7 ms·
If the 100,000,000th uploaded file was actually named Startup-Revenue-Forecast.ppt or 2011-Tax-Return.pdf I'm fairly certain that the name or contents wouldn't
by flyosity 15y ago
If the 100,000,000th uploaded file was actually named Startup-Revenue-Forecast.ppt or 2011-Tax-Return.pdf I'm fairly certain that the name or contents wouldn't have been mentioned. I think the fact that it was cat.jpg spawned the idea of referencing it at all, and honestly if I were in their place I would have made the same joke. I think most people would have. But good on them for pulling a reverse Streisand Effect (http://en.wikipedia.org/wiki/Streisand_effect http://en.wikipedia.org/wiki/Streisand_effect) which frames the discussion in a positive light ("how can we change and do better?") instead of a negative one.
- deleted 15y ago[deleted]
- zefhous 15y agoThat's kind of the point of log files. As a contrived example, what if users suddenly couldn't upload files that ended in .jpeg instead of .jpg. How would they be able to diagnose the problem if they didn't store data about image filenames? Obviously they filter passwords and other sensitive data, but I think they should rightly have access to whatever they judge necessary to do their job. There will always be people who have the ability to access data they are not supposed to, but in the end it comes down to who you will trust with your data. To me, the transparency and contributions of 37signals qualifies them to have that trust. With that, I trust them to make good decisions about who they hire and what they store in their log files.
- teaspoon 15y agoI wonder if parent was merely advocating obfuscating sensitive data so that engineers don't accidentally see things like "Downsizing-2012.xls". As long as the obfuscation is reversible, the data is still there for those who need it. Of course, encryption per se is overkill for that. Something like ROT13 would do the trick.
- Silhouette 15y agoIf you're going to obfuscate reversibly, it is much better practice to use strong obfuscation and log (irreversibly) any time the raw data is accessed so there is an audit trail.
- foreverbanned 15y agoI would be happy if just the filename (not the extension) is at least obfuscated. I can trust someone and still not be comfortable if he accidentally see that I uploaded "how to file a divorce.pdf" for example.
- pgeorgi 15y agoAnd now the problem is that files with "," or spaces in the name fail... The "reversible scrambling" proposal above might work (though not ROT13) - that way the data is there _if needed_, but it takes concious effort to take a look. If in the process of debugging the "," issue, a set of files is uncovered (including "how to file a divorce", tough. Ideally, the usernames could be unscrambled separately, so at least there's no immediate connection to a single user.
- Terretta 15y agoI doubt most web apps encrypt file names before they're written to logs. I'd think the number of apps doing this is much smaller than those that don't, and even then only in cases where file names are replaced with hashes or GUIDs for directory reasons, not for the sake of information security.
- seanalltogether 15y agoA file based POST request always includes the name of the original file as it was uploaded from your computer, you could just as easily blame IE or firefox as you could a webserver log.
- mike-cardwell 15y agoI wonder what they would have done had it been named "Basecamp Competitor Business Plan.pdf". Would have been awfully tempting to take a peak. Exactly why they shouldn't even be looking at filenames.
- corin_ 15y agoUltimately a company storing files is almost certainly going to require its staff to look through directories, log files, database tables. And it is certainly going to require staff to have the ability, even if they never have to use it. By giving them your files you are trusting them not to screw you over.
- prof_hobart 15y agoIf a file storage company that claims to be protecting users' data isn't storing it in an encrypted manner that requires people to jump through all manner of technical and proceduraly hoops to get access to them, then they are failing quite badly.
- corin_ 15y agoWhatever encryption is there (and we don't know what they are doing in this respect), their staff who manage the systems still have access to look up the file name of the Xth file, or if they like to go snooping through all files.
- mike-cardwell 15y agoThis is true. The problem here is that they went looking through private user data when they didn't need to. If they were only doing it when essential, eg to debug a problem, people wouldn't be complaining. It's the fact that they did it without their being an urgent need to that has bothered people I think. What other trivial reasons have they used to look through peoples data?
- sunir 15y agoUnless explicitly authorized by the customer, or for the purpose of providing the service, your staff should not be allowed to look at customer data, and what data they look at should be limited to what's necessary to perform their function. If you do want the right to spelunk through customer data, you need to declare that in the privacy policy. If you declare otherwise, you're breaching the contract with the customer. The problem is that incidents and attitudes like this make the market lose trust with the cloud services industry, which is poison to everyone.
- tpatke 15y agoI think the issue is access control. Clearly they can and do look at their customers personal data. Thats not very funny - even if it happens to be a picture of a cat.
- foreverbanned 15y agoThey didn't mentioned the filename at first. What they actually said was : "And a Basecamp user uploaded the 100,000,000th file (It was a picture of a cat!)". So people got the impression that they actually saw the picture. Hence the backlash. Users of cloud services may be aware that engineers, sysadm or dba may occasionnally see their data but they certainly prefer not to think about it.
- deleted 15y ago[deleted]