Live data from Hacker News

Megaupload Implications are plain scary for Cloud Storage

alexblom.com

31–34 of 34 posts

Re: Megaupload Implications are plain scary for Cloud Storage

#31
post #26

Earlier quoted context omitted.

Amazon also quite clearly keeps hashes of all keys in S3, which Dropbox rides on. Would you expect the government to be able to issue hash based takedowns to amazon across all buckets? I was under the impression that Dropbox, while having the ability to decrypt your files, encrypts them before they hit S3. If so, a hash-based takedown sent to Amazon would at best be able to take down a single encrypted instance of a…

Except that Dropbox dedupe _everything_. So I suspect what happens is that everybodies bittorrented dvd rip of Avatar on dropbox is deduped and stored once on S3, admittedly encrypted, but all with Dropboxes encryption key and all with the same hash pointing at the same single encrypted instance of the file.

I believe Dropbox uses a method analogous to block-level dedupe. That is, files are split up into smallish chunks and then the chunks are what get "deduplicated". A "file" basically consists of a list of pointers to chunks.

This makes things extra problematic because completely unrelated files might share chunks. Standard file formats may lead to duplicate headers. Or consider a political science textbook that contains a complete copy of the US Constitution, and a file that contains just the US Constitution. One is perfectly legal to distribute freely, the other may not be, but both might share some common blocks, and a federal judge with a shoot-first mentality might craft an order requiring the deletion of those common blocks.

Re: Megaupload Implications are plain scary for Cloud Storage

#33
post #22
post #21

Earlier quoted context omitted.

What are the odds the you think any of your files could have a DMCA takedown while on dropbox? I am concerned about the abuses of power under these recent events. However, i still don't see a likely problem for legitimate use (with dropbox), outside of an outlier. The rhetoric on both sides of the argument has me a bit concerned.

I don't store any files on my Dropbox account that even remotely resemble anything owned by media companies, so I suppose the risks are negligible for myself. Using something like EncFS on top of Dropbox wouldn't hurt, either. Other people might not be as lucky. People in some countries could store and share files that are completely legal to distribute where they live, but still protected in the U.S. For example, co…

According to the Berne Convention, that's not how it works. Even if Canadian works only have life + 50 years of copyright, works created in the US are to be protected by copyright in all the countries that signed the convention for life + 70 years.

Quoting:

    In any case, the term shall be governed by the legislation of the
    country where protection is claimed

Re: Megaupload Implications are plain scary for Cloud Storage

#34
post #19

Earlier quoted context omitted.

I don't think Dropbox will suffer anything as drastic as the MegaUpload shutdown. Unlike Dropbox, MegaUpload was shady to begin with, and with a lot more emphasis on public file sharing. But the possibility of individual files being taken down is pretty real. Dropbox probably does it all the time already, otherwise they'd be in trouble with DMCA. Now, whether they will only delete your online copy, or whether they wi…

That's our criteria for takedowns? Whether it feels shady? I understand the law can't always be black and white, but that's a heck of a lot greyer than I'm comfortable with.

Unfortunately, that does seem to be one of the criteria that many governments use to justify takedowns. Selective enforcement at its best.
Post reply on HN