Dropbox axes unlimited cloud storage for businesses
blog.dropbox.com
blog.dropbox.com
There's something abrasive about implying that customers paying and using capabilities of their highest tier as non-genuine.
Conversely, Dropbox never sold this plan as being available forever, and the transition plan seems reasonable overall I suppose.
I disagree. Their website makes it abundantly clear that this product is for employee productivity. The people doing this are well aware that what they're doing is hacky and costing Dropbox lots of money.
Businesses have different needs. Some might use it for employee productivity and some might use it to store a ton of bins.
Dropbox probably tunes their systems to loads and access patterns seen in normal documents-based business usage. Not for backing CDN services and such.
> backing CDN services and such.
That's against ToS anyway.
"As much space as you need. Get as much space as your team needs for storage and collaboration."
https://web.archive.org/web/20221103000218/https://help.drop...
un· lim· it· ed ˌən-ˈli-mə-təd
1: lacking any controls : unrestricted
unlimited access
2: boundless, infinite
unlimited possibilities
3: not bounded by exceptions : undefined
the unlimited and unconditional surrender of the enemy— Sir Winston Churchill
Powerful technology.
On-prem seems to be the best, but carrying around 30 disks is no small feat.
Edit:
The data will not be mutated after write. Might append new data occasionally after the first dump.
Eh, RAID 6 is fine. Your chance of losing two extra drives in a two day rebuild isn't that high if you've been testing your drives regularly.
And if you haven't been testing regularly, even small drives would eventually have some scary risks of dying.
That said, 50% more drives with raidz3 is a lot safer than RAID 6.
One of the more common scenarios with consumer grade hardware is a degraded array getting completely lost while being rebuilt.
The same number of disks as you were using when the disks were smaller.
I'm comparing like-for-like except disk size.
> One of the more common scenarios with consumer grade hardware is a degraded array getting completely lost while being rebuilt.
Which is why I mentioned regular testing. If your disks are on the verge of death it doesn't matter how much parity you have or how big they are, a rebuild has too much chance of failure. You need to make sure they can handle a moderately heavy load.
But if you're putting them under that load regularly, a rebuild is very unlikely to be the last straw for multiple drives.
20-22TB HDDs are available nowadays, so more like 14-15 disks.
https://www.reddit.com/r/DataHoarder/comments/155so84/dropbo...
https://www.reddit.com/r/DataHoarder/comments/15gf2rc/dropbo...
"Updates to our storage policy on Dropbox Advanced"
At this point I just assume that "updates" are always a price increase. For those in the future wondering, this was originally posted with an editorialized headline of "Dropbox Axes Unlimited Cloud Storage for Businesses". While it's generally HN policy to change editorialized headlines back to their defaults, I would argue that HN should not be complicit in businesses' attempts to cowardly soften the blow. HN should keep the editorialized headline.Aside from that annoyance, I'm not surprised in the slightest that this was done. Crypto was designed as a vehicle to push the base assumptions of Austrian Economics - i.e. extreme individual liberty in exchange for no free lunches - and thus the one thing it's good at is eating your free lunches as quickly as possible. If you give things away, people will construct a way to get paid for burning what you've given away. The Internet is uniquely hospitable to this kind of misbehavior, so everything has to have a cost, no charity, no welfare, etc.
Dropbox prices are pretty good. I was looking at even AWS s3 _glacier_ and it seems way more expensive.
Does this mean that if everyone used their entire capacity it's like a bank run and Dropbox goes out of business? Or is storage actually cheap and AWS makes big margins on it?
That's because glacier stores exactly what you tell it to store. Dropbox is taking advantage of a lot of compression techniques to keep their storage volume down. For example, if two users upload the exact same file twice, they can just store it only once (they can also do this for chunks for files that are identical).
> Does this mean that if everyone used their entire capacity it's like a bank run and Dropbox goes out of business? Or is storage actually cheap and AWS makes big margins on it?
I don't know about a bank run, but Dropbox would most likely go out of business eventually if everyone used their full capacity and they didn't adjust their pricing structure. There's most likely some customers they take losses on to keep their pricing structure simple.
I'm not sure what you mean?
Unless you're grandfathered in, the new limit is 5TB for $24 and glacier would be $5 plus bandwidth fees.
And as just one example for competitors, Hetzner offers 5TB of nextcloud for €17 and 5TB of storage for €13.
If you're talking about the 35TB limit, yeah that's a great deal and nobody can have it any more. The larger users were subsidized by the smaller users, which is a delicate balance.
That's ~$14.28/TB.
I don't know Dropbox's Enterprise storage pricing, but I know Backblaze charges $5/TB for simple cloud storage. That means, ignoring drive failures and redundancy, it takes less than 3 months to RoI on hard drive purchases. With the high level of redundancy these services tend to have, it's probably closer to 1-2 years.
On the flip side, AWS S3's standard storage tier is a whopping $23/TB. They're making absolute bank on that. Not to mention their stupidly high egress fees (Which are even higher when using Glacier!) if you ever actually use it.
Their redundancy is only +18% as of their last post about it.
Though don't forget the servers that hold the drives adding another 1/3-ish.
This is my favorite type of corporate weasel-wording. 35TB would actually only be enough for 260 hours of HD video from my camera (300 megabits per second ≈ 0.135 terabytes per hour).
Colloquial versus contract. It's sold as unlimited, because for most people, it is. Similar to how salt and pepper at restaurants is practically unlimited, even if you can't demand they hand you all the salt in their kitchen.
In practice, marketing as unlimited to suss out the use distribution before capping it where it becomes uneconomic seems to be a valid strategy. (The fraction of users curtailed plays into perceptions of fairness.) With that framing, this story has no bad guy.
Neither do they advertise their lack of food poisoning. It's baked into the concept of a restaurant. Unlimited != infinite; it's a fuzzy boundary, and that is okay.
You're talking about unwritten AND unverbalized social contracts.
Entering a restaurant that has salt on the table is nothing like me entering into a written agreement for unlimited salt from a salt distributor.
What in Dropbox's terms of service do you think they're violating with this move?
Buying unlimited storage for common use fits into the paradigm of the not needing to be stated understanding on what unlimited means to a reasonable person. If you want to get more precise, the terms and conditions specify that Dropbox may, at its discretion, take various actions.
If I buy a meal from a restaurant and that restaurant provides complimentary salt on the table I do not expect unlimited salt.
Selling something as unlimited at a fixed price is clearly stupid unless there is a limit on the speed of the consumption (like the salt provider saying that you can have unlimited salt at a maximum rate of 1kg per hour or so). For something like dropbox it is even more stupid since every unit of product sold will increase their running costs.
all you can eat is not actually all you can eat
Really though, I find that buffets are all-you-can-eat with the asterisk that you can't stay more than a certain time (usually 90-120 minutes?) and that you can't take any home.
I don't remember who did it but I recall a skit that went the other way. Someone went to an all you can eat restaurant and to their dismay discovered it meant all you can eat. The restaurant would not let you leave until you could no longer physically eat any more.
I was never charged more because they decided I was full. Certain restaurants have a "no food waste" policy that will make you pay the stuff that you don't eat.
It's a shame to watch the slow death of yet another service that was making people's lives easier. Can't really say I'm surprised, though. I have to imagine that it's incredibly, incredibly difficult to resist the urge to sell. The key differentiator seems to be whether you get to walk away with your reputation intact among the sort of people who take a hardline stance on this.
Thing is, most of those people probably wouldn't gamble a life-changing sum of money for yourself and the people they love on principles - and ironically, we can't really judge them for it with the world we live in and its incentives.
VC-funded blitzscaling is just the latest meta, and it's no fun for anyone. So much useful potential squandered while everyone has to watch the centralised, closed source, S/PAAS tools they rely on becoming more encumbered, limiting and expensive.
As Tom Toro so famously put it, "Yes, the planet got destroyed. But for a beautiful moment in time we created a lot of value for shareholders." If people will make that choice when it comes to the land we live on and the air we breathe, you can see why they'd find it a lot easier to do exactly the same thing for some code tearing its way through a lump of silicon.
Shouganai. Someone will just make another Dropbox. The cycle continues.
https://kottke.org/23/01/the-enshittification-lifecycle-of-o...
I don't get it. Those customers are using the subscription precisely to run a _Business_.
What doesn't make sense here is why they can't detect this and shut it down.
What could one provide an infinite amount of? Shouldn't that empty set inform the reasonable interpretation of "unlimited" in this context?
No. It's not on the customer to decide what a reasonable interpretation of the company's offering is. It's up to the business to inform the customer clearly.
Clarity is in the eye of the beholder. This is why we have reasonableness standards: it's impractical to specify ex ante every term of a trade to infinite precision. Most people understand the intent of the term "unlimited" here, and given the fraction of accounts affected, this seems fine. (Also, until this announcement, it was unlimited. They're just discontinuing that. Unlimited doesn't mean unlimited forever.)
Like if I bought "unlimited" streaming vs. "Streaming limited to one screen at a time for one user" I'd be much happier about finding out that I can't watch one show in the bedroom and a different one in the living room than I would with my "unlimited" service.
And that's why "legalese" is a thing. Every possible interpretation needs to be handled to prevent loopholes.
That's a real defense and has precedent.
I don't think that I'd parse "unlimited" and "infinite" in the same way.
Some things are naturally limited by rate delivery, and advertising "unlimited" seems fine. e.g. I don't see a problem with advertising a phone plan as having "unlimited" minutes, rather than specifying a limit of 10,080 minutes per week. The number of minutes are not infinite, but neither are they limited by the carrier.
If you buy thousands of these phones, hook them up to a modem, and use them to send and receive information over the carrier's airwaves 24/7, you will overwhelm your tower.
Yea it's true that if someone tried to truly exercise the latter, for example by allocating several trillions of bot accounts, then for sure you're going to get a call from the provider politely instructing you to desist. And I think that would be reasonable of them, and the marketing should not be considered deceptive.
The question is, does the same logic apply to TBs of storage? Is there anything that distinguishes these two use cases?
I guess the marketing offer of 'unlimited' could perhaps be read as 'all that 99.9% of customers ever need, but if you're one of the remaining 0.1%, you have to pay extra'.
That is to say, perhaps 'unlimited' could be read as a class of user that encompasses the vast majority of cases, as opposed to a literal resource quota. Is this reasonable or deceptive?
Depends on the facts and circumstances. When cellular providers throttled unlimited plans, I felt like it was deceptive. In this case, I do not. I am curious if those cut off genuinely feel they were deceived.
I'm surprised to hear that Chia is still going, though. That was one of the worst excesses of the crypto boom, driving up prices of storage for real users.
It's a nasty tactic, and gives people the wrong expectations and in turn ruins markets to all start using such terms to offer "competitive" unlimited tiers.
Unlimited applies to some specific attribute, it doesn't mean you can do anything.
But when a natural limitation is lifted, the businesses have to reconsider their "unlimited" policies.
If you mean per license, that scales with the amount of money and a reasonable limit on 3 licenses doesn't have to allow all that many terabytes all that fast.
But I do think that targeted throttling is a good way to deal with this problem. As I said elsewhere, detecting abuse is heuristic and false positives are horrible when the enforcement is to shut down accounts, but a false positive resulting in throttling is not so bad.
This is no different than any other "I could implement this in a weekend" thread that you see here. I'm not saying "Dropbox is incapable of implementing enforcement for this ToS violation", I'm saying that I'm confident they've already spent many millions of dollars on it, and have decided (wisely, in my view) that changing the product to more fundamentally preclude this kind of usage is the better trade-off to take.
So, having said that, to answer your question: at 750GB per day, uploading 1PB in a week only requires parallelism of 200. That is not many users for an "enterprise" account. (And I suspect this becomes costly well below 1PB per week.)
You'll be able to think of "well you can just ..." for that as well, and I promise you that there are "the abusers can work around that by doing ..." for those things. Because, like I keep saying, it's just a normal arms race pattern. It's not that there is nothing you can do about any particular thing that people do, it's that you have to keep doing it ad nauseam.
By the way, this change to the product is also just one more parry in this arms race. It is unlikely to fully solve the problem (and I'm confident they know that), just another useful tool.
Right, but my idea is that the cost is less than the payment they receive.
> So, having said that, to answer your question: at 750GB per day, uploading 1PB in a week only requires parallelism of 200. That is not many users for an "enterprise" account. (And I suspect this becomes costly well below 1PB per week.)
I think you missed part of my argument, which is that if you want parallelism 200 then you need 200 licenses, which means dropbox gets $4800. That's much more than enough to pay for the 120 terabyte-months such a user would consume in that week.
There is the worry about how high of a spike it would be versus their buffer of free space, but someone signing up for 200 licenses at once at maximum upload rate and thinking they'll avoid scrutiny is... pretty unlikely. Also if we assume they'd run it similarly to how they used to do it, they'd have to be manually approving increases on that giant pile of data, so that brings even more scrutiny.
Also I think their limit for quite a while was 100TB per week for the entire organization. No need to worry about petabyte spikes then.
> Because, like I keep saying, it's just a normal arms race pattern. It's not that there is nothing you can do about any particular thing that people do, it's that you have to keep doing it ad nauseam.
Which is not a problem if you're getting enough money for the trouble.
use the Services to back up, or as infrastructure for, your own cloud services;
use the storage space provided by the Services as the basis for cryptographic proof-of-space or proof-of-storage, or any similar proof system;
There are a few challenges that make this harder than you might think:
- It's a never-ending arms race against adversaries working actively to evade detection.
- It is necessary to find detection approaches that abide by security and privacy requirements.
- Detection of this kind of behavior is inevitably heuristic and false positives are incredibly bad.
To put a finer point on that last one: The flip side of "it's easy to detect and shut down abusive accounts" is every article or tweet or blog post like "look at all these normal people who had their accounts permanently disabled without explanation or recourse".
1. It is already in violation of the Acceptable Use ToS which implies they already have solutions in place to detect this behavior. https://www.dropbox.com/acceptable_use
2. It is easy to detect large amounts of disk usage with a high number of read/writes across wide swaths of the storage.
Putting it in the ToS is how they reserve the right to put in place solutions. But writing text in a ToS to ban some behavior does not magically create a working enforcement solution.
I'm quite certain they have spent the last few years: 1. Putting that in the ToS in order to give themselves permission to do the enforcement, 2. Working really hard fighting an enforcement arms race with people not complying with the ToS, 3. Losing the battle and painstakingly deciding to throw in the towel.
> It is easy to detect large amounts of disk usage with a high number of read/writes across wide swaths of the storage.
Again, these are active adversaries. Their first attempt probably fit that pattern in a way that was discernible to the dropbox client or server code, but it is unlikely that their current usage looks like that.
Again, false positives are extremely painful when doing account shutdowns for abuse. Other usage that is not crypto mining are free to exhibit "large amounts of disk usage with a high number of read/writes across wide swaths of the storage".
And again, I'm not saying this is impossible, just that it is actually a very difficult problem. And I am saying that I don't think it is at all worth the effort, and is much better to do what this announcement is doing, and not attempt to provide "unlimited storage" as a product at all.
Of course it doesn't... but if you're running a storage business open to the public, you're going to implement this regardless.
> Again, false positives are extremely painful when doing account shutdowns for abuse.
These are not personal customer accounts, these are business accounts.
> Other usage that is not crypto mining are free to exhibit "large amounts of disk usage with a high number of read/writes across wide swaths of the storage".
They specifically named Chia mining... so they obviously knew what was happening.
Are you seriously telling me that a company in the business of providing storage can't efficiently detect Chia mining? That's not a great look for Dropbox.
Implement what? This specific mitigation for cryptocurrency mining? If so, then no, you weren't going to fight that particular arms race "regardless", and you don't have to at all if you instead implement sensible storage limits, because the whole enterprise becomes unattractive to those miners within those limits.
> These are not personal customer accounts, these are business accounts.
Yes and that makes it even worse. Do you think businesses care about this less than consumers?
> Are you seriously telling me that a company in the business of providing storage can't efficiently detect Chia mining? That's not a great look for Dropbox.
Yes, I'm seriously telling you that it is difficult and expensive for any service to win an arms race like this against an entire internet's worth of potential adversaries. It isn't a bad look for Dropbox at all, it just is how it is; sometimes products become too costly to sell for one reason or another, and this is the case for "unlimited storage" now.
The only question I have is whether they rummaged through private customer data or just made things up.
(see also "less space than a Nomad. Lame")
Here it is: https://news.ycombinator.com/item?id=9224
Would a business using a self-owned rsync+ssh solution now be shopping for yet another cloud service after yet another backtrack on promises several years in?
Here is how BrandonM responded after Drew replied: https://news.ycombinator.com/item?id=9479. If that's a prototypical HN dismissal, we're in the sixth sphere of Paradiso.
https://news.ycombinator.com/item?id=27068148
https://news.ycombinator.com/item?id=23229275
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...