Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

61–70 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#61
post #27

I'm pretty torn. On the one side, this was a realllly stupid mistake that should have been caught earlier, not by some external party who was kind enough to report it to them. I feel like the stakes should be raised a bit for companies who are keeping my data. On the other side, fear of lawsuits leads toward less disclosure and meaningless PR announcements.

I'm with you. I will point out that fear of lawsuits also leads to being more careful.

Re: Dropbox sued for June 19 Authentication Bug

#62

Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…

In America we do have a very litigious society.

In many cases it seems absurd. For some reason people believe that if something bad happens, someone is at fault. They expect 0% probability of anything bad happening and if they don't get that, they may sue.

I don't think anywhere in the world is like this. It's completely unrealistic. It's impossible.

And yet, at the end of the day, perhaps it forces our society to always be improving. Maybe our country is where it is today because we demand the impossible.

Re: Dropbox sued for June 19 Authentication Bug

#63
post #50

Earlier quoted context omitted.

Every developer makes mistakes, to err is human. With that understood, systems and processes should be designed to catch the errors early and hopefully long before they reach live. This is the insurance policy that TDD gives you, this is why you make all of those unit tests, functional tests, etc. I wouldn't sack a developer who did this, I'd look at my processes and ask why they didn't catch this. After all, if 1 de…

This is the insurance policy that TDD gives you, this is why you make all of those unit tests, functional tests, etc. TDD was discussed with Greg Wilson on a recent Stackexchange podcast ( http://blog.stackoverflow.com/2011/06/se-podcast-09/ ) and the (early) evidence seems to be that TDD does not improve quality: [...] while Test Driven Development is very popular right now, a survey of all of the studies that have…

I understand.

However I didn't claim it improved quality, just that it's an insurance policy.

What I mean by that, is that you pay up front in time, to help protect against things going wrong in future... such as shipping code to production that allows anyone to login to anyone else's account.

All unit tests are, are externalised asserts about what your code should and shouldn't do.

There should certainly have been one that said, "User A should not be able to login to User B's account.", or at the very least "Login should fail when the password is not right.".

My point remains: You should expect people to make errors from time to time, just like you expect servers to go down from time to time. Whilst you're busy handling what happens when servers fail, you should also be busy thinking about how to deal with human errors too... and that means detecting and catching those errors early so that the impact that they have is minimal.

Re: Dropbox sued for June 19 Authentication Bug

#64
post #2

I'm sorry, but good. When you respond to such a serious issue with anything less than an immediate email announcement to your entire userbase, and especially if your eventual announcement is an unapologetic, obscure blog post stating something like "that wasn't supposed to happen"/"that wasn't okay", you show that you care very little about the integrity and safety of your users' data.

I think in this case the critical issue was that they needed to focus 100% of their efforts on preventing the damage to those I emailed Dropbox asking if my account was accessed and they replied quickly saying no it wasn't. I think that's a perfectly good response.

A mistake was made, and 1 person made a terrible decision to take advantage of it. I hope we can all rally around Dropbox and cut them some slack so they can do all they can for these When they've resolved the crisis, then if you want to complain about them it'd be the time to do so. Right now I just hope they are doing everything they can for the seriously affected users, because if I was one of those users that's what I would want.

Re: Dropbox sued for June 19 Authentication Bug

#65
post #21
post #17

Earlier quoted context omitted.

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

I completely agree. Dropbox made a huge mistake. Dropbox is run by humans, and humans make mistakes, that's life. But when it came to communicate the issue they screwed up IMHO. I shouldn't need to subscribe to their blog RSS to know this kind of stuff. They should have mailed everyone, encouraging users to change their passwords right away while they investigated the issue.

I see the run by humans argument a lot, but what you need to keep in mind is that a company is NOT a human. No one's suing the individual employees here, but a company. There is a massive difference.

By their nature companies are entirely selfish (especially companies with outside investment) and unless you're going to hold the humans within a company individually responsible for a companies douchebaggery then by the same logic you also shouldn't give the company a break because it's run by humans.

Re: Dropbox sued for June 19 Authentication Bug

#66
post #8

Dropbox attitude towards users data, privacy and security has been troubling, and their responses have been less than comforting. They really need to do some good PR/branding exercises to make sure they dont continue, on what looks like a slippery slope to me.

For this reason, I think I'm jumping ship now and moving to Spideroak or Wuala.

Re: Dropbox sued for June 19 Authentication Bug

#67
post #58
post #37

According to the TOS, which all drop box users claimed of "reading and agreeing with" he's got no case ($100 at most) see https://www.dropbox.com/terms#terms Cloud brings risks, one shall be aware of it, and do the math of advantages/disadvantages. I will keep my dropbox account, despite that incident, and know deep in my heart that such glitch can happen to me as well, no matter how well my develop/test/deploy routi…

Most people don't read the terms of service, but they do read the marketing copy. If the marketing copy contradicts the terms of service, the contract should be based on the marketing copy. The terms of service should not be a license to make false or misleading marketing claims.

No, it should be what you agreed to regardless of whether you were too lazy to read it or not.

Re: Dropbox sued for June 19 Authentication Bug

#68

Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…

Reality matters. Details matter. You seem to have lost focus on them:

- Did Dropbox promise its customers that it had very good security?

- Did Dropbox thereby gain an advantage over its competitors?

- Did customers, trusting Dropbox, put private data on their servers?

- Was some of that data quite valuable, and was there quite a lot of it?

- And did Dropbox open a gaping security hole in their systems and then leave one hundred percent of that data exposed for hours? And did that constitute negligence?

From what little I know I'd say the answer is yes on all counts. But I'll concede that reasonable people might disagree, especially after a detailed investigation. Fortunately we have a mechanism for adjudicating significant disputes among reasonable people by conducting detailed investigations: It's called a court.

Now, what I don't know is: Do these events rise to the level where a legal remedy is called for? How big should the remedy be? And are Dropbox's terms of service, which every customer presumably clicked through at some point, going to protect them from being held liable for negligence? Heck if I know. I'm not a lawyer. Fortunately, lawyers are lawyers.

I can't understand why you've picked this particular case to freak out about. Why are you so alarmed to see a company which was, by all appearances, negligent and in breach of contract getting sued for negligence and breach of contract? What kind of surprise is this? It's like water flowing downhill. If a company "accidentally" appears to break a contract, the company has to explain itself. If it "accidentally" breaks the law, it gets taken to court to plead its case. And if it is found to have "accidentally" committed negligence, it gets held liable.

Yes, I know that it seems like an understandable mistake that could happen to any engineer. I feel for those folks. But this is the big leagues, and excuses are not what engineering is about. Engineering is about anticipating mistakes and designing safeguards, and when real engineers (as opposed to fake "software engineers" like myself) screw up a project badly enough a negligence suit is often the least of their problems. They lose licenses and sometimes even go to prison.

Fortunately, nobody appears to have been seriously injured and perhaps nobody will even lose their job. A corporation has been sued, and maybe it will pay. In the meantime, it will re-prioritize its backlog to include better automated testing. ;) This happens. Don't take it so personally. This is what being a corporation is all about. This is why corporations exist.

Re: Dropbox sued for June 19 Authentication Bug

#70
post #59

Earlier quoted context omitted.

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

It was hot enough to melt her genitals and cause serious disfigurement. If she had spilled it anywhere, she would have been seriously injured... The coffee was scalding hot. The temperature of the coffee was from a corporate order intended to save a few bucks on having to re-brew coffee. The McDonald's corporation was negligent. In this case, Dropbox was horribly negligent. Releasing all of the data in my Dropbox fol…

I think there's no question that Dropbox seriously dropped the ball, but as programmers we should be extremely concerned about the prospect of companies being held liable not just for actual damages but theoretically possible and potentially non-economic yet non-existent damages.
Post reply on HN