Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I love dropbox. Dropbox + git is beautiful as is Dropbox + markdown (for writing).

But I don't pay for it. I'm somewhere around 5+ free gigs of which I might use around 30%. Normally if I loved a product this much which I wasn't paying for, but ought to, then I would. But I'm not stealing my account, so I don't really feel like I should pay.

On top of that, I use a different paid service for storing large amounts of files. It ends up being cheaper and I feel both solutions work best how I have them - dropbox for sharing/working and the other for offsite backups that just transparently syncs every night or something.

I guess all that to ask a question...how the heck is dropbox making money? Between the amount of free storage they give and the fact that there are much cheaper remote backup solutions, I just feel like I'm missing something.



Free storage that they allocate but that you don't actually use costs epsilon more than nothing at all at the margin. The part you do actually use costs them about 10 cents a month on Amazon's published pricing, and one could reasonably assume they have a better deal than publicly available. At a buck a year and what I make out to be a viral factor of something like 20, you're approximately the cheapest cost of customer acquisition ever. (If that worked for my business at scale I would be rolling in it, and my LTV is much lower than Dropbox's is.)

How they make money is fairly simple: use you as a customer acquisition channel to get people who have money using the service. Charge those people many, many times what servicing them actually costs. Does it matter if there are cheaper options? Pfft, no. There are cheaper caffeine delivery vehicles than Starbucks coffee, but since people don't choose coffee primarily based on price, if they hook one more weekday latte drinker that gets them a LTV of several thousand bucks at a margin of ZOINKS%. Dropbox isn't Starbucks, but their unit economics can be reasonably assumed to be "quite favorable indeed."


Try to find a large popular file (a movie or mp3 file downed from the net for instance) and put it in your dropbox folder. Notice that it'll sync almost instantly. When you put a file in your dropbox they calculate a checksum and see if they already have the file somewhere. If they do they just add a pointer instead of having two copies lying around.

Since many large files are saved by a lot of people individually (movies, mp3 files, pdf manuals, etc) this saves them a lot of space. As they get more users this advantage grows.


Is this exploitable in some odd way?

What if I wanted to use Dropbox for piracy purposes (I don't, just using an easy to understand model). Could I upload a copy of Avatar.mp4, compute or find the checksum for it, and then distribute just that checksum to other users? Or distribute a file that wasn't Avatar.mp4, but looked like it to the Dropbox client? Would this effectively trick the Dropbox servers into distributing the file for more, so that I could legitimately claim to not be distributing copyrighted material, but just distributing a "magic" file that caused Dropbox to give me a copyrighted file that someone else had uploaded?


Or distribute a file that wasn't Avatar.mp4, but looked like it to the Dropbox client?

Modern hashing algorithms make this practically impossible, sorry.

Just because you have a hash string that's not technically a copyrighted film, you could still be guilty of copyright infringement. cf. http://ansuz.sooke.bc.ca/entry/23


Thanks. I was using the film distribution as a simple example, but that wasn't the exact use case I had in mind.


If they're using a decent hash algo, manufacturing a collision should be somewhat difficult and I'm really not sure how you could use it as a believable legal defense later.


It's smart. We did the same thing with MagicWaiter back in the day. Saved a TON of space!


Are you sure about this? if so is it good practice?


I observed it from my own usage, and I'm hard pressed to see any alternative.

I don't see how it shouldn't be good practice. The only information you're potentially giving away is that someone else that has a dropbox is in possession of the same file as you.


If I were the RIAA or MPAA, this seems to leak enough information to confirm that my copyrighted material is stored on dropbox, which might be enough to get a subpeona issued.

If dropbox client were to still force the upload to happen, and only discard the object afterwards, this "duplicate file exists" information wouldn't be leaked. Presumably, they want to detect duplicates within an account and avoid the transfer in that case in the interest of user experience, but if I've told dropbox to upload avatar, I'm presumably OK with the transfer happening, even if it's not strictly needed because someone else has already uploaded it.


Dropbox is selling convenience. For many, Dropbox's featureset and ease of use are worth the price premium over similar services in the space.


They make money from subscribers like me. It's just so damn convenient that I had to send them some money - and it just so happens that I exceed the basic amount of space, so it was easily justifiable.


I've always used less than a gig so I never had to pay. I hope they never do start turning the cranks cause I'd definitely start paying if they forced me to.


What is the other backup solution you mention?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: