Live data from Hacker News

"The whole Droplr stack runs on HTTPS" ...except content

support.droplr.com

21–30 of 34 posts

Re: "The whole Droplr stack runs on HTTPS" ...except content

#21
Hi, Josh Bryant, co-founder of Droplr.

First, apologies that we didn't meet your expectations in regards to security on our service. Just to be clear, any password-related data or personal information you've sent in Droplr has been over HTTPS. But, we didn't go as far as we should have. We misjudged where usage was falling on the public-private spectrum, and we're ensuring we meet privacy expectations now.

We can see that it's a priority for people, and it's a priority for us. We've already deployed the fix, so ALL drop content should now be served over HTTPS.

We'll work on getting the pages themselves on the d.pr domain served over HTTPS as well and also look into a solution or better documentation for customers using their own custom domain.

Thanks for your patience with us and I hope you can forgive us and give us another shot.

Cheers

Re: "The whole Droplr stack runs on HTTPS" ...except content

#22
post #18
post #10

Earlier quoted context omitted.

I run a similar service, SSL is available to everyone right now, though it defaults to plain HTTP. Your suggestion is actually what I have in the works, SSL by default for everything premium users touch (and the files they share).

Not sure whether the site you run is localhostr.com (from your profile) or not, but just wanted to tell you that Malwarebytes blocked the site from loading on my PC since they consider the site a potential threat. Not sure what metric they used to determine that, but just wanted to let you know in case it's something you encounter with other users or potential users.

Thanks, I've been in contact with them about it, but they have been slow to respond. We run multiple virus scans against uploaded content, don't allow hotlinking of non-image content and actively remove any malware found.

Edit: Just received a response to a PM, we're no longer on their shitlist :)

Re: "The whole Droplr stack runs on HTTPS" ...except content

#24
post #20
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

In a customer-service system, a ticket should only be closed when the customer has acknowledged that the problem is solved or can't be solved, or it can be aged out to closed after the customer has been non-responsive for a suitable period of time. If your metrics depend on closing tickets rapidly, you are measuring the wrong thing. I don't know that this is supposed to be a customer-service system, though.

Its public and customer facing so yes, it should.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#25
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

The default action on our support system (which we did not develop) is to "Reply and Close".

I believe Tender designed it this way because, at least in our experience, 99% of the time after we reply, we never hear from the OP again. So by always closing the discussion after we answer, it keeps our queue clean and lets us clearly see what discussions are still open awaiting our response.

Anyone can always re-open the discussion if they feel they have more to add. It's not meant in any way to try to discourage discussion. We could just delete it if that's what we had wanted to do. :)

Re: "The whole Droplr stack runs on HTTPS" ...except content

#26

    Bruno de Carvalho closed this discussion
    Glyph re-opened this discussion
    Repeat
This is the current formula for customer service (delivered electronically) these days. Drives me up the flippin' wall.

CSRs: your customer's problem is not resolved when you are satisfied.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#28
post #9

In their defence: * Who uses a free file sending service for critical docs? * The only mention of 'secure' on their homepage has (to my mind) more of an implication of "safe and secure eg your file won't be lost" rather than "secure from hackers" I think it's forgivable, at least for the free version of the service. Maybe they should upgrade then tout the paid version as offering https as a benefit.

They said: "The whole Droplr platform runs on HTTPS. That means when you upload a file, note or shorten a link via any of the apps (Windows, Mac or iPhone), it sends the file over HTTPS."

Yes, they said that. And if you continued reading, you'd see that the OP knew this was not the case. Eventually, they too understood, and apparently fixed it.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#29
post #25
post #7

Why do they keep closing the request? It's obviously a problem. The fact that they seem so willfully ignorant makes me rather nervous about relying on droplr for anything. Edit: Looks like they're fixing the problem after all. It's unfortunate that it took a Hacker News article to bring attention to the problem, but at least they're taking the appropriate steps.

The default action on our support system (which we did not develop) is to "Reply and Close". I believe Tender designed it this way because, at least in our experience, 99% of the time after we reply, we never hear from the OP again. So by always closing the discussion after we answer, it keeps our queue clean and lets us clearly see what discussions are still open awaiting our response. Anyone can always re-open the…

As a user there is nothing that drives me to rage more than a company arbitrarily (from my POV) marking a ticket as closed.

Having read your post I can see the merits but if I were a user who does not know about your workflow it would make me very angry.

Why can you just not have the ticket auto-close after your reply and X days have passed, you can change your internal list to only show tickets that are open and last updated to by the customer?

Re: "The whole Droplr stack runs on HTTPS" ...except content

#30

Bruno de Carvalho closed this discussion Glyph re-opened this discussion Repeat This is the current formula for customer service (delivered electronically) these days. Drives me up the flippin' wall. CSRs: your customer's problem is not resolved when you are satisfied.

I agree to a point, but a satisfied customer is less likely to come back to close a ticket. I prefer a system the automatically closes a ticket after a period of inactivity.
Post reply on HN