4 ms·
When Dropbox deliberately circumvented Apple's security features to make itself difficult to remove [1], was the company's #1 core value of "Be worthy of trust"
by stirner 8y ago
When Dropbox deliberately circumvented Apple's security features to make itself difficult to remove [1], was the company's #1 core value of "Be worthy of trust" in mind, or was that only added in retrospect?
[1] http://applehelpwriter.com/2016/08/29/discovering-how-dropbox-hacks-your-mac/ http://applehelpwriter.com/2016/08/29/discovering-how-dropbo...
- antoncohen 8y agoThis issue has been addressed already: https://news.ycombinator.com/item?id=12464730 https://news.ycombinator.com/item?id=12464730 I don't believe there was any intention of making Dropbox hard to uninstall. I think the intention was to make the process seamless for users, and there was a bug that caused a setting to get reapplied after a user changed it.
- saagarjha 8y agoI believe that Dropbox doesn't really have poor intentions here: they're trying to make their product easy to use or work better or whatever. I don't think their intentions are malicious. However, I strongly disagree with the method that they use to achieve this: installing kernel extensions, bypassing Accessibility prompts, having a hooks in every process they could possibly get their hands on, etc. is going too far. There's a reason those checks are there: they keep the user safe. Trying to get around these is, in my mind, arrogant. They think that they're better than every other company that abides by the rules. Google Drive doesn't do this. Box doesn't do this. Even iCloud Drive doesn't do what Dropbox does. I was talking to someone just two days ago, who was tearing their hair out because their application's "Open" panel took something like ten seconds to open. Why? Because the Dropbox extension decided it didn't want to play along nicely. It's foolish to think that your software will not have bugs, and outright foolhardy to do this for so little benefit.
- antoncohen 8y agoDropbox pushes the state of the art for file sync. They added sync status icons on Mac OS X before Apple had an API for it, later Apple added an API. Those icons are part of what makes the product so usable. The kernel extension is another example. AFAIK it was added for Smart Sync[1] (née Infinite[2]). Infinite is amazing, truly amazing, and the only way to implement it is via a kernel extension. Microsoft tried to implement it via the GUI with OneDrive's "smart files" (aka placeholders), they removed it because the files didn't work in too many places, like via syscalls and from command line. Dropbox Infinite is kind of like the source control systems Google and Microsoft created to handle their huge repos. Microsoft's GVFS uses a file system filter driver (kernel extension) called GvFlt (or ProjFS)[3]. From what I understand, Google's Piper uses FUSE[4], which would be a third-party kernel extension on macOS. My point is, these are technical achievements that provide seamless and intuitive user experiences, they aren't betrayal of trust. [1] https://www.dropbox.com/smartsync https://www.dropbox.com/smartsync [2] https://blogs.dropbox.com/tech/2016/05/going-deeper-with-project-infinite/ https://blogs.dropbox.com/tech/2016/05/going-deeper-with-pro... [3] https://www.visualstudio.com/learn/gvfs-architecture/ https://www.visualstudio.com/learn/gvfs-architecture/ [4] https://cacm.acm.org/magazines/2016/7/204032-why-google-stores-billions-of-lines-of-code-in-a-single-repository/fulltext https://cacm.acm.org/magazines/2016/7/204032-why-google-stor...
- fapjacks 8y ago> My point is, these are technical achievements that provide seamless and intuitive user experiences, they aren't betrayal of trust. You having put a lot of effort in this thread into weaving trust into your description of Dropbox operations, I'm surprised that you wouldn't trust an end user when they tell you that this in fact is a betrayal of their trust in Dropbox.
- saagarjha 8y agoBut I don't think I can disable your "state of the art" features if I really wanted to. I don't want your extra features if they require trapping on file modification syscalls in the kernel. I'm fine with the behavior that other apps provide without your "truly amazing" project Infinite kernel extension. > Dropbox Infinite is kind of like the source control systems Google and Microsoft created to handle their huge repos. Microsoft's GVFS uses a file system filter driver (kernel extension) called GvFlt (or ProjFS)[3]. From what I understand, Google's Piper uses FUSE[4], which would be a third-party kernel extension on macOS. I find that your examples really show a lack of understanding of why I'm frustrated by Dropbox's behavior. The products you linked are source control systems used by software engineers. Dropbox is aimed at nontechnical users. One of those groups understands what a kernel extension is, and the other one can't point their finger at Dropbox when their computer crashes. How is this not betrayal of trust? When a user installs an app they don't expect it to literally put its fingers all over the operating system. Not only does Dropbox look like any other application on the surface, it actively works to perpetuate this myth by spoofing operating system dialogs and prompts. If a doctor did a procedure on a patient that they didn't fully explain or even mention that they were doing they'd be sued for malpractice. Also, I don't really like doing this, but you seem to be overly positive about Dropbox's work in this field. Do you work there, or have you ever worked there? Did you have a vested interest in this project?