Earlier quoted context omitted.
> If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). McDonald's keeps coffee at >82°C, which is much hotter than any coffee served elsewhere.
The jury's still out on that... http://ben.sh/Coffee.png
Dropbox sued for June 19 Authentication Bug
71–80 of 123 posts
Re: Dropbox sued for June 19 Authentication Bug
#72Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…
Reality matters. Details matter. You seem to have lost focus on them: - Did Dropbox promise its customers that it had very good security? - Did Dropbox thereby gain an advantage over its competitors? - Did customers, trusting Dropbox, put private data on their servers? - Was some of that data quite valuable, and was there quite a lot of it? - And did Dropbox open a gaping security hole in their systems and then leave…
I don't think I've lost my touch on reality. Details? Maybe. I'm also not proposing that Dropbox didn't do something stupid.
But why would you sue? Because someone told you that your data ~could've~ been potentially accessed? I'm not against calling a lawyer in general. But these kinds of (class action) cases regularly look like [Note: Still firmly anchored in reality here. Maybe just in a different culture..] witch hunts to me personally. Like angry/annoyed mobs.
Again: Note that I don't say "these people have no right to sue" nor "the people in this particular case are equivalent to a medieval party of farmers with torches and improvised weapons". This whole thread is mostly "Why oh why?" and less "You're doing it wrong".
In the end I really like edw's comment further down in this thread:
"I think there's no question that Dropbox seriously dropped the ball, but as programmers we should be extremely concerned about the prospect of companies being held liable not just for actual damages but theoretically possible and potentially non-economic yet non-existent damages."
Re: Dropbox sued for June 19 Authentication Bug
#73Re: Dropbox sued for June 19 Authentication Bug
#74Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…
At some point in the last 50 years the US has developed a significant subculture of lawyer-worship. It's not unusual to see commercials hourly on TV asking for people who might have suffered in one way or another to contact a law firm for a lawsuit. Lawyers find "little people" who have been wronged, sue in court, pocket millions, then go on to the next case. Effective lawyers make a killing at this business, and don…
It's the same reason "mesothelioma" was the most expensive keyword on Google.
Re: Dropbox sued for June 19 Authentication Bug
#75Earlier quoted context omitted.
Reality matters. Details matter. You seem to have lost focus on them: - Did Dropbox promise its customers that it had very good security? - Did Dropbox thereby gain an advantage over its competitors? - Did customers, trusting Dropbox, put private data on their servers? - Was some of that data quite valuable, and was there quite a lot of it? - And did Dropbox open a gaping security hole in their systems and then leave…
Somehow this thread of mine got larger than I imagined. I don't think I've lost my touch on reality. Details? Maybe. I'm also not proposing that Dropbox didn't do something stupid. But why would you sue? Because someone told you that your data ~could've~ been potentially accessed? I'm not against calling a lawyer in general. But these kinds of (class action) cases regularly look like [Note: Still firmly anchored in r…
A potential settlement in this Dropbox case could be: Dropbox pays off the lawyers (of course) but also agrees to hire a Chief Security Officer and submit to quarterly security audits by an outside company for the next year.
In the absence of a strong government consumer protection bureau, the class action lawsuit is one of the primary ways Americans force corporations to take responsibility for their actions.
Re: Dropbox sued for June 19 Authentication Bug
#76I wonder if the developer who caused the bug got fired. As a developer, this is one of the few nightmares I get at night :) (making a small change and bringing every thing down)
Re: Dropbox sued for June 19 Authentication Bug
#77This is a ridiculous response, and one which seems very ungrounded in the law. Dropbox made a mistake—a big one. They pushed bad code to production that allowed for unauthenticated account access. But, they're still a startup. There's no SLA. They responded quickly, fixed the bug as soon as they caught it, and have been thorough in investigating any unauthorized access of accounts. Why sue them? It's just going to di…
So what?
Aww... the cute widdle startup gets the bar lowered for them because we love startups here on HN?
Re: Dropbox sued for June 19 Authentication Bug
#78Sure, in the latter example people could get killed, but a big security error with Dropbox could also lead to serious personal damage (personal health documents published, business confidentiality breached, etc, etc).
It seems like people don't understand that building a "structure" in the software world should be the same as building a "structure" in the real world. Would you not sue the safe company that produced a safe that just opened by itself the day you were robbed (leading to theft of personal important documents, money, jewelry). Would you not sue the produced of an over-heating oven that leads to your house burning down?
Why do people assume that it is acceptable to make mistakes in the software world, but not in the "physical" world? Maybe this points towards some kind of basic problem with the software/web business model. Maybe all these free/premium product are really too cheap (and can be so cheap because they are inadequately produced). Maybe we need to accept that these ship-quickly products are not really acceptable, that there really needs to be considerable investment into such products (and thus increasing prices)...
Note: I do understand that nobody would accept a 50/50 % chance-of-breaking bridge, but may very well accept a 50/50 % chance-of-being-breached "Dropbox". But then don't advertise differently.
Re: Dropbox sued for June 19 Authentication Bug
#79Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…
Re: Dropbox sued for June 19 Authentication Bug
#80Earlier quoted context omitted.
>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…
Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…