Dropbox - Transparency Report
dropbox.com
dropbox.com
> * This report doesn't include national security requests.
What good is this "Transparency Report" if it excludes an unspecified number arbitrary wide secret information access requests? The one kind that actually ignited the fire under Dropbox ass.
How can they seriously think this could calm and reassure anyone who cares about privacy of their data held with Dropbox?
It would be as if a city fighting crime releases statistics on muggings but not homicides.
Fact is, that's not a Transparency Report, it's PR Report, to make you feel better and not run away screaming. I've decided that Dropbox/Google Sync shouldn't be trusted for anything of any importance.
Considering how self-congratulatory HN readers are about this community's intelligence, you'd think more of them would be able to read between the lines.
Not to mention these two claims are contradictory:
"This report doesn't include national security requests."
"Unfortunately, the government allows services to disclose only the aggregate number of all law enforcement and national security requests received "
Does it include the NSA request, or not in the aggregate? First sentence says no, second implies yes.
You are not the world. You are not even most Dropbox users.
"Today we filed a legal brief asking the court to confirm that we have the right to report the number of national security requests we receive, if any. You can check out our brief here: Dropbox FISC Brief. We'll keep you updated about any developments."
Maybe you don't find that information important, but I do.
huhtenberg's point is simply that he doesn't agree with the classification of the page. That is contains too much information, and cannot include other information.
When people focus their disappointment on companies that are forced to comply you get civil war while the real aggressor is just laughing at you. Let's instead focus on how government got so much brutal power, how can we possibly reduce it and prevent from increasing again in the future. That's the real issue here.
If a company publishes a "Transparency Report" that is woefully incomplete, they shouldn't call it a "Transparency Report", should they now? They effectively fudge the numbers to make things look better than they are.
Im sorry, but that won't happen to you in a lot of other countries. Even with data retention in the european union there's still no such thing as NSL in most european countries.
Had Dropbox received just one national-security request [... the report would] look like this:
Jan-Dec 2012 United States 1-1000
Reporting in this way decreases transparency. [...] It would also obfuscate the number of [...] requests [...] which were not sealed and are in the public record.
so they are arguing that you either get the numbers shown or 1-1000 and nothing else (which seems odd to me, as google seem to manage to show both - see my link below).
cut + paste from pdf not working so may be typos above. https://dt8kf6553cww8.cloudfront.net/static/docs/DropboxFISC...
[Update - 9/23/2013] – Today we filed a legal brief asking the court to confirm that we have the right to report the number of national security requests we receive, if any. You can check out our brief here: Dropbox FISC Brief. We'll keep you updated about any developments.
They've phrased their document to suggest they have 1-1000 requests without actually saying it. For all we know they could have served thousands of requests last year but are using this as an excuse not to show that.
> This report doesn't include national security requests. We want to report the exact number of national security requests we receive, if any. Unfortunately, the government allows services to disclose only the aggregate number of all law enforcement and national security requests received (and even then the disclosure must be in large bands). A report in that form decreases transparency, especially for companies that receive zero or very few national security requests.
They can't report on how many national security requests because they have to lump them in with regular law enforcement requests in bands of 1000. Since there were less than 1000, it would be 1-1000, and that's it. They're working on being able to release the exact number, so they had to file a brief with FISA.
There are warrants/court orders, which everyone is familiar with.
Then there are NSLs. Those usually come from the FBI, and with a gag order. These can be included in transparency reports in aggregate, which is what the numbers provided by Google etc (and presumably dropbox) show.
"By law, NSLs can request only non-content information, such as transactional records, phone numbers dialled or sender or recipient email addresses. They also contain a gag order, preventing the recipient of the letter from disclosing that the letter was ever issued."
Worse than the NSL is the FISA order. These are not included in any "transparency reports", and they do not have to target specific users. They allow surveillance without a warrant. They don't even have to be for seeking evidence related to a crime, and can be issued just for "intelligence gathering".
"And it's even worse for FISA subpoenas, which can be used to force anyone to hand over anything in complete secrecy, and which were greatly strengthened by Section 215 of the USA PATRIOT Act. The government doesn't have to show probable cause that the target is a foreign power or agent — only that they are seeking the requested records "for" an intelligence or terrorism investigation. Once the government makes this assertion, the court must issue the subpoena."
In short, none of these transparency reports are worth anything, because they don't acknowledge FISA requests.
This right here is the contentious "Section 215", which is colloquially summarized as get everything, sort it later.
Its broad-sweeping and baseless nature is what's ruffling lots of feathers, and NSA's General Alexander praised it frequently in the much-reported congressional hearings from ~3 months ago.
The FISC has recently declassified their court opinion on it (they love it):
http://www.uscourts.gov/uscourts/courts/fisc/br13-09-primary...
"We've urged the government to allow online services to disclose the exact number of national security requests received in a reporting period without revealing details about specific requests."
If so, how do you decide when to decline requests?
How often do you get a request, decline it, then get another request against the same user or account?
Never thought of it. So its possible to always give the information asked and still keep response rate bellow 1%!
"... and statistics".
So the numbers are interesting and a good start but the good stuff is left out for the moment.
Google: Search Microsoft: Office Dropbox: File sync/sharing etc.
You don't have to go cold turkey, but it's easy enough to switch one at a time. Help other people (friends/family/etc.) to switch as well. Big changes happen one person at a time.
More importantly, you will see change if a major corporation sees a threat to their revenues.
Cast your economic vote. Repeat. Encourage others to do so as well.
Giving the government hell is all well and good, but it is unlikely to cause much in the way of change. If businesses start to feel the pain on the other hand, then they have the incentive to challenge the government about the massive monetary losses they face because the government fucked up the internet. Both giving the government hell and boycotting compromised services are valid ways of fighting back.
Good luck with that.
If your reasoning is that they're not lobbying against this, then you're wrong. You can't expect people not to use the Facebooks or Apples, it's a policy issue. Pressure the government, vote for the right people.
Does it mean that essentially the companies are intimidated to comply without the rule of law? Under what law and what sanctions do they face if full statistics is published?
[1] https://dt8kf6553cww8.cloudfront.net/static/docs/DropboxFISC...
I truly love this country, but this progress is worrying.
A bit of cold shower if you think hosting abroad is a viable solution to data privacy. You have nowhere to go.
does this mean that the account holder will personally be told by Dropbox, or that we're being told by being shown this data?
So does the total number include NSRs or not?
1 - https://dt8kf6553cww8.cloudfront.net/static/docs/DropboxFISC...