6 ms·
drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapids
by dhouston 15y ago
drew from dropbox here. i hope you guys can give us the benefit of the doubt: when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent (the title on HN was suggesting it could be the successor to torrents), you can imagine how that could ruin the service for everyone -- illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. the internet graveyard is filled with services that didn't take this approach.
so, when something like this gets called to our attention, we have to do something about it. note that this isn't even by choice -- if we don't take action, then we look like we are tacitly encouraging it. the point is not to censor or "kill" it (which is obviously impossible and would be idiotic for us to try to do), but we sent kindly worded emails to the author and other people who posted it to take it down for the good of the community so that we don't encourage an army of pirates to flock to dropbox, and they voluntarily did so.
there were no legal threats or any other shenanigans to the author or people hosting -- we just want to spend all our time building a great product and not on cat-and-mouse games with people who try to turn dropbox into an illegal file sharing service against our wishes. (for what it's worth, dropship doesn't even work anymore -- we've fixed the deduplication behavior serverside to prevent "injection" of files you don't actually have, for a variety of reasons.)
that said, when we disabled public sharing of that file by hash, it auto-generated an email saying we had received a DMCA takedown notice to the OP, which was incorrect and not what we intended to do, so i apologize to dan that this happened.
(*edited the last paragraph: we didn't send a takedown notice, we sent a note saying that we received a DMCA takedown notice, which was also in error)
- wakeup 15y agoHow about you kill yourself capitalist cunt?
- huhtenberg 15y ago> we've fixed the deduplication behavior serverside Great, and that's all you should've done in this case.
- slackerIII 15y ago> Great, and that's all you should've done in this case I doubt that is what the lawyers said.
- random42 15y agoThen they should fire the lawyer who a-OKed to send the invalid DMCA takedown notice(s), which makes Dropbox culpable for it.
- rhizome 15y agoI appreciate the nice-guy approach here, but there remains two problems with it: relying on the goodwill of internet strangers not to abuse the service and exposing Dropbox to false DMCA takedown liability. "Under penalty of perjury," I think the clause goes. That auto-takedown workflow might need a little revision, but I'm sure you already realize this.
- random42 15y ago> illegal file sharing has never been permitted and we take great pains to keep it off of dropbox. Which is great, except you are punishing the crime, before it even occurred. Remember use of torrents are not illegal per se, sharing files which you do not copyright of, and piracy is. > there were no legal threats or any other shenanigans to the author or people hosting. (EDIT - No applicable. Read Drew's edit.) DMCA takedown notice is a legal threat. Worse part is, its not even valid, IANAL, but do you own the copyright of the data or the copyright owner approached you to issue a DMCA takedown notice? > it auto-generated a DMCA takedown notice to the OP, which as many pointed out here was invalid and particularly inappropriate in this case, and was absolutely not what we intended to do. Please do not send legal notices, without lawyers reviewing them?
- atacrawl 15y agoWhich is great, except you are punishing the crime, before it even occurred. This is pretty disingenuous. You really think their assumption that Dropship would quickly turn Dropbox into an illegal file sharing haven is an unrealistic grasping of straws?
- random42 15y agoAs mentioned before, IANAL, and I do not have deep/any knowledge of the laws Dropbox is incorporated in. However, "Presumption of Innocence" (http://en.wikipedia.org/wiki/Presumption_of_innocence http://en.wikipedia.org/wiki/Presumption_of_innocence) aka "Innocent until proven guilty" is one of the universally applied (if not, also accepted), legal concept. Can dropship be used for illegal file sharing? Yes. Is dropship being used for illegal file sharing? No, until proven otherwise. Legal penalties are applied for the cases depending upon what happens/happened, not what could happen. That being said, my understanding of law is deeply based on my country's law. The case might be different in the country dropbox is incorporated. EDIT - I got a lot of downvotes for this reply. Can someone (who intend to downvote this comment), please explain where I am missing the point and/or being wrong?
- uxp 15y ago
- marshray 15y agoHelp me, I'm trying to get my head around this. You developed a file sharing system that allows anyone to obtain the full contents of a file by simply knowing its hash? Then when developers make tools to allow using this for simple cross-account file transfer you send DMCA takedown notices, claiming you are the rightful copyright holder of their code, to places like GitHub? You seem to equate other file transfer services with "illegal file sharing". Did you ever consider the possibility that someone could steal the contents of another person's file by knowing the hash of it? Sometimes hashes are public info and the file contents are not. Or am I not understanding what just happened here?
- arashf 15y agoNo DMCA takedown requests were sent to GitHub. We simply nicely asked the author of Dropship to take down the link and he fully understood our position and took the code down. The only erroneous use of DMCA was when we attempted to take down the link on Dropbox, which was an entirely honest mistake.
- kunjaan 15y ago"He requested that I not only remove the archive from Dropbox but delete my posts on Hacker News, which at that point included the fake DMCA takedown." What you tried to do there is censor and resorted to fake legal repercussions. You can brush it aside saying that it was a mistake but it is still uncool for a corporation to do that to an individual.
- rorrr 15y agoI'm pretty sure sending fake DMCA requests is illegal, and it doesn't matter if it's a mistake.
- rprasad 15y agoIt's illegal only if it was intentional. A mistakenly sent DMCA request is okay, as long as the sender follows up with a disregard notice.
- TheAmazingIdiot 15y agoRegardless, I can completely understand the actions of staying away from Rapidshare (read the full comment for a day pass of $5, or wait 30 seconds). However, pissing off the constituency that originally promoted your service isn't exactly #1 in your marketing plan. I'm not well known, but many who reside here are. Scaring off hackers just seems wrong, being Hacker News and all.
- dhouston 15y agoi can promise you we're not trying to piss off the HN audience, but sometimes we manage to anyway :)
- jk8 15y agoAny news on fixing the exploit? Is the option being considered by dropbox?
- mrud 15y ago> we've fixed the deduplication behavior serverside to prevent "injection" of files you don't actually have, for a variety of reasons.) Already done.
- gergles 15y agoDoesn't seem to be done, as I just used the code in question to get the example trailer and I did not have the file in advance.
- trotsky 15y agoThis is one of the more interesting comments in this thread. Can anyone confirm it still works? EDIT: I get the following error: [xxx@xxx laanwj-dropship-464e1c4]$ ./dropship examples/sintel_trailer-1080p.mp4.json ('Oops, blocks are not known: %s', ['lykR7INbdxXNk04IpJUxTvO97GeETwAbobol2283eqY', 'ciZ4YYqkiA9VssSpfmcagRJaYMtD3wNqZ4NTeV9BvOc', '7qe_U9KLL8t1RRH3K01PdTxnEGCnm1nP8S30ZkXK0KI', 'cPJPJ_uch8hJFhKaEeXufETDZ-q6Fqz1cibxoYwL8G8'])
- wladimir 15y agoIt calls your bluff now :)
- y0ghur7_xxx 15y ago"when we disabled public sharing of that file by hash" Sorry, I may sound harsh, it's not my intention, but I have to ask: how often does it happen that you disable public sharing of files you don't like?
- dgreensp 15y agoFrom what I understand about Dropbox's anti-piracy system, he's talking about what they do when, say, someone posts a public link to "Spiderman.3.DVDRip.avi" in a forum in China. This obvious and illegal use of Dropbox is a big liability, not to mention source of traffic.
- sycren 15y agoOut of interest, how do you plan to stop people using dropbox like rapidshare? It would be easy for one to upload a file divided into multiple rar files and distribute them to different dropbox accounts. The only way you would be able to block this is watching for a large amount of downloads of a particular file and finding out the context of the file which may prove impossible (and possibly illegal). In terms of the software, it is unlikely that the general user will use it without some technical skill.
- TheAmazingIdiot 15y agoIf I wanted to be a complete ass about using dropbox for piracy, I'd use GPG. Share the GPG private key, the public key, the archive, and the password to use the key. It's too computationally expensive to automate opening these. And you could always spread the keys and keyphrase to where ever you want it. But dropbox works well for what it is. I see no reason to trash it with pirated stuff.
- sycren 15y agoIf dropbox opened the archives (to check) then it would be against the British data protection laws (and probably most other countries) if they were not given the access by the owners. I have no want or need to trash it with pirated material either.
- metageek 15y agoEven in the US, it might be illegal under the ECPA.
- allwein 15y agoDropbox already has provisions for restricting those accounts which use an excessive amount of bandwidth. They'd be able to block those files without needing to know the actual contents.
- jrockway 15y agoAsking people to remove stuff from HN? That's utter bullshit, and if true, I'm basically done with Dropbox. Asking people not to talk about something (with access to your service as the gun to their heads) is not something I will tolerate in someone I do business with. I don't actually use Dropbox for anything, though, so perhaps my thoughts don't matter.
- JshWright 15y agoYou're done using something you don't use because they _asked_ someone to do something (rather than taking the industry standard approach of getting lawyers involved)?
- elliottcarlson 15y agoWhat would they be able to do with their lawyers? There is no case.
- JoachimSchipper 15y agoHarassing people can be pretty effective. (I'd say "ask Sony", but they might have actually won.)
- zhoutong 15y agoIt's biased to say that torrents and rapidshare are equivalent to illegal file sharing. Illegal file sharing is just how people use these platforms, but not these platforms themselves. Dropbox is just another file sharing platform which directly exposes to the threat of illegal file sharing. The de-duplication feature greatly helps pirates to gain access to files that don't belong to them, or even other people's privacy. If illegal file sharing service is something against your wishes, what you can do is to concentrate your effort to fight against copyright infringement (if you'd like to), instead of killing an innocent open source project that simply helps cross-account file sharing. I used to love Dropbox's de-duplication feature, and I think that helps a lot of people with low bandwidth connections. Since I started noticing the existence of such feature, I'm already aware of: 1. My files are no longer mine. Anyone who knows the hash can access my files immediately. 2. Dropbox's claims about encryption are totally pointless in this case. Encryption is not going to help. 3. Requests from government agencies are going to be fulfilled very promptly. 4. Even hackers can access my files with the knowledge of only the hash, why can't employees of Dropbox? I don't understand the "strict access policy" on employees inside Dropbox. Are there any difference between Dropbox's de-duplication and eDonkey's hash-to-file P2P? To me, Dropbox is doing something here that against their wishes.
- abofh 15y ago(Well) encrypted data is fundamentally indistinguishable from random data. De-duplication requires commonality between files, which could not be found in encrypted data if users had unique keys. Thus, if they have the ability to de-dupe _after_ you've uploaded a copy, they have the ability to decrypt your entire archive. I'm not saying that's how they do it, but it would seem the logic is that your data never was particularly well encrypted.
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- trotsky 15y agowe've fixed the deduplication behavior serverside to prevent "injection" of files you don't actually have, for a variety of reasons I think this was a good call, and not just for the piracy issues but for the substantial information disclosure and possible misappropriation of sensitive documents that it could have facilitated. This is something that's been on my radar for some months, and frankly seemed like a significant reason to not trust dropbox with anything that wasn't effectively public. So I'd consider the event a net positive for your firm and customers. I might consider trying to get out in front of any negative publicity that's going on here by publicly thanking the programmers and researchers that have brought these risks to light in the past month paying a few bug bounties to them. A few bounties similar in size to the ones the mozilla and chromium projects pay out certainly wouldn't break the bank, and might do something for public opinion. Not to mention the benefits of an ongoing program - people might be more inclined to contact you first instead of immediately going public with future issues.
- naz 15y ago> ... the substantial information disclosure and possible misappropriation of sensitive documents that it could have facilitated They match duplicate files with an SHA256 sum and size in bytes. With those two factors, the probability of a collision is incredibly tiny and impossible to exploit usefully. If you tried a trillion combinations you might find a useless file, but by then you would be detected and banned from Dropbox.
- trotsky 15y agoI agree that random collisions is an unlikely attack vector. However, there is not a general understanding that disclosing sha256 hashes is the same as disclosing the file. Imagine a social engineering attack that requested employees run a 'sha256sum ~/Documents/* > hashes.txt' and mail the results with the explanation that this is to make sure they have no infected documents/old versions/unauthorized files on their hard drives. Many people would be willing to do something like that if it appeared to be from a legitimate source, but if they had been asked to email all their documents they'd be much more unlikely to comply. Hashes are also disclosed in other ways. In certain cases security researchers will reveal a hash of a file publicly to provide proof of a file that might contain a proof of concept exploit against a privately disclosed bug - with the idea that the contents of the file could be revealed at a later date. If someone the researcher shared that file with privately placed it on dropbox, that file could be revealed publicly. Online AV systems could be another form of disclosure. Many "online scan" products report the hashes of local files back to the server for malware detection - it is faster to upload your hashes than download the hashes of the many millions of signatures a product can scan for. Another version of this is virustotal.com or similar services that will scan a submitted file against a large number of AV products. The resultant scans include the sha256 hash and are often publicly accessible, while the contents of the file isn't. In the days after several recent Adobe flash 0-days, virustotal reports on infected documents were reported publicly days before the bug was fixed or the actual exploit was publicly revealed. Here is one such example for CVE-2011-0611 submitted on 4/9/2011, made public on 4/11/2011 but no patch was available until 4/15/2011: http://www.virustotal.com/file-scan/report.html?id=1e677420d7a8160c92b2f44f1ef5eea1cf9b0b1a25353db7d3142b268893507f-1302359653 http://www.virustotal.com/file-scan/report.html?id=1e677420d... Granted, all of these presume that sensitive files are being placed on dropbox when they probably shouldn't be. But these things do happen. As far as information disclosure, someone who has a legitimate copy of a file could then use the hash to determine if the file is being leaked off site or distributed inappropriately. This may be seen as a feature to some document owners, but it could serve to detect exfiltration that one might otherwise agree with. Whistle blowers come to mind. If you suspected a leak, one might provide slightly different copies of a sensitive document to a group of employees and see if any of the hashes appeared on dropbox after admonishing them to not allow the file to leave the enterprise. I understand that many of these concerns could be dismissed with well, they already have bad document handling procedures, etc. Which would be valid, however in the real world a lot of poor behavior goes on. I'm just listing these as examples of the kind of problems that could arise, I'm not trying to take a stand on how likely any of the attacks might be.
- allending 15y agoDMCA notices are no joke, especially for the receiver. Your 'automated' system should probably be either: a) manual b) have a big ass 'THIS F-ING SENDS A DMCA NOTICE' warning before you disable a file.
- blasdel 15y agoYes, in an ideal world their system would only ever store and forward a received DMCA notice. But here in the real world Dropbox doesn't really give a shit whether they actually got a real DMCA notice from Sony regarding the presence of "Spiderman.3.DVDRip.avi" in a particular 13-year-old's public folder — since none of those accounts are paid, they're just saving themselves money, and noone would discover it normally or have a reason to be pissed off at them. They can't even get in trouble for perjury since they were never sending DMCA notices to users, but rather telling users that Dropbox had received a notice.
- jsprinkles 15y agoI would like you to answer a simple question because after reading Arash and your responses I have doubts about using Dropbox. Since you fixed the problem server side, why did Dropbox feel it necessary to then attempt to stamp out the no longer functional tool? Would you remove the ability for people to download DeCSS from my public folder due to potential harm? Would you remove the ability for people to download penetration testing tools from my public folder due to potential harm? Would you remove the ability for people to download disassemblers from my public folder due to the potential harm? The code could be an interesting technical exercise and the censorship you are being accused of arises from this pointless action. That is what people are questioning. Where does that rabbit hole end?
- allwein 15y agoAt the time they requested the removal of the tool, they hadn't yet fixed the problem server side. I don't think it's egregious to request that the tool be taken down while they worked on fixing the problem. Much like how security exploits aren't just immediately published without notifying the company so they have a chance to fix it.
- bdesimone 15y agoI sympathize. But could you please explain how that email was "auto-generated"? I'm trying to give you the benefit of the doubt, I love what dropbox does, I understand the need to protect yourself from people looking to abuse the service, but... come on... was it really autogenerated? I think that is the part that has everyone scratching their heads.
- UnFleshedOne 15y agoI think they only ever planned to manually remove user's files in the event of receiving a DMCA takedown notice. So they implemented an automatic notification stating that. Or maybe it was a default option, one of several, and it wasn't changed to something more appropriate.
- nateberkopec 15y agoThat was such a classy response. Well done Dropbox - I don't want you become rapidshare either.
- Shorel 15y agoHonestly, the title is very sensasionalistic. It tries to make it sound like you tried to enforce patents on a Dropbox clone or something, while the truth is that the software was a parasitic service incapable of existing without Dropbox itself. To me that last part makes irrelevant that the software was OSS or not.
- GrandMasterBirt 15y agoJust a quick thing to point out. The rabbit is out of the hat (or whatever is the correct proverb for it). As with all technologies seen in years past, don't fight it on "legal" terms, and I don't mean legal as in suing the crap out of them (the Sony method), I also mean pleading to the community (the Valve method). In reality if Dropship is illegally accessing a person's private files without "sharing" or making it public, fix that. The approach is quite novel in that you can create a one-off dropbox account, make it private, and claim someone "hacked" into your account to acquire it as it would appear Dropship's methods cannot be proven different than a hacking attempt, which means the uploader is not "responsible". However to counter people's points, dropbox has no choice but to demand that any copyright violation even in private files is forbidden, otherwise they are hit with DMCA, the US laws give them zero wiggle room here. Dropship is a nifty loophole in the DMCA rules allowing dropbox to become the legal rapidshare in the US, probably involuntarily and taking on legal risk they don't want in any way.
- alexhektor 15y agoHey Drew, Alex from JDownloader (an OS project with over 15M activeusers, btw) here. >>"when something pops up that encourages people to turn dropbox into the next rapidshare or equivalent, you can imagine how that could ruin the service for everyone" You don't want to be the next Rapidshare. I encourage you to overthink this. They're your competitor. Sure, if with Rapidshare you mean "illegal file sharing service", which I assume you do, because you use it in one sentence with Torrents, you might be right. Although Rapidshare hasn't hit the deadpool yet and is still around and strong and in compliance with current law etc. But if you mean the highly profitable business of sharing (legal) files, you should think again. They offer the same thing you offer in a way. Cloud storage + backups on a very similar freemium business model. Only for larger files. For some use cases your product might be exorbitantly better (automatically syncing files on a harddrive and not just having it in a filesystem in the cloud like RS), in some ways Rapidshare's product is a lot better though(e.g. sharing larger files with multiple people). But the nature of Rapidshare's product of course comes with a few strings attached. Since the incarnation of filehosting there have been people who try to exploit it for illegal purposes. Rapidshare obviously doesn't have the cleanest image, yet, they comply with the DMCA and offer an incredibly valuable product. And, most importantly: Rapidshare (as well as the majority of one-click-hosters) learned about the Streisand-Effect (see http://en.wikipedia.org/wiki/Streisand_effect http://en.wikipedia.org/wiki/Streisand_effect) early and did not as aggressively about things like this the way you did. Of course our and your situation is different, yet there are a few similarities you could have learned from. This time you have successfully dodged the bullet and made a good strategic move, but I sincerly hope you have also learned sth. from this for the next time, because with user base that is still growing like crazy the next time WILL come. And next time it might hit mainstream media even bigger and not only be on HN and Techmeme. BTW: I can of course understand that you try to fight piracy as good as you can in order to protect the brand as well as the company from expensive lawsuits and their even more hurtful consequences. It's just the way in which you handled things. You should have known better. The Streisand effect has happened to so much companies already. But congrats on handling the situation so well after seeing all the negative feedback. It shows true entrepreneurial skills as well as hard work that some arrogant entrepreneurs don't put in anymore once they have moderate success (in startup terms).