Live data from Hacker News

Tell HN: Dropbox now requires access to contacts for Google login

news.ycombinator.com

11–20 of 393 posts

Re: Tell HN: Dropbox now requires access to contacts for Google login

#11

DropBox seems to have decided that the only way for them to grow is to turn their data sync platform into a collaborative platform. Makes a whole lot of sense to steal contacts from all your users. FYI - never use oauth to log into anything you care about.

Not following. What's wrong with oauth?

When Google's AI (=RNG) decides to terminate your account (maybe you typed a few too many comments on YouTube, this has happened to people), you'll lose every service for which you used Google to sign in with.

Also, the usual tracking stuff.

Re: Tell HN: Dropbox now requires access to contacts for Google login

#12
post #7

Isn't that against GDPR for european users?

I was going to say no (and I've left my logic below for posterity), but maybe you have a point. The OP can't continue to use Dropbox without giving up some more privacy. They can't even get in to get their data out (although GDPR does take care of that). Previous logic: They've asked for permission, been clear about what data they and presumably haven't prechecked anything (because they don't have control over that U…

Exactly. Consent must be freely given to be valid under GDPR. Here is some analysis on what this means by the European Data Protection Board:[0]

“ 3.1 Free / freely given12 13. The element “free” implies real choice and control for data subjects. As a general rule, the GDPR prescribes that if the data subject has no real choice, feels compelled to consent or will endure negative consequences if they do not consent, then consent will not be valid.13 If consent is bundled up as a non-negotiable part of terms and conditions it is presumed not to have been freely given. Accordingly, consent will not be considered to be free if the data subject is unable to refuse or withdraw his or her consent without detriment.14 The notion of imbalance between the controller and the data subject is also taken into consideration by the GDPR.”

[0] https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_gui...

Re: Tell HN: Dropbox now requires access to contacts for Google login

#13

DropBox seems to have decided that the only way for them to grow is to turn their data sync platform into a collaborative platform. Makes a whole lot of sense to steal contacts from all your users. FYI - never use oauth to log into anything you care about.

Is there an oauth provider that offers what mobiles have started to do with permissions, where "deny" just gives empty data to to the requesting application instead of actually rejecting the claim?

It'd be nice to see Google offer something like that.

Re: Tell HN: Dropbox now requires access to contacts for Google login

#14
post #10

Hmm. My Dropbox Pro subscription renewal is coming up. Is there an alternative to Dropbox that isn't iCloud or Google Drive? I would like to pay for Tarsnap but I don't understand 250 picodollars / byte-month.

i switched to microsoft 1Drive a long time ago, works seamlessly on windows

Re: Tell HN: Dropbox now requires access to contacts for Google login

#16
post #10

Hmm. My Dropbox Pro subscription renewal is coming up. Is there an alternative to Dropbox that isn't iCloud or Google Drive? I would like to pay for Tarsnap but I don't understand 250 picodollars / byte-month.

Check out https://koofr.eu/ Disclaimer: I work there :)

Re: Tell HN: Dropbox now requires access to contacts for Google login

#17
post #10

Hmm. My Dropbox Pro subscription renewal is coming up. Is there an alternative to Dropbox that isn't iCloud or Google Drive? I would like to pay for Tarsnap but I don't understand 250 picodollars / byte-month.

I use SyncThing [0]. It can work without a server if your devices are often up at the same time. Otherwise you can get a small cheap server from the provider of your choice to suit your needs.

[0] https://syncthing.net/

Re: Tell HN: Dropbox now requires access to contacts for Google login

#18
I left dropbox when they changed the full page upsell to "dropbox business" so that I couldn't easily figure out how to skip it and get on with my work.

I had a paid pro account at the time.

I actually had a conversation with a product manager; I checked the yes you can contact me when I cancelled my account. They simply refused to admit that an upsell was a advertisement and that disrupting my workflow on my paid, professional account for an ad was wrong.

The other interesting thing about that conversation, they could not understand how a sole proprietor would see no benefit from collaboration tools and kept making up bizarre scenarios where I could use them.

I actually asked them if they were a product manager or a salesperson at one point.

To Dropbox's credit, that product manager didn't try to retain me, they were genuinely trying to figure out why I had quit; they just couldn't grok the reason.

Re: Tell HN: Dropbox now requires access to contacts for Google login

#19
post #10

Hmm. My Dropbox Pro subscription renewal is coming up. Is there an alternative to Dropbox that isn't iCloud or Google Drive? I would like to pay for Tarsnap but I don't understand 250 picodollars / byte-month.

I am really happy with Nextcloud!

Re: Tell HN: Dropbox now requires access to contacts for Google login

#20

DropBox seems to have decided that the only way for them to grow is to turn their data sync platform into a collaborative platform. Makes a whole lot of sense to steal contacts from all your users. FYI - never use oauth to log into anything you care about.

I am not so sure if oauth is to blame alone. I mean, it is a technology that lets you control what you want to share. However, engaging in business with a partner who decides to change the rules, is something I see a lot more critical.

So maybe the lesson should sound more like

- 'Don't use Dropbox for anything you care about' or

- 'Don't do business with large corporations for anything you care about'

To clarify, I am not saying it to protect oauth (in its current state I am not a particular fan of it), but to show, that the technology doesn't change by itself and that someone decided to change it. So the company who decided to execute this unethical change should take its share of the blame too.

Post reply on HN