Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

11–20 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#11
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

> This is a ridiculous response, and one which seems very ungrounded in the law.

What is the basis of such assertion? Let the courts decide that if the basis is unfounded or not.

> But, they're still a startup.

This is no excuse, if you charge money for your services AND claim to be military grade secure with respect to data. https://www.dropbox.com/security

> There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts.

They took 4 hours to know entire dropbox was accessible to everyone, and tried to sweep the incident under the rug by not emailing the issue to users.

> Why sue them? It's just going to disrupt a very good service. It's not going to help them recover (I'm sure they've already learned heavily from the mistake.)

Because they are not entitled to be on the goodside of the user, which unacceptably bad handling of the situation. They, like everyone else, are not entitled to anything, other than what is contracted. You screw users, you get screwed. It is as simple as that.

Re: Dropbox sued for June 19 Authentication Bug

#12
Any company with even a small amount of success will be sued for any public mistake, whether it violates the law or not - especially if you're open and transparent about what happened and why.

Class-action trolls, like patent trolls, are just another business risk.

Re: Dropbox sued for June 19 Authentication Bug

#13

Any company with even a small amount of success will be sued for any public mistake, whether it violates the law or not - especially if you're open and transparent about what happened and why. Class-action trolls, like patent trolls, are just another business risk.

Sure they were transparent? They didn't say what the bug was, how it was introduced, what they are doing to stop it happening again. They didn't email all their customers immediately.

Re: Dropbox sued for June 19 Authentication Bug

#14
post #13

Any company with even a small amount of success will be sued for any public mistake, whether it violates the law or not - especially if you're open and transparent about what happened and why. Class-action trolls, like patent trolls, are just another business risk.

Sure they were transparent? They didn't say what the bug was, how it was introduced, what they are doing to stop it happening again. They didn't email all their customers immediately.

No, I'm not sure they were all that transparent.

I'm sure that in this situation and legal climate, the only way they could've potentially avoided a lawsuit was to try and keep it quiet (to the detriment of their user base.)

Sadly, doing the right thing just makes you a target.

Re: Dropbox sued for June 19 Authentication Bug

#15
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

> This is a ridiculous response, and one which seems very ungrounded in the law. What is the basis of such assertion? Let the courts decide that if the basis is unfounded or not. > But, they're still a startup. This is no excuse, if you charge money for your services AND claim to be military grade secure with respect to data. https://www.dropbox.com/security > There's no SLA. They responded quickly, fixed the bug as…

[deleted]

Re: Dropbox sued for June 19 Authentication Bug

#16
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

> This is a ridiculous response, and one which seems very ungrounded in the law. What is the basis of such assertion? Let the courts decide that if the basis is unfounded or not. > But, they're still a startup. This is no excuse, if you charge money for your services AND claim to be military grade secure with respect to data. https://www.dropbox.com/security > There's no SLA. They responded quickly, fixed the bug as…

That website describes their storage security measures. It doesn't cover this type of incident and doesn't guarantee there will never be a bug in a code push.

Fact is: if you don't like their security measures, don't use the service. Suing them is a cheap disgusting money-grab that is far too prevalent in this country (cough cough hot coffee cough).

Stop being such a victim. You have to assume a startup growing as fast as Dropbox is will have its growing pains, just like Facebook did. If that troubles you, store your files some other way.

Re: Dropbox sued for June 19 Authentication Bug

#17
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

Re: Dropbox sued for June 19 Authentication Bug

#18
post #9

Earlier quoted context omitted.

...they're still a startup... What? Is this an excuse? They charge money for the service and they will pay for their mistakes.

Yes, they'll pay for this mistake through bad press and lost customers. A punitive lawsuit isn't going to improve anything in terms of making sure they don't do it again.

How do you know? (Note that the point of a punitive lawsuit is not only to encourage the culprit not to do it again, but also to encourage other potential culprits not to do it again.)

I guess the answer is "because it was just a mistake", but (1) not informing their customers promptly when they found they'd made a disastrous security screwup wasn't just a mistake, and (2) since they themselves say they're improving their procedures in response to the incident, it seems clear that there are things they could have done that would have either avoided the just-a-mistake or mitigated its consequences.

Re: Dropbox sued for June 19 Authentication Bug

#19
post #17
post #3

This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

She was not mailed because there was no access to her account or did I read it wrong that everyone whose account was accessed was mailed?

What should they have told her? "Someone could have accessed your account in the last few hours due to a bug, but that didn't happen. Nothing to worry about!"

Re: Dropbox sued for June 19 Authentication Bug

#20
This is a valid response if you ask me.

There is a culture of half-arsedness with some businesses where they don't respect user's security and privacy requirements. This is partially down to plain old incompetance but in my experience it's usually down to the fact that if doing something properly and testing it properly doesn't add business value, then it's not done. At the risk of pissing people off here; that culture is prevalent amongst startups.

They screwed up, they're getting sued. They should have tested it properly.

If this was a public organisation that left everyone's files in an open skip overnight they'd get sued too.

Post reply on HN