Ah, Elsevier. It's probably not that difficult to reverse-engineer and extract the decryption keys, but doing so opens you up to DMCA risks.
I don't think the DMCA would apply, as presumably you own the copyright of whatever's in the database. You would need EFF or other support to prove it though...
Mendeley encrypts users' database after Zotero provides an importer
11–20 of 122 posts
Re: Mendeley encrypts users' database after Zotero provides an importer
#12Zotero has improved a lot, while Mendeley has repeatedly regressed. Mendeley used to be quite a good program, but recently you can not export annotated PDFs meaningfully. For example, sending a folder of annotated PDFs to a co-author during a literature review is impossible. This is obviously the case since Elsevier does not want you to trade research papers, whether you have lawfull access or not. The updates that t…
Re: Mendeley encrypts users' database after Zotero provides an importer
#13Luckily, my Linux desktop was still running an old version of Mendeley so I was able to make the switch. My reason for wanting to switch was that Zotero has Google Docs integration. After making the switch, I was pleased to pay a modest amount for storage of my PDFs, which makes me feel like a customer instead of a product.
If your institution does offer f1000 subscription, I suggest you take a look at f1000 workspace.
Re: Mendeley encrypts users' database after Zotero provides an importer
#14Zotero = Your personal research assistant. Zotero is a free, easy-to-use tool to help you collect, organize, cite, and share research. https://www.zotero.org/
Mendeley = Reference Management Software, produced by Elsevier who also happens to be the publisher of many peer-reviewed journals. Elsevier come under fire for it's high costs and gateway actions to restrict access to information they've published in journals and host in archives. This most recent action of making the database of references in Mendeley difficult to export is a continuation of their attempt to protect what they, and some legal systems, would see as their IP. Others disagree.
The battle continues...
Re: Mendeley encrypts users' database after Zotero provides an importer
#15And hey, user security is a pretty good reason to encrypt a database, but if security were the only aim, they could have made the data accessible for export purposes (after all, it's accessible for the user to read).
At this point in history I'm not even sure it's worth going into all of the reasons this is a terrible thing to do on their part. At best, they'll scare off some users from migrating away briefly and buy themselves some time to figure out what they need to do to produce something that's better than the competition they're attempting thwart. More likely, they'll simply fail (quickly or slowly). It's that last point that really matters to me. If I'm buying an application that I'm going to rely on, I want comfort that the company will continue to maintain the product -- or in the case of open-source, confidence that the product is still regularly maintained (or in languages/frameworks that make it practical for me to maintain myself).
Aside from the fact that I wouldn't want that feature 'as it has been designed, today', I wouldn't want to rely on a product that's being designed by individuals who aren't well versed in the perils that DRM-like behavior causes. After all, that's what this is -- it's an attempt to keep the user from transforming their own data for the purposes of locking that customer into the product while attempting to position the lock-in as a security feature. And it failed on both accounts, Zotero worked around the encryption (which means the bad guys can to) and if people looking for a product like this care about that capability, they'll likely refine it to the point that it's as capable encrypted as it is decrypted.
Every time I've been asked to implement a DRM solution I've either outright refused or paired it down so much that the "R" didn't really exist. They're horribly complex to write, off the shelf solutions are already cracked and time would be better spent giving customers something they're willing to pay for. The thing that makes me roll my eyes every time I read one of these is "there are still engineers out there who think this is a good idea?"
I can't wrap my head around what causes this kind of thinking -- it's not a zero-sum game, there's room for more than one product in the marketplace -- even if one of them is free and open-source. Trying to beat the competition by sabotage rather than by making a better product doesn't work ... at least not for very long.
[0] And they also do my least favorite "other marketing thing" -- "Create a Free Account" and no hint of what the thing costs in any obvious place. So maybe this other product is free? I doubt it -- Like most companies, I'm assuming they're perfectly happy collecting your personal information for free (in order to send marketing to you to get you to pay for whatever service is tied to the free account). It's the little deceptive things that drive me crazy -- you didn't trick me, you only managed to make me suspicious of your product.
[1] I've gotten lucky ... usually budget and time doesn't allow for wasting energy on customer-hostile features that won't achieve the ends they're aiming for. The only case where something "DRM-like" was in an application I wrote was to be the opposite of customer-hostile. We had an app that provided information to users based on their permissions, determined by them logging in. I pushed to make the automation (sending us the login information) opt-in, with manual provisioning options. It worked well, since if they failed to true up after months of warnings, the application would deactivate (due to the size of the customers, months of warning was somewhere near a year and could also be disabled with a flag).
Re: Mendeley encrypts users' database after Zotero provides an importer
#16For those wondering, here's what I gathered as some context. Zotero = Your personal research assistant. Zotero is a free, easy-to-use tool to help you collect, organize, cite, and share research. https://www.zotero.org/ Mendeley = Reference Management Software, produced by Elsevier who also happens to be the publisher of many peer-reviewed journals. Elsevier come under fire for it's high costs and gateway actions to…
I read a scientific paper or look up a citation. I add that with a click or two to my reference manager. It also stores the PDF for me.
In the future, I can easily re-read the PDF. I can annotate it and the annotations will be stored.
Critically, when writing my own paper, I can import those citations and trivially change the format to whatever the publisher wants without any effort.
To me, across most features, these two programs do exactly the same thing. When picking a citation manager, it's more about which one I trust will be around for the long haul and will not interfere with my research.
Re: Mendeley encrypts users' database after Zotero provides an importer
#17Zotero has improved a lot, while Mendeley has repeatedly regressed. Mendeley used to be quite a good program, but recently you can not export annotated PDFs meaningfully. For example, sending a folder of annotated PDFs to a co-author during a literature review is impossible. This is obviously the case since Elsevier does not want you to trade research papers, whether you have lawfull access or not. The updates that t…
Elsevier is to science as Oracle is to database software licensing.
However, as someone who worked in a large IT organization for a huge company and wrote software for license compliance tracking, I completely understand. Grab me a pitch fork, I'll march.
Re: Mendeley encrypts users' database after Zotero provides an importer
#18Luckily, my Linux desktop was still running an old version of Mendeley so I was able to make the switch. My reason for wanting to switch was that Zotero has Google Docs integration. After making the switch, I was pleased to pay a modest amount for storage of my PDFs, which makes me feel like a customer instead of a product.
If your institution does offer f1000 subscription, I suggest you take a look at f1000 workspace.
Re: Mendeley encrypts users' database after Zotero provides an importer
#19I re-un-recommended Mendeley back in June 2018 when this news first broke. (I was initially too sketched out by Elsevier to recommend Mendeley, and this just confirms these suspicions.)
tl;dr Zotero is a pretty good bet for most people, especially since they added support for citation management in Google Docs at the end of last year (very important for academic writers). PaperPile (https://paperpile.com) and Papers (https://www.papersapp.com) are also worth checking out.
Re: Mendeley encrypts users' database after Zotero provides an importer
#20Zotero has improved a lot, while Mendeley has repeatedly regressed. Mendeley used to be quite a good program, but recently you can not export annotated PDFs meaningfully. For example, sending a folder of annotated PDFs to a co-author during a literature review is impossible. This is obviously the case since Elsevier does not want you to trade research papers, whether you have lawfull access or not. The updates that t…
This is exactly why you should not depend on proprietary software for anything even remotely important. This is not the first nor will it be the last time that something like that happens. Letting a company (or an individual) dictate how and if I can access my work is unacceptable to me.
Thankfully Zotero is FOSS, I will be staying with BibTeX though.