Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arashf
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
arashf
14y ago
this is arash from dropbox. a similar thing happened to us a couple years ago and mattcutts helped resolve it pretty quickly ( https://twitter.com/mattcutts ). I would try to reach out to him ASAP. edit: ack. just read his twitter feed and
2.
▲
by
arashf
14y ago
hmmm, I think it's fairly common practice amongst similar software (i.e. firefox, chrome, etc.) to use system time as a signal that you may be connecting to a server that has an outdated SSL certificate. while it's not perfect, it's a good
3.
▲
by
arashf
14y ago
that's just SSL cert validation :-)
4.
▲
by
arashf
15y ago
hi all, we've been reading all the feedback carefully and made a change to licensing section to clarify what we meant. the change is highlighted on our blog: http://blog.dropbox.com/?p=846
5.
▲
by
arashf
15y ago
I know - right? :-). (wladimir wrote dropship)
6.
▲
by
arashf
15y ago
No DMCA takedown requests were sent to GitHub. We simply nicely asked the author of Dropship to take down the link and he fully understood our position and took the code down. The only erroneous use of DMCA was when we attempted to take dow
7.
▲
by
arashf
15y ago
We didn't remove the file - we simply banned public access to it.
8.
▲
by
arashf
15y ago
This is Arash from Dropbox. We removed the ability to share the project source code because it enables communications with our servers in a manner that is a violation of our Terms of Service. By our TOS, we reserve the right to terminate t
9.
▲
by
arashf
15y ago
you're right in that all these things are theoretically possible in a system where the encryption key is not stored client-side. I don't know of many services that advertise every way in which their systems could be compromised. I think you
10.
▲
by
arashf
15y ago
basically, the government could try to make that type of request independent of backend implementation. what protects users against such an obtrusive action (effectively violating every user's privacy in search of the bad guys) are the prov
11.
▲
by
arashf
15y ago
de-duplication doesn't make users any more vulnerable to intrusive government actions. today, a government agency could ask any online service to provide the names of all users who have a particular file, whether or not the service employs
12.
▲
by
arashf
15y ago
it's unclear to me what statements we're making are 'not true'. if you don't believe our statements, I'm not going to be able to convince you to trust us over the discourse in this thread :-)
13.
▲
by
arashf
15y ago
cryptographic signatures of files are never transmitted over plaintext. yes, the current incarnation of the mobile apps don't encrypt the names of the files but we are working on a fix for this as soon as we can adequately improve the SSL
14.
▲
by
arashf
15y ago
we take as firm as stance as possible on user privacy (google faces and fights these very issues) the government needs to comply with the provisions of the electronic communications privacy act by obtaining a warrant supported by probable c
15.
▲
by
arashf
15y ago
at the expense of conveniences like web access, document previewing, simple sharing, etc. - sure :-). if your answer to the web access concern is: derive the key from the password, who's to say we wouldn't store the key and later use it to
16.
▲
by
arashf
15y ago
hi there, arash from dropbox here. all data is (as we state in the referenced help article) encrypted before it's stored on the backend. all data on dropbox can be made shareable and is web viewable. as a consequence, we do need the ability
17.
▲
by
arashf
15y ago
hi there, arash from dropbox here. all data is (as we state in the referenced help article) encrypted before it's stored on the backend. I'm not sure why you're concluding that de-duplication implies lack of encryption. the de-duplication o
18.
▲
Dropbox on Fox (TV)
(video.foxbusiness.com)
8 points
by
arashf
15y ago
|
0 comments
19.
▲
by
arashf
15y ago
It wasn't a premature optimization. It was both a better experience for the user (saves bw/reuploads for the user) and was simpler to implement (can keep things in one global bucket) given we didn't want things like renames to trigger reupl
20.
▲
by
arashf
15y ago
Hi all, Arash from Dropbox here. We understand the concern that the government could try to guess whether a particular file has been uploaded to Dropbox based on processing times and then request that Dropbox identify a user who has access
21.
▲
by
arashf
16y ago
dropbox (only sf positions, sorry!) http://www.dropbox.com/jobs
22.
▲
by
arashf
16y ago
the iOS update just hit the store a few minutes ago
23.
▲
by
arashf
16y ago
dropbox! http://www.dropbox.com/jobs
24.
▲
by
arashf
16y ago
I should probably already know this (and we'll email you about it), but I was wondering how you're currently keeping your dropbox index up to date. our existing APIs don't make it all that easy (or efficient :).
25.
▲
by
arashf
17y ago
we can't tell you that! :-)
26.
▲
by
arashf
17y ago
digg us please? ;-) http://digg.com/software/Dropbox_iPhone_app_finally_released
27.
▲
by
arashf
18y ago
not exactly ;-) pasted from terms: Dropbox does not claim any ownership rights in Your Files. You acknowledge that Dropbox does not have any obligation to monitor the Files or User Posts that are uploaded, posted, submitted, linked to or ot
28.
▲
by
arashf
18y ago
hi all, arash (from dropbox) here. as mentioned elsewhere in the discussion, the terms are referring to contact information, not data.
29.
▲
Dropbox (YC Summer 07) seeking designer
42 points
by
arashf
18y ago
30.
▲
by
arashf
19y ago
I'd never do that.
More ›