Live data from Hacker News

Dropbox sued for June 19 Authentication Bug

consumeraffairs.com

81–90 of 123 posts

Re: Dropbox sued for June 19 Authentication Bug

#81
post #59

Earlier quoted context omitted.

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

It was hot enough to melt her genitals and cause serious disfigurement. If she had spilled it anywhere, she would have been seriously injured... The coffee was scalding hot. The temperature of the coffee was from a corporate order intended to save a few bucks on having to re-brew coffee. The McDonald's corporation was negligent. In this case, Dropbox was horribly negligent. Releasing all of the data in my Dropbox fol…

How do you heat liquid water to more than 100°C? Coffee is supposed to be just below 100°C when you brew it, or it is not good. Goes for home made or McD coffee. Whatever, maybe in some parts of the world, the laws of physics don't apply and liquid water does not lose energy though evaporation...

Back on topic: Dropbox is telling everybody that they are "encrypting" stuff on their drives. How do they decrypt without a password? This case is a much different from the "stupid McD coffee customer" case, because details on cloud storage technicalities are not common knowledge, whereas "boiling water may be hot" kinda is.

Re: Dropbox sued for June 19 Authentication Bug

#82
post #52
post #42

Earlier quoted context omitted.

I've always wondered if these really work. We all use these EULAs and TOS that essentially say "you can't sue us for anything no matter what!" but I have a feeling that kind of thing doesn't actually hold up in court.

It doesn't that's why they have: > Severability > In the event that any provision of these Terms of Service is held to be invalid or unenforceable, the remaining provisions of these Terms of Service will remain in full force and effect. In Australia, Europe and the UK, there are laws that make "unfair" clauses unenforceable... where unfair includes all kinds of things you see in every consumer level contract like no…

In the UK the legislation is 'the unfair contract terms act 1977'. http://www.legislation.gov.uk/ukpga/1977/50 Also, the case law suggests that if you are providing a professional service your appointment should make it clear that you will take 'reasonable skill and care' in carrying out the services otherwise you will be judged as to whether the service you have provided is 'fit for purpose' which is a much harder test to pass. I dont know if this test would apply to SAAS T&C's and IANAL by the way. Edit: Clarity & Bad grammar.

Re: Dropbox sued for June 19 Authentication Bug

#83
post #19
post #17

Earlier quoted context omitted.

If you see the OP, the woman behind the lawsuit seems angry that she had to find out about it in the news rather than with Dropbox informing her. That is a serious mistake and one that Dropbox should take heat for. Bugs happen but not communicating to users was a deliberate move.

She was not mailed because there was no access to her account or did I read it wrong that everyone whose account was accessed was mailed? What should they have told her? "Someone could have accessed your account in the last few hours due to a bug, but that didn't happen. Nothing to worry about!"

Yes.

Re: Dropbox sued for June 19 Authentication Bug

#84

Any company with even a small amount of success will be sued for any public mistake, whether it violates the law or not - especially if you're open and transparent about what happened and why. Class-action trolls, like patent trolls, are just another business risk.

Dropbox is being sued for not being open and honest about it.

Re: Dropbox sued for June 19 Authentication Bug

#86

Earlier quoted context omitted.

Reality matters. Details matter. You seem to have lost focus on them: - Did Dropbox promise its customers that it had very good security? - Did Dropbox thereby gain an advantage over its competitors? - Did customers, trusting Dropbox, put private data on their servers? - Was some of that data quite valuable, and was there quite a lot of it? - And did Dropbox open a gaping security hole in their systems and then leave…

Somehow this thread of mine got larger than I imagined. I don't think I've lost my touch on reality. Details? Maybe. I'm also not proposing that Dropbox didn't do something stupid. But why would you sue? Because someone told you that your data ~could've~ been potentially accessed? I'm not against calling a lawyer in general. But these kinds of (class action) cases regularly look like [Note: Still firmly anchored in r…

we should be extremely concerned about the prospect of companies being held liable not just for actual damages but theoretically possible and potentially non-economic yet non-existent damages

Well, perhaps if they are held liable for unreasonable sums, and that decision survives appeal, I'll be concerned. But nobody has held anything yet. The issue has gone to court.

Witch hunt? Angry mob? The issue is in court. That is the complete opposite of an angry mob.

How, exactly, are people supposed to seek redress if they have signed a contract with Dropbox, the contract was breached, and they were dissatisfied with the response? If they shouldn't go to court and file suit, what should they do? Bribe the czar's ministers? Recruit their relatives and start an old-fashioned Kentucky feud, complete with snipers and ambushes? Start an astroturf campaign of character assassination on Twitter?

And, again, this isn't some patent troll seeking a quick settlement.

Re: Dropbox sued for June 19 Authentication Bug

#87
post #40

Earlier quoted context omitted.

>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…

Okay, okay. I don't claim to be an expert on that case. But: If you buy coffee, it's hot enough to hurt you (or it's crap. There's a range of temperatures that are decent, and personal factors determine what is deemed too hot as well). I don't buy the 'had to put between the legs to open the cup' thing. In that case don't do it near your private parts, open it properly. Not between your legs, probably sitting in a ca…

    If you buy coffee, it's hot enough to hurt you
No, that's not true - it depends on where you buy it from and what their policy on coffee temperature is.

And I don't know if you bought coffee from McDonalds, but at some point they used to serve coffee in containers made out of a thick layer of cellulose (from what I could see) which wasn't leaking any heat; giving you absolutely no clue whatsoever to how hot or cold the coffee was just by holding it. Think about that for a second - when you're holding a glass with hot tea or coffee, you can feel it in your hand. But what if that glass was cold as if holding iced tea?

Yes, I got burned too, but not as badly as to suffer 3rd degree burns and I still buy coffee from McD. But I imagine I would get pretty pissed too above a certain threshold.

Re: Dropbox sued for June 19 Authentication Bug

#88
post #40

Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…

>braindead users don't get the concept of 'hot coffee' and it's your fault The coffee was served hotter than it should have been, and wastely hotter than it would have been if it had been taken from the machine at home, it was served in a cup that was so difficult to open that the customer had to put it between her legs, and when the coffee was spilled she suffered 3th degree burns to her crotch. And she only asked t…

"So difficult to open that ....between her legs"

Where is the logic there? Something is difficult to open so the immediate response is to put it between your legs? And it's a hot beverage? Sorry...that's idiotic. Zero dollars. Stop wasting the court's time. It doesn't matter what McD did or did not do. You are primarily responsible for your own well being. Nobody tricked her into thinking the coffee was iced tea. Nobody told her that she must use her thighs (?!) to open it.

Re: Dropbox sued for June 19 Authentication Bug

#89
Here's some attorney practice materials (a whitepaper) on the California's Unfair Competition Law: http://www.stroock.com/SiteFiles/Pub168.pdf (PDF). In the first paragraph it is described, quoting a CA Supreme Court Justice, as "a standardless, limitless, attorney fees machine" that, because of its "broad and sweeping provisions," "will continue to be alleged in almost every consumer protection action."

Re: Dropbox sued for June 19 Authentication Bug

#90

Disclaimer: Subjective, no offense intended. This is once again proving that, while I understand the language, probably shop the same things, the USA is a strange place for me. This 'just sue' culture seems weird. It seems that the whole point is to run to the court and claim 'He did something wrong. Please spend a lot of time to check that I actually have a point and if I'm lucky, please define a grossly exaggerated…

The U.S. has made a choice not to have any effective regulation of such things. Perhaps in another country, there are data security regulations with a regulatory agency in charge and when you have such a breach, you get a call from the government which is annoyed with you. The regulator imposes some sort of fine, demands an action plan to fix the problem, and generally fixes things and reduces the chances of them happening again.

The public, being satisfied that things are now fixed and realizing they weren't really harmed, declines to litigate.

Or there's the U.S. model. Since there is no regulator fixing things, the only way of effecting change is to litigate. The regulatory role has been outsourced to the courts. Of course, the courts are poorly equipped to be regulators, but it's like using a hammer when you really need a wrench: you haven't GOT a wrench, so the hammer must make do. So the courts make do and in general it costs more and regulates worse than a proper regulator would, but hey: you haven't GOT a wrench.

Post reply on HN