If you mean per license, that scales with the amount of money and a reasonable limit on 3 licenses doesn't have to allow all that many terabytes all that fast.
But I do think that targeted throttling is a good way to deal with this problem. As I said elsewhere, detecting abuse is heuristic and false positives are horrible when the enforcement is to shut down accounts, but a false positive resulting in throttling is not so bad.
This is no different than any other "I could implement this in a weekend" thread that you see here. I'm not saying "Dropbox is incapable of implementing enforcement for this ToS violation", I'm saying that I'm confident they've already spent many millions of dollars on it, and have decided (wisely, in my view) that changing the product to more fundamentally preclude this kind of usage is the better trade-off to take.
So, having said that, to answer your question: at 750GB per day, uploading 1PB in a week only requires parallelism of 200. That is not many users for an "enterprise" account. (And I suspect this becomes costly well below 1PB per week.)
You'll be able to think of "well you can just ..." for that as well, and I promise you that there are "the abusers can work around that by doing ..." for those things. Because, like I keep saying, it's just a normal arms race pattern. It's not that there is nothing you can do about any particular thing that people do, it's that you have to keep doing it ad nauseam.
By the way, this change to the product is also just one more parry in this arms race. It is unlikely to fully solve the problem (and I'm confident they know that), just another useful tool.
Right, but my idea is that the cost is less than the payment they receive.
> So, having said that, to answer your question: at 750GB per day, uploading 1PB in a week only requires parallelism of 200. That is not many users for an "enterprise" account. (And I suspect this becomes costly well below 1PB per week.)
I think you missed part of my argument, which is that if you want parallelism 200 then you need 200 licenses, which means dropbox gets $4800. That's much more than enough to pay for the 120 terabyte-months such a user would consume in that week.
There is the worry about how high of a spike it would be versus their buffer of free space, but someone signing up for 200 licenses at once at maximum upload rate and thinking they'll avoid scrutiny is... pretty unlikely. Also if we assume they'd run it similarly to how they used to do it, they'd have to be manually approving increases on that giant pile of data, so that brings even more scrutiny.
Also I think their limit for quite a while was 100TB per week for the entire organization. No need to worry about petabyte spikes then.
> Because, like I keep saying, it's just a normal arms race pattern. It's not that there is nothing you can do about any particular thing that people do, it's that you have to keep doing it ad nauseam.
Which is not a problem if you're getting enough money for the trouble.
There are a few challenges that make this harder than you might think:
- It's a never-ending arms race against adversaries working actively to evade detection.
- It is necessary to find detection approaches that abide by security and privacy requirements.
- Detection of this kind of behavior is inevitably heuristic and false positives are incredibly bad.
To put a finer point on that last one: The flip side of "it's easy to detect and shut down abusive accounts" is every article or tweet or blog post like "look at all these normal people who had their accounts permanently disabled without explanation or recourse".
1. It is already in violation of the Acceptable Use ToS which implies they already have solutions in place to detect this behavior. https://www.dropbox.com/acceptable_use
2. It is easy to detect large amounts of disk usage with a high number of read/writes across wide swaths of the storage.
Putting it in the ToS is how they reserve the right to put in place solutions. But writing text in a ToS to ban some behavior does not magically create a working enforcement solution.
I'm quite certain they have spent the last few years: 1. Putting that in the ToS in order to give themselves permission to do the enforcement, 2. Working really hard fighting an enforcement arms race with people not complying with the ToS, 3. Losing the battle and painstakingly deciding to throw in the towel.
> It is easy to detect large amounts of disk usage with a high number of read/writes across wide swaths of the storage.
Again, these are active adversaries. Their first attempt probably fit that pattern in a way that was discernible to the dropbox client or server code, but it is unlikely that their current usage looks like that.
Again, false positives are extremely painful when doing account shutdowns for abuse. Other usage that is not crypto mining are free to exhibit "large amounts of disk usage with a high number of read/writes across wide swaths of the storage".
And again, I'm not saying this is impossible, just that it is actually a very difficult problem. And I am saying that I don't think it is at all worth the effort, and is much better to do what this announcement is doing, and not attempt to provide "unlimited storage" as a product at all.
Of course it doesn't... but if you're running a storage business open to the public, you're going to implement this regardless.
> Again, false positives are extremely painful when doing account shutdowns for abuse.
These are not personal customer accounts, these are business accounts.
> Other usage that is not crypto mining are free to exhibit "large amounts of disk usage with a high number of read/writes across wide swaths of the storage".
They specifically named Chia mining... so they obviously knew what was happening.
Are you seriously telling me that a company in the business of providing storage can't efficiently detect Chia mining? That's not a great look for Dropbox.
Implement what? This specific mitigation for cryptocurrency mining? If so, then no, you weren't going to fight that particular arms race "regardless", and you don't have to at all if you instead implement sensible storage limits, because the whole enterprise becomes unattractive to those miners within those limits.
> These are not personal customer accounts, these are business accounts.
Yes and that makes it even worse. Do you think businesses care about this less than consumers?
> Are you seriously telling me that a company in the business of providing storage can't efficiently detect Chia mining? That's not a great look for Dropbox.
Yes, I'm seriously telling you that it is difficult and expensive for any service to win an arms race like this against an entire internet's worth of potential adversaries. It isn't a bad look for Dropbox at all, it just is how it is; sometimes products become too costly to sell for one reason or another, and this is the case for "unlimited storage" now.
The only question I have is whether they rummaged through private customer data or just made things up.
use the Services to back up, or as infrastructure for, your own cloud services;
use the storage space provided by the Services as the basis for cryptographic proof-of-space or proof-of-storage, or any similar proof system;