How Not to Deliver Bad News: Dropbox CTO Arash Ferdowsi | Effectual Analysis
blog.effectcheck.com
blog.effectcheck.com
My BS-meter went way up, when I scrolled down and saw the charts that conveniently "verified" the sentiment on Hacker News. I hope they don't think I typed this message, because I am depressed and lack compassion.
I would be hugely surprised if that actually gave reliable results! Human languages are hugely nuanced and context is a key part of interpreting mood in text, and even humans fail often at that. People often express surprise, for example, at pg's personality in person or in televised events, because his comments often seem (as one person put it) "Vulcan".
I'm starting to try to think of ways to thoroughly debunk their method, mostly because I'm curious if it would actually stand up.
The bar charts in the article would have been much easier to read if the horizontal axis would start at "typical". That way low would be seen as negative, while high would be seen as positive.
"presumably with the proper voting rings in place" -- [citation, etc]
Your users should not find out about these things via HN (or any other news site).
At this point, I don't think I can trust Dropbox with anything remotely valuable or private, and I bet I'm not the only person who feels this way.
They also don't give an example of what might be a better way. It's easy to say things are wrong. And I'm not sure if their data is an indication of anything. Ok people react with anxiety (or the analysis of their comments suggests this). But wouldn't you suspect that people don't react happy if their data could've been stolen? You should measure if people would trust dropbox again in the long run.
That doesn't leave a warm fuzzy feeling for storing my important personal information with Dropbox. It also makes me wonder; why didn't they clarify what the problem was? Are they hiding a big vulnerability?
Wether or not one agrees or disagrees with the actual technical setup of Dropbox is a separate question altogether.
The axes used by EffectCheck don't make sense to me. For example, can a post simultaneously score highly in "anxiety" and "confidence"? Aren't these opposites?
As a designer and programmer — Don Norman's newest article for Core77[1] got me thinking about this — I am a bit quick to roll my eyes when I see the powerful visuals ("Oh, a chart!") deployed to trivial ends (a relatively simple Bayesian classifier?), and EffectCheck has the hallmarks of something as unsophisticated as ELIZA[2] or the Myers-Briggs personality test.
"I'm absolutely utterly sure that climate change is real; we are all going to die in two years! PANIC!"
Indeed they are opposites. People can hold many dual emotions simultaneously-- love and hate, belief and doubt, etc.
No it doesn't present the reaction of the audience. It shows the reaction of a specific audience (i.e. HackerNews) - which is a very specific demographic. I love HackerNews like the next person, but people on here need to realize there is a whole big world out there that wears a different pair of glasses...and don't sport neck beards.
EDIT: I too detect the pungent stench of imitation lawns.
"This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again."
How is that not clear enough? All of the criticism is either unfounded (saying they need PR doesn't explain the problem) or minimal in nature (not saying the word "sorry" when explaining an outage).
The message is fine. The venue is wrong.
We are writing to let you know that there was some activity in your Dropbox account that we'd like you to review. On June 19, 2011, there was a brief bug with our authentication system that could have allowed unauthorized access to accounts. You can read more about it at our blog post linked here.
Based on a careful review of our records, we noticed that your account settings page was accessed during the time the bug was in effect. While it's unlikely, we'd like to be cautious and make sure this was you because if the activity was unauthorized, the information in your account could have been improperly accessed. Please review recent activity in your account, which you can view at http://www.dropbox.com/events, and let us know if you find anything suspicious.
We noticed that during the time the bug was in effect you also:
Logged into the Dropbox website Linked the desktop application to your Dropbox
As a precautionary measure, we logged you out of the website and disabled any apps.
We are very sorry and this should never have happened. We are scrutinizing our controls and will be implementing additional safeguards to prevent this from happening again. If you're not able to access your account or have any other questions or concerns, please contact us at support@dropbox.com.
I don't know what else they are supposed to do. They should have never screwed this up to begin with, but grandted that they did I think they've responded just fine.
IMHO All the moaning about how they've handled this is just a bunch of baloney. If a company spokesperson speaks out of both sides of their mouth, people cry for honesty. When a company is blunt and honest, they need to hire a PR person. I wonder how many people on these threads are 'PR' people.
"We fucked up. Not cool. We're going to work hard to prevent these things in the future and earn your trust."
Then the tone of the response would have been very different. That email was pretty good – they should have said something closer to that in their blog, too.
bingo. they needed a message that was easily understandable and relatable by all clients. there's nothing inherently wrong about the post and would've been a good status update or part of a post mortem, but not the entire PR statement of the company about the incident.
I can't disagree with this sentiment enough.
The word "sorry" isn't about being nice – it's about being accountable. What we're seeing here is a second lapse in Dropbox's security – a hard problem! – but little acknowledgement that hey, this really isn't okay, these files are important to users, and this is a breach of trust that needs to be remedied.
Moreover, this isn't an outage as in "boy, wish I could access my dropbox." This is a security outage as in "boy, wish the entire world couldn't access my Dropbox." The period of time, the cause, the impact is, in the end, immaterial to the outcome of breached trust.
So when we fuck up, as grownups, we take a moment to acknowledge it, explain the cause, and express how much we value the trust we've been given. The alternative is to leave the impression that trust is taken for granted. Which, in this case, it sure as hell feels like it is because Dropbox is doing nothing to dissuade that impression.
These are good guys with a great product that makes a lot of people's lives better. They just need to be accountable for their shit – that's all people are asking for here. Perfection is impossible but being good in your relationships with users is something anyone can do with a little empathy.
"This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again."
this is absolutely unarguably taking full accountability.
Users expect something like "There was a solar eclipse that caused a bit flip on our login server which caused strcmp to give the wrong result ...". We expect an explanation of why it happened and why it will never again happen, and "lulz sry" is not very confidence inspiring.