is identical to the final product because he built exactly what he wanted for himself no pivot. no customer discovery calls. just "I need this, maybe 10 other people do too" now he's testing tiktok and youtube not even for this app but just to learn distribution for the next one
-
The Redeemed Artist (@Peace_Grenade81) reportedI know I'm just screaming into the void. And there's probably less than like one or 2% of users that actually use this function. But I'm going to do it anyway. For the longest time the X app beta was absolute garbage on Android. It had serious stability problems, I couldn't use voice to text properly, and I couldn't access my memes from Dropbox, my cloud provider. The most recent change fixed all of the other problems except for my Dropbox integration. At first, I blamed X for this but I have since come to learn that the real culprit is Google. If you go into your app section and look for cloud providers they give you all sorts of choices so long as you like the choice that is Google's. Theoretically, other providers should be in here like Box or Dropbox. But Google has been playing footsie making rules about cloud provider integration and not actually approving anyone else. Google has become Microsoft. Google will tell you what cloud provider to use and it will conveniently be their own. Google will continue to upgrade their operating system closing off any other provider options or applications they simply disagree with for any reason at all. Meanwhile what this means for me is that I can't insert any memes or videos because they are all stored on Dropbox. Yeah, yeah, yeah I could go into Dropbox and then click on a photo and then share it to X and then make a post out of it. But what I can't do is respond to a post and insert a picture or a video directly through the X app. Don't know when this gets fixed, if ever. But I think it's time for Google to be investigated for monopolistic practices. I realize that this doesn't affect many people, but if you think they aren't coming for your various conveniences, I'm pretty certain that that's going to be proven wrong. Since I can't post a meme but only a local photo, here's an unrelated picture of a quilt we bought at auction. 🙄