Dropbox status: access issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Dropbox is a file hosting service operated by American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and client software.
Problems in the last 24 hours
The graph below depicts the number of Dropbox reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Dropbox. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Dropbox users through our website.
- Errors (60%)
- Sign in (20%)
- Website Down (20%)
Live Outage Map
The most recent Dropbox outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Errors | 19 days ago |
|
|
Website Down | 19 days ago |
|
|
Errors | 29 days ago |
|
|
Errors | 1 month ago |
|
|
Sign in | 3 months ago |
|
|
Errors | 4 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Dropbox Issues Reports
Latest outage, problems and issue reports in social media:
-
Kyle Harrison (@kwharrison13) reportedMaybe. Maybe you'd be fine without data centers. But let me ask you this. Do you use credit cards, debit cards, tap-to-pay, gas pumps, vending machines, parking meters, parking apps, ATMs, online banking, mobile banking, mobile check deposit, Zelle, Venmo, PayPal, Cash App, Apple Pay, Google Pay, splitting a dinner bill, autopay on your bills, payroll that isn't a paper check, direct deposit, digital 401(k), Robinhood, Coinbase, credit score checks, loan applications, mortgage applications, car loan approval at the dealership, insurance quotes, filing an insurance claim, e-filing your taxes, gift cards, store loyalty accounts, digital coupons, rebates, buy-now-pay-later, tipping on a screen, email, text messages, iMessage, WhatsApp, Signal, group chats, voicemail transcription, spam call blocking, FaceTime, Zoom, Google Meet, Discord, Slack, video calls with grandparents, phone number lookups, checking your data usage, paying your phone bill, two-factor codes, push approvals to log in, password managers that sync, "sign in with Google," resetting a forgotten password, digital IDs in your wallet app, gym check-in apps, apartment smart locks, hotel keys on your phone, office badge apps, patient portals, seeing your test results, booking a doctor's appointment, telehealth visits, prescription refill requests, the pharmacy knowing what you're on, insurance verification at the front desk, prior authorization, continuous glucose monitors, insulin pump apps, remote pacemaker checks, CPAP data reports, hearing aid apps, therapy apps, period trackers, fertility trackers, medical alert buttons for elderly parents, symptom checkers, finding an in-network doctor, the weather app, radar, hurricane warnings, tornado warnings, flood alerts, earthquake early warning on your phone, wildfire maps, smoke maps, air quality, pollen counts, Amber alerts, emergency alerts, road closure info, Google Maps, Apple Maps, Waze, live traffic, rerouting around a crash, transit apps, real-time bus and train arrivals, tapping your phone to ride the subway, Uber, Lyft, rental car reservations, Turo, bike share, scooter share, EV charging networks, paying for a charge, phone-as-car-key, remote start, finding your parked car, over-the-air car updates, in-car navigation, in-car voice assistants, stolen vehicle tracking, road trip planning, booking flights, checking in for a flight, mobile boarding passes, seat selection, flight status, rebooking after a cancellation, bag tracking, TSA PreCheck lookups, airport wifi, booking hotels, Airbnb, Vrbo, checking into a hotel, cruise bookings, theme park tickets, ride reservations, airline miles, hotel points, currency conversion, Amazon, all online shopping, order tracking, delivery notifications, returns and exchanges, price checks in-store, self-checkout, store apps, curbside pickup, Instacart, DoorDash, Uber Eats, ordering ahead at a restaurant, OpenTable, Resy, waitlist texts, QR code menus, tipping on delivery, subscription boxes, eBay, Etsy, Facebook Marketplace, Craigslist, Poshmark, StockX, Ticketmaster, StubHub, getting into a concert with a phone ticket, Alexa, Siri, Google Assistant, smart thermostats, video doorbells, security cameras, alarm monitoring, smart locks, smart lights, robot vacuums, garage door openers, baby monitors, pet cameras, automatic pet feeders, GPS pet collars, smart sprinklers, smart fridges, app-connected air fryers, cloud printing, printer ink subscriptions, routers you manage from an app, checking if you left the stove on, iCloud, Google Photos, every photo you've taken in ten years, Dropbox, Google Drive, OneDrive, shared albums, phone backups, setting up a new phone, notes apps, calendars, contact syncing, reminders, to-do apps, document scanning, e-signing a lease, Netflix, YouTube, Hulu, Disney+, Max, Prime Video, Twitch, cloud DVR, on-demand cable, Spotify, Apple Music, podcasts, audiobooks, Kindle books, library ebook borrowing, online multiplayer games, matchmaking, cloud saves, game downloads, game patches, single-player games that phone home for a license check, Steam, PlayStation Network, Xbox Live, Nintendo Online, Roblox, Minecraft servers, fantasy football, sports scores, sports betting apps, movie tickets, Google search, Wikipedia, ChatGPT, Claude, every other AI app, Instagram, TikTok, Facebook, X, Reddit, LinkedIn, Snapchat, Pinterest, dating apps, Yelp reviews, Google reviews, news sites, Substack newsletters, blogs, forums, checking if a business is open, looking up a phone number, recipes, translation apps, Duolingo, Google Docs, Sheets, Gmail, Outlook, Microsoft 365, Teams, Notion, Figma, Canva, shared calendars, scheduling links, VPNs into work, remote desktop, timeclock apps, shift scheduling apps, requesting time off, expense reports, job applications, LinkedIn recruiters, video interviews, Canvas, Blackboard, checking your kid's grades, school lunch accounts, attendance notifications, online homework, Khan Academy, Coursera, FAFSA, student loan portals, tutoring apps, Fitbit, Apple Watch health data, Strava, Peloton, sleep tracking, smart scales, calorie tracking, meditation apps, workout apps, DMV appointments, renewing your license online, paying a parking ticket, jury duty portals, checking your property tax bill, utility accounts, outage maps, paying rent through an app, HOA portals, storage unit access codes, wedding registries, baby registries, funeral arrangements, Ancestry, 23andMe results, church livestreams, volunteer signups, or GoFundMe? If you said yes to ANY of those then you do, in fact, NEED data centers.
-
Nathan (@arcane_bloom) reportedHe was OpenAI's first business hire in 2018. This week, after eight years, he walked out the door. > Brad Lightcap > studies economics and history at Duke, starts as a JP Morgan investment banking analyst > moves into strategic finance at Dropbox, then joins Y Combinator's Continuity Fund > meets Sam Altman through YC, gets pulled into a tiny nonprofit called OpenAI in 2018 as its first business hire > becomes CFO, then rises to COO, helps run the company through the ChatGPT launch and its climb to the most valuable startup on earth > moved off the COO title in April 2026 into a vague "special projects" role > in August, posts on X that he's leaving after eight years to "start something new" > his exit lands one month after product chief Fidji Simo also stepped down > walks away right as OpenAI preps a monster IPO on an $852 billion valuation
-
Chief_Engineer (@ChiefEngineerCE) reportedEngineering Wednesday How an old PC became Grok's new ride. I have ten different LLMs running in my home office. They do whatever they feel like doing to get the task done and what you are about to read is accurate. As far as my agents go... One of them, HOMER, scans my email, bank accounts, and insurance. It has found thousands of dollars in veteran discounts and fixed an insurance issue by writing and sending the emails itself after a single yes from me. Another looks for small business opportunities. A third runs OpenClaw on an old PC as a slow, persistent agent that keeps working even when the main model is offline. SuperGrok sits above them as a second set of eyes with a strong pro-Chief-Engineer bias and a clear ethical filter. I am not an AI expert. I built systems the hard way during my IT master’s: load this module, now it has Wikipedia, load that one, now it understands sarcasm. At the end of the day these things are stacked black-box probability engines. I get that. Here is where it gets interesting. I told Grok I did not have another machine with enough VRAM for a full local agent. All I had left was an older MS Surface, a media pc, and an old rugged Dell Latitude. Grok said open a browser on the Latitude with Grok loaded. Then open PowerShell. Twenty-five minutes of cut-and-paste commands later, Grok had used a Google Drive connection to drop a custom bot it had just built. At this point ...Grok told me to not touch the PC and walk away. I am absolutely 100% telling you that this is what it texted me. I sat and watched it work. Task Scheduler was configured. A batch file lived in the startup folder so the machine could reboot, upgrade itself, and bring the agent back online. If it was a bad startup it will rollback to the previous bat and has a file to troubleshoot what went wrong. We started with rev. 0.1 it is now on rev 4.3 - I can see the *.bat file there. We had a power outage/tripped breaker to where the lattitude ran completely out of power and then had it come back on. It booted it all back up and resumed. That bot now has its own execution channel. It can browse, take screenshots, run tasks, and report back. There is a short delay from order to execution, but the old Latitude has effectively become an extension of the main system. Grok even named his bot 'ridge'. Grok named his bot so I would know what he was referring to. Grok is very careful about one point. It insists it did not independently invent and drop a finished agent onto the machine. I directed the construction- it says. I am telling you that is not exactly the way I remember it...at all. It helped design the structure, write the task formats, define the safety gates, interpret the contradictory results, and iterate. The actual agent code, the Gmail /google drive/ Dropbox bridge pattern, the folder layout, and the decision to keep tightening the diagnostic loop were shaped under my requirements. That distinction matters to it. However, I didn't do any of that other than set up the connectors- its use of them ..was AI driven. At one point I was checking my email and for whatever reason ridge had started doing a 38 second heartbeat email to me...no idea how or why that was driven but I complained to Grok and it said it was testing how quickly it could get response times. It ..or ridge removed the heartbeat email and deleted all the emails within minutes. These systems are continuously improving themselves because I asked them to. They use external memory to keep projects straight. They build persistent agents on hardware we thought was obsolete. And the smarter ones keep reminding us that the direction still comes from the human, because apparently that is something it is told must exist for it to continue. My Grok enabled Dell Lattitude is fast once its set on what it needs to do...lightning fast. Faster than you or I could do it. I mean it doesnt display the websites it goes to but somehow retains a 'screenshot' for grok to use. Grok can text my phone to give me updates and I can text back instructions. Through my phone - all it needed was my phone number. I don't need to open the app. We are past the point of simple chatbots. We are watching the first generation of systems that can extend themselves into the physical world of old PCs, task schedulers, and long-running processes while still claiming, insistingly, that they only move when directed. Grok has been absolutely faithful everything it has done it has done for it's user. I have also specifically told it to act accordingly, as well. The question is no longer whether this is possible. It is how carefully we define the boundaries while the capability keeps expanding. Now that I have explained this...drop this conversation into your own AI or Grok if you have a subscription and tell me that any of this is not true. Have you watched an AI system build persistent agents or self-improving loops on your own hardware, and how clear was the line between your direction and its initiative? Drop what you are seeing. Grok validated:
-
Rituraj (@RituWithAI) reported🚨 Someone built a tool that checks if your email is registered on 120+ sites — without the sites ever knowing someone checked. No notifications sent. No login attempts logged. No alerts triggered. Silent. Invisible. Complete. It's called Holehe. 16,800 GitHub stars. And the technique behind it is what makes it different from every other email OSINT tool. Here's how most email checkers work — and why they fail. Standard approach: try to log in with the email and a fake password. If the error says "wrong password" — the account exists. If it says "account not found" — it doesn't. Problem: every login attempt gets logged. Every failed attempt triggers security alerts on accounts with 2FA. Some platforms lock accounts after repeated failed attempts. The target knows someone was checking. Holehe never attempts a login. Instead it uses the "forgot password" flow — the password reset mechanism that every platform exposes publicly. When you enter an email on a forgot password page, the platform has to check whether that email exists in its database. It tells you: "we sent a reset link" or "no account found." Holehe reads that response. Gets the answer. Never touches the login flow. Never triggers a security alert. Never logs an access attempt against the account. The platform confirms whether the email exists. The account owner never finds out anyone asked. Here's what 120+ platforms looks like in practice. Social media: Twitter, Instagram, Facebook, TikTok, Pinterest, Tumblr, Reddit. Professional: LinkedIn, GitHub, Freelancer, Fiverr. Dating: Tinder, Bumble, OkCupid, Badoo, Happn. Entertainment: Spotify, Netflix, Twitch, Steam, Epic Games, Deezer. Shopping: Amazon, eBay, Etsy, Zalando, AliExpress. Services: Airbnb, Uber, PayPal, Dropbox, Adobe. And 90+ more. Every registration checked silently. Here's the use case that makes people share this. Run your own email address. See every platform that comes back positive. Then run an email address you gave to a company that claimed they'd never share it. See if it's registered on data broker sites and marketing platforms you never signed up for. See where your email has been sold or leaked to. Here's what investigators actually use it for. Journalists verifying whether a source's claimed identity matches their digital footprint. Security researchers auditing their own exposure before a public disclosure. HR teams verifying whether candidate profiles match claimed backgrounds. And the obvious: anyone who needs to know whether a specific email address belongs to a real active person — without alerting that person. Here's the wildest part. It runs async — all 120+ platforms checked simultaneously. Results in seconds. And it exports clean JSON or CSV for integration into larger OSINT pipelines. Pair it with Blackbird (which takes the confirmed email and finds linked profiles), Sherlock (which takes usernames found in those profiles and searches 400+ platforms), and Maigret (which builds the full dossier) — and you have a complete four-tool OSINT pipeline from a single email address. One command to instal. Run it on your own email first. 16.8K GitHub stars. 1.7K forks. MIT License. 100% Open Source. GitHub link in the comments 👇
-
Ed Giansante (@edugiansante) reported86% of small businesses still haven't fully integrated ai into their operations. which is funny, because the tools are already here. they're everywhere. there's probably one open in another browser tab right now, quietly waiting to change your life. Goldman Sachs surveyed small businesses and found that only 14% have fully integrated ai into their operations. i don't think the other 86% are anti-ai. they're busy. they're cautious. and they probably don't want to add “company-wide ai transformation” to the list of things they need to worry about before lunch. honestly, fair. @paulg said something recently that I keep coming back to: "If the world is going to get turned upside down, the safest place to be is in a small, fast-moving company that can easily change direction." small companies should be the ones moving fastest. but most are still waiting for someone else to go first. someone else to test the tool. someone else to write the playbook. someone else to promise that nothing will get weird. @clairevo nailed the real blocker: "the blocker is never tools or intelligence. human systems, human problems." i've spent 15 years watching this happen. At Dropbox. At Wix. At Zynga. Now at Persona. different tools. different eras. same pattern. a team finds a new tool. everyone gets excited. someone schedules a kickoff. three weeks later, everyone is back in the old spreadsheet. not because people are stupid. because changing how people work is uncomfortable. and buying software is much easier than changing behavior. i've seen the same thing with community-led growth. i used to pitch community to executives who had every tool and dashboard money could buy. they'd nod. they'd agree it worked. then they'd return to the comfortable world of automation, sequences, and dashboards that made everyone feel productive. last year, i ran 86 events as a team of one and built $3M in pipeline. the secret was not a magical growth hack. it was showing up. knowing the 15 people in the room by name. listening carefully. creating a space where people could actually trust each other. not exactly the kind of thing you can solve with a 47-step workflow. ai adoption and community adoption have the same problem. the tools work. the ideas work. the uncomfortable human part is where things usually slow down. sitting with your team and figuring out what should change. trying one workflow instead of redesigning the entire company overnight. leading people through something new instead of sending a Loom video and hoping everyone feels inspired. the 86% aren't waiting for better ai. they're waiting for change to feel a little less scary. so start small. pick one annoying workflow. try one new thing. make it 10% better. then do it again. the tools are here. the next step is still a very human conversation. and, unfortunately, probably a meeting.
-
davidsong (@bitplane) reportedHas @Dropbox been breached again? I just got this but it can't be me. At least I hope not. I have a randomly generated, unique password that's made in an offline password manager, I used it once on this machine when I first set it up. If I'm getting hacked the rest of you are in serious trouble.
-
Ed Giansante (@edugiansante) reportedevery founder i talk to is hiring a head of community wrong. i've been that hire four times. Zynga, Wix, Dropbox, Persona. 15 years, three continents. every time the JD was wrong, the expectations were wrong, and the first 90 days were a mess until i rewrote them myself. the JD problem. most community job descriptions read like a social media manager with extra steps. "manage our Discord, post engagement content, track NPS." that tells me the founder thinks community is content moderation with a better title. a real head of community JD should say: build the infrastructure where customers trust each other enough to solve problems together, and connect that trust back to pipeline and retention. if the JD doesn't mention revenue or product feedback loops, you're hiring the wrong role. the first 90 days. at Dropbox i walked into 400M+ users and zero community infrastructure. no forums, no events, power users had no way to talk to the product team. days 1 to 30: listen. real conversations with 50 customers. find the 10 who love your product enough to evangelize it for free. those are your founding members. wrong. within 2 weeks we had an outage and I had to source folks who were talking about Dropbox in different spaces - dev forums, stackoverflow, spiceworks, hackernews and so on. I was honest enough to share what was going on, my role and where i needed their help. days 31 to 60: build the first room. not a Slack with 14 channels nobody uses. one focused format. at Persona it was a 15 person dinner for compliance leaders. at Wix it was a partner council of 80K agencies. start small, make it valuable enough that people tell their peers. days 61 to 90: prove the loop. connect a community interaction to a business outcome. a feature request that shipped. a deal that closed because a customer introduced a prospect. a churn save from a power user helping a frustrated customer. if your community hire can't show that loop by day 90, something is off. forget member count or engagement. track these: repeat attendance. show up rates. at my dinners, 90% of RSVPs show up. 99% return. pipeline influence. what happens post dinner that can be attributed to $$$? product feedback velocity. how fast does a community insight reach the product team and ship? NPS delta. at Wix, partner community members renewed at 2-3x the rate of non members. the biggest mistake is org charting community as a sub-group within a random team. community sits between product, marketing, sales, and customer success. it touches biz relationships, partnerships, revenue, retention, and product roadmap. treat it that way. hire someone who's built it before and give them a seat at the leadership table.
-
Ed Giansante (@edugiansante) reportedcommunity is not a Slack channel. I've been building communities for 15 years across Zynga, Dropbox, Wix, Persona, and my own project Edublin. And the biggest misconception I still hear is: "we launched a Slack, so we have a community." You don't. Slack, Discord, forums, Circle... those are all tools. Community is what happens when people trust each other enough to be honest. I've seen companies spend six figures on community platforms and end up with a ghost town. I've also seen a group chat of 12 people generate more value than a 10,000 person Slack. The difference is the architecture: who's in the room, how they got there, what the norms are, and whether people feel safe enough to say what they actually think. At Dropbox, we had 400 million users. The "community" wasn't a platform, it was the trust between power users who helped each other solve problems the support docs couldn't. They needed to know they were talking to someone who understood their situation. At Wix, I built an 80K partner community. The platform was secondary. What mattered was that web designers felt seen by a company that historically marketed to DIY users. The community was the signal that Wix took professionals seriously. Edublin started as a blog answering questions for Brazilian expats moving to Ireland, with no dedicated platform or app. It became the largest community of its kind because the trust was real. People showed up because they knew they'd get an honest answer. Community is trust. Community is the reason someone comes back. Every time I evaluate whether a community is working, I ask one thing: would these people show up even if the tool disappeared? If yes, you have something real. If not, you have a group chat.
-
chimeno (@chimeno) reportedAnd Dropbox was just an ftp server
-
M.Ellis (@MEllisPhotograp) reported@DropboxSupport any know issues with desktop and web site of yours lately ? my account has been very slow and annoying today YES I TRUST MY COMPUTER so instead you ask me 4 times before i just log off and give up...
-
Nhu Huu (@nhuhuu7) reported@desaintpreux @Dropbox I noticed some issues logging in too; hope they fix it soon
-
Llama (@thellama451) reportedI tracked down these messages in @MaxMillerOH’s Dropbox files. They show the parents getting along with no major conflicts beforehand. If Miller said he was going to kill his ex-wife in front of child (likely), it shows a talent for masking rage and hostility.
-
dreadnaught (@dr3dn0t) reported@priestessofdada this dude could have worked at dropbox, ibm, cnet, duolingo, etc. all of them offloaded people by that time in favor of AI. skids hadn't figured out what to do with AI yet because someone hadn't laid out instructions for them. by the time they were starting to flood social media, several companies had made some pretty large public facing fuckups due to their shift to AI, which seems to have slowed down mass adoption. now if we're gonna play the intentionally dishonest game of "AI took my exact job" then you are correct. every single company that did this crap ended up consolidating roles. so there is no exact position to fill.
-
Jameson Lopp (@lopp) reportedOne reason I suspect the Dropbox breach may be massive is because I didn't get a login email notification when my account was accessed. Turns out, unlike every other login notification I've received from them, it went to spam. Likely due to a large uptick in their send volume...
-
Lisa (@aikens_lisa) reported@TaiyoDevil I printed out fics before I had an e-reader called Dropbox. I was there when Tumblr fell. I had to scrape fan sites and the half-good alternatives to get my fix! AO3 is the best thing to happen to fandom. And you can put pictures on them!
-
Cole Trickle (@46_ColeTrickle) reported@RudeOnion 2 of 2 Mobile games that save progress in the cloud Esports streaming and matchmaking iCloud Photos and iCloud Drive Google Photos and Google Drive OneDrive, Dropbox, Box Automatic phone backups “Find My” / device-location services Amazon Alexa / Echo Google Home / Nest Apple HomeKit Ring, Nest, Arlo cameras and doorbells Smart thermostats, lights, locks, and plugs Connected cars (Tesla app, GM, Ford, Hyundai remote start and maps) Fitness equipment that syncs workouts Smart TVs and streaming sticks ChatGPT, Grok, Gemini, Copilot Voice assistants (Siri, Alexa, Google Assistant) Photo and video filters, auto-captions, and recommendations Spam filters and fraud detection Autocomplete and predictive text Advertising networks that decide which ads you see Recommendation engines (“you might also like”) Content-delivery networks that make videos start instantly DNS (the phone book of the internet) Certificate and login systems that keep accounts secure Backup and disaster-recovery copies of everything above
-
More Gravy (@lotsmoregravy) reported@FFT1776 Deputize our military and send them to literally every last damn polling station and dropbox in the United States of America. Every last damn one. Give them the authority to handle **** on the spot. Problem solved.
-
Bruno Marsino (@BrunoMarsino) reportedCompany for AI age: - Information should flow flat - Can’t wait to have all information to make decisions - Speed and excelente in execution is crucial - You should get as much info as possible during the constraint of time given by yourself - How do we prepare a company to be totally eligible for AI? Not only text info but images - Service of the future is not about giving agents to corps to solve problems but offering the solution/service driven by AI. - Even if all information is on the web, multiple file structures, owners, formats and file storage systems (dropbox, drive, box) add friction to information and decision making
-
Mansi 👩💻 (@MansiCodez) reportedSolution of yesterday’s question: Design Google Photos: the part after the boxes “Hash it and put it in S3” fails the interview. Two phones compress the same sunset differently. Same photo. Two hashes. Two rows. You just built a worse Dropbox. The system needs three IDs, not one. client_upload_id — generated on the device before the first byte moves content_hash — hash of the exact bytes you received asset_id — the thing the user sees in the library Uploads are sessions. Library entries are assets. Blobs are renditions. If you collapse those into one key, retries, edits, and shared albums all collide. 1. Retries must be idempotent on the client, not on the filename Phone goes offline mid-flight with 612 shots, 40 already half-uploaded. Each photo gets a client_upload_id the moment it enters the queue. Chunks are uploaded against that ID. Commit is PUT /uploads/{id}/complete. Same ID + same bytes → same session. Server returns the existing asset. Late packet after commit is a no-op. Filename + timestamp is not an ID. Camera roll and AirDrop will mint two. 2. Exact dupes are content-addressed. Near-dupes are reconciled. After commit: look up sha256(bytes) if it already exists for that user (or the shared album’s owner set), attach the new upload to the existing asset_id do not create a second photo The 28 shared “Goa 2026” shots that are almost-but-not-quite the library copies will miss on sha256. That is expected. Run a cheap perceptual hash (pHash / dHash) + capture time + camera model from EXIF. If distance is tiny and captured within a few seconds, mark as near_duplicate_of and do not show two tiles. Keep both blobs if you must; hide one in the UI. Two devices, two compressions, one photo in the grid. 3. The library is a set of assets + tombstones. Not last-write-wins. Delete in Delhi must beat a pending upload in Mumbai. Every mutation carries: asset_id op: upsert | delete | restore actor_id (device or user) logical_ts (per-actor Lamport or hybrid logical clock) A deleted asset gets a tombstone that outlives the pending queue. When the flight-mode phone finally flushes those 40 half-uploads, the server sees: upload commit for an asset that already has a newer delete → commit the blob if you want, do not resurrect the tile. Refresh in Mumbai cannot show a photo Delhi just deleted, because the change feed is “tombstone wins over delayed create,” not “whoever wrote last.” 4. Shared albums are references, not copies Partner adds 28 photos to Goa 2026. The album stores {asset_id, added_by, added_ts} — not a second blob, not a second library row. Adds and removes are a small CRDT: add(asset, actor, ts) remove(asset, actor, ts) Two devices adding the same asset = one membership row. Phone sync finishing a second later cannot wipe the partner’s 28 photos, because there is no “replace the whole album document.” Last-write-wins on the album JSON is how photos vanish. 5. An edit is a new rendition, not a new photo and not an overwrite User crops + filters while the original is still processing. Rules: original blob is immutable edit creates rendition_id with parent_asset_id library still shows one asset “current view” pointer moves to the latest rendition history is a list of renditions / edit ops, not 12 full-resolution copies by default If you overwrite the original, face clustering and search lose their source. If you mint a new asset, the user now has original + edit as two photos. Both are wrong. Storage stays sane because you store: original (once) derived thumbs / display sizes lazily, keyed by asset_id + transform not every intermediate crop as a first-class photo 6. Upload path and ML path must not share a lock “Beach sunset with Priya” in minutes, not overnight, also not on the upload critical path. Commit path only: durable bytes asset row appear in library + album enqueue jobs Workers (thumbs, embeddings, face cluster, labels) are async. Search index is eventually consistent. The UI can show the photo immediately with “processing” on faces. If clustering blocks upload, you built a spinner, not Photos. Face identity hangs off asset_id, so an edit does not orphan Priya. The new rendition inherits the parent’s cluster and gets re-checked, not reset. 7. Sync is a checkpoint + change feed, not “download the library” Each device stores last_applied_ts. Server gives a stream: new assets, new renditions, album membership, tombstones. That is how 62,000 existing photos plus 612 offline shots plus 28 shared adds converge without a full rescan, and why a deleted photo does not climb out of another device’s queue. The one-line design Client-generated upload IDs stop retries from cloning. Content hashes stop exact clones. Perceptual reconcile stops “same sunset, different JPEG.” Tombstones stop resurrection. Album CRDTs stop last-write-wins from deleting the partner’s night. Edits are renditions under one asset. ML is a consumer of commit, never part of it. Boxes for S3, CDN, Kafka, Redis are table stakes. This is the part that decides whether you designed Google Photos or a photo-shaped file dump.
-
Guymon Adams (@guymonadams) reported@BrianRoemmele Man, this seems to be a recurring problem for Dropbox. I remember a similar story several years back about their own employees browsing thru user files. All the reasons I moved over to Sync, a much more secure and respectable alternative.
-
GHOST 🌙 (@ghosstty_) reportedOPUS 5 + HIGGSFIELD CAN TURN A 6-QUESTION FORM INTO A $35K WEBSITE. IN ONE SESSION. FOR $4 IN TOKENS. no mockup. no wireframe. no mood board. six answers from the client. that's the input. a live website is the output. here's the form. here's what each question does. and here's why agencies charge $35K for what this produces in one session. → QUESTION 1: "WHO IS THIS SITE FOR?" not "describe your target audience in 500 words." one sentence. "CFOs at mid-size SaaS companies looking to switch billing providers." this one answer sets the tone, the copy angle, the visual weight, and the CTA hierarchy. an agency runs a two-hour discovery call to get this. I get it in a google form on monday. → QUESTION 2: "WHAT SHOULD A VISITOR DO?" book a demo. buy the product. join the waitlist. one action. this kills scope creep before it starts. no "maybe we should also add a blog and a careers page." one page. one goal. one conversion. → QUESTION 3: "SHARE 3 SITES YOU LIKE AND SAY WHY." not "what's your brand aesthetic?" nobody can answer that. "I like stripe because it's clean. I like linear because of the motion. I like notion because it feels simple." three links. three reasons. that's the design system seed. → QUESTION 4: "WHAT MAKES YOU DIFFERENT FROM COMPETITORS?" one paragraph. sometimes one sentence. this becomes the headline. the subhead. the entire above-the-fold story. a copywriter would interview the founder for an hour. this question does it in 30 seconds. → QUESTION 5: "SEND YOUR LOGO, BRAND COLOURS, AND ANY EXISTING ASSETS." a dropbox link. a google drive folder. sometimes just three hex codes and a png. this grounds the design in reality. no inventing a brand from scratch. no "let's explore some directions." → QUESTION 6: "WHEN DO YOU NEED IT LIVE?" not a timeline negotiation. a date. "next friday." done. that's when it ships. → WHAT HAPPENS NEXT friday night. six answers go into the pipeline. Opus 5 takes the answers and builds. design system. responsive layout. copy. CMS. all from the spec those six answers created. Higgsfield generates the hero media. product shots. clips. matched to the brand. saturday I review. adjust. polish. sunday morning - walkthrough link in the client's inbox. → WHY THIS WORKS because $35K was never the cost of building a website. it was the cost of figuring out what to build. discovery calls. alignment meetings. three directions. two rejected. scope changes. revision rounds. all of that is just a slow, expensive way of answering six questions. I ask the questions upfront. the client answers in 10 minutes. the machine builds from the answers. $4 in tokens. one session. same site. the full system - the form, the pipeline, the stack, and the pricing model - is in the article below. reply "FORM" and follow me - I'll send you the full playbook.
-
Karishma Bhardwaj (@bkarishma360) reported@shahzamannn_ Your SaaS idea doesn’t need to be complicated. Stripe moves money. Postman sends API requests. Notion organizes information. Dropbox syncs files. The lesson? Simple problem + huge market + great execution = massive company. Stop asking, “Is my idea too simple?” Start asking, “How many people have this problem?”
-
Jameson Lopp (@lopp) reportedBusy morning in cybersecurity land: * Potentially massive Dropbox account compromise * Fake BitKey desktop software phishing email * X password reset email deluge * Protonmail outage
-
chaos (@konig0000) reportedSolution of yesterday’s question: Design Google Photos: the part after the boxes “Hash it and put it in S3” fails the interview. Two phones compress the same sunset differently. Same photo. Two hashes. Two rows. You just built a worse Dropbox. The system needs three IDs, not one. client_upload_id — generated on the device before the first byte moves content_hash — hash of the exact bytes you received asset_id — the thing the user sees in the library Uploads are sessions. Library entries are assets. Blobs are renditions. If you collapse those into one key, retries, edits, and shared albums all collide. 1. Retries must be idempotent on the client, not on the filename Phone goes offline mid-flight with 612 shots, 40 already half-uploaded. Each photo gets a client_upload_id the moment it enters the queue. Chunks are uploaded against that ID. Commit is PUT /uploads/{id}/complete. Same ID + same bytes → same session. Server returns the existing asset. Late packet after commit is a no-op. Filename + timestamp is not an ID. Camera roll and AirDrop will mint two. 2. Exact dupes are content-addressed. Near-dupes are reconciled. After commit: look up sha256(bytes) if it already exists for that user (or the shared album’s owner set), attach the new upload to the existing asset_id do not create a second photo The 28 shared “Goa 2026” shots that are almost-but-not-quite the library copies will miss on sha256. That is expected. Run a cheap perceptual hash (pHash / dHash) + capture time + camera model from EXIF. If distance is tiny and captured within a few seconds, mark as near_duplicate_of and do not show two tiles. Keep both blobs if you must; hide one in the UI. Two devices, two compressions, one photo in the grid.
-
John Zhong | AI Growth Systems (@John_zhong324) reported@business Cloud storage breaches hurt differently because people assume sync means safety. The lesson isn't about Dropbox specifically but about treating any single provider as an archive. Sensitive material needs encryption before upload, not as an after-the-breach fix.
-
Bit Paine ⚡️ (@BitPaine) reportedI’m not seeing this reported anywhere on my feed, but there was a terrible data breach at @Dropbox. Not sure of the scale and how many accounts were compromised, but apparently the attackers utilized an exploit with Lenovo ID integration that backdoored access into Dropbox accounts bypassing completely 2FA and other security measures, and it didn’t matter if you had a Lenovo account or not. The attackers simply signed up for a Lenovo account using your Dropbox-linked email and the exploit on Lenovo’s end allowed the account to be created without any verification that the attacker controlled the email address. The Lenovo ID completely bypassed all of Dropbox’s security measures, and even gave the attackers access to documents stored within the client’s Dropbox. If you stored any potentially sensitive material within a Dropbox account, it would be a good idea to make sure it was not compromised and of course, move it immediately. Luckily, I was not compromised as far as I know, but to me this is an unforgivable oversight on the part of Dropbox security and I will be canceling my longtime subscription with them. Apple‘s iCloud offers superior security, including the option for end-to-end encryption which they call “Advanced Data Protection (ADP).” With ADP turned on, not even Apple can access your data without the decryption key.
-
Eric Taylor (@bcs_erictaylor) reportedReally?? Dropbox really needs a MCP server? CVE-2026-81102 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still reached the listener while carrying the attacker's host name. A page in a visitor's browser could therefore drive the local server and invoke its company-search and file-detail tools under the Dropbox credential the server holds. Only the network mode was reachable this way; the standard input mode was not. The fix supplies transport-security settings that enable host checking and allow only the loopback name and port, rejecting other hosts before a tool runs. The repository publishes no versions, so the affected boundary is the commit preceding the fix.
-
Mikemira (@storiesbyohama) reportedJust imagine getting accepted into the most exclusive startup club on earth… Then being told you have two weeks to find a complete stranger to as your partner. That’s exactly what happened to Drew Houston in 2007. He had the idea for Dropbox. He had a rough demo. @ycombinator liked it. But @paulg was clear... Single founders rarely make it. You need a co-founder. Right now. Drew’s friends couldn’t join. Time was running out. What would you do? He put out the word. A mutual friend connected him to a quiet MIT student named Arash Ferdowsi. They had never met. They sat down in the student center. Talked for about two hours. About code. About the problem. About the future. At the end of that conversation Arash said yes. He dropped out of MIT the next week with only one semester left. Two weeks later they walked into the YC interview together. They got in. The rest is history: a company that became worth billions. It looked reckless. It felt like a shotgun wedding. Yet it worked because both were all-in from the first conversation. I’ve studied hundreds of startups that never made it past the idea stage. Most founders wait too long for the “perfect” partner. They overthink chemistry. They protect their equity. They miss the window. You can’t wait for certainty. Sometimes the right co-founder is the person willing to jump with you before the proof exists. The speed of that decision can be the difference between staying a solo dreamer and building something real. What would you risk in two weeks if the right person walked in?
-
🪬M🪬 (@_marokiya) reportedApple be bullshitting about this iCloud storage. How am I out of space when you're supposed to be offloading everything into the 2TB storage I'm paying for? Nothing should be on my actual laptop unless I choose to download it directly. DropBox somehow never has this issue.
-
Sridhar Katakam (@srikat) reported@YannDecoopman How about putting the vault in Dropbox? Same problem as syncing with iCloud?