Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

41–50 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#41

Would the "Limitations on Liability" section on their TOS help them in this case? FREE ACCOUNT HOLDERS: YOU AGREE THAT THE AGGREGATE LIABILITY OF DROPBOX TO YOU FOR ANY AND ALL CLAIMS ARISING FROM THE USE OF THE SITE, CONTENT, FILES AND/OR SERVICES IS LIMITED TO TWENTY ($20) U.S. DOLLARS. THE LIMITATIONS OF DAMAGES SET FORTH ABOVE ARE FUNDAMENTAL ELEMENTS OF THE BASIS OF THE BARGAIN BETWEEN DROPBOX AND YOU. PREMIUM A…

I'd love to hear a professional chime in here. Does adding this to your Terms of Service actually have an impact?

If the answer is yes, why are the woman and her lawyer suing Dropbox anyway?

And if no, why do most Terms of Service include similar wording?

Re: Dropbox sued for June 19 Authentication Bug

#42
post #37

According to the TOS, which all drop box users claimed of "reading and agreeing with" he's got no case ($100 at most) see https://www.dropbox.com/terms#terms Cloud brings risks, one shall be aware of it, and do the math of advantages/disadvantages. I will keep my dropbox account, despite that incident, and know deep in my heart that such glitch can happen to me as well, no matter how well my develop/test/deploy routi…

I've always wondered if these really work. We all use these EULAs and TOS that essentially say "you can't sue us for anything no matter what!" but I have a feeling that kind of thing doesn't actually hold up in court.

Re: Dropbox sued for June 19 Authentication Bug

#43
post #42
post #37

According to the TOS, which all drop box users claimed of "reading and agreeing with" he's got no case ($100 at most) see https://www.dropbox.com/terms#terms Cloud brings risks, one shall be aware of it, and do the math of advantages/disadvantages. I will keep my dropbox account, despite that incident, and know deep in my heart that such glitch can happen to me as well, no matter how well my develop/test/deploy routi…

I've always wondered if these really work. We all use these EULAs and TOS that essentially say "you can't sue us for anything no matter what!" but I have a feeling that kind of thing doesn't actually hold up in court.

I am neither a judge nor a lawyer, yet, can assume, most of us simply lie when we click on "Yes, I have read, understand and agree to the terms!" buttons.

None of us read them (most of us TBMA), but we "sign this contract"

Re: Dropbox sued for June 19 Authentication Bug

#44
post #40

Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…

>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…

Okay, okay. I don't claim to be an expert on that case.

But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well).

I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a car. Why is there no applied concept of common sense?

Leaving the whole cause of the accident aside, the next part was really emphasized my point:

The jury gives you millions for 'damage'. Let's not discuss if the problem was the person sueing, but what you have to think about is this:

What message are you sending out, if someone suing a company for (arguably only) slightly irritating service (a couple degrees ~too~ hot, usability issues with a coffee cup, both probably annoying but didn't completely destroy the tiny rest of that company's customers..) could get you the FU money this community is often obsessed about? If you asked for the money on day one of the trial or made the jury feel so sorry for you that they drown you in money at the end is not relevant.

Which leads to my first post again: A culture of fear for being sued, with damages completely out of proportion [1].

1: In a large area of the world. I understand that it can seem completely normal if you limit your view to the area where this is happening.

Re: Dropbox sued for June 19 Authentication Bug

#45
IANAL but an advantage of this lawsuit is that Dropbox will be forced to disclose in greater detail what happened, and we will be able to determine if the "1% of accounts possibly compromised" really was that low (it probably was, but given the seriousness of the bug, and their tendency to downplay this, confirmation would be good). As it stands currently, users are forced to rely on scant information released by Dropbox.

Re: Dropbox sued for June 19 Authentication Bug

#46
post #40

Earlier quoted context omitted.

>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

And at the same time a culture, where you can sue if someone hurt you, and even set a precedent if it's a first-time thing.

Re: Dropbox sued for June 19 Authentication Bug

#47
post #40

Earlier quoted context omitted.

>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

> If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well).

McDonald's keeps coffee at >82°C, which is much hotter than any coffee served elsewhere.

Re: Dropbox sued for June 19 Authentication Bug

#48
post #35
post #21

Earlier quoted context omitted.

I completely agree. Dropbox made a huge mistake. Dropbox is run by humans, and humans make mistakes, that's life. But when it came to communicate the issue they screwed up IMHO. I shouldn't need to subscribe to their blog RSS to know this kind of stuff. They should have mailed everyone, encouraging users to change their passwords right away while they investigated the issue.

Why change their passwords? Isn't that FUD?

Yes and no :-) What else could a user do once damage is done? (before they started investigating, but after the fix was pushed)

Re: Dropbox sued for June 19 Authentication Bug

#49
post #47

Earlier quoted context omitted.

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

> If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). McDonald's keeps coffee at >82°C, which is much hotter than any coffee served elsewhere.

The jury's still out on that...

http://ben.sh/Coffee.png

Re: Dropbox sued for June 19 Authentication Bug

#50
post #31

I wonder if the developer who caused the bug got fired. As a developer, this is one of the few nightmares I get at night :) (making a small change and bringing every thing down)

Every developer makes mistakes, to err is human.

With that understood, systems and processes should be designed to catch the errors early and hopefully long before they reach live.

This is the insurance policy that TDD gives you, this is why you make all of those unit tests, functional tests, etc.

I wouldn't sack a developer who did this, I'd look at my processes and ask why they didn't catch this. After all, if 1 developer can push low quality code to production, then they all can.

The problem isn't with the developer... as with everything in the cloud, expect failure and design to handle it. Sometimes the failure is human, so design to handle that too.

Post reply on HN