Live data from Hacker News

A recent security incident involving Dropbox Sign

sign.dropbox.com

71–76 of 76 posts

Re: A recent security incident involving Dropbox Sign

#71
post #36

Earlier quoted context omitted.

I'm not a business, I'm a paying customer on the most expensive personal tier. It's silly that they don't offer this feature for me. I also can't upgrade to a business plan because those require at least 3 users. It just feels like feature gatekeeping to me, but no way for me to pay more to get this feature. But I also understand that personal users are not Dropbox's main focus.

A Synology/QNAP/TrueNAS NAS is a far better solution, with no restriction.

QNAP does not seem secure at all, IMO its not worth it. I have not used the others you mentioned.

Re: A recent security incident involving Dropbox Sign

#73
post #69
post #48

Earlier quoted context omitted.

Acquired in 2022? IMO that's enough time to bring their service up to the same security standard as the rest of their services, assuming it's a priority. Google and others normally have a 6 month grace period for bug bounty reports in acquisitions.

> that's enough time to bring their service up to the same security standard If you can get competent people to work for you while keeping Wall Street happy, sure, but there are much "cooler" companies across the street that Wall Street is more excited about, are hiring right now, and the competent folk are going there. At the end of this extreme is Equifax-like companies that have leaks and lots of other issues. Bef…

I worked at equifax.

Just sort of ended up there when the fun startup I was at got acquired by them. I soon burnt out and checked out mentally and eventually they noticed and we parted ways.

I just wish I had had the wisdom to get myself out before I burnt out. Looking back, it was a slowly boil the frog type of situation.

Re: A recent security incident involving Dropbox Sign

#74
post #56

Earlier quoted context omitted.

I used to love Dropbox, then they limited devices and storage so much it was barely worth it, and spamming me with nag popups all day to upgrade because my storage was near full sealed the deal and I just started using OneDrive (not much better but it's integeated and convenient, probably going to just go foss with a home server eventually). Another sad downfall of a once good company.

They only limited devices for free accounts.

Paywalling existing free functionality is the most creatively bankrupt and fast way to get me to never buy your product.

Re: A recent security incident involving Dropbox Sign

#75
post #67

Earlier quoted context omitted.

In the grand scheme of things, expecting your name and email address to really stay private is not all that reasonable. You probably gave them to the person who then used Dropbox Sign to send you a document. If you were really worried you could have used a throwaway account. The old saying is, once you tell someone, it's no longer a secret.

> In the grand scheme of things, expecting your name and email address to really stay private is not all that reasonable. In the grand scheme of things, nothing matters and we’re all going to die. It’s been a while since I read the GDPR, but I don’t remember a section titled “personal data which is OK to leak because it doesn’t matter in the grand scheme of things *shrug emoji*”. > You probably gave them to the perso…

> In the grand scheme of things, nothing matters and we’re all going to die. It’s been a while since I read the GDPR, but I don’t remember a section titled “personal data which is OK to leak because it doesn’t matter in the grand scheme of things

Best comment on HN. Ever.

Both clever and informative on so many levels. It seems half of the HN crowd work in the Ad industry and never cease coming up with ridiculous excuses for why it's OK to abuse other people's PII. I was surprised to see there wasn't the usual gnawing of teeth this time, about the GDPR which tend to follow whenever that fine regulation is mentioned.

Post reply on HN