Earlier quoted context omitted.
I have a similar success story. Thanks to Dropbox spamming me with "OMG UPGRADE!" every time I clicked anything, I found out about SyncThing (specifically SyncTrayzor for Windows). Thanks, Dropbox!
Also checkout Seafile if you want something more Dropboxy.
Dropbox: Going Deeper with Project Infinite
61–70 of 95 posts
Re: Dropbox: Going Deeper with Project Infinite
#62So..the cost of an extra kernel/userspace switch was too much for a file request that is going to be serviced by a server on the other side of the internet?..really?
Reminds me of the performance arguments for kdbus.
Re: Dropbox: Going Deeper with Project Infinite
#63As a paying Pro customer, I am a bit worried how intent they seem to be on pushing the business/enterprise products. First of all, Dropbox the web application is spammed with Dropbox Business advertising. I am already paying. And, no, my employer (a European university) is unlikely to roll out Dropbox Business. So please stop bugging me :(. Secondly, more and more features are rolled out to business users first. Why?…
Re: Dropbox: Going Deeper with Project Infinite
#64So instead of using a FS shim to userspace on security grounds they decided to distribute a custom kext that's closed source -- ie a great way for normal bugs to turn into dangerous ones? I'm not sure I understand the logic here
I complete agree. Are there that many people running performance-sensitive I/O bound apps directly out of their Dropbox? Shouldn't they contribute back to libfuse rather than reinvent the VFS, with all the (sure as death and taxes) pitfalls and CVEs that will come along with it?
Re: Dropbox: Going Deeper with Project Infinite
#65If you want to try out a FUSE-style Dropbox filesystem, I write one. It's available on Mac, Windows and soon Linux. [shameless plug] http://www.expandrive.com The bit I don't quite understand about Project infinite is that you still have to manually decide what gets sync'd or not. It's also not a network volume, so things like virus scanners or search indexers can just page in-data? And if you want to offload data, y…
Re: Dropbox: Going Deeper with Project Infinite
#66Earlier quoted context omitted.
Regardless of how much they've changed, 2011 Dropbox was decidedly not two guys in a garage and their complete and total lack of security engineering diligence and multiple overlapping process failures that must have occurred to lead to that incident call every future "At Dropbox we take security seriously" into question. (See also: "goto fail".) At some point, Dropbox clearly didn't take security seriously. They cla…
Google most certainly does not fall into the former. Google has had multiple security incidents during the lifetime of the company that resulted in an increasing investment in upping their security profile. Operation Aurora ( https://en.wikipedia.org/wiki/Operation_Aurora ) was one of them (which of course bit a number of companies and was quite a sophisticated attack), but they have had other screwups, like the SRE…
Re: Dropbox: Going Deeper with Project Infinite
#67Re: Dropbox: Going Deeper with Project Infinite
#68Earlier quoted context omitted.
Exactly, we should be moving in the opposite direction: make as much software as possible user-space and sandboxed. I assume a party as large as Dropbox can request Apple to extend the APIs where necessary?
> I assume a party as large as Dropbox can request Apple to extend the APIs where necessary? As large? Dropbox is like a fly to Apple. Not to mention competitors. And they haven't budged for much larger parties. So, unless it's something that Apple intends to do anyway, Dropbox's request will don't have much success.
Re: Dropbox: Going Deeper with Project Infinite
#69Earlier quoted context omitted.
Google most certainly does not fall into the former. Google has had multiple security incidents during the lifetime of the company that resulted in an increasing investment in upping their security profile. Operation Aurora ( https://en.wikipedia.org/wiki/Operation_Aurora ) was one of them (which of course bit a number of companies and was quite a sophisticated attack), but they have had other screwups, like the SRE…
Will you run the closed-source Dropbox kext on your machine?
Re: Dropbox: Going Deeper with Project Infinite
#70Earlier quoted context omitted.
Google most certainly does not fall into the former. Google has had multiple security incidents during the lifetime of the company that resulted in an increasing investment in upping their security profile. Operation Aurora ( https://en.wikipedia.org/wiki/Operation_Aurora ) was one of them (which of course bit a number of companies and was quite a sophisticated attack), but they have had other screwups, like the SRE…
Will you run the closed-source Dropbox kext on your machine?
Running closed source code clearly involves a level of trust that permits abiding ignorance. Nothing more to say then.