Live data from Hacker News

"The whole Droplr stack runs on HTTPS" ...except content

support.droplr.com

11–20 of 34 posts

Re: "The whole Droplr stack runs on HTTPS" ...except content

#12
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

I use droplr for quick screen-sharing, pastes, file-transfers, etc. I do not use it for anything sensitive whatsoever.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#13

The reason why the content itself is not served under https is precisely to avoid the SSL warning. As I've said before, this particular issue is not high priority right now, which doesn't mean we're not aware or aren't going to fix it. Something about the tone of this response irks me.

> Something about the tone of this response irks me.

Reminds me of someone doing it right: http://www.chiark.greenend.org.uk/~sgtatham/putty/faq.html#f...

Re: "The whole Droplr stack runs on HTTPS" ...except content

#15
post #9

In their defence: * Who uses a free file sending service for critical docs? * The only mention of 'secure' on their homepage has (to my mind) more of an implication of "safe and secure eg your file won't be lost" rather than "secure from hackers" I think it's forgivable, at least for the free version of the service. Maybe they should upgrade then tout the paid version as offering https as a benefit.

They said: "The whole Droplr platform runs on HTTPS. That means when you upload a file, note or shorten a link via any of the apps (Windows, Mac or iPhone), it sends the file over HTTPS."

Re: "The whole Droplr stack runs on HTTPS" ...except content

#16
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

The default button in Tender (which is the support software they are using) is "Reply and Close". It's easier to do that and I think the support guy got used to it.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#17
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

I never used droplr and now i know i will never use it. Support staff was never able to understand how SSL works or what problem is. Yet he choose simply to ignore it.

>The reason why the content itself is not served under https is precisely to avoid the SSL warning.

That annoying warning is the hearth of the secure connection. It surprises me how people choose an easy way and doesn't care about "doing things right"

Re: "The whole Droplr stack runs on HTTPS" ...except content

#18
post #10
post #9

In their defence: * Who uses a free file sending service for critical docs? * The only mention of 'secure' on their homepage has (to my mind) more of an implication of "safe and secure eg your file won't be lost" rather than "secure from hackers" I think it's forgivable, at least for the free version of the service. Maybe they should upgrade then tout the paid version as offering https as a benefit.

I run a similar service, SSL is available to everyone right now, though it defaults to plain HTTP. Your suggestion is actually what I have in the works, SSL by default for everything premium users touch (and the files they share).

Not sure whether the site you run is localhostr.com (from your profile) or not, but just wanted to tell you that Malwarebytes blocked the site from loading on my PC since they consider the site a potential threat. Not sure what metric they used to determine that, but just wanted to let you know in case it's something you encounter with other users or potential users.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#19

They really should have more intelligent individuals manning public-facing support channels.

The person (Bruno) replying on behalf of Droplr is "in charge of the whole server-side circus — API server, system administration, web app backend —, the SDK libraries for third-party clients, the Windows app and the iOS app." http://biasedbit.com/about/

(I realize there is a risk of sending a mob by linking to his personal page, but I think there is evidence he is indeed "intelligent" and simply misunderstood this particular piece of the puzzle. He just need a bit more humility.)

Re: "The whole Droplr stack runs on HTTPS" ...except content

#20
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

In a customer-service system, a ticket should only be closed when the customer has acknowledged that the problem is solved or can't be solved, or it can be aged out to closed after the customer has been non-responsive for a suitable period of time. If your metrics depend on closing tickets rapidly, you are measuring the wrong thing.

I don't know that this is supposed to be a customer-service system, though.

Post reply on HN