Dropbox on Mac now updates itself with a process in background
dropbox.com
dropbox.com
And if you're conscious enough about your digital security that you really do mind Dropbox updating itself automatically, why did you install their app in the first place? The only OS I actually expect to protect me from the apps I install is iOS, and only in combination with the AppStore review process.
From what I hear, Apple's attempts at creating similar safeguards in macOS with the Mac AppStore has not been received that well with developers because of the restrictions sandboxing place on the apps.
In this case the reality probably is closer to: because they don't know they should be worrying about it.
(Sample of one, obviously, but I certainly didn't know I should, and yet never got any kind of notification to that effect until I sought to delete the app a few weeks ago.)
It's so matter of factly on consumer devices that things just update themselves or nag you to do it from time to time, that it somewhat boggles the mind that it wasn't automated.
I want the peace of mind to know that if something stops working, that it's not because of an update.
If you're going to introduce feature regressions, you'd better at least make it easy to undo them.
If you're going to make users update on your schedule, you'd better be really really good at making your updates smooth. Google can almost get away with this, but Dropbox, OneNote, Skype, and especially Firefox have introduced major bugs without telling me.
Firefox is the worst offender, because even if you explicitly disable automatic updates, it will just repeatedly download updater.app anyway. I discovered this when I had to fix something on a 3G cellular connection on a strict deadline. Another morning, I woke up to find a bell icon added[1] next to my clock, with no obvious way to remove it. It brought me back to the bad old days of Windows 98 where drive by installers would just add stuff to your computer. Eventually, I just chflags -R schg /Applications/, and ripped out all of the updater daemons out of frustration, and I'm happier ever since.
The thing I object to the most, is for software you already have installed to have features removed and replaced with a nag to buy back the features you just had before the update. LogMeIn's Hamachi app did that, but thankfully I keep backups. Or, a classic example from a long time ago, was iTunes 4.01, which had an "emergency" update for iTunes 4 that removed the local network music sharing feature. [2]
Think about what's really going on with the updating ecosystem we have. Are you really OK with software like the deceptively named "keystone agent" running as root, that can add and execute data anywhere on your filesystem? Google Drive and Google Earth will try to reinstall it if you remove it, and nag you with deceptive messages about how they need you to authorize superuser access for them so that they can run properly, when in reality they are just adding the updater daemon, which they do not require to function.
After having been burnt by new bugs, and outright dishonesty, I'm very careful now.
[1] http://osxdaily.com/2014/03/30/disable-chrome-notification-b...
[2] https://apple.slashdot.org/story/03/05/27/2114240/apple-upda...
Which is good because we do nothing wrong. Apart from Youporn, where only one underage model that you didn't know about could lead you to jail. You know, accusations do wonders for your career.
Apart from this catastrophic scenario, I don't either see what's wrong. How many people per year are accused of pedophilia, that could be due to conflicting work/nation interests?
> Which is good because we do nothing wrong. Apart from Youporn, where only one underage model that you didn't know about could lead you to jail. You know, accusations do wonders for your career.
> Apart from this catastrophic scenario, I don't either see what's wrong. How many people per year are accused of pedophilia, that could be due to conflicting work/nation interests?
Thank you. And to people who think this won't affect them, it doesn't even have to be cp charges. NSA has lost the fight to keep its uncensored dragnet data to itself. Today, it is FBI who has access to it. Tomorrow, it will be the IRS which is fine. However, the real kicker will come when state departments of revenue and city police get their hands on it.
Remember, we as a people, legitimately break the law millions of times every day. It doesn't have to be cooked up evidence. If someone wants to hang any of us "upstanding" citizens, they just have to look hard enough.
Certainly the former wouldn't hold up with current laws, but how long until the laws are changed?
The more we allow our privacy to be eroded, the closer we are to having this come true.
And to do that, there's no need to work with Dropbox. Eve could just work her way through your colleagues you are sharing files with to find the weakest link, plant the documents on his computer and wait for them to automatically sync to yours.
What's wrong is that the capability to safely serve and share files over the Internet to people you want to serve, safely and with some modicum of security, is perfectly within the reach of the vendors of Operating Systems.
However, these vendors have fallen asleep at the wheel and are allowing basic system services to be fractured at the base (i.e. in the base OS install), in order that third parties might fill the gap.
This is a heinous state of affairs for anyone thats been paying attention over the years, because there are no good reasons we can't just use our existing computers, and their operating systems, to provide the same kind of user experience as one might obtain with Dropbox, albeit without the creepy commercial-control/exploitation aspect.
I mean, honestly, if folks would just have a way to create their own VPN's out of the box, share the details, and set up a peer network as if it were .. y'know .. a function of the operating system instead of something you learn about from seeing it on a billboard or the back of a bus ..
Dropbox seems to be singled out for doing things like this, despite browsers, Win10, etc.
The updater changes nothing unless someone has done a full audit of the Dropbox binary.
Updater or not, Dropbox/$minitrue can read/write anything you store there. If you have any executables (incl. source code, word docs with macros enabled, git repos via hooks…) in Dropbox, you're pwned as well.
If you don't trust Dropbox, an updater is the least of your concerns.
This is strictly about being able to install anything on users' machines at will and having a formal consent to do that.
The fact that Chrome and others do that doesn't make it any less _unacceptable_. You are losing control over what exactly and when you allow to run on your machine.
For the majority of typical users of Dropbox (and HN certainly doesn't count as typical), this is a net win in every way. They get the latest bugfixes, and they don't need to worry about all this downloading installers rubbish that seems so last decade.
Also - if you were deathly worried about Dropbox and what they could do - firstly, why would you install their client to begin with, considering it's entirely closed-source? Secondly, why would you use a cloud storage provider like them to begin with?
You talk about "losing control" - why not spin your own Dropbox? (I suspect many people, nerds included, underestimate the sheer amount of engineering and technical man years that go into something like this). However, for the Stallman's among it, it may make sense.
They could also distribute Dropbox through the Mac App Store, then they wouldn't have to sneak in SUID binaries and run background processes with launchd. As an added bonus, Dropbox would be sandboxed.
Before someone says it can't be done: the OneDrive app is installed via the Mac App Store, is sandboxed and provides Finder integration. (Yes, the Office badge would probably be a problem, but that is a hack now anyway.)
Edit: that sounded too negative. I agree that this benefits a lot of users, I just wanted to point out that an App Store version would be even better.
I agree that auto update is a net positive and most people will be fine with the arrangement. But your line of argument is flawed . by this logic anyone who wants to enquire and wantto have an informed discussion on health he /she should go study medicine ? Right !
No, it won't.
It's an urban legend.
For every support request that cannot be answered from a stock pile of answers, the first reply is "update to the latest version and then come back." and not once did I see anyone ever complain about it (leave alone become angry) in my 20+ years in IT business. Never. Not a single complaint. Those who can upgrade will upgrade when asked.
Point being is that the extra load from having to deal with clients on outdated versions is insubstantial and it certainly does not justify force-shoveling updates down everyone's throats.
To the best of my knowledge I haven't updated recently, so they've basically had an auto-update feature sitting dormant for a while.
Nothing fishy here.
The number of extremely negative comments here here about using a second process [just like Chrome, Creative Cloud and countless others] to auto-update is really surprising. I can understand people not being thrilled with a kernel extension being installed, but most of those comments there seem misguided or uninformed.
The obvious transition point [to me, it seems] was when they put Condi on the board. HN opinion on nearly everything Dropbox does has really soured since then.
Funny enough, I came to HN looking for something like Dropbox. I even remember when Dropbox was doing odd things that Apple had to ask them about because they didn't know how they put the check marks in.
Yet here we are, angry at Dropbox for continuing down that path of making things more and more user friendly.
I might be OK with running this bit of their code on my computer, but it's not an open bar for dropping anything executable onto my machine at will.
Don't install their apps then. There are lots of alternatives out there.
If you actually look at the competition, most of them do not have LAN sync or block sync (OneDrive, Google Drive), they do not have proper support for revisions (Resilio Sync), or are hard to set up for most people (Syncthing).
[1] So that if I change a small piece of a large file, it does not upload the complete file again.
seafile.com
It's open-source (Chromium project) - just compile it yourself?
Once you've run somebody else's binary, you're already conferring significant trust on them. And I might be biased, but the Chrome team has shown themselves to be very vigilant with security, and generally on-the-ball on all of these things. (Memory issues aside...although I'm not going to get into that...lol).
Many newer projects do this - e.g. Atom from Github auto-updates.
VS Code from Microsoft does this - I think it's awesome! =)
This is the "you agreed to a date, that means you agreed to go all the way" argument.
Even when a someone extends trust or tentative trust, that doesn't mean they should be expected to give up the right to maintain control of that choice at each successive moment in time.
EFF strongly discourages auto updates that can't be turned off, because they can be used for enabling DRM and curtailing freedom.
If you remove it, and then try to run any Google Software, it will first lie to you and say that it needs you to authenticate so it can "function" properly. If you refuse, it will try to install it's code in ~/Library instead. If you intercept that, it will stop asking and work properly.
Google software does not depend on its updater in any way. There is no technical reason to keep asking you to install it. They just don't respect your agency. And if you say no to root installation, they will settle for just a user installation.
A lot of software that asks for authentication on first run is doing it solely to install it's helpers.
Not just is it creepy asf and wrong, but sometimes features will be removed or changed without my consent.
Software that was free when you downloaded it just got "upgraded" to shareware. Or maybe it just irreversibly converted all of its saved data to the new format that isn't backwards compatible.
You would never have agreed to install that update if you actually knew what it was going to do. That makes it dishonest.
My impression was that at least in Debian based systems (Ubuntu and others), it updates with apt now?
EDIT: Sorry if this sounded accusative. Wasn't meant that way.
Would be fun trying to autoupdate deb packages though.
But unless you audited the chrome code (with a team of 1000 experts) you have already trusted them, both to write quality code and to prevent malicious code sneaking in. Why not trust them to patch your browser against malware?
Feel free to contribute to ungoogled chromium: https://github.com/Eloston/ungoogled-chromium
The Dropbox sync service, on the other hand, is literally just the client half of Dropbox's own proprietary backend. If Dropbox makes an ABI-incompatible change to their sync protocol on the server side, the non-updated client will just break until you update.
Wanting to disable updates to such a service, would be like wanting to load the old version of a webapp SPA whenever you visit the site. What's the point? It's not going to (have been designed to) work that way.
So... don't break ABI compatibility?
https://translate.google.com/translate?sl=ru&tl=en&js=y&prev...
Though this is not a phone app and Dropbox does have a history of mistakes causing data loss.
I assume it's true because: "If you don’t want Dropbox Update to run on your computer, you can uninstall the Dropbox application. You can still access your files on dropbox.com and using the Dropbox mobile apps."
A history of random forum posters making huge assertions which inevitably turn out to be significantly overstated. It's trendy in certain circles to complain about Dropbox and the hype factor makes it easy to forget that for every person repeating anecdotes on HN there are a million normal people who use the service without issues.
Its not rocket science to understand that a cloud data storage company is (a) going to have bugs, hence (b) data will be lost, and (c) customers will be dissatisfied.
The only saving grace for Dropbox is that the Google Drive windows client is a totally catastrophic data destroying pile of rubbish, and the Azure/Onedrive system is so microsofty and has no linux client either.
I know my phone is a security mess. But I want my desktop not to be.
Now I just want to smash my phone with a hammer. Smash it into tiny tiny pieces.
I'm on the latest iOS (10.2.1), and it's optional - I have 23 apps ready for updates, but I can scan through the release notes before initiating the update.
(and since this is HN: as for the updating, fine. It's no different from visiting a web site and having the pages served by different revisions of the back end, and it's not like it has a complex UI that could cause user confusion. I assume DB doesn't update all that often anyway).
Disclaimer: I run Ubuntu.