Live data from Hacker News

Dropbox telemetry can't be disabled

dropboxforum.com

211–220 of 249 posts

Re: Dropbox telemetry can't be disabled

#211

Don't use any if these proprietary shit apps in the first place. I find it silly to complain about things like that. Even if they have opt-out or even opt-in. They will eventually change it, they will abuse you. They will have "bugs" that leak data. You can only trust open source. And there are plenty of alternatives, that you can self host.

Can you list top-3 fully-featured Dropbox alternatives of the plenty?

Re: Dropbox telemetry can't be disabled

#212
post #82
post #45

Earlier quoted context omitted.

Dropbox's specific popularity on HN may partially stem from its original backing by YC. It will have enjoyed additional exposure here thanks to that, and to be fair to Dropbox, it was a good product. I say *was because I cannot speak for how it is now, I do not have any data to judge how it is now. I stopped using it a long time ago – not because I disliked it, I just picked a different solution.

I’m still using it, but to me their service has become worse over time as more and more features were tacked on that I don’t want or need… and they are really not listening to their users who want a better experience instead of more junk. I’m also in the market for a better alternative, but haven’t found one so far that is as easy to use as Dropbox. I’d prefer to not have to manage my own servers.

I have heard good things about Syncthing but it depends on your use case.

https://syncthing.net/

Re: Dropbox telemetry can't be disabled

#213

Wouldn't get this with a FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem.

I bet you could setup all that up over a weekend roo

If you go with a modern equivalent ("rclone mount" or sshfs) you could probably set those up faster than the Dropbox client.

Re: Dropbox telemetry can't be disabled

#214

Many times on HN, commenters have mocked those who questioned why someone would use Dropbox instead of a method controlled by the user. I guess becausse someone made lots of money from it or it became popular or something. I always found this perplexing because I look at solutions from the perspective of the user, namely, me, not from the perspective of a third party "tech" startup founder. It's insensitive to the pe…

> I confess I have never used it. I still rely on USB sticks Phew boy. You really should try dropbox or a competing service.* Picture this: 1. Double click a file 2. Type some words 3. Save the file That's it. There is no step 4. Your file is now synced to all your other computers and to any colleagues who also need that file. Seriously you shouldn't be using USB sticks these days. Also - I'm guessing you haven't sta…

> Also - I'm guessing you haven't started the transition to USB-C yet?

Shit, not more painful than nearly everything else. You're gonna need a USB-A/C hub anyway, unless you only use very new equipment and you've gone out of your way (and, not infrequently, spent more money) to make sure you get C instead of A versions of everything—lots of A devices still being sold.

If not for current-generation console video game controllers, I'd still have almost nothing in my house that natively uses C, aside from Macbooks and one newish iPad.

(However, I am, like you, a tad scandalized at the notion of favoring flash drives over network sync of some sort—I'm a luddite in a lot of ways, but god do I not miss losing flash drives, having them mysteriously fail in 6-24 months of light use [even the good brands! If anything, that part's worse now than it used to be], the "whoops, forgot to copy the file", not being able to have any of the stuff unless you physically have it with you, "let me just print this from my phone—oh, right, I don't have an adapter to plug a USB stick into it", et c. A bunch of extra stress and fiddling, to gain... ???)

Re: Dropbox telemetry can't be disabled

#215

I get that for some classes of "local-only" apps like compilers (famous from a recent discussion on the same topic), network communication can be surprising and therefore feel unnecessary. But for an app whose sole purpose is sending and receiving lots of sensitive private data to Dropbox servers, who has the energy to be outraged that there is also some other anonymous data sent such as program crash info? I mean Dr…

I'm wondering where the line is between acceptable and unacceptable logs. Obviously no one appreciates analytics used by marketing teams, but virtually every internet service has logs used by engineers (which seem to be what this post is about). A few factors that seem relevant: - Is the service running locally? - Do we trust/expect that the data is not used for marketing (i.e. would the user have complained if the d…

It’s not that difficult to make anonymous (usually pseudonymous) usage stats. Of course you don’t store IPs, computer names, user names, emails, detailed geographical data etc. I think in the past this was a lot messier but these days with GDPR it’s quite easy to draw the line. Basically store nothing that is individual, nor enough data (entropy) associated with one pseudonymous user that they could be identified as individuals.

Re: Dropbox telemetry can't be disabled

#216

Earlier quoted context omitted.

Well... if you run owncloud (or any other alternative in fashion) you need off site backups and a plan for disaster recovery to match what an external service can offer. Backup machine or funds to get one at short notice. If you use a 3rd party service they'll handle that too. It's not the initial setup that's the problem.

> you need off site backups Yes, but that's not technically difficult or time-consuming. > a plan for disaster recovery to match what an external service can offer. I'm not sure what you really mean by this. Isn't that what the backups are for?

> > you need off site backups

> Yes, but that's not technically difficult or time-consuming.

Yes, you just pay for some server space on a cloud service... oh wait...

The point is all this trivial to do stuff just adds up, and sometimes it does make sense to use a 3rd party.

Your pain threshold may just be larger than mine.

Re: Dropbox telemetry can't be disabled

#217

Earlier quoted context omitted.

If you’re okay with a VPS, Servarica’s 2022 Black Friday offerings (which are still available) has a 2 TB HDD VPS for $48/year.

I haven't heard of them before, but those prices are almost _suspiciously_ good. Have you found them to be reliable? Edit: they're using the older unity logo for their "disk" column. That doesn't inspire confidence in their legitimacy.

I'm using mine primarily as a redundant backup host. So, for that usage, they're perfectly reliable and functional.

However, the machine is absolutely slow. It usually takes a few seconds before SSH brings me to a shell prompt. Web apps I have running on it (basically just Gitea and Vikunja at the moment) can take upwards of 10 seconds to render pages, and it's just me using it. If you just want a storage host, they're fine. Running your website off it? I would probably not recommend.

Reliability, I have not had any issues so far, but I'm hardly a power user. My own personal anecdote is that my backups get validated monthly and, so far, have not had any issues.

I would probably agree that these machines alone would not suffice to make a good Dropbox alternative if what you're storing there isn't backed up elsewhere. I would recommend supplementing with off-site backups to B2 at the very least.

Re: Dropbox telemetry can't be disabled

#219
post #109

Earlier quoted context omitted.

False, I will rephrase: it is a regulatory requirement under the GDPR to disclose the fact that you are collecting data, to provide a detailed and easily accessible specification of the information contents, a precise definition of how this data is processed and used, and your legal justification(s) for doing so, and to do so for each separate type or kind of collection involving individuals, regardless of whether th…

> it is a regulatory requirement to disclose the fact that you are collecting data Not if the data isn't PII, no. Not in any way shape or form. > The few exceptions that exist are only applicable in cases where there is no potentially identifiable data collected at all The whole point of collecting "anonymous usage data" (which is what telemetry usually does) is that it shouldn't be possible to attribute to a physica…

Ah gotcha, yes, you're right, except that only holds when you are not collecting any other data from the "subject" at all.

The major differentiating factor here is that that Dropbox does in fact process PII - convenient storage and distribution of their customers digital life is their raison d'être, after all, it's precisely what those people expect of Dropbox and pay them their monthly fee for.

In this case, where telemetry is gathered by the same desktop application that is also a primary component of their legitimate and consented-to data processing activities no less, they would at minimum be required to specify what information goes where, how it is anonymised, and for what purpose they require it.

I'm not assuming ill intent or unsanctioned data mining activities or anything of the sort, but whatever it is that they are collecting and doing is not as clear as it should be.

Re: Dropbox telemetry can't be disabled

#220
post #90

Earlier quoted context omitted.

You don’t expose data just by enabling the sharing, because it’s only accessible via a URL containing a hash-like identifier that can’t be guessed. It’s not more realistic than someone guessing your Syncthing password.

Unfortunately this is not true. Your browser likes to send any URLs it comes across to indexing services. If you share the link via Discord or whatever, it'll be scrapped. This is also just very outside Syncthing's functionality.

> Unfortunately this is not true. Your browser likes to send any URLs it comes across to indexing services. If you share the link via Discord or whatever, it'll be scrapped.

You still have to manually create the URL first. You don't need to worry about accidentally having everything exposed because the feature is enabled.

> This is also just very outside Syncthing's functionality.

The context was specifically "as a Dropbox replacement".

Post reply on HN