Live data from Hacker News

Dropbox Attempts To Kill Open Source Project

razorfast.com

251–260 of 323 posts

Re: Dropbox Attempts To Kill Open Source Project

#251
I've seen a lot of comments that misunderstand the DMCA. Many people seem fixated on this issue. Had I realized this would be the case I wouldn't have emphasized it as much.

It was an automatic email sent by mistake and was retracted by when discovered. It's certainly an issue worth mentioning and discussing but don't fixate on it.

Don't get me wrong, I was completely enraged when I received it but I think Dropbox has done well in addressing it.

Re: Dropbox Attempts To Kill Open Source Project

#252
post #108
post #56

Dropbox has a simple technical recourse to prevent de-duplication from being used for file sharing - issue a random challenge (a slightly more sophisticated version of "ok, what is the 100th word in the file?") before acknowledging a collision as a true duplicate. Edit: Thinking about this a bit more, the primary expense of this scheme would probably be accessing the file to verify the challenge results. Here's a que…

AIM used to ask for a cryptographic checksum of a randomly chosen byte range of the AIM executable. The Gaim (now Pidgin) developers had to set up a server that would return checksums on demand. This doesn't meet your requirement of the verifier needing a small key. Given that Dropbox apparently has no qualms about perjuring themselves in order to stop Dropship (or, as discussed in an earlier thread, lying about thei…

"* they could insert faked evidence of such crimes into the user's files, and then tip off the appropriate authorities. "

No need to fake it even - they could insert files which are illegal to posses into your Dropbox account, wait for you to sync them to some/all of your devices, then tip off the relevant authorities.

Keep in mind too, you're running their closed source application on your machine with at least the same privileges as your user account - if you don't trust them, you're already hosed. I have no way of knowing the Dropbox app on my laptop or iPhone isn't rummaging around my filesystem looking for interesting stuff and uploading it to their servers. The very feature that makes Dropbox so much more useful than, say, tarsnap or Tahoe or any of the many S3 backed cloud storage options, the fabulous filesystem integration - fundamentally giver their app an enormous amount of access to my system. If you really think Dropbox are crooks, you need to uninstall their software from every machine you care about, and change every password, key-pair, credit card number, and any other credentials those systems might have ever stored in the file system in a way that's readable by the user accou t the Dropbox app was running with, or for the truly paranoid, any piece of data the system has ever stored or accessed...

Re: Dropbox Attempts To Kill Open Source Project

#253
post #237

Am I the only one who finds it refreshing to see a business trying to protect itself with a friendly email rather than legal threats? Kudos to the Dropbox guys for walking that fine line with such finesse.

Yes. I think that's the only thing that's deserved to be said here.

People here should just relax, I'm sure there are many companies that deserve your rage but Dropbox is not one of them.

They simply asked me to take down the repository while they could work on blocking Dropship technically on the server side. No threats involved. This should be very good PR and many companies can learn from this.

Sure, trying to prevent people from writing/distributing programs that use a service in unexpected ways is pointless in the long run. If something is technically possible it will be done.

Hence, as some more validation is added, Dropbox will overall be a more secure service. In my opinion it was a feature instead of an exploit :) but hey, it's their service.

All the meanness flunged in this thread at either me or Dropbox is completely uncalled for.

Re: Dropbox Attempts To Kill Open Source Project

#255

  Dan DeFilippi: "In my unhumble opinion censorship is never an option."
Dan DeFilippi would certainly not like it if all his documents and code from his personal hard drive were splashed across the internet.

What he considers "censorship", another person would call "not pushing someone in front of a train". He knows full well that (a) Dropbox is a pretty friendly company with reasonable people solving a real problem and (b) the RIAA and MPAA are NOT friendly and NOT reasonable.

This linkbait title ("kill open source project") is the equivalent of police going after students for bike tickets while avoiding the dangerous parts of town. Dan DeFilippi is going after the good citizen (Dropbox) for the minor philosophical crime of not supporting everything that calls itself "open source", while completely lacking the balls to actually take on the real bad guys here, namely the RIAA and MPAA's real lawsuits.

Indeed, even if he did set up his own torrent server, they'd ignore him for a while. Dropbox has financial resources, so they'd actually be the target. So DeFilippi is getting behind them and trying to push them in a fight that is certainly NOT one they want to engage in, without taking any personal risk himself. Not particularly ethical, IMHO.

Re: Dropbox Attempts To Kill Open Source Project

#256
post #21

This is Arash from Dropbox. We removed the ability to share the project source code because it enables communications with our servers in a manner that is a violation of our Terms of Service. By our TOS, we reserve the right to terminate the account of users in this case. However, we chose to remove access to the file instead of terminating the account of the user. We recently built a tool that allows us to ban links…

Guess its time to drop Dropbox, so to speak, and move definitely to UbuntuOne

Re: Dropbox Attempts To Kill Open Source Project

#257
post #97

Earlier quoted context omitted.

> Yes, they tried to kill an open source product, whose purpose was to facillitate illegal file sharing over DropBox. Where are you getting that information? My understanding it that its purpose was explicitly to facilitate legal file sharing over DropBox - Linux ISOs, for example.

Linux ISOs are always the example people come up with when they're defending protocols and methods which are primarily used for illegal purposes. The original post for DropShip gave, as an example, the trailer for a movie. Not the movie itself, but the trailer. That's the equivalent of saying "I've developed this great way to share files, such as videos, but am not going to explicitly say that it could be used for pi…

Stop trying to second-guess my motives. I used that trailer because it was:

- a nicely sized file, consisting of multiple 4MB blocks but not overly huge

- already available on the network

- free to distribute (yes, that movie is free to distribute, so the trailer certainly is)

- apart from that, the blender foundation is simply awesome

I could also have used something like the tar archive of the source code or a photo, but this proved that it works for multiple blocks...

Re: Dropbox Attempts To Kill Open Source Project

#258
post #192
post #61

Earlier quoted context omitted.

You do realize that Dropbox submitted the DMCA request under penalty of perjury, and that if it was in fact incorrect Dropbox has perjured themselves?

Dropbox did not send a takedown request. They (erroneously) claimed they had received one from a third party which is not perjury.

[deleted]

Re: Dropbox Attempts To Kill Open Source Project

#259
post #189

Earlier quoted context omitted.

> Can Drew/Arash clarify what Terms were being violated actually by dropship? http://www.dropbox.com/dmca#terms Access, tamper with, or use non-public areas of the Site (including but not limited to user folders not designated as 'public' or that you have not been given permission to access), Dropbox's computer systems, or the technical delivery systems of Dropbox's providers; Attempt to access or search the Site, Co…

yes, but that has nothing to do with having the code, as I said in a port below... using it would be a violation, but why block open source code.

Even I am struggling to understand how exactly did this violate ToS? Was it "illegal code/file"? No! It was a file to a s/w that had the potential to be used maliciously, but the file uploaded itself wasn't, but hadn't really manifested in that form (yet). I feel asking the dev to take down the Github project is ok, but blocking/restricting access to the file itself, until proven malicious was a bad idea. And if that part about taking down the HN is true, its a dick move. Yes, its their platform and from an ethical stand point, being proactive this way helps everyone, but it could have been handled better.

Re: Dropbox Attempts To Kill Open Source Project

#260

Earlier quoted context omitted.

You're done using something you don't use because they _asked_ someone to do something (rather than taking the industry standard approach of getting lawyers involved)?

What would they be able to do with their lawyers? There is no case.

Harassing people can be pretty effective. (I'd say "ask Sony", but they might have actually won.)
Post reply on HN