Live data from Hacker News

Dropbox Attempts To Kill Open Source Project

razorfast.com

111–120 of 323 posts

Re: Dropbox Attempts To Kill Open Source Project

#111
post #96

Earlier quoted context omitted.

Sorry, as written, your sentence seems fairly calculated to give the impression something minimal is happening when you clearly know something other than "a friendly discussion" is happening. My post above says why I believe this. Feel free to answer the specific problems I raise.

No, I think something minimal is probably going on here. My spidey sense tells me Dropbox is not the evil empire trying to suppress freedom of expression among coders. I can imagine that were I in Arash's shoes, I too would be very worried about impending Rapidsharization of my service. That doesn't mean Dropbox handled this flawlessly. They appear not to have. It does, however, imply: * The nerds angry about the req…

I can completely understand Arash not wanting Dropbox to be used as a Rapidshare or other similar site - he has every right to enforce his Terms of Service - that's what they are there for, and what users agree to when they signed up (their own fault for not reading it and just now seeing that their files can be removed or their account can be suspended).

My concern is the system they are using for DMCA notices. If it is indeed an automated system, then they are doing things wrong. Yes, have a DMCA notice generated, but someone should physically vet that notice prior to it being sent out - and that should most likely not just be a member of the support staff.

I am also concerned that Arash was using a tool, meant for support staff, that he was not familiar with to perform a mass-removal as well as a mass-DMCA takedown notice when it is obvious any such tool would require him to enter the claiming company name - in this case Dropbox. He should have asked, or been told what is going on with such a tool.

Re: Dropbox Attempts To Kill Open Source Project

#112

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

> we've fixed the deduplication behavior serverside

Great, and that's all you should've done in this case.

Re: Dropbox Attempts To Kill Open Source Project

#113

Most interesting comment to that article: Thankfully all DMCA requests are filed under penalty of perjury. If he claims that he owns the copyright to material he doesn’t own, he has now opened himself up to civil litigation. Really. Seems so: http://www.aaronkellylaw.com/Internet-Law-and-Intellectual-P...

By policing and issuing a dmca notice dropbox seems to be risking their status from "carrier/hoster"? IANAL but the dmca provides hosting sites protection against users who infringe. By actively checking for infringement of users having dropship could they be openning themselves to legal complications if they lose "hoster" status?

You're mixing up your concepts, thinking of common carrier status that is used for communications networks. DMCA takedowns were designed so that hosting companies could avoid contributory copyright infringement accusations only. Common-carrier was designed, for example, to prevent telephone companies from being accused of contributing to crimes hatched on their wires.

Re: Dropbox Attempts To Kill Open Source Project

#114
post #99
post #56

Dropbox has a simple technical recourse to prevent de-duplication from being used for file sharing - issue a random challenge (a slightly more sophisticated version of "ok, what is the 100th word in the file?") before acknowledging a collision as a true duplicate. Edit: Thinking about this a bit more, the primary expense of this scheme would probably be accessing the file to verify the challenge results. Here's a que…

Considering Dropbox doesn't do automatic upgrades (at least on a Mac it doesn't), you can always stay at an older version of the client where this new protocol isn't supported and thus Dropship still is valid. I doubt that Dropbox would ever ban previous versions of their client purely for this purpose.

They could still do something. In cases where they have reason to suspect this is going on (which could be based on file usage patterns), they could start asking clients to send the file. Clients that start an upload and then disconnect when asked for the file are pretty much caught red handed, and you could just block their accounts until they upgrade to the next version.

Re: Dropbox Attempts To Kill Open Source Project

#115
post #78

Earlier quoted context omitted.

Why does everyone make the assumption that torrents and services like Dropship must be used for piracy? Major video game companies use torrents all the time to distribute patches and betas. A knife can be used to commit murder, but most often it is simply used to cut food. The problem with the way DMCA works is that it bars the development of new technologies because one of many uses could be harmful. The law stifles…

"A knife can be used to commit murder, but most often it is simply used to cut food." Most of the time, a knife is used for cutting food and it can be used for murder. Most of the time, torrents are used for piracy and they can be used for legitimate and legal files. Search for "torrent" on Google. The majority of the results are search engines for pirated material (and in many cases, direct links to the torrents). S…

I would tentatively disagree.

You are indeed correct that most Torrent Sites are mainly piracy distribution hubs. However, torrent sites are not indicative of torrent traffic by _Clients_. *

From what I understand, Blizzard uses torrents to spread patches for World of Warcraft. It is also used, I believe, in Steam as well.

* I would also argue that, although copyright violations, transfers of TV shows are already done via the main distributors' websites. Other than where the source is from, I do not see much a difference.

I would also argue that piracy itself is a response to market failure. When it's easier to get working media (notably cracked programs and music/movies/shows) via a 3rd party distribution than from the source, there is _something_ wrong. Many times, it is because of "We wont sell to that country until $later", or "Our antipiracy software wont run on your computer", or it just is infeasible to find it. But essays have been done on this topic alone.

Re: Dropbox Attempts To Kill Open Source Project

#116
You know, I really don't understand the rage around this case, or more specifically that it's supposedly all coming from people who otherwise love Dropbox.

So let's examine what you're (potentially) doing by forcing this issue and so on:

(1) Calling down a streisand effect on Dropbox. Perhaps you believe that code is meant to be free to such an extent that this is part of your goal, so, sure.

(2) They clearly have no intention of allowing DropShip to become a common use case. If your Streisand effect results in wide adoption by people who just latch onto your censorship angle, they will have to take rushed action to prevent further spread.

(3) This rushed action could be a technical solution (maybe challenge-response, as mentioned) or a banhammer once they have narrowed down the use signature for dropship.

--

(3a-technical) If it's the technical solution, as it was produced under rapid duress, is buggy. Suddenly, your beloved dropbox starts corrupting your files, or refusing to sync some in edge cases. Oops. Some [paying] users who never even heard about this 'censorship' issue notice this issue and take their business elsewhere, and of course it's less useful to you too as a tool until they fix it.

(3a-technical alternative) It's not a buggy fix because they're supercoders. Still, their team had to put in an ungodly week to make and stress-test the fix; congratulations on ruining their quality of life for a week while still losing dropship.

(3b-banhammer) Well, they figure out how to track people using dropship, and maybe institute a 3 strikes policy (2 emails, 1 ban.) So you stop using dropship after the first email, with a bit of simmering resentment at dropbox; still no dropship. Meanwhile, there are false positives because of course there are; this generates a second, far louder streisand effect, and dropbox again loses some paying customers.

-

In summary: sure, open-source code is meant to be free. But your actions don't exist in a vacuum. At the end of the day, Dropbox is clearly not going to tolerate dropship on its network. Consider whether you would rather keep using dropbox as it is, or shoehorn yourself into basically open war on dropbox unless you can dropship on it.

(Tangentially: it was a neat enough hack, but it still doesn't seem any functionally different than sharing public URLs for the file, with the only differences being that you circumvent the bandwidth limits - again, congrats on fighting the TOS of a service you supposedly love.)

Re: Dropbox Attempts To Kill Open Source Project

#118
The DMCA notice came as a result of an automated support system. The CTO's understanding was the system blocked access to individual files, but the real purpose is blocking access as part of DMCA requests, so it automatically sends the DMCA notices out.

This wasn't somebody trying to strong-arm somebody else. It was an understandable mistake.

Re: Dropbox Attempts To Kill Open Source Project

#119
post #41

Consider that maybe what's happening here is boring. Recognize that we all have a cognitive bias towards narratives, and especially interesting narratives. The discussion on this story is trying to build a narrative about Dropbox vs. open source developers. The real story is probably not that interesting. The CTO of a service as technically interesting as Dropbox certainly knows that he can't prevent the disclosure o…

Let's put this in context. Here's what I don't get: the DropShip code is just an exploit of the fundamental architecture flaw of cross-user content deduplication, revealed earlier this month [1]. As the closest thing to a resident security expert around here tptacek (at least to me, I find your comments very enlightening on the whole), how do you feel about a company dismissing an exploit when it's still just an idea, then rushing to erase all evidence of the exploit once it's realized?

[1] http://news.ycombinator.com/item?id=2438181

Re: Dropbox Attempts To Kill Open Source Project

#120

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

> we've fixed the deduplication behavior serverside Great, and that's all you should've done in this case.

> Great, and that's all you should've done in this case

I doubt that is what the lawyers said.

Post reply on HN