Live data from Hacker News

Dropbox S-1

sec.gov

371–380 of 404 posts

Re: Dropbox S-1

#371
post #141
post #82

Earlier quoted context omitted.

Give us the dirt on this one!

There's nothing shocking and I think that bodes very very well for Dropbox. It looks like a solid foundation with great growth. The standouts to me were - * They cut costs on an absolute and relative basis for the last two years. This is fantastic and I hope the trend continues. * I don't understand how the $112 ARPU number foots with their pricing. They are telling a story that "teams" is driving growth but on the s…

>> No idea where they expect new users to come from given they have 500M accounts.

500M accounts, but only 11M paying users.

Re: Dropbox S-1

#372
post #349

Earlier quoted context omitted.

Once you are established, have applicants work long hours for entry level wages as "associates" in the hopes they could become "partner" one day. This is obviously the law firm model. I have also wondered why it hasn't been (to my knowledge) replicated in tech. The cynical answer is that once you have a suite of profitable applications bringing in money, why share that with new employees when you can get the same wor…

Law firm hours are directly tied to revenue. You can't measure things this way in a SAAS shop.

True. But law/accounting is similar to an MLM model, where the rain-makers kinda get paid some proportion of the hours billed of their subordinates.

Re: Dropbox S-1

#373
post #322
post #311

Earlier quoted context omitted.

Ok, personally, I do care about the imbalance, and I strongly encourage my fellow techies to care, too. Why? Because when enough of us care, we can change the sandbox itself. None of this stuff is set in stone. Great that you're content with crumbs, but I'm not, and I certainly don't want to see the next generation of technicians laboring under the same conditions as so many of ours has done. I'll do my part to leave…

> Because when enough of us care, we can change the sandbox itself. no need to wait, you can change the sandbox right now, you can create your own startup and give equal ownership to everyone.

I could do that.

And, at the same time, my fellow techies in any given megacorp (I'm not in one now, used to be long ago) can start organizing and negotiating together, to establish better working conditions, better pay, more autonomy, more of a say in how the company is run.

This isn't an either/or situation.

Re: Dropbox S-1

#374
post #311

Earlier quoted context omitted.

Ok, personally, I do care about the imbalance, and I strongly encourage my fellow techies to care, too. Why? Because when enough of us care, we can change the sandbox itself. None of this stuff is set in stone. Great that you're content with crumbs, but I'm not, and I certainly don't want to see the next generation of technicians laboring under the same conditions as so many of ours has done. I'll do my part to leave…

So why just the techies? Shouldn't you be advocating for everyone to be receiving a larger share of the pie when the company does well? > I certainly don't want to see the next generation of technicians laboring under the same conditions as so many of ours has done. Oh please. US West coast engineers already have it nearly as good as it can possibly get on this planet, in all of human history. The violin playing for…

As I said in another comment, there are other groups working to help lower-paid service workers organize. They're better suited to that task than I'd ever be. (And I'm not even a part of any union, I just think we in the tech world are long overdue for organized negotiation.)

And, so, you do agree with me, but don't like some of my word choices? Can you maybe put that stuff aside and see that, organizing and negotiating together in our very individualistic field starts somewhere?

Re: Dropbox S-1

#375
post #374

Earlier quoted context omitted.

So why just the techies? Shouldn't you be advocating for everyone to be receiving a larger share of the pie when the company does well? > I certainly don't want to see the next generation of technicians laboring under the same conditions as so many of ours has done. Oh please. US West coast engineers already have it nearly as good as it can possibly get on this planet, in all of human history. The violin playing for…

As I said in another comment, there are other groups working to help lower-paid service workers organize. They're better suited to that task than I'd ever be. (And I'm not even a part of any union, I just think we in the tech world are long overdue for organized negotiation.) And, so, you do agree with me, but don't like some of my word choices? Can you maybe put that stuff aside and see that, organizing and negotiat…

Yes, I do agree with you wholeheartedly. Unfortunately, in my own environment, any attempt to organize among workers has fallen upon deaf ears.

The workers themselves seem to be resistant (or perhaps fearful) to organizing in a manner that would give them more rights and fairer compensation.

Re: Dropbox S-1

#376
post #373
post #322

Earlier quoted context omitted.

> Because when enough of us care, we can change the sandbox itself. no need to wait, you can change the sandbox right now, you can create your own startup and give equal ownership to everyone.

I could do that. And, at the same time, my fellow techies in any given megacorp (I'm not in one now, used to be long ago) can start organizing and negotiating together, to establish better working conditions, better pay, more autonomy, more of a say in how the company is run. This isn't an either/or situation.

> I could do that.

“Be the change you wish to see in the world.” Mahatma Gandhi

Re: Dropbox S-1

#378
post #376
post #373

Earlier quoted context omitted.

I could do that. And, at the same time, my fellow techies in any given megacorp (I'm not in one now, used to be long ago) can start organizing and negotiating together, to establish better working conditions, better pay, more autonomy, more of a say in how the company is run. This isn't an either/or situation.

> I could do that. “Be the change you wish to see in the world.” Mahatma Gandhi

Right?? Why do you think I'm writing about how much better we could make our working conditions, if we organized and negotiated together?

These ideas and methods aren't new (organizing and negotiating together), and they've been largely effective in this country and elsewhere.

And, hey, like I said to the other person, you don't have to do it, if you're happy with the crumbs the owners toss your way. You do you.

For the rest of us, we don't have to be content with our lot in life--we can be the change we wish to see. Good quote!

Re: Dropbox S-1

#379
post #374

Earlier quoted context omitted.

As I said in another comment, there are other groups working to help lower-paid service workers organize. They're better suited to that task than I'd ever be. (And I'm not even a part of any union, I just think we in the tech world are long overdue for organized negotiation.) And, so, you do agree with me, but don't like some of my word choices? Can you maybe put that stuff aside and see that, organizing and negotiat…

Yes, I do agree with you wholeheartedly. Unfortunately, in my own environment, any attempt to organize among workers has fallen upon deaf ears. The workers themselves seem to be resistant (or perhaps fearful) to organizing in a manner that would give them more rights and fairer compensation.

Awesome.

And yeah, I think there's a big element of fear to it--fear of losing what is, right now, a pretty sweet deal for a lot of technical folks. That fear isn't entirely misplaced, anyway; individually, any of us could get fired for almost anything at almost any time. And there's a long and storied history of firing folks when they even whisper about organizing.

So I don't think the fear of organizing is irrational--but it is a fear that, I think, should be overcome, because the benefits are, of course, huge.

I dunno, I don't think it's all fear, I just think that's a much larger underlying force than people really want to recognize. If the risk were minimal, why wouldn't people be lining up to do this stuff?

OH, and FYI I am all in on addressing CEO/worker pay disparity. And, while we're at it, on how low-paid workers (janitors, call center stuff, etc.) get outsourced to another corp, etc.

Those are just problems that, I think, would need to be addressed directly through the political system, and not one that workers can take on in an organizing campaign of their own. They're all part of this constellation of "the American worker is getting screwed" but I feel like I gotta pick my battles, at least when I'm posting on the internet.

Re: Dropbox S-1

#380
post #327

Earlier quoted context omitted.

Can you explain?

The whole point of encryption is that you cannot meaningfully compare 2 pieces of plaintext. Homomorphic encryption doesn't change that. The only way to compare plaintext is to decrypt the whole thing. So either you must trust a centralized org (like dropbox today), or you must trust a single centralized key (that could be done with homomorphic encryption). (Also the best homomorphic algorithms still make small progr…

Consider a scheme in which:

Each user generates a symmetric "user key", kU.

The plaintext of each file (or without loss of generality, block of data, etc.), pFile, is encrypted with a randomly generated symmetric key, kFile, producing the ciphertext cFile. pFile is also hashed with a cryptographically strong hash, producing hpFile. kFile is then encrypted with hFile, producing ckFile. The user encrypts pFile with kU, producing chpFile. Finally, the user takes the first N bits of hpFile (for N on the order of, say, 16 or 32), producing hpFileTrunc. The user then submits hpFileTrunc to the server.

The server is, semantically, just a list of 3-tuples: (cFile, ckFile, hpFileTrunc).

The server sees if it knows of the existence of records with the same hpFileTrunc value as the client's submission. If so, it returns them to the client.

The client then tries, for each record returned by the server, decrypting ckFile2 with the client's hFile value, potentially producing kFile. If this is successful, the client then decrypts cFile with kFile, producing pFile. Finally, it compares this pFile to the original. If it matches, a match has been found, and the client exits the loop. If not, (or if either of the two decryption steps failed), it continues to the next record the server returned. If there are no more records, the client instead submits the tuple (cFile, ckFile, hpFileTrunc) to the server, which stores it.

Finally (whether or not a match was found), the client stores chpFile locally, to be used when retrieving the file.

To retrieve the file, the user decrypts chpFile with kU, producing hpFile. They truncate hpFile, producing hpFileTrunc, and submit it to the server. They perform the same process described earlier to retrieve the matching pFile.

(Note: truncation may also be replaced by, or combined with, a second round of hashing.)

With this scheme, assuming secure primitives (authenticated encryption and hashing), I don't believe it's possible to learn any information about a file unless you already have its contents.

So the server can tell if you're accessing (storing or retrieving) a particular file if and only if the server knows what it's looking for.

TL;DR: you can totally construct a scheme that allows meaningful comparison of plaintexts!

But... this is probably a bad thing. Comparison of plaintexts is a vulnerability: the server being able to see who's storing a particular "bad" file has a real impact on privacy. And likely more subtle impacts, too...

Post reply on HN