macOS Sierra Addresses Dropbox Security Concerns by Explicitly Asking for Accessibility User Permission

by

Following Dropbox-related security concerns that surfaced earlier this month, developer Phil Stokes has confirmed that macOS Sierra now explicitly requires apps to ask for user permission to access Accessibility (via Daring Fireball). Users can give access to an app, or click "not now" to deny the request.

dropbox-accessibility-permission
Concerns were raised after it was demonstrated that Dropbox appears in System Preferences > Security & Privacy under Accessibility, despite the fact that users were never prompted to grant access to the features. More details can be found in our previous coverage and in a Dropbox support document.

Let’s assume for the sake of argument that Dropbox never does any evil on your computer. It remains the fact that the Dropbox process has that ability. And that means, if Dropbox itself has a bug in it, it’s possible an attacker could take control of your computer by hijacking flaws in Dropbox’s code. Of course, that’s entirely theoretical, but all security risks are until someone exploits them. The essence of good computer security and indeed the very reason why OSX has these kinds of safeguards in place to begin with is that apps should not have permissions greater than those that they need to do their job.

At the time, Dropbox said it was working with Apple to reduce its dependence on elevated access in macOS Sierra, and would respect when people disable the app's Accessibility permissions, but now a much-needed safeguard exists regardless.

In a new blog post, Dropbox still recommends that Mac users running macOS Sierra update their Accessibility permissions, if needed, to ensure smooth syncing and access to certain features of the cloud storage service.

Advanced Dropbox collaboration features, such as the badge, require Accessibility permissions. You’ll be prompted to grant these permissions when you install the Dropbox desktop app on macOS Sierra. To do so, follow the instructions on screen. The same will apply for older versions of OS X in the coming weeks. For more information on Dropbox Mac permissions, visit our help center.

macOS Sierra was publicly released today as a free update on the Mac App Store.

Top Rated Comments

dragje Avatar
55 months ago

Drop-who?

However in all seriousness, I abandoned Dropbox ages ago and migrated to Google Drive and have never looked back.

Dropbox are "ok" no doubt but lack so many features and compared to Google are seriously slow. My file transfers since switching to Google Drive have more than tripled!

I'll never move my documents to Google Drive which enables the company to look inside within each document for commercial exploitation usage. For the same very reason I rarely using Google as a search engine, simply because I truly hate the so called targeting adds, as if I'm considdered to be a f*beep*ing monkey that would be interested in camera's for weeks just because I was searching for one at one given day. Google makes sure that all the adds on websites, in one way or the other, has something to do with camera's.

I'll regret the day that I might not care about this any longer, that I'm willingly stop using my brains and surrender myself entirely to commercial exploitation and accept that I've become a slave for a company by providing them personal information about myself and by agreeing that "to think yourself" is something one should not do. For the same reason I don't make use of facebook, delete apps that requires a facebook and/or a Google account and doesn't enable me to login besides these options.

I grew up in the world where the internet became big. And I'm really became fascinated with the phenomenon called the internet. And I should because it delivers also so much good. But I've never been able to understand why people willingly give away all of their private information, especially knowing that there is no such thing as: 'I've nothing to hide'
Score: 7 Votes (Like | Disagree)
simonmet Avatar
55 months ago

I came here to say the same thing. No matter which box you click: "Not Now", "Learn More", or obviously the third one, it puts itself in Accessibility.

My response was to remove Dropbox from my computer.

This is an OS X behaviour and unrelated to Dropbox. OS X is putting it there and this I believe is nothing new. The problem before was that Dropbox seemingly exploited loopholes or weakness in OS X to enable those privileges without asking.

It also replicates behaviour in iOS. If you deny an app permission to send you notifications or have access to your location the app still appears in the relevent settings so you can subsequently enable the permissions later if you so choose without having to delete and reinstall the app.

So it's entirely appropriate and normal that OS X puts it there.
Score: 5 Votes (Like | Disagree)
Michaelgtrusa Avatar
55 months ago
Well done Apple.
Score: 2 Votes (Like | Disagree)
Pakaku Avatar
55 months ago

I chose "Not Now" and Dropbox still jumped into Accessibility—though unchecked. My question is, how does it get in there?

Sounds like the OS itself just keeps a history of whatever has attempted to ask for permission, and anything the user denied permission for is just left there unticked.
Score: 2 Votes (Like | Disagree)
sesnir Avatar
55 months ago

I chose "Not Now" and Dropbox still jumped into Accessibility—though unchecked. My question is, how does it get in there?

I came here to say the same thing. No matter which box you click: "Not Now", "Learn More", or obviously the third one, it puts itself in Accessibility.

My response was to remove Dropbox from my computer.
Score: 2 Votes (Like | Disagree)
smacrumon Avatar
55 months ago

Drop-who?

However in all seriousness, I abandoned Dropbox ages ago and migrated to Google Drive and have never looked back.

Dropbox are "ok" no doubt but lack so many features and compared to Google are seriously slow. My file transfers since switching to Google Drive have more than tripled!

And I guess you're happy for Google to peruse your files on a daily basis.
[doublepost=1474429813][/doublepost]This is really interesting. Who would have thought MacOS could be circumvented like this? I certainly didn't. Yep post those permission warnings just like iOS vigilantly does.
Score: 1 Votes (Like | Disagree)

Top Stories

apple top apps games 2020

Apple Shares Top 20 Most Downloaded Games and Apps of 2020

Tuesday December 1, 2020 9:38 pm PST by
Alongside picks for the top iPhone, iPad, and Mac apps and games of the year, Apple today shared charts featuring the Top Games of 2020 and the Top Apps of 2020, revealing the most popular free and paid apps and games during the year. Among Us! was the top free game of 2020, followed by Call of Duty: Mobile, Roblox, and Subway Surfers. Ink Inc. Tattoo Drawing was the number four free app,...
m1 chip macbook air pro

Developer Delves Into Reasons Why Apple's M1 Chip is So Fast

Monday November 30, 2020 1:57 pm PST by
Apple's M1 chip is the fastest chip that Apple has ever released in a Mac based on single-core CPU benchmark scores, and it beats out many high-end Intel Macs when it comes to multi-core performance. Developer Erik Engheim recently shared a deep dive into the M1 chip, exploring the reasons why Apple's new processor is so much faster than the Intel chips that it replaces. First and foremost,...
maxresdefault

Italy Fines Apple $12 Million for Misleading iPhone Water Resistance Claims

Monday November 30, 2020 3:10 am PST by
Apple has been slapped with a 10 million euro ($12 million) fine by Italy's antitrust watchdog for unfair commercial practices related to its iPhone marketing in the country. One of the Apple ads cited in the Italian watchdog's proceedings (credit: setteBIT) Specifically, Apple is being charged for misleading claims in promotional messages about how deep and how long iPhones can be submerged...
General cyber monday 20 sale feature

Apple Cyber Monday 2020: Discounts on iPads, Macs, AirPods, and More [Updated]

Monday November 30, 2020 6:25 am PST by
Today is Cyber Monday, a shopping event that sees many of the same deals from Black Friday bleed over into a new week, along with a few brand new offers on everything from Apple products to related accessories. In this post we'll highlight the best online discounts that you can find on Apple devices today. Note: MacRumors is an affiliate partner with some of these vendors. When you click a...
16 inch MBP Mini Led

Mini-LED M1 MacBook Pro and Mini-LED iPad Pro Models Coming First Half of 2021

Monday November 30, 2020 2:24 am PST by
Apple is widely reported to be embracing mini-LED display backlighting technology for some products next year, and a new report today by DigiTimes has named several of Apple's partners in the supply chain that are expected to benefit from the switch. According to the report, Apple is set to launch its first mini-LED iPad Pro in the first quarter of 2021 and mass produce mini-LED MacBook Pro...
iphone8guide b

iOS 14.2 Quietly Added FaceTime 1080p Support to iPhone 8 and Later Models

Wednesday December 2, 2020 3:21 am PST by
Back in early November, Apple released iOS 14.2 and announced with it a slew of new features for iPhones, but one thing it didn't mention was the apparent addition of support for 1080p FaceTime calls on iPhone 8 and later devices. The little-known fact was discovered by MacMagazine, which found that Apple quietly updated the specs pages for devices like iPhone XR shortly after the release of ...
Mac Mini 2018

Apple Developers Now Able to Natively Run macOS Within AWS With Amazon EC2 Mac Instances

Monday November 30, 2020 9:01 pm PST by
As AWS re:Invent kicks off, Amazon Web Services today announced new Mac instances for Amazon Elastic Compute Cloud, allowing AWS customers to run on-demand macOS workloads in the AWS cloud for the first time. Amazon says that the new feature extends the flexibility, scalability, and cost benefits of AWS to all Apple developers as those creating apps for iPhone, iPad, Mac, Apple Watch, Apple...
best apps of 2020

Wakeout! Named Apple's Best App of 2020, While Zoom Earns the Title for Best iPad App

Tuesday December 1, 2020 9:26 pm PST by
Apple today shared its App Store Best of 2020 winners, highlighting its picks for the top iOS, iPadOS, and macOS apps and games released over the course of the year. Apple's iPhone App of the Year award went to Wakeout!, which is a family friendly exercise and movement app that encourages people to complete easy exercises while at home. Apple's iPad App of the Year was Zoom, which soared in...
magsafe duo charger

MagSafe Duo Charger for iPhone 12 and Apple Watch Now Available for Purchase

Tuesday December 1, 2020 4:15 pm PST by
Apple today began selling the MagSafe Duo Charger that was announced alongside the new iPhone 12 models back in October. Priced at $129, the MagSafe Duo offers a MagSafe charging puck for the iPhone 12, 12 Pro, 12 Pro Max, and 12 mini, along with an Apple Watch charger. Though the accessory was announced in October and was listed as coming soon, it was not clear when it would launch. Orders...
imac 5k 2014 video

Apple Adds First iMac Models With Retina 5K Display to Vintage Products List

Tuesday December 1, 2020 8:09 am PST by
The first iMac with a Retina 5K display is one of several iMac models that have been added to Apple's vintage products list this week. In the past, vintage Apple products were no longer eligible for repairs at the Genius Bar or at Apple Authorized Service Providers, but Apple began offering extended repairs of select vintage products in 2018. Many of the iMac models listed below will likely...