Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

1–10 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#2
I'm sorry, but good. When you respond to such a serious issue with anything less than an immediate email announcement to your entire userbase, and especially if your eventual announcement is an unapologetic, obscure blog post stating something like "that wasn't supposed to happen"/"that wasn't okay", you show that you care very little about the integrity and safety of your users' data.

Re: Dropbox sued for June 19 Authentication Bug

#3
This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access.

But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts.

Why sue them? It's just going to disrupt a very good service. It's not going to help them recover (I'm sure they've already learned heavily from the mistake.)

Re: Dropbox sued for June 19 Authentication Bug

#4
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

>>they're still a startup

That sounds very troubling to me. When it comes to user data/privacy, how does being a startup vs a huge corporation make any difference?

Besides, a company with tens of millions of users and billion dollar valuation is not really a startup anyway, if at all that matters.

I love dropbox and use it every single day on so many devices, but I did feel violated by this fiasco.

Re: Dropbox sued for June 19 Authentication Bug

#5
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

Even though I don't like frivolous lawsuits, it's way too early to say there's no legal basis for the claim.

Re: Dropbox sued for June 19 Authentication Bug

#6
Shouldn't someone have to show actual damages in order to sue? The California Unfair Competition Act seems to be about unlawful, unfair or fraudulent business practices - I don't immediately see how that is relevant.

My guess is this is going to just force Dropbox into some kind of settlement because it will be cheaper than fighting it. And the lawyers promoting this get a nice cut, of course.

Does corporate insurance cover this sort of thing? How does a company protect itself from these kind of lawsuits?

Re: Dropbox sued for June 19 Authentication Bug

#7
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

...they're still a startup...

What? Is this an excuse? They charge money for the service and they will pay for their mistakes.

Re: Dropbox sued for June 19 Authentication Bug

#8
Dropbox attitude towards users data, privacy and security has been troubling, and their responses have been less than comforting. They really need to do some good PR/branding exercises to make sure they dont continue, on what looks like a slippery slope to me.

Re: Dropbox sued for June 19 Authentication Bug

#9
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

...they're still a startup... What? Is this an excuse? They charge money for the service and they will pay for their mistakes.

Yes, they'll pay for this mistake through bad press and lost customers.

A punitive lawsuit isn't going to improve anything in terms of making sure they don't do it again.

Re: Dropbox sued for June 19 Authentication Bug

#10
post #9

Earlier quoted context omitted.

...they're still a startup... What? Is this an excuse? They charge money for the service and they will pay for their mistakes.

Yes, they'll pay for this mistake through bad press and lost customers. A punitive lawsuit isn't going to improve anything in terms of making sure they don't do it again.

>>A punitive lawsuit isn't going to improve anything in terms of making sure they don't do it again.

What's stopping us to say the exact thing in defense of any xyz alleged offender?

Post reply on HN