Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually, I think you're missing the point.

1. People seem to want to use Dropbox to store sensitive, private data. Most sensible people don't trust AT&T, Facebook, Microsoft, etc. for this purpose anymore because of their past gaffes.

2. Dropbox makes numerous "marketing" statements all over their site purporting to be safe for confidential, private information.

3. The licenses that companies need in their TOS can be scoped appropriately to what's strictly necessary for them to provide you the service you signed up for. Companies that reserve rights in their users' stuff beyond what's necessary do so for a reason – and it's not likely to be in the user's interest.



You've evaded this person's comment, possibly because it doesn't fit a point you want to make.

The comment you're responding to says, "Legally, any service that does the basic things we expect Dropbox to do for us probably needs to have these terms in place. The point raised about not trusting Dropbox after an AT&T acquisition is irrelevant; every large company already has those terms, because they have to."

You can want to trust Dropbox more than Microsoft, but that doesn't change the legal landscape.

Your third point comes closest to actually addressing the discussion here, but how do they scope their ToS narrowly enough to satisfy you? And how do they then do that without having to then announce ToS changes every time they add a new feature?


I don't think I've evaded the comment at all.

1. The issue is the scope of the license.

2. The overly-broad scope chosen by Dropbox (and many others) is a valid reason to question their trustworthiness as a custodian of sensitive private information.

3. In the case of AT&T, Facebook, etc., we have a history of actual disclosure incidents to draw from, adding some context to their trustworthiness. In fact, Dropbox itself has joined that club, with their recent security gaffe and their handling of it, and statements surrounding it.

4. As I say in a few places around this thread, I think the correct scope of the license would be strictly what's required to carry out the user's instructions. At the very least, it should be limited to uses that are in the user's interest, not the interest of Dropbox or a third party.

EDIT: I said "overly-broad scope chosen by Dropbox" above in error. In fact, I think the Dropbox TOS is dead-on in terms of the scope of the license. As far as I can tell, it's limited to what they need in order to "do what you ask us to do with your stuff (for example, hosting, making public, or sharing your files)".

(This post is information only, is not intended as legal advice or to create an attorney-client relationship.)


This reads like a smokescreen. If providers need these licensing terms to safely provide this service, then they either need to post them or get out of this business. "Actual history of disclosure incidents" and "trustworthiness" simply don't have anything to do with it.

If you're a lawyer, it would be helpful if you could just straight-up answer the question, which I'll restate for you: what are specific things Dropbox could do to their ToS to scope it down without making the ToS so narrow they can't introduce new features without constantly revising it?


I'm not sure why you're being so cranky about this. I'm doing my best to be as clear as possible.

1. The Dropbox license is scoped correctly, IMO. It's as narrow as it should be, and not so narrow that it would impair their ability to provide the service.

2. All commercial relationships come down to trust. Contracts only take you so far. If a provider offers acceptable contract terms, but has also shown signs of incompetence or untrustworthiness, I would avoid them. After all, how likely are you to enforce the contract terms against them?

HTH – and again – this is not intended to be legal advice or to create an attorney-client relationship.


I'm confused. Upthread, you said (paraphrased) "companies that reserve rights beyond what's absolutely necessary tend not to be doing this in their users best interests". You didn't then qualify this with "but of course that's not what Dropbox is doing".

Maybe we just agree about Dropbox --- that this latest ToS karfluffle is just a banal legal/administrative thing, not evidence of any cavalier attitude at Dropbox about user data.


We do agree. I also agree that my comment above was a little misleading. That's because the OP's article quotes a version of the Dropbox TOS that isn't the current version anymore, apparently.

Sorry for the confusion!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: