Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Welcome to the cloud!(tm)"

Some heuristics for evasion of the observed colateral damage scenario:

* Store your files in several places. For example use Dropbox and link two machines with it. One at home and your laptop maybe.

* Rent a cheap vserver and install your own URL-Shortener (http://freecode.com/search?q=url+shortener&submit=Search)

* For files you'd like to distribute, put them into the Dropbox public folder. Generate your own short links with your own shortener.

* distribute the shortened links

* If Dropbox goes down, copy files to other webspace. Adjust URL-Shortener entries to new location.

If you don't trust Dropbox or any other file storage service, rent some webspace and sync your files there. There are a couple of 'How to build your own OpenSource Dropbox clone' recipies out there. (https://duckduckgo.com/?q=dropbox+clone). AFAIR they all suck in different regards. Simply choose the one that does the job and sucks least.

If you are not capable of doing stuff like that, then contact your friendly neighbourhood tech collective. Where to find them? Start here: http://www.hackerspaces.org . Don't ask them to do stuff for you. Ask them to teach you how to do it. Then donate. DONATE!? Yes, donate. And remember, with all the commercial services you have been cheapsurfing on, if you are not paying for it, then you are not the customer, but the product.

The interwebs have offered us the opportunity of an empowered, self organized distributed digital information society. But alas! we lazy bums are opting for the cheap consumerism solution. And on top we are whining and sobbing, when the freebies are being taken away from us.

I have little compassion for people who store their files in the cloud only.

/rant



You're not wrong, Walter.

On the other hand, one of the reasons Normal People dislike the hacker community is the prevalence of "see I told you so" and/or "bad things wouldn't happen to you if you weren't such a dumbass" culture.

The fact that a technical workaround exists for this particular brand of destructive and capricious behavior by the U.S. Federales is not, in itself, a great reason to transform the story into Yet Another Personal I.T. Teaching Moment.

The safety deposit box example is apt here. If my local bank gets busted for some shady-ass shit, and the Feds confiscate some family heirloom along with all the bricks of heroin from the bank vault, what should we demand from our government in that case?

And if we're not likely to get what we feel entitled to demand, what are our realistic options for doing something about that?


The Libertarian community has been on top pf this sort of thing for decades and would surely be able to offer a lot of "see I told you so" as well. Remember that analogy about how people said SOPA provisions were like shutting down the Ritz Carlton because occasionally politicians cheated on their wives there? Take away a few layers of class, and there have been some motels that the government has seized (or tried to sieze) because occasionally tenants would do drug deals there.

A handy article on the topic that was easy for me to find: http://reason.com/archives/2010/01/26/the-forfeiture-racket/...

In short, don't hold your breath waiting for your data to come back.


> The Libertarian community

Note for the future: This adds no value to your comment, and makes you look like you're trying to spin this story in someway to benefit your political alignment.


It's a shout-out to the parent poster's use of the phrase "the hacker community" and its own attendant "I-told-you-so"-ism (which I'm pretty sure is construed as a negative). It's a community I personally completely identify with but I've read some of their work and respect certain parts of it. Here, let me write a 50-page essay on the minutae of my political views, that'll be real interesting reading for the HN people.

cut me some slack, jack.


somehow i dropped the words 'not' out of 'a community i personally completely identify with'. I blame acute lack of caffeine. my shipment of Tonx coffee was delayed 2 days on account of MLK day and the local postal worker.

my apologies.


Gee, maybe that's because some "political alignments" are substantially better than others when it comes to this sort of issue.


I would have just pointed out that the phrase "Libertarian community" is an oxymoron, heh.


The cops at various levels do this kind of thing all the time. Let's say you shoot someone breaking into your house. Let's say it's a clean shoot - the guy was a serial killer (or whatever) and you're 100% inside the bounds of the law. The cops show up and take your gun. "We'll give it back after the investigation," they say.

Time stretches on. They investigate. The DA agrees it's a clean shoot and declines to file any charges. It's been 18 months. You ask for your gun back.

"No," they explain. And that's... all, pretty much. They have no legal right to keep it. They offer no explanation. You can always spend ten grand suing over an item worth less than $1000, but you won't and they know it.

So if you had files at Megaupload, even though (I think we agree) you have a perfect right to expect the feds to return your property, you probably shouldn't actually expect them to do so.


I don't get this. We're* quick to shoot down any arguments which equate online piracy to real world piracy, but when it's "our" files which are affected, we're quick to go back to the online-real world analogies.

*"We" might not include you, OP, so apologies. Not directed at you. Just noticing a trend.


After the countless threads about this topic, I don't get how the distinction between copying bits and deprivation of property isn't clear. If the FBI mirrored megaupload's entire data store (ala piracy), none of those tweets would exist and most people wouldn't even be aware anything happened (since copying a sequence of ones and zeroes has no quantifiable impact on one's property). I'm not defending megaupload for copyright infringement, but your allusion to hypocrisy makes no sense since these people are being denied access to their legal IP.


Probably because we* have stupendously weaker protection of our data than pirated-content-providers, be it in the form of multiple backups or the quality of the hosting. When MegaUpload went down, I doubt any software companies lost their only copies of what they were building, or any music groups completely lost their albums. An Average User™ with files on MU though...

*"we" intentionally including non-tech-savvy people.


If they don't have a copy of the file any more and their last copy is taken, it's quite a bit different than if the Feds made a copy of their files.


"If my local bank gets busted for some shady-ass shit"

Except that you will probably not put your money in a bank that's widely known for being a drug dealers haven, will you?

I also am not a big fan of the "see I told you" attitude, but it seems to me that no sane person would ever put some valuable/important things on megaupload.

Of course there is not guarantee that services like icloud or dropbox will never get shut down, but they do look much more reliable than megaupload..


As others have said, "widely known" is an awfully big assumption to be granting yourself with no argument. There is a wide gulf between a user expected to competently interact with a web front end, per the features and cost/benefit directly expressed by that front end, and a user who is expected to evaluate (on what basis, exactly?) the probability with which a given Company/Ownership is likely to be obliterated by fiat.

What's worse, HN readership is arguably an upper-crust-of-savvy environment for making that sort of appeal, but imagine:

- two weeks ago, someone offers HN readers $100 bets that megaupload will get raided / shuttered / data frozen in the next two weeks

- if you take the bet, and you win (megaupload raided), you get $200 back

- if megaupload doesn't get raided, you get $90 back (i.e. you pay as much for losing the bet as a megaupload user pays to access to service)

Do you honestly think more than 10% of HN readership would have taken the bet and tried to double their money? Or would the "smart money" (and again, some of the smartest money available on the internet) been on megaupload staying up and available?


You're right, my apologies for going overboard with a non-justified argument. When I succeed in looking further than my tech-savvy like-minded friends, I fall into the trap of thinking about other people about my age.

I don't know about you, but my facebook stream has been polluted with dozens of messages crying over what happened to megaupload (and not because they had there work uploaded on it), which (wrongly, I know admit) let me to think that everybody knew about megaupload shadiness.

Now as you and others rightly pointed out, I forgot about the rest, maybe the majority of people who used in a totally legal way.

Anyway, point taken !


no sane person would ever put some valuable/important things on megaupload

How do we explain to sane, but non-internet-savvy, people what rules they should use to tell "safe" places to store their data from "unsafe" ones.

Megaupload took pains to not show infringing content on their home page and they did not provide a search engine that would return it. I'd ended up at the site several times and, though it set off a few of my red flags, I can't really explain why.


Simple.

File in two widely separated places: pretty safe

File in three widely separated places: safe

File in only one place, no matter where it is: unsafe


This is what I usually tell non-tech-savy people to do. "Remember to make backups" seems to be too abstract and thus they tend to procrastinate the "make backup" topic away.

"Copy your important stuff to at least one other place, be it an external hard disk, a USB-Stick, a DVD or an online storage service."

And then I usually configure Dropbox for them and show them how to use it. And I tell them not to put sensitive information like online banking PINs on there. And tell them that I can also show them a way to further secure the data with TrueCrypt.

But some are even resistant to this. I don't bother pushing them, because I know they will lose data at some point. When that happens I "told you so" them once and after having a good laugh at their dangling unmentionables I help them setting up backup/redundant storage.


A great answer...but to a slightly different question.

Which, I think, confirms my suspicion that with both financial institutions and websites it's probably impossible to explain to nonexperts how to judge their credibility.


Except that you will probably not put your money in a bank that's widely known for being a drug dealers haven, will you?

Yes. No one would ever use Wells Fargo now, would they?

(If you didn't get the reference: http://www.guardian.co.uk/world/2011/apr/03/us-bank-mexico-d... )


I think you overestimate the "common" knowledge that Megupload is used for illegal file sharing. I can bet you that 90% of my parents' friends have no idea.


And remember, with all the commercial services you have been cheapsurfing on, if you are not paying for it, then you are not the customer, but the product.

I need to print T-shirts with this quote.


Sometimes you're both (see magazines)


Also realize that Dropbox's architecture leaves an evidentiary trail - nothing is ever actually deleted from your account. If you upload anything copyrighted, you have opened yourself up to the possibility of being sued or prosecuted for copyright infringement. For most, that's a minuscule chance, but it exists and you have no ability to delete your history - http://forums.dropbox.com/topic.php?id=48975


Dropbox has builtin 30 day history for everyone, through the web interface. You're saying they keep track of things indefinitely (when you haven't purchased that addon)? Do you have a citation for that?


Yes you can. If you delete an item from your Dropbox you can see it by choosing "Show deleted files" from here you can choose to permanently delete the file. In my testing this also removes any trace of the file ever being created from Events. While Dropbox certainly could be keeping an undeletable log of everything you ever upload, there is no evidence that they are doing so.


While Dropbox certainly could be keeping an undeletable log of everything you ever upload, there is no evidence that they are doing so.

It is safer to assume that they are than to assume they are not. Maybe they got an NSL with a gag order that requires them to silently store logs indefinitely. There's no way of knowing, so just assume that's the case and plan accordingly (e.g. don't upload embarrassing college photos that would cause you problems if the upload logs were hacked and released to the public).


Yes.

In Germany it is allowed to make a small number of copies for friends and family (Privatkopie). So if I transfer a song to DB for a friend, the evidentary trail will also show that the file has only been downloaded very few time, which is legal.


Wow, that's actually a very nice law. And yet, despite reading a bunch of threads about copyright, this is the first time I've run into it. I wonder why something like this doesn't get brought up more often.


Of course the copyright industry is trying to kill this law and is undermining it by running ads that constantly repeat that copying is illegal. Lots of people in Germany have no idea that they are legally allowed to make a small number of copies (up to seven) for personal purposes.

It is even allowed to make a copy of a copy. So if I recieve a song from a friend, I am allowed to give it to a couple of my friends. But I am not allowed to simply seed it to strangers through anonymous filesharing.

Translation of the german wikipedia entry on "Privatkopie": http://translate.google.com/#de|en|https%3A%2F%2Fde.wikipedi...


"I have little compassion for people who store their files in the cloud only."

That's all well and good, but what about the other 95% of the population that just want to pay someone to host their files?

Why should consumers have to know the best technical solution? All they want is to pay for a solution to a problem.


You can change your last sentence to be about anything a consumer buys though.

"Why should consumers have to know the healthy food? All they want is to pay for a solution to their hunger."

"Why should consumers have to know which cars have good gas mileage? All they want is to pay for a form of transport."

Because there are advantages to consumers in being knowledgeable about what they buy. Like knowing your cloud storage isn't (and can never be) perfectly reliable.


I don't care how cars work, I trust the mechanic to fix the problem.

I don't care how the financial markets work - I trust my 401k to pay for my retirement.

Life is far too short for me to want to know about things that don't interest me. One of the points of an advanced society is that we can pay people to do things for us.

People shouldn't have to second guess every professional service they use. Maybe it's time to add legal guarantees to the cloud?


"Maybe it's time to add legal guarantees to the cloud?"

So... Lets make it illegal for a site to lose your data by being shut down by the FBI? Seriously though, is it really a good idea to make more (artificial and unsolvable) problems for cloud service providers to worry about?


Better idea: Lets make it illegal for FBI to lose your data by shutting down a site.


that's alright, but don't whine when your car breaks down in the middle of a desert or you find out you're below poverty when retired.


If I was driving in the desert, of course I would learn how to fix a car. You might as well have said, "if you go scuba diving don't whine if you get decompression sickness while surfacing". What a really bad analogy.

Where do you draw the line? Do you make your own yoghurt? What about milk your own cows? I very much doubt you do that. My time is valuable enough that I'm comfortable paying people to do these things for me.

If person A offers a service to person B, there needs to be some level of trust and expectation. In this instance, the government is responsible for destroying people's assets and I hope they get sued to oblivion for screwing up. Other times, companies are at fault.

Gotta love the Libertarian mindset that appears to prevail here. Sheesh.


My time is valuable enough that I'm comfortable paying people to do these things for me.

I think it's still worthwhile to have a superficial understanding of the services you buy, as this allows you to maximize the value of your dollar and avoid getting fleeced.


They're not going to be able to get around the fact that the third-party they're entrusting their files to don't care about their data as much as they do. Its not a technology problem. You could pay more for a service that has a contract with an SLA, but all that does is give you legal recourse if they do lose your data. It doesn't mean that they're actually protecting it.

Today it was the Feds. Tomorrow, it could just be a poorly run company going out of business. Or a massive failure in a technology stack without redundancy. Consumers can't reasonably predict these sorts of thing, so the only reasonable course of action is to keep redundant copies of your data. Use SpiderOak and sync a few computers. Get an External HD.

So what the consumer should take away is that they shouldn't trust a third-party with the only copy of their unrecoverable data. The fact that they don't want to care doesn't mean that they shouldn't or that they can actually not care.


Welcome to the cloud indeed. And what we discovered that just coping data to your home computer in a format which can be used back in some other cloud services is gettings harder and harder as virtualization of data and information increases. And you need to upload all that data again...

So the right solution is to have your (important) data replicated in a couple of different cloud services (Google Docs replicated with Dropbox, etc.).

That is reason I started cloudHQ: just sync and replicate data between cloud services in real time. Nothing sexy: but fast and reliable.


Use personal cloud devices like TonidoPlug. Allows you to keep copies both local and public cloud: still you can access from anywhere.


Why use a shortener at all? All it seems to get you is another point of failure.


Because if you use your own shortener, then you can switch the storage without breaking the links. And using you own domain and service gives you control.

Obviously this only works when you use your own personal URL-Shortener and not one of the ubiqious cost free shortening services like bit.ly et.al.


This is not a welcome to the cloud, this is a welcome to the crappy legislature. Dropbox provides 2gb free, how much time will it take to have a megaupload v0.2?


Cloud storage providers can go down for different reasons. Crappy legislature is one of them. If you entrust your valuable data exclusively to one provider without having copies and/or backups somewhere else, you are doing it wrong.


I agree. It's 2012 for God's sake, How times do you have to see the commercials and ads about not backing your stuff up before you get a clue?? I would also add if you think using shady file serving companies to store your legitimate files is a good idea, then you're also doing it wrong.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: