Live data from Hacker News

Dropbox Attempts To Kill Open Source Project

razorfast.com

131–140 of 323 posts

Re: Dropbox Attempts To Kill Open Source Project

#131
post #83

Earlier quoted context omitted.

"Thus far, the only thing Dropbox is purported to have done here is to politely ask a developer to remove an application; then, presumably believing that the mirror posts were simple nerd-rage, and that the author of the application agreed with Dropbox, Dropbox's CTO filed takedowns at Github" It's the "write a sentence long enough you hope they won't reach the end" rhetorical strategy! Lawyer: "Your honor, the only…

I don't appreciate being told that I'm being deliberately disingenuous. I have no dog in this hunt. I've never spoken to any of the founders of Dropbox. Maybe you didn't mean to be this dramatic in your response? Or maybe I said something that specifically set you off, in which case, let me know so I can amend my comment.

Your comment does appear disingenuous, though I'm sure that's not deliberate. Neither false DMCA notifications nor github takedown requests are legitimate responses to "simple nerd-rage" when it's about MIT-licensed code. I'm sure you understand this and you say as much elsewhere in your comment; but your sentence appears to trivialize these actions by including them after a soothing "the only thing... purported to have done... to politely ask...", and dismissing their significance with "simple nerd-rage".

Sure, this isn't a big deal in the larger scheme of things; but it isn't as trifling a deal as your comment's rhetorics make it out to be. Dropbox's actions are hurting its geek credibility, and rightfully so; I take your point about them possibly wishing to appear tough on rapidshare-ization of their service, but they don't have to do this employing tactics that are widely considered to be low. A proper amount of posturing and some real tech work behind the scenes to make this sort of access harder, if not impossible, would achieve more and not hurt their image.

I do have another, more substantive disagreement with your original comment, not about style. I don't think it's as clear as you present that the code in question was obviously not going to be suppressed by Dropbox, and they obviously understood that, etc. Yes, the author of the blogpost is possibly biased towards seeing himself as the hero; but I see nothing to contradict his claim that if it weren't for this one stubborn developer, the code would've disappeared from public access. The amount of goodwill towards Dropbox in the community (notably so in the case of the original author) and their swift attempt at censoring the code might have helped this succeeded.

Re: Dropbox Attempts To Kill Open Source Project

#132

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

Regardless, I can completely understand the actions of staying away from Rapidshare (read the full comment for a day pass of $5, or wait 30 seconds).

However, pissing off the constituency that originally promoted your service isn't exactly #1 in your marketing plan. I'm not well known, but many who reside here are. Scaring off hackers just seems wrong, being Hacker News and all.

Re: Dropbox Attempts To Kill Open Source Project

#133

Earlier quoted context omitted.

I don't think that the unjustified and unilateral removal of code from someone else's access or threatening anyone with legal action is ever an acceptable mistake, let alone "trivial". The law is not a toy, and it's not supposed to be wielded casually. The DCMA is certainly not treated with the respect it is supposed to afford citizens, and this is just another example of that.

We disagree. The mechanism for getting Github to take down code is the DMCA request; it's what you use when someone at Github is hosting code that they didn't own that you'd like removed and you feel you have some grounds to have removed. It was a mistake for them to use a DMCA request here, because the code was MIT-licensed and thus even the author can no longer ask for it to be taken down. But nobody paid legal fee…

I understand the justification for the DMCA's existence. I agree with the measures that Google for instance has put in place both to file DMCA requests and to file counterclaims. Google also goes to great pains to proactively inform users of possible infringement on Youtube. That's all well and good.

However, requests should be filed in good faith, under the understanding that you have standing to file the requests. Clearly Dropbox does not, nor does the original author, having MIT licensed the code himself.

That pretty succinctly summarizes why this is problematic. Everyone here knows that they can't do this. The fact that they prepared letters and fired off the requests anyway demonstrates that they were acting in bad faith.

You don't accidentally reach for the DCMA and accidentally shoot off requests to github.

(and it's on that count alone that i criticize Dropbox, i think otherwise that i totally understand why they think this is a huge problem, and exposes them to legal liability.)

Edit: just read (http://news.ycombinator.com/item?id=2482803 ) explaining that the DCMA takedown letter that was email was in fact accidentally sent via an automated system. :P

Re: Dropbox Attempts To Kill Open Source Project

#134

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

Any news on fixing the exploit? Is the option being considered by dropbox?

Re: Dropbox Attempts To Kill Open Source Project

#135

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

"when we disabled public sharing of that file by hash"

Sorry, I may sound harsh, it's not my intention, but I have to ask: how often does it happen that you disable public sharing of files you don't like?

Re: Dropbox Attempts To Kill Open Source Project

#136
post #75

The journalist A.J. Liebling said, "Freedom of the press is guaranteed only to those who own one." I guess the corollary here is, "If you don't own the server, you don't own the file." Maybe this is why Richard Stallman calls cloud computing "careless computing."

Something Eric Raymond agrees with him about - http://esr.ibiblio.org/?p=932

Eric also had another post Three Systemic Problems with Open-Source Hosting Sites a few months later (October 2009) - http://esr.ibiblio.org/?p=1282

Re: Dropbox Attempts To Kill Open Source Project

#137
post #94
post #21

This is Arash from Dropbox. We removed the ability to share the project source code because it enables communications with our servers in a manner that is a violation of our Terms of Service. By our TOS, we reserve the right to terminate the account of users in this case. However, we chose to remove access to the file instead of terminating the account of the user. We recently built a tool that allows us to ban links…

I'm sure I'm not alone in not quite getting how mere possession of software which enables the violation of your TOS is itself a violation of your TOS. Can you clarify that?

It's not a violation until they rewrite their TOS to make it one. Dropbox is indulging in handwaving.

Re: Dropbox Attempts To Kill Open Source Project

#138

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

Help me, I'm trying to get my head around this. You developed a file sharing system that allows anyone to obtain the full contents of a file by simply knowing its hash? Then when developers make tools to allow using this for simple cross-account file transfer you send DMCA takedown notices, claiming you are the rightful copyright holder of their code, to places like GitHub? You seem to equate other file transfer serv…

No DMCA takedown requests were sent to GitHub. We simply nicely asked the author of Dropship to take down the link and he fully understood our position and took the code down.

The only erroneous use of DMCA was when we attempted to take down the link on Dropbox, which was an entirely honest mistake.

Re: Dropbox Attempts To Kill Open Source Project

#139
post #119
post #41

Consider that maybe what's happening here is boring. Recognize that we all have a cognitive bias towards narratives, and especially interesting narratives. The discussion on this story is trying to build a narrative about Dropbox vs. open source developers. The real story is probably not that interesting. The CTO of a service as technically interesting as Dropbox certainly knows that he can't prevent the disclosure o…

Let's put this in context. Here's what I don't get: the DropShip code is just an exploit of the fundamental architecture flaw of cross-user content deduplication, revealed earlier this month [1]. As the closest thing to a resident security expert around here tptacek (at least to me, I find your comments very enlightening on the whole), how do you feel about a company dismissing an exploit when it's still just an idea…

I hope this point does not get lost in the shuffle. This whole issue is very much due to the fact that Dropbox did not handle the initial reporting of this problem when it was announced.

Their initial solution to the problem was updating the TOS and calling it a day. DropShip proved there was a deeper problem that needed to be addressed and the fact that their solution did not start and end with a fix to the problem in the code is mind-blowing. This isn't a huge enterprise company. These guys should know better.

Re: Dropbox Attempts To Kill Open Source Project

#140
post #108
post #56

Dropbox has a simple technical recourse to prevent de-duplication from being used for file sharing - issue a random challenge (a slightly more sophisticated version of "ok, what is the 100th word in the file?") before acknowledging a collision as a true duplicate. Edit: Thinking about this a bit more, the primary expense of this scheme would probably be accessing the file to verify the challenge results. Here's a que…

AIM used to ask for a cryptographic checksum of a randomly chosen byte range of the AIM executable. The Gaim (now Pidgin) developers had to set up a server that would return checksums on demand. This doesn't meet your requirement of the verifier needing a small key. Given that Dropbox apparently has no qualms about perjuring themselves in order to stop Dropship (or, as discussed in an earlier thread, lying about thei…

caveat utilitor.
Post reply on HN