Live data from Hacker News

Dropbox telemetry can't be disabled

dropboxforum.com

161–170 of 249 posts

Re: Dropbox telemetry can't be disabled

#161

Earlier quoted context omitted.

>Maybe there will someday be telemetry in USB sticks. We'll see. Meanwhile... I have had experiences where putting in a USB stick automatically installs malware on the computer.

That's only if your computer is configured to automatically run whatever autorun.ini specifies, which it really should not be.

Do you trust that the USB stick is just storage and not something additional?

Do you trust that the USB "power port" is just power and not a host?

Re: Dropbox telemetry can't be disabled

#162
post #28

Earlier quoted context omitted.

> I guess becausse someone made lots of money from it or it became popular or something. No, it’s because it was useful and simple in a way that non-techies could and would set up and use. That’s why Dropbox got popular.

Even as a techie, why would you put in the work to set up your own thing? Though, I moved away from Dropbox long ago when they introduced device limits. One phone, one laptop and one triple booting desktop -> over the device limit already.

Putting in the work to setup your own thing is great. You learn a lot, if your doing it at an advanced level you start to understand some of the designs/tradeoffs that the commercial products made.

Keeping that running and reliable and operating it for years or decades sounds like an absolute nightmare and I'd suggest avoiding that at all costs.

Re: Dropbox telemetry can't be disabled

#163
post #39

Wouldn't get this with a FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem.

Or use an open source client without telemetry such as https://maestral.app ㋡

I wish there would be a Google Drive equivalent of this.

Re: Dropbox telemetry can't be disabled

#164
post #39

Earlier quoted context omitted.

Or use an open source client without telemetry such as https://maestral.app ㋡

This. Recently came back to macOS after a decade on the other side, and one surprise was how terrible the official Dropbox client was. Installed Maestral instead and it just works -- just like Dropbox used to. I see Dropbox as one of the biggest failures of the VC model. If only they had been bootstrapped, they would probably have stuck with their initial sync offering: A perfectly executed solution to a problem ever…

Sure, but without VC money the product space wouldn't exist at all, at least not as a free service.

Who doesn't want free storage? No one, that's who.

See also: everything from Sourceforge to Docker Hub. Very few can complete the transition into a paid service.

The important distinction is whether you sell a product or a service. Dropbox is clearly a service, but it's easy to envision a product instead.

Had the user paid for storage up front, the product would be incentivized to support multiple backends to be able to compete on cost. But it doesn't, because it is the storage service that is the actual thing being sold.

Re: Dropbox telemetry can't be disabled

#166
post #161

Earlier quoted context omitted.

That's only if your computer is configured to automatically run whatever autorun.ini specifies, which it really should not be.

Do you trust that the USB stick is just storage and not something additional? Do you trust that the USB "power port" is just power and not a host?

Regarding rogue client devices: Suppose it's not just storage and instead is something additional, like a device for which the host will decide (without autorun.ini in this case) to install drivers, or interact in some other capacity along those lines. Can this automatically cause arbitrary code execution? I would not consider code supplied through official OS channels ("let windows search for a driver online" type of stuff) to be arbitrary, because those repositories ought to be trusted as not containing malware. Rather, by arbitrary I mean the USB device supplies the payload or supplies a URL that the OS requests, and then the OS automatically executes that. I've never heard of such a thing, but it's conceivable... source?

Regarding rogue host devices (not just a power port): I agree 100%, these are dangerous. Luckily a typical USB port on a Windows computer can only interact with client devices, not host devices, as far as I'm aware. The inverse of OTG doesn't seem like it would exist.

Re: Dropbox telemetry can't be disabled

#167

Many times on HN, commenters have mocked those who questioned why someone would use Dropbox instead of a method controlled by the user. I guess becausse someone made lots of money from it or it became popular or something. I always found this perplexing because I look at solutions from the perspective of the user, namely, me, not from the perspective of a third party "tech" startup founder. It's insensitive to the pe…

USB sticks fail. Also the default file system is fat32 which doesn’t support journaling or file versioning.

Re: Dropbox telemetry can't be disabled

#168

Earlier quoted context omitted.

This. Recently came back to macOS after a decade on the other side, and one surprise was how terrible the official Dropbox client was. Installed Maestral instead and it just works -- just like Dropbox used to. I see Dropbox as one of the biggest failures of the VC model. If only they had been bootstrapped, they would probably have stuck with their initial sync offering: A perfectly executed solution to a problem ever…

Sure, but without VC money the product space wouldn't exist at all, at least not as a free service. Who doesn't want free storage? No one, that's who. See also: everything from Sourceforge to Docker Hub. Very few can complete the transition into a paid service. The important distinction is whether you sell a product or a service. Dropbox is clearly a service, but it's easy to envision a product instead. Had the user…

People have been burned enough times by now that any fly-by-night that shows up promising free storage gets taken with a huge grain of salt.

Why would I upload my data for you to hold for free if history shows you are going to be gone in 6 months?

So to answer your question "Who doesn't want free storage?", everyone who's been burned before, that's who.

Re: Dropbox telemetry can't be disabled

#169
post #163
post #39

Earlier quoted context omitted.

Or use an open source client without telemetry such as https://maestral.app ㋡

I wish there would be a Google Drive equivalent of this.

If you're using Linux with GNOME desktop, GVFS can mount Google Drives automatically once you set your google account up in GNOME Online Accounts.

Re: Dropbox telemetry can't be disabled

#170
post #35

One can install and use nextcloud. You get similar client and similar experience. You need to care about your data and server though.

Taking care of data and servers is the big problem, even for people who are more into computers. There are many holes to fall into.

Also some of us here work at public companies and these systems are under scope since finance needs away to share/edit financial documents with each other. These big firms have soc1s. Running our own infra would put that infra under scope which is a huge burden.
Post reply on HN