Dropbox disconnects Boxopus for unwanted features
blog.boxopus.com
blog.boxopus.com
Dropbox provides a file sharing service, Boxopus uses this to provide torrent downloading services. Should Boxopus become popular, how will this impact Dropboxes cost base? Will people buy more dropbox space?
Are Dropbox possibly obliged to deactivate Boxopus due to onerous copyright rules? Is there anything in their underlying contractual arrangements with their suppliers for example that could result in the termination of dropbox's service, or are they just trying to cover their backsides?
I think this shows a good example of the increasingly common problem where startups tie themselves to a platform and suffer for it as well as benefit. They're looking for another storage provider, but who's to say this won't happen with a new provider too?
If I were Dropbox, I would see arbitrary action by the US authorities as one of my greatest risks, and would do whatever it takes to stay in the good graces of the MPAA, given the apparent influence that they have over US law enforcement.
If your TOS states that Dropbox can't be used for files above a particular size, or can only be used by individuals and not corporations, or something like that, then fine.
But companies that discriminate based on the purpose of usage -- this seems fundamentally wrong. MasterCard blocking WikiLeaks payments, Dropbox blocking torrents, PayPal banning a VPN provider... Private companies have no business deciding what is "acceptable" in this manner. If it's illegal for them to provide services, then obviously they can't, but if it isn't, then they should continue to provide services.
Honestly, is this any different from a company ninety years ago denying service to non-whites because it "could be perceived as encouraging the races to intermarry?"
There's a reason we have anti-discrimination laws for races, gender, orientation and religion. Why don't we have them for "purpose of use of services"?
This is the fundamental problem with SaaS and web APIs more generally (a SaaS application is just a web API for humans in some sense): you don't control it.
It isn't installed on your hard drive. If the vendor says "you can't use this any more" you can't give them the middle finger and keep using your copy while you find a good lawyer. You're done. That's it.
Does that mean I think everyone should stop using SaaS and APIs? Absolutely not. I would cry if I had to give up Google Docs, Gmail, etc. But I'm not under any illusions about who is in charge, and I make decisions accordingly.
>Honestly, is this any different from a company ninety years ago denying service to non-whites because it "could be perceived as encouraging the races to intermarry?"
I think we can both agree that it's a hyperbolic statement. Moving beyond that, as a company, I should have every right to decide who can and cannot use my service. Just because I provide a public-facing API doesn't mean I have to allow you do to what you want with it. You're building off of my brand and my infrastructure. If I don't want Initech Inc. to be associated with file sharing, fire arms, or even the Irish, that's entirely within my rights. I'd be far more aghast if companies were forced to take any comers.
On this specific issue, scan the headlines:
"Pirate’s dream come true: Boxopus pushes torrents to your Dropbox account" "Boxopus Is A Pirate Friend, Drops Torrents Directly Into Dropbox" "New App Makes Pirating Movies A One-Click Process"
The articles also point out that Boxopus was quickly integrated with a number of torrent sites that host bootleg downloads.
The absolute last thing Dropbox wants to be associated with is piracy. The company is in much more danger of going out of business due to piracy issues than to any competitor.
I'm rather aghast that any companies think this way. You might as well say that it is well within Google's right to shut down my Google Docs account because they don't want to be associated with the bad poetry I write using it.
One problem with this attitude is that it doesn't lead to a smoothly functioning economy. If I have to worry that any online service might chose to shut down my access for any arbitrary reason, then I am strongly disincentived from using online services. The strength of any economy is in no small part due to the ease and fluidity with which trusted transactions can take place. Remove the forces that allow us to trust the transactions, and the economy will falter.
The only reason that people are mostly willing to overlook this issue is because service providers exercise their putative right to deny service for arbitrary reasons rarely. But if you as a service provider exercise this putative right more liberally, then you are damaging the entire economic system (albeit only to some small degree for an isolated provider).
The only silver lining in all this free market rhetoric is that hopefully the free market will step in and put you out of business. Unfortunately, however, this often takes a lot longer than it should once network effects have engaged.
P.S. What's with this trend of downvoting people just because someone doesn't happen to agree with what someone else has to say. This is rather rude, if you ask me.
What he is saying is that he believes it is Google's right to do that and it is irrelevant to the fact it is stupid.
> One problem with this attitude is that it doesn't lead to a smoothly functioning economy.
Sure if people just put up with it but I don't think anyone is suggesting we just accept dropbox's position and pretend it never happened.
And what I'm saying is that it is NOT within Google's right to do this. Among other reasons, it is not within Google's right to fsck up the economy that everyone depends on.
On the other other hand, I fully acknowledge that the best remedy is not always more government, since that doesn't always lead to the greatest utility either.
> it is not within Google's right to fsck up the economy that everyone depends on.
I shut down a non-technology brick and mortar store almost a year ago, partly because of dwindling sales due to the economy, and more importantly because I had a single customer that maintained over 60% of my revenue. That customer decided to move the business they were giving me in-house. Negotiations had been ongoing for over 4 years, both to (naively) prevent them from doing so (it wasn't a surprise that they did, they had been talking about it for years), and to suggest that we could merge businesses. Suffice to say, they hired someone else and I was forced to walk away.
I went through a period of "Fuck them", but I had known all along that if they walked away from me, I was screwed. Relying on a single 3rd party API is exactly the same thing. It's a contract with another business entity. If they decide to implement your additions into their core product (take for example today's Podcast app release form Apple), or if don't like your hair color, or they just don't like what you are doing, it's not "fuck them" it's "what's phase 2?". Grow up and move on. This is business. No one is entitled to consume another company's API, or else there would be no such thing as an API key.
That would depend on what you mean by "entitled" and by "consume". Lawsuits happen all the time because one entity believes that another entity backed out of a deal in bad faith.
You're looking at only one side of the issue, and the smaller one at that. Let me flip it around for you:
One problem with the attitude that by providing an online service I'm obligated to maintain it for users I don't wish to is that it doesn't lead to a smoothly functioning economy. If I have to worry about supporting users when it's against my better interest, then I am strongly disincentivized from offering an online service.
The situation is different for individuals or small companies than it is for large companies. Large companies (that are not structured as mutuals, or somesuch) generally only have one interest: maximizing their profit. But they often tend to use a Prisoner's Dilemma's strategy against the world that might maximize their next quarterly return but does not act to make the economic pie bigger for everyone.
Regarding the Irish part, I don't think that is within your rights.
In the US Title II of the Civil Rights act Outlawed discrimination based on race, color, religion or national origin in hotels, motels, restaurants, theaters, and all other public accommodations engaged in interstate commerce;[1]
In other countries article 7 of the UN Declaration on Human Rights (All are equal before the law and are entitled without any discrimination to equal protection of the law. All are entitled to equal protection against any discrimination in violation of this Declaration and against any incitement to such discrimination.)[2] may outlaw that kind of discrimination (depending on your countries international treaty obligations and local laws)
[1] http://en.wikipedia.org/wiki/Civil_Rights_Act_of_1964#Title_...
[2] http://en.wikipedia.org/wiki/Universal_Declaration_of_Human_...
Nearly all of the comments on HackerNews said that the decision showed a lack of conviction and that we should have denied service to the patent troll. I don't think that's appropriate for all the reasons you listed, but it would seem that we're in the minority.
Note: I agree with you that companies should not be allowed by their users to get away with this, I don't agree there should be a law prohibiting it.
Furthermore, saying 'in Europe' doesn't mean anything. You might mean 'in most European jurisdictions I know of', or 'under EU law', or 'under Council of Europe law', or whatever, but even then there are so many nuances that that statement alone doesn't say anything.
An answer from a Swedish "ask a lawyer" site, regarding whether it is allowed to deny entrance to a club. The answer is "only if that person is disturbing the public order, or if it is required to avoid a punishable offense from occurring". [Swedish]: http://lawline.se/answers/780
Yes it different, in degree, effect and legal status.
Not only that, it is extremely offensive to compare a company stopping another company using their service to download files with an evil social institution closely related to the lynching of people affected by it.
* * *
Once upon a time there were three little pigs. One pig built a house of straw while the second pig built his house with sticks. They built their houses very quickly and then sang and danced all day because they were lazy. The third little pig worked hard all day and built his house with bricks.
A big bad wolf saw the two little pigs while they danced and played and thought, “What juicy tender meals they will make!” He chased the two pigs and they ran and hid in their houses. The big bad wolf went to the first house and huffed and puffed and blew the house down in minutes. The frightened little pig ran to the second pig’s house that was made of sticks. The big bad wolf now came to this house and huffed and puffed and blew the house down in hardly any time. Now, the two little pigs were terrified and ran to the third pig’s house that was made of bricks.
The big bad wolf tried to huff and puff and blow the house down, but he could not. He kept trying for hours but the house was very strong and the little pigs were safe inside. He tried to enter through the chimney but the third little pig boiled a big pot of water and kept it below the chimney. The wolf fell into it and died.
The two little pigs now felt sorry for having been so lazy. They too built their houses with bricks and lived happily ever after.
The other part of people's defense of Boxupus is this whole idea that just because it could be used to violate copyright doesn't mean it will. Anyone who honestly, deep down, truly believes this and isn't just towing the Pirate Party Line needs to wake up. The majority of people downloading from torrents are downloading copyrighted material which is not legal, like it or not, the legalities of copyright law are irrelevant here. While I'm sure you can pop in and say "but I was using it for legit use case x, y, and z", most people were using it for downloading music and movies. Where's my proof? Fuck my proof. Where's your proof (I'm using the royal "your" here, not aimed at the op here) that it was being used so innocently? It really makes me upset that I just know someone will try to call me out for not having evidence on that one point despite the fact that we all know what was up just like we all knew what was up with MegaUpload. Demanding my evidence on that one point is the last defense of a person who's just grasping at straws, defending some pro-piracy ideology. But piracy isnt even the issue nor is it relevant!
Dropbox is a company here to make money. Just mentioning torrents puts people in a frenzy. So they're protecting themselves from liability by making sure their product is not associated in any way with torrents. It doesn't matter whether they have a legit purpose or not. It's a case of perception trumping all else and you have to remember that even beyond legal issues, Dropbox has a brand to protect. The perception of Dropbox is that of an exceptionally wholesome file storage/sharing service. Why would they even risk being seen as even the teensiest bit shady?
If this principle had a name (ie "<someone's> law") then maybe people would pay more attention.
(And OT: I read "boxopus" as "box o' pus", which makes me think perhaps its a poor name)
I'm sure the actual reason was "torrent user == pirate" and they just didn't want any juvenile connections, bad news in any language.
Everyone who read the original story saw this coming.
Look at Megaupload, they were supposedly complying with the law.
[1] Pure speculation
Megaupload is commonly understood to have been "complying with the law" based on a misapprehension of what the law actually is.
The misapprehension is that "compliance" with US copyright law means "honoring takedown notices".
The reality of US copyright law is that there are two sides to compliance: first, takedown notices need to be honored, and second, the service can't operate with foreknowledge of infringing use.
You can execute takedown notices within milliseconds of their arrival, but if an opposing lawyer or prosecutor can demonstrate that you repeatedly (a) came into knowledge that your service was used for piracy and (b) took no action, you effectively forfeit the service provider "safe harbor".
It was discovered by prosecutors that Megaupload not only knew about infringing content on their own site (trading links among staff for particular films, for instance), but also ran a promotional/affiliate program that rewarded uploaders for pushing popular copyrighted material to the site.
You are at the sole discretion of the company whose API you are using.
Different cloud storage provider, different API. I wish they all started using the remoteStorage protocol. http://www.w3.org/community/unhosted/wiki/RemoteStorage
instead of torrent -> local dropbox -> cloud dropbox,
you get only use your bandwidth for cloud dropbox -> local dropbox.
Given that many residential ISPs that meter data service don't differentiate between uploaded vs. downloaded data, that's a potentially valuable way to externalize the bandwidth requirements for your torrent (of undoubtedly legal/paid or public domain content, I'm sure)...
If you could move or process large files though a third party without having to physically download the file to a temporary location, it would be awesome... but apparently Dropbox doesn't think so. I deemed my project DOA because I had a feeling that what happend to Boxopus would happen to me across multiple platforms that I wanted to integrate.
[1]blizzard uses it for WoW updates, but I don't think that really counts.
How is Dropbox ever going to stay relevant in the future if they go around telling people what they can and can't store in their directories?
If you wanted to store BitTorrent downloads in Dropbox, all you gotta do is tell your torrent client to use your local dropbox folder as a save location...