Transparency report for the first half of 2016
blogs.dropbox.com
blogs.dropbox.com
It's interesting that West Virginia is the only state that didn't receive any account information requests. Hey everyone, if you want to dodge the feds, move to rural Appalachia! I also find it hilarious that they got a half-dozen requests issued to the wrong company. Who do you think they were supposed to go to? My money's on Box.
And it is complete bullshit that they can only give a range of '0-249' for national security requests. But the big NSL case is still grinding through the 9th circuit court of appeals, right?
Anyways, my biggest concern is with the phrase, "Non-content provided." This feels like a similar weasel word to "it's only metadata," and it reeks of parallel construction to me. It's odd that they provided "non-content" for 96% of subpoenas which didn't refer to nonexistent accounts, but provided actual content for 0% of subpoenas. I'd like them to go into more detail about why that is. If they're constantly resisting requests to provide full content, then good on them. But they don't go into any detail.
I was already not hugely impressed by the service, so I just switched to a more secure cloud backup provider that costs about the same. I guess it was more the straw that broke the camel's back.
She's on the board, it has absolutely nothing to do with the day to day of this sort of thing. If you want to get a good idea of how any company handles your data look at it's legal team, past and present. And Dropbox's legal team has an amazing record of fighting for users privacy and constitutional rights.
(full disclosure I am an ex-employee of Dropbox)
For a while, I've actually tried uploading stuff to small TrueCrypt containers. Everything above 50 MB per container is absolutely unusable for cloud storage.
Now I'm simply on ownCloud (well, Nextcloud to be precise) with the encryption enabled on the backend when the data is at rest.
Only problem what I see is illegal content, because If uploader changes just only one bit in file, they will not be able to detect it.
* The Best Unlimited Online Backup and Cloud Storage Services || https://www.backblaze.com/
The only thing I've learned is that they're a part of some coalition about the transparency. The report itself is much more interesting.
Maybe it's worth switching the link to https://www.dropbox.com/transparency/ ?
I'll speak to risk first.
If you are a company delivering a report to shareholders, the risk is primarily downside risk. It's unlikely for your stock to skyrocket if you say something clever, but it might fall if you spook them. This is because the default assumption for companies is that management is already competent, so the risk distribution has more downside than upside. I see corporate speak as a tool to avoid spooking folks and triggering this downside risk. (Notably, there is a positive feedback loop, where non-corporate speak becomes a stronger signal as it becomes rarer.)
On the other hand, if you are a startup company trying to break into a market, the risk is primarily upside risk -- if your communications go well, your business could eventually grow by many multiples. And achieving growth almost always means differentiating yourself from competitors. The reason that many startups eschew corporate speak is not necessarily because they are smarter, but simply because they are adapted to their environment. Avoiding corporate speak is the correct strategy when your upside risk is high.
The second issue is scale. It applies to both the receivers of the messaging and the senders of the messaging.
If you are selling to a specific niche, you can use the language and sensibilities of that niche when crafting your message. But if you are selling to a broad base composed of many niches, this customization of language is no longer possible. Anything too non-standard risks distancing certain niches. This is why when you are selling to a large audience, your communication necessarily needs to be blander than if you are a selling to a specific niche.
Another force that pushes corporate speak is coherence. When you have one voice, as individuals or startups might, it's easy to keep messaging consistent and coherent. Avoiding mistakes is easier, because there's only one point of failure. But as your company scales, you suddenly have hundreds of people putting out communications (and there is constant turnover among these folks). In this setting, it's hard to keep the style of these communications unique and consist. It's also harder to prevent dumb mistakes, since there are now hundreds of points of failure. Relative to more personal or unique styles, corporate speak is easier to apply across large organizations.
Lastly, and relatedly, I think corporate speak often arises as a result of people optimizing individually. If I'm putting out communications, I could get fired if someone doesn't like my bold/honest/creative take. But if I put out something bland, especially in an environment while others are putting out something bland, I'm not going to get fired. It's a similar risk argument as above, but applied to people. If I write a great a blog post for my company, no one is going to double my salary. But if I write a disastrous blog post for my company, I'm getting canned. The risk is asymmetric.
I think you nailed it.
- what is up with client's high CPU usage when there is disk activity outside Dropbox folder;
- actual technical reason for needing to install kernel extension on macOS (previous answers on HN were something like "we need to do things that Finder API does not allow").
One way we work to earn that trust is through our commitment to transparency about government requests for user information.
I think explanations for these kinds of things would work significantly better for making users trust Dropbox more.
No need to include those in report, but I'd rather see a page about reasons behind weird behaviors than a bunch of numbers (which might as well be random from my layman's POV).