Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When the new TOS were announced I think a lot of balked at reading those statements. The examples given in the TOS (e.g. "to convert your files") all seem reasonable, but as Indyan pointed out, it sure leaves the door open to some fuzzy interpretations.

Quick question, if AT&T suddenly bought Dropbox, would you all feel as passive about the new TOS or be quick to get your files out of there?

What about Facebook? Microsoft? or Silver Lake Partners?

I understand it's easier for Dropbox to be vague in their TOS so they don't have to spell out the service or future features that might require expanded agreements.... but given the nature of the service and the previous fiascos Dropbox has had already this year, it sure seems like they are cutting themselves some undeserved slack with regards to specificity.

I appreciate that they rewrote the terms to be more human readable, but why not spell out "You agree to let us duplicate, read and write your files in the case where you share, copy, publish or convert your files via the web or client software interface" -- or something following that.

I don't have a company with 200 million users though, so maybe the logistics of being that specific are an impossibility. I'd also be a lot more forgiving of this broad language if Dropbox has never had any hickups, so my personal nervousness is mixed in there.



You are missing the point.

Those companies do have similar terms in their agreements! Any service that accepts user content should. It's in everyone's benefit to make it clear that you own your content, but you're giving the service a license to copy it, display it, etc.

AT&T: "while you retain any and all of your lawfully owned rights in such Content, you grant AT&T a royalty-free, perpetual, irrevocable, non-exclusive and fully sublicensable right and license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display..."

Facebook: "you grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook"


Actually, I think you're missing the point.

1. People seem to want to use Dropbox to store sensitive, private data. Most sensible people don't trust AT&T, Facebook, Microsoft, etc. for this purpose anymore because of their past gaffes.

2. Dropbox makes numerous "marketing" statements all over their site purporting to be safe for confidential, private information.

3. The licenses that companies need in their TOS can be scoped appropriately to what's strictly necessary for them to provide you the service you signed up for. Companies that reserve rights in their users' stuff beyond what's necessary do so for a reason – and it's not likely to be in the user's interest.


You've evaded this person's comment, possibly because it doesn't fit a point you want to make.

The comment you're responding to says, "Legally, any service that does the basic things we expect Dropbox to do for us probably needs to have these terms in place. The point raised about not trusting Dropbox after an AT&T acquisition is irrelevant; every large company already has those terms, because they have to."

You can want to trust Dropbox more than Microsoft, but that doesn't change the legal landscape.

Your third point comes closest to actually addressing the discussion here, but how do they scope their ToS narrowly enough to satisfy you? And how do they then do that without having to then announce ToS changes every time they add a new feature?


I don't think I've evaded the comment at all.

1. The issue is the scope of the license.

2. The overly-broad scope chosen by Dropbox (and many others) is a valid reason to question their trustworthiness as a custodian of sensitive private information.

3. In the case of AT&T, Facebook, etc., we have a history of actual disclosure incidents to draw from, adding some context to their trustworthiness. In fact, Dropbox itself has joined that club, with their recent security gaffe and their handling of it, and statements surrounding it.

4. As I say in a few places around this thread, I think the correct scope of the license would be strictly what's required to carry out the user's instructions. At the very least, it should be limited to uses that are in the user's interest, not the interest of Dropbox or a third party.

EDIT: I said "overly-broad scope chosen by Dropbox" above in error. In fact, I think the Dropbox TOS is dead-on in terms of the scope of the license. As far as I can tell, it's limited to what they need in order to "do what you ask us to do with your stuff (for example, hosting, making public, or sharing your files)".

(This post is information only, is not intended as legal advice or to create an attorney-client relationship.)


This reads like a smokescreen. If providers need these licensing terms to safely provide this service, then they either need to post them or get out of this business. "Actual history of disclosure incidents" and "trustworthiness" simply don't have anything to do with it.

If you're a lawyer, it would be helpful if you could just straight-up answer the question, which I'll restate for you: what are specific things Dropbox could do to their ToS to scope it down without making the ToS so narrow they can't introduce new features without constantly revising it?


I'm not sure why you're being so cranky about this. I'm doing my best to be as clear as possible.

1. The Dropbox license is scoped correctly, IMO. It's as narrow as it should be, and not so narrow that it would impair their ability to provide the service.

2. All commercial relationships come down to trust. Contracts only take you so far. If a provider offers acceptable contract terms, but has also shown signs of incompetence or untrustworthiness, I would avoid them. After all, how likely are you to enforce the contract terms against them?

HTH – and again – this is not intended to be legal advice or to create an attorney-client relationship.


I'm confused. Upthread, you said (paraphrased) "companies that reserve rights beyond what's absolutely necessary tend not to be doing this in their users best interests". You didn't then qualify this with "but of course that's not what Dropbox is doing".

Maybe we just agree about Dropbox --- that this latest ToS karfluffle is just a banal legal/administrative thing, not evidence of any cavalier attitude at Dropbox about user data.


We do agree. I also agree that my comment above was a little misleading. That's because the OP's article quotes a version of the Dropbox TOS that isn't the current version anymore, apparently.

Sorry for the confusion!


Eli, no where did I say those companies don't have similar TOS, I was trying (badly?) to make the point that while some of the commenters below (and folks on Slashdot) wave-away concern over the open-endedness of Dropbox's TOS because the company isn't seen as evil, if we suddenly put a different company in charge of their data, do those folks suddenly have problems with the TOS?

If they did, then I was suggesting that the TOS could use improvement (tightening of terms) to better clarify what is happening to the data you are putting up there.

For example, given a TOS that is sufficiently well specified with regard to what rights are owned in what scenarios, etc... I wouldn't care which company had my data if the TOS protected me enough (let's wave-away the discussion of enforcement here) where as with open-ended TOS's, my level of OK'ness with it is directly tied to the company holding my data and their behavior more than anything.

To me, that suggests that TOSs could benefit from some user-favoring tweaks and clarifications, especially if the company doesn't need the wide birth they have written in for themselves for particular reason.

To address the followup question of amending the TOSs every time a new feature ships, sure on the other extreme end of the spectrum this would be a problem; I'm suggesting something more strict than we have now, but not so strict it's ridiculous.


The irrevokable nature of the licence is important.

If you leave facebook, you can revoke the licence for them to use your images. Ditto if you post an image on facebook then later delete it.


See, I wouldn't trust say my source code to AT&T or Facebook. I already get a fishy feeling with them having some of my pictures.

Drop Box on the other hand is a private data storage service (at least I thought they were) - where I expect to be confident with them having my sensible data. Such TOS additions are just undermining any trust I might still have to them (after their "encryption" and password fiasco).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: