Live data from Hacker News

Dropbox: Going Deeper with Project Infinite

blogs.dropbox.com

1–10 of 95 posts

Re: Dropbox: Going Deeper with Project Infinite

#4
post #3

So instead of using a FS shim to userspace on security grounds they decided to distribute a custom kext that's closed source -- ie a great way for normal bugs to turn into dangerous ones? I'm not sure I understand the logic here

The blog article goes into great detail, for performance.

Re: Dropbox: Going Deeper with Project Infinite

#6
As a paying Pro customer, I am a bit worried how intent they seem to be on pushing the business/enterprise products.

First of all, Dropbox the web application is spammed with Dropbox Business advertising. I am already paying. And, no, my employer (a European university) is unlikely to roll out Dropbox Business. So please stop bugging me :(.

Secondly, more and more features are rolled out to business users first. Why? Are regular paying customers going to be treated as second-class citizens to bully them into business accounts?

Re: Dropbox: Going Deeper with Project Infinite

#7
post #3

So instead of using a FS shim to userspace on security grounds they decided to distribute a custom kext that's closed source -- ie a great way for normal bugs to turn into dangerous ones? I'm not sure I understand the logic here

Exactly, we should be moving in the opposite direction: make as much software as possible user-space and sandboxed. I assume a party as large as Dropbox can request Apple to extend the APIs where necessary?

Re: Dropbox: Going Deeper with Project Infinite

#8
post #3

So instead of using a FS shim to userspace on security grounds they decided to distribute a custom kext that's closed source -- ie a great way for normal bugs to turn into dangerous ones? I'm not sure I understand the logic here

I complete agree. Are there that many people running performance-sensitive I/O bound apps directly out of their Dropbox? Shouldn't they contribute back to libfuse rather than reinvent the VFS, with all the (sure as death and taxes) pitfalls and CVEs that will come along with it?

Re: Dropbox: Going Deeper with Project Infinite

#9
post #3

So instead of using a FS shim to userspace on security grounds they decided to distribute a custom kext that's closed source -- ie a great way for normal bugs to turn into dangerous ones? I'm not sure I understand the logic here

Exactly, we should be moving in the opposite direction: make as much software as possible user-space and sandboxed. I assume a party as large as Dropbox can request Apple to extend the APIs where necessary?

Especially since Apple already has! There are new extension APIs in El Capitan specifically designed for apps like Box and Dropbox to extend the Finder.

And they also released APIs designed to eliminate the need for KEXTs for virtualization products (see: Veertu and Docker for Mac beta), so I would expect them to also have/make APIs for Dropbox's use case as well.

I was excited for this. Was.

Re: Dropbox: Going Deeper with Project Infinite

#10

As a paying Pro customer, I am a bit worried how intent they seem to be on pushing the business/enterprise products. First of all, Dropbox the web application is spammed with Dropbox Business advertising. I am already paying. And, no, my employer (a European university) is unlikely to roll out Dropbox Business. So please stop bugging me :(. Secondly, more and more features are rolled out to business users first. Why?…

I killed my Dropbox Pro account and upgraded iCloud storage because the integration with the Photos app in iOS is way superior and the lack of something like Project Infinite, which results in a lot of manual folder management for my long tail of old docs. Dropbox's core sync technology is still unmatched, but the Pro offering leaves a lot to be desired over some of the better integrated experiences of Google and Apple's photos products.

I expect this to become even more of an issues after WWDC.

Post reply on HN