Live data from Hacker News

"The whole Droplr stack runs on HTTPS" ...except content

support.droplr.com

31–34 of 34 posts

Re: "The whole Droplr stack runs on HTTPS" ...except content

#31
post #21

Hi, Josh Bryant, co-founder of Droplr. First, apologies that we didn't meet your expectations in regards to security on our service. Just to be clear, any password-related data or personal information you've sent in Droplr has been over HTTPS. But, we didn't go as far as we should have. We misjudged where usage was falling on the public-private spectrum, and we're ensuring we meet privacy expectations now. We can see…

Thx for the response! I've always been a droplr fan and, even thought ssl should've been there, I'm glad it's fixed and I'll happily continue to use it :)

Re: "The whole Droplr stack runs on HTTPS" ...except content

#32
post #21

Hi, Josh Bryant, co-founder of Droplr. First, apologies that we didn't meet your expectations in regards to security on our service. Just to be clear, any password-related data or personal information you've sent in Droplr has been over HTTPS. But, we didn't go as far as we should have. We misjudged where usage was falling on the public-private spectrum, and we're ensuring we meet privacy expectations now. We can see…

Why didn't your support guy understand what the problem was?

Re: "The whole Droplr stack runs on HTTPS" ...except content

#33
post #28

Earlier quoted context omitted.

They said: "The whole Droplr platform runs on HTTPS. That means when you upload a file, note or shorten a link via any of the apps (Windows, Mac or iPhone), it sends the file over HTTPS."

Yes, they said that. And if you continued reading, you'd see that the OP knew this was not the case. Eventually, they too understood, and apparently fixed it.

zwass, I'm not sure why you're using that tone to reply to me. It seems you're assuming that my reply was made AFTER they posted the fix. In fact I had read the thread until the end before I posted. The fix came after my comment.

Anyway, I still stand by it, in my reply to the previous comment that maybe the user had misunderstood what they meant by security, and I backed my argument with the words of the service provider's representative.

Re: "The whole Droplr stack runs on HTTPS" ...except content

#34
post #21

Hi, Josh Bryant, co-founder of Droplr. First, apologies that we didn't meet your expectations in regards to security on our service. Just to be clear, any password-related data or personal information you've sent in Droplr has been over HTTPS. But, we didn't go as far as we should have. We misjudged where usage was falling on the public-private spectrum, and we're ensuring we meet privacy expectations now. We can see…

> Just to be clear, any password-related data or personal information you've sent in Droplr has been over HTTPS.

Unless there was personal information in a file I shared using Droplr.

I'm not the person who raised this issue on your support site. I'd never even heard of Droplr until somebody shared this link with me for a laugh. While the title of my submission might not reflect it, I find the lack of comprehension and dismissive attitude of your customer service representative more off-putting than the original security flaw. He closed the ticket multiple times claiming that "the whole Droplr platform runs on HTTPS," when that clearly wasn't the case. Glyph was remarkably patient in re-opening and re-explaining the issue until the rep finally seemed to realize why he was wrong, whereupon the answer changed from "this isn't an issue, we already support the feature you're requesting" to "we're already aware of this issue but it's not a big deal," without even an acknowledgment that he'd so fundamentally misunderstood the request, let alone an apology for blowing him off repeatedly.

Post reply on HN