Dropbox Hasn't Learned Their Lesson
sethvargo.com
sethvargo.com
Syncthing is a free software (MPL-2.0) cross-platform [1] and decentralized peer-to-peer file synchronization utility with end-to-end encryption, and with support for relaying [2].
Check out their getting started guide [3].
[0]: https://syncthing.net [1]: https://docs.syncthing.net/users/contrib.html [2]: https://docs.syncthing.net/users/relaying.html [3]: https://docs.syncthing.net/intro/getting-started.html
Could I rely on this just like I would rely on Dropbox to instantly get my files synced or do I still need a centralized option for that?
I've been using it for a while now, and though I feel there's room for improvement, it's definitely much more reliable than it used to be before and I haven't had to restart the daemon multiple times.
As for your second question about instant syncing, there's syncthing-inotify [0] which detects file changes immediately (instead of 60 second rescan interval), but I haven't tried it yet.
For syncing outside your local network, Syncthing supports relaying, which I linked in my previous comment.
I started using Syncthing for some of my projects after Dropbox stopped syncing files without notice for the third time. The failed Dropbox syncs were related to either C++ or Doconce+LaTeX projects where many temporary build files were being modified often. Syncthing doesn't seem to have a problem with these files, and it is even possible to configure Syncthing to ignore specific file patterns if you just don't want it to sync such files at all.
I mean... there's a certain point where you are now syncronizing "crap" that shouldn't be needed (bin/obj/etc)...
The default setup in Qt Creator is to have a build folder next to the sources, but after the first big sync failure I configured Qt Creator to always build outside of Dropbox. But I experienced failed syncs after that, even with only C++ sources inside Dropbox and when building Doconce+LaTeX projects.
If you want to access your own files anywhere, you're not really in it for the sync aspect, and you're willing to host your own, there's this great piece of software called OpenSSH, that implements remote shell access as well as a protocol called SFTP that you can use to remotely access files. There are clients available on all systems, frequently installed by default, it's incredibly secure - you may have heard of it. It's kinda new, and the up-and-coming thing in personal cloud software. The investors are really excited.
:-D.
But for most HN readers, if it's the sort of thing you're looking for, it'll do the trick.
Please let me know if you know of such a solution!
You can use it as a way to bridge all computers. Basically, have all computers create a tunnel to this computer and then you can access them.
I do something similar with a small VPS, but it could be something at home. What I do is that all my computers automatically connect to this VPS and bind to a different port. This is with SSH (and autossh). If I want to access computer X, I can SSH to this VPS use the port that I know computer X has.
For your scenerio, you can forward this port to your local machine and run rsync -p to it...
That, I would use maybe half the time. However, sometimes my devices are on the same network. What if both of my devices are on the same network? I think that I would prefer not to send the files through the internet in that case.
One solution for each vae would be nice (please share if you do have one). However, one solution for both would be nice.
Computer A > router > local server > router > Computer B.
Instead of: Computer A > router > Computer B
You can use some scripting and configuration to get the second one if at home. But basically you have to have a way to guarantee that both devices are at home.To make sure both devices are home, you can assign static IP at the router level to the devices.
Now, if both devices are wireless.
– Check you are home by checking the SSID you are connected to.
– If you are home, ping the other device static ip.
– If it responds, you can connect directly to it
If any of these fail, connect to example.com.I have a central SSH server where I store all my files. When I want a file on a given device, I pull it down from there. If I want to add a new file or update a file, I push a file up. Pretty simple. You do need at least one computer that stays in a constant location (typically at your house) to do this. From there, you portforward SSH to a high numbered port (it keeps every bot in the world from knocking, and some ISPs block 22) on your router. However, if you're like most of us, your ISP doesn't assign you a static IP. But, because your IP probably changes only rarely (probably only sometimes if your router goes down), you actually needn't use dynamic DNS. Furthermore, because you aren't actually publishing on that address, you can use any domain, regardless of ugliness, and there are plently of DNS services willing to offer you a subdomain for free. I reccomend freedns.afraid.org, myself.
It doesn't work for everyone, likely, but it works well enough for me.
If these are public IP addresses, any DynDNS provider could work well.
If these are internal IP addresses chosen by DHCP and you control the DHCP server, pin the MAC addresses of the devices to fixed IPs. They will still do DHCP, but get the same IP every time.
Their UI is crappy and laggy, and doesn't look like it belongs in any platform.
It takes forever to sync files between devices.
It sometimes gets confused when I rapidly switch between branches in a git repository, touching thousands of small files each time.
But I love the ability to pick and choose exactly which files and folders to backup and sync. SpiderOak adapts to my workflow, instead of demanding that I put my files in specific folders. If inefficiency is a necessary cost of combining this kind of flexibility with full client-side encryption, I can live with that.
I agree, the UI is not great and it's quite slow. It often uploads the same files again and creates multiple versions, with no way to delete older versions of files at a folder or device level. The skewed non-linear pricing is also heavily biased toward those who use less but like the 1TB option, with the next tier below being a paltry 30GB.
1000s of small files, or one rapidly changing file cause me problems as well. It's also annoying that each client has to decode new data whenever something is backed up on another machine. This causes my cpu to hit 100% on my laptop while my desktop is backing up a bunch of new files.
I think Dropbox's problem is mostly Google. I used Dropbox at home but once Google got their drive up to speed and it integrates with other things like Gmail and such, it is hard for me to justify using Dropbox. So I uninstalled it and just use Google for everything.
HN thread: https://news.ycombinator.com/item?id=12261409
Here's a nice overview of differences compared to Syncthing from the developer: https://news.ycombinator.com/item?id=12262704
Offering file watching without any extra configuration and supporting decentralized discovery though the mainline DHT are its most compelling advantages over Syncthing for me.
[1] https://www.vpscheap.net/pricing.aspx Section “Budget Servers”
Try https://hubic.com/en/offers/ it was created by "The number 3 internet hosting company in the world" OVH works quite well if you don't mind the dated interfaces
I see it has no mobile clients, that's almost a dealbreaker for my every-day use. Syncthing runs great on my Android.
From My understanding, SyncTrayzor is the GUI version for SyncThing with MIT license[1].
[0]:https://github.com/canton7/SyncTrayzor
[1]:https://github.com/canton7/SyncTrayzor/blob/master/LICENSE.t...
Syncthing is great if your goal is to synchronize files between different machines. However, if you want to share files/folders with people who do not have a strong tech background it's not really an option.
I use it to share stuff on Dropbox. I run Linux and have never installed the Linux client (if there is one, I don't know!)
PS I wrote rclone!
https://www.seafile.com/en/home/ / https://github.com/haiwen
This is how simple it is to set up the server https://manual.seafile.com/deploy/using_sqlite.html
This is an experiment that is being tested with a fraction of users primarily on beta releases (which Seth is on, as evidenced by the version number in his screenshots). We haven’t shipped it to everyone so that we can continue to iterate and incorporate feedback. I checked with the team about the “Finder Toolbar” drop down and it looks like it requires a restart of the Dropbox client in order to take affect — let us know if that doesn’t work.
Edit: if you'd be willing to file a ticket here: https://www.dropbox.com/support/s/219/5481540/c/219 with "att. Of Luke" in the subject it'd really help us get to the bottom of this.
Choosing to use beta software and then posting rants about something you don't like is a pretty shitty thing to do, especially without disclosing you are using a beta.
Edit: Also the language I used was a reference to the language in the authors post. I agree somewhat that was unnecessary, and I accept that I could have said the same thing different ways.
When shit goes sideways, you have no idea what is broken. Logging also seems mostly non-existent, at least via macOS' Console app.
Shit went sideways around 9/23 for many people across different platforms. It was definitely on the service side, but status.dropbox.com reported no problems. At some point on 9/26, someone fixed it, but no one was notified. Most people eventually re-tried, for the 100th time, of unlinking and re-linking their account. No system logs showing problems and no reports from Dropbox.
If it wasn't such an established service, i.e. widely supported by applications, I'd have ditched it long ago.
This is not the first time that Dropbox ignores the system guidelines (or even permissions if the user explicitly disallowed Dropbox access to Accessibility features). Why are you ignoring the feedback concerning Dropbox' way of "hacking" itself into system areas like Finder?
On Windows, immediately adding Dropbox to 'Favourites', and the icon integration to show sync status is an awesome feature. It is invasive for Dropbox to hijack your icons and overlay a checkbox? Yup. But incredibly helpful in my opinion.
Maybe it isn't everyone's cup of tea, but the close integration with file browsers on multiple OSes is (was?) definitely one of the differentiating aspects of Dropbox, polarizing or not.
Seamless Finder integration is why I like Dropbox. Sure, this is an annoying bug, but I'd hate it if the stopped doing it.
To me, the Finder integration was straight up spooky, suggesting an extraordinarily high risk profile.
When my consulting gig was up, I uninstalled Dropbox precisely because of the Finder integration, and I have advocated against using Dropbox as a file-sharing solution in all subsequent consulting arrangements.
I've also avoided using it as part of my day job, even though some of my teammates used it.
It's clear that there is some diversity of opinions on this topic, but we already knew that.
To me, your datapoint shows that Dropbox is right to behave the way they do: in 2011 you thought it was high risk, they have kept with that behavior and yet nothing bad has happened. I'm unsure if that was your intention, but that is how it looks to me.
It is entirely unclear why you think this is particularly risky: If Dropbox can do it, then other malicious programs can too.
Dropbox's behavior creates no additional security risk, but increases the usability of their software.
If there really is a security problem here, then surely that is a problem with the OS, not Dropbox, and it is the OS that should be fixed?
To my mind, the security risk comes in having multiple points of connection in the local file system that are tightly bound to files on an external system.
In the case of inexperienced users (and even a few experienced ones), those points of entry could be scattered throughout the local file system. Consequently, these external files were effectively pipelines from systems all with unknown security profiles. This combined with the Finder integration troubled me enough to stop using Dropbox as soon as was practicable.
EDIT: Clarify meaning in first sentence. Correct plural. Split last sentence into two. Change tense.
That's fine, but don't pretend it has anything to do with the finder integration. A more consistent position would be to praise that because it makes the other functionality more visible, reducing the security concerns.
I wasn't pretending but was, in fact, the victim of my own faulty rationalization.
That is, you're right that Finder integration has nothing to do with connections to potentially insecure systems.
By way of explanation: when I first saw the Finder badging, I intuitively understood the insecure nature of connecting my system to others. So, I conflated the two ideas in my head: "Finder integration is terrible", which of course is just plain wrong.
It was never my purpose to misrepresent my feelings. I wasn't "pretending". I simply tried to make rational something I only intuitively understood.
Good catch. Thank you.
You've also missed the point of the rant. It's not that this specific thing has bugs, is that it takes control and ignores the user's preferences.
My comment is based on that assumption.
could you please start including proper changelogs in your release notes on the Dropbox forum?
Beta testing makes no sense when the changelog states "bug fixes and improvements". That's also a common complaint of the people in the forum, which you're ignoring completely.
The best you can get is 'I will forward this to the team', but usually there is a wall of silence.
Please Dropbox, fix this, listen to your most valuable asset, paying users!
This post is full of ridiculous hyperbole, and it really detracts from the actual message.
stunned silence in the courtroom
You'd expect bugs in beta.
Blatant disregard of user-specified OS-level permissions and inability to access your own files when there are more than fifteen in a folder, no.
Anyway both things you mention are bugs even if you find them frustrating. The original poster was having issue with the option to turn off the Finder integration but the option was put there so you can control it. The only reason you can't access files with more than fifteen in a folder is clearly due to a bug in the beta.
If you want to say that a company the size of Dropbox should never have bugs of that scale even in their beta, then I would point at several of Apple's broken iOS updates (bricking phones, etc.) or Samsung's recent Galaxy Note 7 fiasco as evidence that much larger companies ship software and hardware that isn't in beta and has undergone much more due diligence with catastrophic bugs.
Anyway I don't use Dropbox really but I felt compelled to comment because I couldn't understand how you could say you expect bugs but don't expect the reported bugs in a beta.
I'm not sure the beta testers understood they were giving up that level of control by installing Dropbox's new software. The post's author certainly didn't.
True, Dropbox got away with grabbing permissions that apps shouldn't have, and then getting away with it. But it's still IMHO a bit more than a bug to take this attitude of "let's take whatever we can! It's Easier To Ask For Forgiveness..."
Well, if they succeeded at that it means the permission model is broken, and you can not trust the sandbox boundaries, whether you have Dropbox installed or not. So no reason to be angry at Dropbox; ask Apple to fix the sandbox model instead.
I am guessing that Dropbox has roughly 4 stages of "releasing":
1. Something for devs working on this feature get to see it in action. I would guess this means a few hundred people see this release.
2. A release for dropbox employees. I would guess a few thousand people see this release, and since they work at Dropbox I would guess that 99.9% of them keep these features enabled.
3. A beta release. This is the first time that we are likely to see anyone who actively disables integration features use the product, and even that is probably minimal.
4. Official release.
You are extremely unlikely to see people disabling features like this in (1) and (2) unless the feature is so broken they can't use it. In fact they probably encourage people not to disable it so they can get more feedback about how the new integration is working. This leaves (3) the beta release as the most likely spot for this type of bug to pop up.
This isn't a non-reversible bug. It doesn't delete your files or do anything that can't be reversed by reverting to an official release of Dropbox or quitting the app, both of which are relatively easy fixes.
It also isn't a bug that is likely to be caught by the majority of Dropbox users. Based on my interactions with people, at least 75% of them keep the OS integrations enabled. Only techies even consider disabling it.
As a result, this seems like exactly the type of bug that I would expect to see in a beta release, and I can't see any real harm in it making it that far.
They prompt continuously for access to Accessibility and the "control other applications" permission, no matter how many times you deny it.
As soon as I finish this project (where I need access to Dropbox) I'm uninstalling it.
I think it's completely reasonable to suspect at least some of Dropbox to be old code pushed quickly into production and caste almost instantly into legacy-matenence-mode that can not be easily refactored or iterated upon ("move fast and break things har har"). While this is almost inexcusable for an established and well-funded company that does not have a shortage of resources to fix the problem, I find it significantly more likely then some 5-eyes-esque surveillance or data mining strategy as you allude to.
s/ignorance/incompetenceNow you have the ability to selected nested folders to sync, it does everything I need, and the storage is shared with Gmail, Photos, etc.
* It does not do chunked syncing. Change one bit of a 5GB file, it gets resynced completely.
* You cannot get a list of shared files/folders. You basically need to check sharing per file/folder by hand or write/use a Google Apps script (which is very slow).
* It does not support LAN sync. When I share large directories with colleagues on Dropbox, sync is very quick, because the transfers are just over the local network.
* The last time I tried, the Google Drive client regularly had problems syncing some files when syncing a very large set of files.
(* There is no first-party client for Linux.)
A colleague just had google drive not properly syncing for 2 weeks, and all of the sudden it started working except it overwrote a very active Sketch file with the two week old copy (and no duplicate "conflict" copy made as Dropbox does). Google around and you'll find many such stories across all services.
Another thing the OP hasn't mentioned is which service he/she will move to. Dropbox is by far the best file sharing/storage product I have used. I don't think about sharing/storing files anymore - all the tools and convenience Dropbox offers (and Finder integration is a big part of that) take care of this itself!
I'm toolbar free and it was a very minor inconvenience - not worth a rant-filled blog post like this.
I mean, it's not even competitive on the pricing. 1 TB @ 9.99$/mo while Microsoft gives you the whole Office suite plus 1TB of OneDrive at less than that.
1) I have zero usage for MS office, and if I did I could just use my wife's version she got for being a student. So this isn't a value add for me.
2) I find the web interface and the windows integration much better on the dropbox side
3) Most importantly, Onedrive has zero support for tracking versions of non-document files. Since I have the extreme need to quickly exchange files between my several computers the last thing I need is for some ransomeware to get activated by some 0-day and compromise my primary backup. Yes I have secondary backups but it is not nearly as easily as rolling back files in dropbox.
4) I REALLY did not like how integrated windows is with OneDrive, going as far as making it a royal PITA to not make it the default save location for new files, and the complication of now having 2 "My Documents" folders.
There were other misc issues that I had with Onedrive that I can't remember at this point in time but I really did not like one drive as a whole and have been happy since moving to Dropbox.
Also, subscriptions add up quickly. One less is always better.
Also, you are not only paying for storage, but also maintenance of network infrastructure and the client/server software.
I did mix up consumer and development, but I think the general point still stands.
I don't think so, especially because you are mixing the two. For an employee that costs $6000 a month, $10 per month per employee that increases productivity significantly is a steal.
If you have a household budget where you can spend $100 per month on luxury goods, you might want to forgo the technical advantages of Dropbox over competitors and opt for a competitor that undercuts Dropbox' pricing.
The parent said: "Price sensitivity to consumer SaaS always catches me by surprise." - which is what we both seem to agree on - even consumer prices add up and people will go for cheaper alternatives.
I find the interface (both local and web) to be much nicer with DropBox as well, especially over things like Drive.
The price differences are relatively small, and I have no use for the Office suite.
Dropbox circumventing security restrictions is particularly worrying because they have board members who support warrentless surveillance.
In my mind Dropbox became a company not worth supporting when Rice joined Dropbox's board (http://www.drop-dropbox.com/). Personally, with a board member who advocates warrentless surveillance it seems unlikely that we share similar views on the security of my data, and I wont be using their service.
I am not an OS hacker but as a user I am pretty sure the desktop app should not access files outside my dropbox folder. The excuse of "testing some desktop features" is pretty lame. If you catch your housemaid sniffling your panties it is simply not an effing feature, even if your panties are clean and sexy!
And this is not part of the mass surveillance...
I recently signed up for Sync.com, due to their prioritisation of security features and they seem like a good company. I have come across some minor bugs, but I sent these onto their customer support who were reasonably responsive. Even with these minor bugs I'm still happy with the trade-off to move off Dropbox.
I must admit the most difficult part was definitely the services I used that directly integrate with Dropbox, like 1Password syncing. So I also had to find solutions to not just Dropbox, but also third-party services that integrated. For 1Password, I signed up for their Account option where they handle the syncing for you at a cost of $2.99 per month. Again, another trade-off I was happy to make.
I mostly use Resilio Sync besides Dropbox. It works really great: fast syncing, nice user interface, etc. What keeps me from fully switching is that I hit some nasty bugs in the past (e.g. all folders suddenly getting disconnected, etc.).
I recently signed up for Sync.com, due to their prioritisation of security features and they seem like a good company.
I also tried sync.com recently. Unfortunately, the client did not look very native on macOS (poking around revealed a lot of .exe files, so I guess they are using Mono). Besides that sync was quite slow compared to Dropbox.
I also noticed this. But I have the mind frame that they are still a fairly "new" company, 3 years old, compared to Dropbox, 9 years old, and their growth and features continue to improve. In saying that, I would definitely prefer a more native look on macOS.
Besides that sync was quite slow compared to Dropbox.
I'm from a place in Australia with a generally slow Internet speed, especially upload speed, and may not have noticed this pitfall as much as others might.
This company gets $120/yr from me and they can't answer a support ticket? There have many competitors who charge less and I bet some of those competitors actually support their paying customers. You are looking at one soon-to-be-ex-customer unless DB pulls a rabbit out of their hat very soon.
Not sure if it prompts, but I usually untick optional things, and I still have that when right clicking on the desktop.
[1]: https://derflounder.wordpress.com/2016/09/23/icloud-desktop-...
Space isn't an issue. I pay $0.99/mo for 50GB of space in iCloud, that's about 5x as much space as I need currently, including all the photos I have stored in it. And in the event that I do manage to use that 50GB up, $9.99/mo for what 500GB? is again well worth it.
I'm well invested into the Apple ecosystem and that does not bother me. I have 3 MacBook Pro's, an iMac, an iPad, 5 iPhones and an iPod Mini. The benefits of removing yet another app that just sits there taking up resources, and utilizing the ecosystem to handle something I've always done, is value enough for me.
I appreciate the concerns, but like I said, none of it is an issue to me.
http://talkingpointsmemo.com/edblog/maybe-be-careful-with-os...
In general Apple has simply been terrible at ensuring reliability of their iCloud services. Their idea of hiding everything away simply doesn't work - there are legitimate and regular edge cases that won't be handled if you don't give a UI.
If want to hear the Siracusa story, see this:
https://www.reddit.com/r/apple/comments/44auj0/atp_155_liste...
I don't know about you, but I simply don't trust iCloud with documents. Personally, I've tried it with something very simple first: Notes. It just doesn't sync reliably at all, totally useless.
If Dropbox really, to quote 'SilasX, "broke the entire permission model, where I can no longer trust the sandbox boundaries" - well, the cat's out of the bag, Apple's sandbox model sucks. You should bring it up with Apple so that they fix it (either allow proper extensions or just patch up the hole and brick Dropbox in the process).
Another point is, you're using someone else's drive somewhere in the cloud and storing there (more or less) sensitive files and you're talking about privacy and security? Gimme a break.
Third and last, if you're that unhappy with a piece of software that's for the most part free, go ahead and pick something else. Nobody's forcing you. Same goes for Windows, Office, Gmail and whatnot.
It's there in the article
It seems to work, but you need to restart... /shrug
https://www.dropbox.com/en/help/9249
I don't believe a program needs to integrate so deeply into the system just to sync the files.
(It might have been that some programs were doing IO that avoided triggering the change notification, and a sufficiently large {number of customers,customer} complained about it.)
I don't work for Dropbox, and I haven't used the API, but as I said, I really doubt they added a (signed) driver requirement lightly.
[1] - https://msdn.microsoft.com/en-us/library/aa364417%28VS.85%29...
I don't understand why, once already installed, they are trying to get me to use it more. They won't make more money will they? Are they using this as a way to get me to get close to a limit and upgrade?
SSH and Git work pretty well for that.
I'll take a trusted piece of open source sofware with strong security running on my own server (openSSH) over a magic pocket any day.
As alternives, depending on your requirements, I recommend SpiderOak, SyncThing, or a third-party offering / your self-hosted Nextcloud.
If you have a little time, you don't need Dropbox at all. And you can't get much cheaper than raw S3.
I went ahead and disabled it a few months ago.
For instance, client side encryption? Mwahahaha. Studiously ignoring that for the better part of a decade, why change now?
Valuation is OK, ain't it? Doing fine, then.
- OP needed to state he used the beta release, which are prone to be in an unfinished state,
- Dropbox needs to be more transparent about their releases, with including proper changelogs (they're only stating "bug fixes and optimisations" in the Dropbox forum). If you're adding/changing the UX in some way, document it. If you want a feature to be developed discretely, make a private beta, but still - document it.
It's an opportunity to learn something from this.