Live data from Hacker News

Dropbox Attempts To Kill Open Source Project

razorfast.com

201–210 of 323 posts

Re: Dropbox Attempts To Kill Open Source Project

#201

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

we've fixed the deduplication behavior serverside to prevent "injection" of files you don't actually have, for a variety of reasons I think this was a good call, and not just for the piracy issues but for the substantial information disclosure and possible misappropriation of sensitive documents that it could have facilitated. This is something that's been on my radar for some months, and frankly seemed like a signif…

> ... the substantial information disclosure and possible misappropriation of sensitive documents that it could have facilitated

They match duplicate files with an SHA256 sum and size in bytes. With those two factors, the probability of a collision is incredibly tiny and impossible to exploit usefully. If you tried a trillion combinations you might find a useless file, but by then you would be detected and banned from Dropbox.

Re: Dropbox Attempts To Kill Open Source Project

#202

Earlier quoted context omitted.

Which is great, except you are punishing the crime, before it even occurred. This is pretty disingenuous. You really think their assumption that Dropship would quickly turn Dropbox into an illegal file sharing haven is an unrealistic grasping of straws?

As mentioned before, IANAL, and I do not have deep/any knowledge of the laws Dropbox is incorporated in. However, "Presumption of Innocence" ( http://en.wikipedia.org/wiki/Presumption_of_innocence ) aka "Innocent until proven guilty" is one of the universally applied (if not, also accepted), legal concept. Can dropship be used for illegal file sharing? Yes. Is dropship being used for illegal file sharing? No, until p…

That's not how the presumption of innocence works. I say that as someone who has practiced both civil and criminal law. Presumption of innocence only applies to crimes. Copyright violations are not crimes, they are civil torts. (Though some actions incident to copyright violations, i.e., circumventing DRM, can be crimes.)

Can dropshiip be used for illegal fire sharing? YES, in fact, that was the suggested and intended use. Under American case law, which governs Dropbox, that alone is enough to constitute a DMCA violation (see, e.g. Napster, Kazaa, and succeeding cases).

Dropbox took dropship down to prevent future legal issues. Since it's their service, they don't have to wait until they occur actual legal liability to act.

Re: Dropbox Attempts To Kill Open Source Project

#203
post #103

Isn't the so called DMCA take down notice in this example not just a notification for the user that Dropbox received such a take down notice and not a DMCA takedown notice?

Shhh. You're spoiling everyone's fun. How can you expect me to get all worked up about a notice about a non-existent notice?

Re: Dropbox Attempts To Kill Open Source Project

#204
post #193
post #138

Earlier quoted context omitted.

No DMCA takedown requests were sent to GitHub. We simply nicely asked the author of Dropship to take down the link and he fully understood our position and took the code down. The only erroneous use of DMCA was when we attempted to take down the link on Dropbox, which was an entirely honest mistake.

I'm pretty sure sending fake DMCA requests is illegal, and it doesn't matter if it's a mistake.

It's illegal only if it was intentional. A mistakenly sent DMCA request is okay, as long as the sender follows up with a disregard notice.

Re: Dropbox Attempts To Kill Open Source Project

#205

Earlier quoted context omitted.

Which is great, except you are punishing the crime, before it even occurred. This is pretty disingenuous. You really think their assumption that Dropship would quickly turn Dropbox into an illegal file sharing haven is an unrealistic grasping of straws?

As mentioned before, IANAL, and I do not have deep/any knowledge of the laws Dropbox is incorporated in. However, "Presumption of Innocence" ( http://en.wikipedia.org/wiki/Presumption_of_innocence ) aka "Innocent until proven guilty" is one of the universally applied (if not, also accepted), legal concept. Can dropship be used for illegal file sharing? Yes. Is dropship being used for illegal file sharing? No, until p…

The Internet IS being used for illegal file sharing. Should we take it down? No! Classic baby/bathwater.

Re: Dropbox Attempts To Kill Open Source Project

#206

Earlier quoted context omitted.

Which is great, except you are punishing the crime, before it even occurred. This is pretty disingenuous. You really think their assumption that Dropship would quickly turn Dropbox into an illegal file sharing haven is an unrealistic grasping of straws?

As mentioned before, IANAL, and I do not have deep/any knowledge of the laws Dropbox is incorporated in. However, "Presumption of Innocence" ( http://en.wikipedia.org/wiki/Presumption_of_innocence ) aka "Innocent until proven guilty" is one of the universally applied (if not, also accepted), legal concept. Can dropship be used for illegal file sharing? Yes. Is dropship being used for illegal file sharing? No, until p…

I downvoted you because you are discussing DropBox as though it is a public utility that you have a right to, and some form of due process needs to take place. In my mind, you are completely and absolutely missing the point.

DropBox is a private company, whose behavior should be viewed based on what their ToS are, and how they stick to them.

They don't have to prove anything - if one is engaging in behavior, or taking action that jeopardizes Drop Box as a service, or as a company, something they have worked really, really hard for, their rational response is to shut down the person engaging in that behavior.

What DropBox is saying is that regardless of whether you think they should become the next RapidShare, or BitTorrent - that's not a business they are interested in - regardless of whether you think you might have some excuse as to why your behavior hasn't proven to be illegal file sharing.

These are not legal penalties. This is not about the Law. Drop Box is not the government. They do have the right to refuse service, and, in fact, to shut down uses of their service that they are not comfortable with.

I think another reason why you are getting down voted is that a lot of the people on YC have worked really, really, really hard to build these types of services, and get frustrated when people fundamentally don't get it.

Re: Dropbox Attempts To Kill Open Source Project

#207
post #79

Earlier quoted context omitted.

It is a shame your developers allowed you to commit perjury in such an automated fashion. With all due respect to you and your company (and while I fully support your right to invoke your TOS to take down content within your own service) I'd actually love to see one of the people you DMCA'd slam you on that aspect of this situation legally if for no other reason than to make other companies think twice (or three time…

Go back and reread the article. The recipient of the supposed takedown notice is listed as being... dropbox.

That's interesting: how could Dropbox be the recipient if their system is automated as stated by the founders?

Re: Dropbox Attempts To Kill Open Source Project

#208

drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the inte…

Asking people to remove stuff from HN? That's utter bullshit, and if true, I'm basically done with Dropbox. Asking people not to talk about something (with access to your service as the gun to their heads) is not something I will tolerate in someone I do business with. I don't actually use Dropbox for anything, though, so perhaps my thoughts don't matter.

You're done using something you don't use because they _asked_ someone to do something (rather than taking the industry standard approach of getting lawyers involved)?

Re: Dropbox Attempts To Kill Open Source Project

#209

Most interesting comment to that article: Thankfully all DMCA requests are filed under penalty of perjury. If he claims that he owns the copyright to material he doesn’t own, he has now opened himself up to civil litigation. Really. Seems so: http://www.aaronkellylaw.com/Internet-Law-and-Intellectual-P...

Not an invalid DMCA request, even assuming one was sent out.

Copyright applies to original and derivative works, though multiple parties may own copyrights to a derivative work.

In America, derivative works include software programs which are inseparably reliant on code or features (including APIs) of another program. It's basically the same argument that WordPress and Drupal make in regard to themes, plugins, etc., falling under the same open source licenses (i.e., copyrights) as the platforms themselves.

In this case, dropship is entirely reliant on unique features of Dropbox. This makes it a derivative work, and would mean that Dropbox has copy rights over dropship. The programmer of dropship also has copyrights over dropship to the extent that the code is an original work, but Dropbox's rights trump his b/c they own the rights to the original underlying work.

Re: Dropbox Attempts To Kill Open Source Project

#210
post #119
post #41

Consider that maybe what's happening here is boring. Recognize that we all have a cognitive bias towards narratives, and especially interesting narratives. The discussion on this story is trying to build a narrative about Dropbox vs. open source developers. The real story is probably not that interesting. The CTO of a service as technically interesting as Dropbox certainly knows that he can't prevent the disclosure o…

Let's put this in context. Here's what I don't get: the DropShip code is just an exploit of the fundamental architecture flaw of cross-user content deduplication, revealed earlier this month [1]. As the closest thing to a resident security expert around here tptacek (at least to me, I find your comments very enlightening on the whole), how do you feel about a company dismissing an exploit when it's still just an idea…

Ouch, I hope this isn't all my fault...

http://news.ycombinator.com/item?id=2440066

(note, the solution Dropbox should have implemented instead of fake-lawyering up was offered very quickly there...)

Post reply on HN