7 ms·
Study of Thousands of Dropbox Projects Reveals How Successful Teams Collaborate
- plg 8y agoThis is deeply troubling. As a scientist who uses* Dropbox I gave no informed consent. I know they claim personally identifiable information was removed but still I gave no consent for this. *not for long, perhaps
- raphman 8y agoExactly. See also https://twitter.com/kopfnuss/status/1020575998205710336 https://twitter.com/kopfnuss/status/1020575998205710336 and https://twitter.com/RaphaelWimmer/status/1020582873345163264 https://twitter.com/RaphaelWimmer/status/1020582873345163264
- bsder 8y agoI continue to be stunned that people still somehow think that these services have any modicum of consideration for their users. If you don't want your information accessed--run your own servers, people. That's your only option.
- yborg 8y agoI can't speak to how informed you were when you gave the consent, but if you are using the service, you provided it. "Law & Order and the Public Interest. We may disclose your information to third parties if we determine that such disclosure is reasonably necessary to: (a) comply with any applicable law, regulation, legal process, or appropriate government request; (b) protect any person from death or serious bodily injury; (c) prevent fraud or abuse of Dropbox or our users; (d) protect Dropbox’s rights, property, safety, or interest; or (e) perform a task carried out in the public interest." I would assume that this research fell under the "task carried out in the public interest" clause.
- plg 8y agoIf THAT is their defense —- we all agreed to it even if we didn’t understand it at the time —- well then good luck to them
- smokeyj 8y agoWhy else would Condi Rice be on the board /puts on tinfoil hat
- Alex3917 8y agoIsn’t public interest a criteria for getting IRB approval? Having read all the recent AoIR threads on ethics, this doesn’t seem outside of the accepted norms.
- krageon 8y agoAccepted by who? Obviously not the person you are responding to. Ethics is a relative field, not one full of absolutes.
- IshKebab 8y agoThat doesn't stand up under the GDPR any more as far as I know.
- trampypizza 8y agoI imagine the work was carried out by a processor, which could be perfectly legal if the contract between the two entities had adequate data protection clauses. This is just a guess though, I'm sure its much more complex than that.
- blub 8y agoIf they asked consent specifically for these types of studies, then it's legal. As in: a form asking the user if their information can be used in this way and giving them the possibility of opting out. Adding one more clause to the privacy policy doesn't count.
- ErikVandeWater 8y agoThis may come across as argumentative, but it's still a valid question - What's the harm to you?
- ggg9990 8y agoThe harm is that 1) data which seems anonymized can be de-anonymized due to carelessness or advances in analytical techniques, and 2) it’s mine. I have laptops in my house for example that I’ve not used in years and will never use again. That doesn’t give you the right to steal them even if there’s no explicit “harm” to me.
- another-one-off 8y agoThe point of consent is that it isn't your (or Dropbox's) opinion on what constitutes harm that matters. It is the person who gives consent.
- jeffwass 8y agoMaybe the parent was performing a research project on Dropbox collaboration techniques and got scooped? But seriously, as an example, I know people that share sensitive personal information with their accountants at tax time using Dropbox. Would suck for any of that to be made available to any third parties.
- nl 8y agoGiven it was from universities, then prior disclosure of IP for patent applications could be a "harm". Even the directory names and structures could be key information in some applications.
- ggg9990 8y agoImagine you have a folder in your Dropbox with 237 subfolders, and each of those subfolders has a certain number of files in it. The largest folder has 1,132 files, for example, the second largest has 916, the third-largest has 771, etc. Then imagine you have a second folder with 117 subfolders with another pattern like above. Now imagine that the first folder structure matches a torrent of embarrassing pornography and the second appears to be a superset of a project published to GitHub under your name (i.e. with some directories being gitignored)
- pacbard 8y agoI wonder how they got approval from the Northwestern Institutional Review Board. Not having explicit consent from research subjects might indicate that they qualified for some form of exempt status. Did they sell them that Dropbox collects that data as part of their normal operation, therefore consent is not required? Did they say that Dropbox's anonymization was enough to guarantee subjects' anonymity? Did they say that Dropbox's user agreement already enrolls users into research projects?
- fhsm 8y agoLooks easy enough to ask: https://irb.northwestern.edu/participants/questions-and-concerns https://irb.northwestern.edu/participants/questions-and-conc... Participant questions go to eyates@northwestern.edu and non-participant questions go to irb@northwestern.edu.
- ggg9990 8y agoAs a Dropbox paying customer and never having heard of the Northwestern Institutional Review Board it's not them that pisses me off. I haven't reconsidered my usage of Dropbox for a very long time, since I made the decision to stay with them after their no-password fiasco. Today is the first day in a long time.
- projektir 8y ago> Teams at lower-performing institutions were more likely to have one person or a small number of people doing more of the “heavy lifting.” Is there some way to address this when it does happen? Or is it just a matter of the right people being involved?
- munchbunny 8y agoMy guess is that this is a symptom of only specific people being competent/engaged. Alternatively, this is specific team members hating process. In the latter case, I think that means you adjust process to be lighter. In tbe former, there is no procedural fix, only hiring fixes.
- rahimnathwani 8y ago"To invesitage the impact on peformance" Wow, can't HBR afford a proofreader?
- Cyphase 8y agoOr a spell-checker at least.
- whitepoplar 8y agoI love Dropbox, but this kind of data-gathering without explicit permission is bananas. What I'd really love to see added to Dropbox is client-side encryption (i.e. I want to manage my own keys so nobody can monkey with my data). And yes, I know I can store an encrypted container inside Dropbox, but that defeats the purpose of easily accessing my data from every device.
- swaroop 8y agoSee https://cryptomator.org/ https://cryptomator.org/
- kilroy123 8y agoDidn't know about this. Thank you!
- newscracker 8y agoDropbox may not natively add client side encryption in the near future. The way Dropbox has stored data from the beginning is by deduplicating information across all its users to save space. So if you upload a book or a movie or a song and I upload the same, Dropbox stores one single copy of it for the both of us. This is just a simplified explanation. The actual deduplication is done in smaller blocks. If you want client side encryption with Dropbox, you have to add a layer before the Dropbox client sees your files on your system, using Cryptomator or Boxcryptor or encrypted volumes with Veracrypt, etc. Or you could switch to other online backup/sync services that claim to have client side encryption, like SpiderOak and a few others.
- whitepoplar 8y agoThat's true, but I'm sure businesses (and many individuals) would pay a premium for native client-side encryption with keys they hold themselves.
- zkms 8y ago> Dropbox gave us access to project-folder-related data, which we aggregated and anonymized, for all the scientists using its platform over the period from May 2015 to May 2017 — a group that represented 1,000 universities. This included information on a user’s total number of folders, folder structure, and shared folder access This seems like heaven for industrial espionage purposes. Just because there's some anonymisation doesn't mean that the metadata is useless. I sincerely hope they get GDPR'd over this.
- kimdotcom 8y agoIt is only data from universities, not real for-profit businesses.
- bigkm 8y agoha. Have you seen what some countries charge for tuition.
- jessaustin 8y agoUniversity administrators are not shareholders! Their greed is much better for society...
- toast_coder 8y agoWhy the heck would an administrator care if they 'hold shares' when they are pulling 200k-500k per year as base pay?
- jessaustin 8y agoOuch! Is "greed" a bad word? It's not an inaccurate one...
- zkms 8y ago> It is only data from universities, not real for-profit businesses. Plenty of universities work (often in collaboration with national laboratories and/or with corporations) on work that's far more important and critical than many "real for-profit businesses".
- unepipe 8y agoWhat kind of junk statistics are these? HBR ought to be more discerning in what it publishes. "How successful teams collaborate"... wait, I meant "the average number of users who update the same directories in Dropbox from institutions that tend to have influential research. Sound insights. Make sure you're collaborating with no more than 2.3 people or else you'll have to move your research projects over to Yale.
- projectramo 8y agoYes this was curious. I wonder if these insights (2.3 v 3 collaborators over 180 vs 130 days with the top person contributing x%) was really effective or just a coincidence.
- jpmattia 8y ago> 2.3 v 3 collaborators over 180 vs 130 days Yeah, that caught my eye too especially the missing RMS so we could see whether the difference between 2.3 and 3 is significant.
- jmknoll 8y agoAgreed, these sound like completely arbitrary measures. I agree that senior researchers probably bring valuable experience and insight to research projects, but I don’t think you can validly arrive at that conclusion from the number of times they open a doc in Dropbox.
- primedteam 8y ago- The researchers claimed they could see "every Dropbox folder associated with a given researcher." - Dropbox denies giving researchers non-anonymized user data https://www.zdnet.com/article/dropbox-denies-giving-researchers-non-anonymized-user-data/ https://www.zdnet.com/article/dropbox-denies-giving-research...
- staticfloat 8y agoAs the linked article states, all personally identifiable information is removed, but you still want to be able to say "Alice worked with Bob in folder 1, and that same Alice worked with Charlie in folder 2", so you assign unique identifiers to each user, such that you can't tie Alice to "Prof. Smith at University of Chicago", but you can tie folder 1 and folder 2 to the same Alice.
- krageon 8y agoThe GDPR has provisions for information like this, specifically to say that small pieces of information can together still constitute personal data. Consider that you can retrieve names if you map someone's professional interactions with this kind of detail. Regardless of whether or not the GDPR applies to these people, it's a useful tool to illustrate why this kind of data is still wrong to share (especially without any kind of consent!).
- bmarquez 8y agoThe lack of consent requested is ridiculous. There may be some sort of 'obscure paragraph in the terms and conditions that says Dropbox can do whatever they want' but this is horrible for privacy and business security. I'm glad I've been client-side encrypting my Dropbox files. For the past two years I've using a free open-source encryption app called Cryptomator (https://cryptomator.org/ https://cryptomator.org/) for my Dropbox folder without problems. The only caveat is the mobile apps aren't free. Another Dropbox encryption app is BoxCryptor, but I quit using them when they went subscription-only.
- ycombinete 8y agoI've just looked on Boxcryptor, and they appear to have a free tier. Are you sure it's subscription only?
- bmarquez 8y agoBoxcryptor used to be a one-time purchase to allow an unlimited number of cloud providers and devices. However they decided they needed a consistent revenue stream so they renamed their software "Boxcryptor Classic", stopped updating it, and now users have to pay $48/year to get features previously available as a one-time fee. This was about 2 years ago, by now they've probably scrubbed all references to the "Classic" version on their website. To be fair the subscription version does have new group/admin features for multiple users or businesses.
- ycombinete 8y agoAh, okay I see. Thanks man.
- newscracker 8y agoThis was a very poor read, and just listed correlations based on some numbers. I personally didn't learn anything that I, or anyone else, could apply. It's just a "correlation=causation" based list.
- brian_herman 8y agoI am sorry this might be a cliched post and doesn't add to the discussion but if they do things like this to academics what do they do with other peoples private data that we dont know about?
- sbr464 8y agoIf using a Mac, it’s pretty easy to encrypt a drive and store it in Dropbox, then mount it when you want to use it. Kind of negates the whole point of Dropbox (mobile access, small sync etc) but I started doing it for more sensitive things. Doesn’t require any 3rd party addons. I really can’t believe they shared this data. Universities do work for businesses all the time. Imagine a folder of research subjects organized by geo/age/sex then full patient name or SSN, under a folder called HIV survey or something. I mean really?
- tempaccount777 8y agoDropbox sharing your data without consent? Nothing new. I've been using dropbox paper for a year now and only recently found out that by default all docs are shareable. That means, if you log into dropbox -> open a dropbox-paper doc -> Logout you're not safe. Anybody with your browsing history can re-access the document you've been working on even after you log out. So essentially if you're using dropbox paper on a shared computer or on a public/library computer and logout, people will still have accesss to your docs that you've worked on. Only way to turn this off, is to manually click the 'invite' button and uncheck the share option for each and every document seperately. I had some personal/sensitive info on a few docs and was shocked to learn of this. Completely unacceptable from dropbox!
- ebikelaw 8y agoIf you are leaving browser history in public libraries, you have bigger problems than Dropbox Paper.
- j_koreth 8y agoCare to expand? I wouldn't usually think of browser history as particularly sensitive.
- ebikelaw 8y agoThere are a _LOT_ of services that treat the URL as a secret. If you're leaving these URLs in your browser history on a public computer other people can access them. For example, the images served up by Google Photos, that have the form lh3.googleusercontent.com/[kilobytes of base64-encoded spew], can be accessed by anybody having the URL. So if you use a public computer to access these, even though you need to be authenticated to browse Google Photos, and despite the fact that you conscientiously logged out, anybody with access to the history can still look at your photos. This is not be any means the only such example.
- kerng 8y ago>> Dropbox gave us access to project-folder-related data, which we aggregated and anonymized[...] Wait, Dropbox gave away non-anonymized data to a third party and they then anonymized it. Wow, what could go wrong? Just thinking of the endless possibilities of where all that data is now... Its deeply troubling how much unwarranted trust there is when it comes to handling of personal data.
- bad_user 8y agoI just cancelled my subscription. Truth be told I've also been dissatisfied with the price of the Plus and Pro subscriptions, relative to what they provide, with their support and their direction, so was looking for motivation to move. This is just icing on the cake.
- xevb3k 8y agoThis is not at all surprising. Dropbox put Condoleezza Rice on their board, who supports warrentless wiretaps [1]. I deleted my account when they did that. Not so much because it would have any direct effect, but because it’s clear that we have differing views on how user data should be treated. I surprised that people are shocked by them treating user data like this, it’s absolutely in character. [1] http://www.drop-dropbox.com http://www.drop-dropbox.com
- TomK32 8y agojust deleted mine (which I hadn't used in years anyways).
- c3534l 8y agoGiven the very public failure of Netflix to "anonymize" data, they shouldn't be even giving away anonymized data without user permission on account of anonymized data not actually being anonymous.
- greggman 8y agoIt's not already in their TOS that they'll share any data they feel like with any one they feel like? https://www.dropbox.com/terms#privacy https://www.dropbox.com/terms#privacy It certainly says the words: "We may share information as discussed below, ... Others working for and with Dropbox."
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- mywacaday 8y agoHow is this analysis even valuable "The average number of people on a project at a top-10% university was 2.3" Analysis where the majority of the projects have less than 3 people tells you nothing on how to collaborate.
- chiefalchemist 8y agoThe five rules listed feels more like correlation and less like cause. Also, there's more to true collaboration than sharing files.
- deleted 8y ago[deleted]
- Dowwie 8y agoI am surprised by the comments here. No one seems to have actually read the article nor taken the time to learn about how Dropbox partners with researchers: https://blogs.dropbox.com/business/2018/06/nico-customer-story/ https://blogs.dropbox.com/business/2018/06/nico-customer-sto...
- herf 8y agoHow do you determine "whether they were senior or junior faculty" from anonymized data?