How Dropbox Knows When You’re Sharing Copyrighted Stuff
techcrunch.com
techcrunch.com
Secondly there is lot of potential for abuse. Hacker could sneak hash collision into their database and essentially censor-ship any document he wants.
And finally I do not understand why there has to be protection from working with copyrighted stuff. Most of work I created is copyrighted, nearly every open-source product have copyright.
Even if there would be a movie there, it does not strictly mean it is illegal. Most people have right to create backups of their DVDs. Many jurisdictions allow to create copy for personal use and so on.
By this logic we should shutdown Github and SourceForge, until we "clear up some legal stuff".
However, takedown notices have been abused on YouTube to censor criticism, and dishonestly claim ownership. The problem could be even worse if what it covered wasn't limited to when links are posted publicly, but also covered shares between family members, colleagues, and friends.
While distributing backups from your DVD collection to a colleague may not make sense, and that isn't much better than posting public links, qwerta has a point when it comes to the potential for someone unethical to abuse the system.
I appreciate the challenges Dropbox faces with respect to copyright, and that it is easier to focus on making a viable business if a broad policy wastes less of their time on the issue. However, it's also a complicated when you've given a service read/write access to your hard drive—not necessarily because its reasonable to assume that Dropbox would take a legal risk like proactively deleting content on your computer, but because it's almost an unreasonable amount of trust you're granting them in the first place.
Anyway, maybe you meant, "Not all of your arguments apply to shared files."
"Only when a file is shared from user-to-user (or with the Internet at large) does the DMCA check system come into play"
"Some thought the original file was deleted from the user’s Dropbox — that’s not the case, either. Dropbox just blocks the file from being shared."
Personally I think cloud services are super convenient and the downside for most people is really small.
Uh sure they do. Both legally and morally. It's their servers! Their right to snoop files stored on their servers is quite strong. Your right to store files on someone else's servers is zero. If you would like to pay someone to store your stuff on their servers that is a business deal which can be arranged and the fine print can be negotiated between the two private parties.
You could try negotiating a contract that says you can store your data on their servers but they aren't allowed to look at that data under any circumstances ever.
There are a variety of Dropbox competitors that focus on letting you run the server so you can control the data. If data privacy is of maximum concern, and that is a legitimate thing to be concerned about, then I'd recommend one of those options.
What if it's stored within a government's territorial jurisdiction? Do they have the legal and moral right to snoop?
Why not?
The do. Read the TOS, it's written in perfectly understandable english. If you accepted them, then you have nothing to say.
http://www.daemonology.net/blog/2012-01-19-playing-chicken-w...
Obviously, the sharing and interoperability of Dropbox are key features, but for lots of use cases I'd much prefer technical barriers to policy barriers.
The article claims that technical barriers exist at Dropbox as well, but considering they hold all the encryption keys, and I have to trust they're even encrypting in the first place, any "technical barriers" they erect are really no more assurance than policy.
> We need your permission to do things like hosting Your Stuff, backing it up, and sharing it when you ask us to. Our Services also provide you with features like photo thumbnails, document previews, email organization, easy sorting, editing, sharing and searching. These and other features may require our systems to access, store and scan Your Stuff. You give us permission to do those things, and this permission extends to trusted third parties we work with.
However congenial this sounds, they reserve the right to look at your stuff —— worth noting.
I know that the rights holders haven't been blameless in their history but piracy is still wrong and getting upset about people trying to stop it is wrong.
EDIT: I also think that Dropbox's method of detecting copyrighted files is a perfectly reasonable way of doing it. By now we all (should) know the rights we give up for the convenience we get when using consumer cloud services. I think Dropbox are well within their legal and moral rights to do this.
It is user who has to deal with blocking, false positives and other negative externalities of this. Copyright holders are just passing on their costs to entire society.
Funny speaking about externalities on copyright. The entire purpose is to get rid of externalities.
> Only when a file is shared from user-to-user (or with the Internet at large) does the DMCA check system come into play.
Doing a DMCA takedown on a broadcast share with the whole internet? OK. Fine.
Doing it on a share with a specific other user? Not OK. Bad.
IANAL, but: There are limited exceptions such as fair use. For example if a teacher were sharing copyrighted work with a student or another teacher, that could be appropriate. I think it is inappropriate for Dropbox to prevent an appropriate share like this. Their ToS may allow them to do so, but I'm saying they ought not to do so. I think that's taking it too far.
If you mean we shouldn't do it because it is illegal, that's fine, although personally I don't find that a compelling reason. I think some people here think maybe the copyright laws should be different then they are. Said that way, it isn't unreasonable opinion, compared to "OMG! You think piracy is acceptable!" There's a better level of conversation here: What do they think should be different? Why? Why do you think its wrong? What does wrong even mean in this case?
Care to enlighten us?
Sure, we can debate the merits of intellectual property or property rights or whatever, but it's not really relevant to the parent comment, you are just picking a fight. Few think it's ok for people to just take things that aren't theirs, and few think stealing music is ok either.
> it's not really relevant to the parent comment ... and few think stealing music is ok either.
Maybe I misunderstood the parent comment, but wasn't the poster complaining that so many people on twitter outraged about Dropbox's behavior think privacy is acceptable?
I think a lot of people are unhappy with the current intellectual property law and they feel powerless to influence it. The kind of frustrations that produces the GPL and Creative Commons, although not all of us have the vision, leadership or influence of a Stallman or a Lessig. I suspect some current attitudes about piracy are related to those frustrations. I also think a debate about piracy -- rather than just shouting "It's wrong." -- can be very profitable. I'm reading Adrian John's history of Piracy (highly recommended). From the Introduction:
"Those who were called pirates almost never [took the charaterization at face value]: they always repudiated the label as inaccurate and unjust. The point is that when they did so, they often triggered debates that threw light on major structural issues and had major consequences as a result. We can profit by focusing on precisely these contests -- and the more prolonged, variegated, and ferocious they were, the better. They strained relations between creativity and commercial life, and at critical moments caused them to be reconstituted."
How would I deal with it? To me it's clearly none of Dropbox's business and they shouldn't be doing this in any way, shape, or form.
Actually, it's a core piece of Dropbox's business. One of the ways they save on storage is by comparing hashes of files (or even parts of files - how many bits of any two JPG or DOC files are identical?) being stored and, if identical, only store one copy of the file. That and they explain in plain english that they're allowed to do that. That they explicitly say they do as much in their TOS puts the onus on the user to not store anything they're concerned about the privacy of on Dropbox's servers.
Not that I would know anything about obtaining copyright protected materials in that manner, of course. A friend told me about it, honest...
If I have copyrighted data on my Dropbox folder, and the system detects it, what happens? If I sync the copyrighted data with several of my computers, does that count as sharing?
Yes, I know what hashing is and yes, it seems the original reporter of the DMCA may have shared the file link through email or a website. Still, I need assurance that my data (including the copyrighted ones) will be backed up at Dropbox and available for my use at my leisure, indefinitely -- provided I don't "share" them in any public way.
Side note: all of my data on Dropbox is encrypted by a separate system, so it's unlikely that I'll be affected, but I still am interested in the issue.
Encoding an mp3 is not a deterministic process. So if multiple people start with the same .wav file ripped from a CD (which itself may introduce errors) and then downcode it, they will end up with files which sound the same but are slightly different (and therefore hash differently).
So, it should be straightforward to test whether Dropbox does anything more sophisticated than what's described in the article.
If I had a copyrighted ebook and changed a single "o" to "0" I bet I could still be busted for distributing it (although it appears Dropbox would no longer automatically catch me). But what if I changed every single "o" to a "0"? Re-arranged words? Chapters? Upcased every lowercase letter?
My guess is that's it's based around "intent" which is hard to quantify, but it's still interesting to ponder.
Teachers can generally copy something to use in class as an example. However, they may not copy the same content every year after that. Same action, but slightly different context.
Fun to think about, though. Especially if you start thinking about writing alternate endings, etc.
Now, if users provide their own key and it's never transmitted, that would be secure, but obviously the data would be un-decryptable if the key is lost.
Right now if you forget your login/password your account is lost unrecoverably. We have a feature slated that would let you download a file version of your account key, meaning if you lost your username or password, you could log in with the special key file and reset your info. Obviously, you'd have to keep the file encrypted/safe, but that's the user's responsibility ultimately.
Of course it does seem that anyone can abuse the DMCA with impunity, so strictly speaking this wouldn't stop the "notice and takedown" actions. It would however prevent the automated detection and might increase cost and difficulty for copyright complainers.