I uploaded a legit Office ISO I downloaded from MSDN to SkyDrive (as it was called back then) to test throughput up and down.
After 3-4 hours it was gone.
My data isn't going near it.
Edit: just to clarify... I think they hash incoming files and delete known ones as part of a takedown system. This was an ISO that had been shared on TPB as well as MSDN. Of course their policy allows these measures but I'm not happy putting something up there on the basis that they can arbitrarily delete it.
Hey pling, I work on the OneDrive team. We definitely don't do the type of content scanning that you're describing. I wouldn't be comfortable with that. The only time we currently use file hashes for automated takedown is when known child pornography is re-uploaded to the service after being reported.
For copyrighted content, we have to respond to DMCA notices like other services. Sharing content to the public and getting reported by a third party is the only path for that. And in those cases, you definitely get a specific notice about the takedown. The web UI would also show you exactly which file was affected, and prevent you from sharing it again. It doesn't just delete files. (That would be unacceptable.)
Note that there's currently a 2 GB file size limit. It seems like the most likely explanation is that you put a large ISO in your SkyDrive folder, and it never succeeded in uploading because it exceeded the limit.
The file was 600Mbish. It successfully uploaded via the desktop client then was later downloaded on another machine via the desktop sync thing. Later that evening it was gone. I didn't delete it (it wasn't in the recycle bin) and I confirmed it was the correct live account I was signed in as. To be clear it was still on the source machine but not the destination. No antivirus had quarantined at either end.
That by elimination would suggest that either:
1. There is a reliability limit somewhere which is unknown and unpublished or a synchronisation bug.
2. You're unaware of a process or a false positive.
I should have opened another account to test this against with the same file but to be honest if I found a bug, windows live support has been abysmal. Hell they couldn't even work out how to close my account when the close account page refused to work...
Yuck. Sorry that you had a bad experience. It sounds like you hit a nasty sync bug on the destination machine. We've been patching a bunch of issues with client sync reliability over the last year. It's hard to diagnose at this point, but please reach out if you can reproduce it on the current version.
FWIW, I can say with confidence that your issue had nothing to do with the fact that the file was an Office ISO.
There are 3 processes: PhotoDNA hashing [1], automated flesh tone detection, and manual review.
1. PhotoDNA runs on every upload. It's only used to identify known child pornography that has already been reported, to make sure it can't be re-uploaded.
2. Automated flesh tone detection only runs when a photo is shared. (This is a change in policy; it used to run on upload.) There are heuristics that try to measure whether it's personal sharing or broad sharing, and we're continually improving those. The goal is to make flesh tone detection only run during broad sharing.
3. If the broad sharing criteria is met and automated flesh tone detection triggers a positive result, that is the only case in which an item is anonymously sent to manual review. It's some highly controlled clean-room environment where a dedicated team tries to determine whether the content is a legal risk or not. Clear cases of shared child exploitation porn are reported. (A parent's "baby in bathtub" type of photos are not the target here.) In most cases, it's adult pornography or family photos. In those cases, the folder is marked as porn and simply can't be shared again. (There's a user-visible message on the web UI.) It's not deleted, and it continues to be fully accessible to the owner across all machines.
The scanning policy used to be more aggressive and didn't exclude content that was unshared or only shared to a small set of people. None of us liked that policy to begin with, and then some high-profile false positives helped force the policy to be revised.
I keep reading that OneDrive lets users upload adult porn either through here, or reddit AMAs, etc.
However, the terms that are linked to me at the bottom of OneDrive.com specifically tell me that uploading porn is not allowed and presumably (haven;t double checked) tell me that if I do my MSA will be deactivated.
It's nice to have you and co. tell me that you allow porn, but the fact that the terms I legally agree to contradict what you say sort of puts me in an uncomfortable position.
Have you thought about changing the terms of use to accurately reflect your policies?
Why don't you encrypt those pictures before getting them out of your control on the "cloud"? I would extend this suggestion to every other file but those in particular kind of scary me to be available somewhere else without encryption.
Might be a dumb question ("have you tried restarting your computer?") but does the ISO come up through the web browser at onedrive.com? You only mentioned checking the sync folders.
They really need to increase the maximum file size to be competitive. As a comparison, Dropbox files can be up to 10 GB each[0], and Google Drive files can be up to 1 TB each[1].
Its disingenuous to say that Dropbox has a file size limit of 10GB, when the first thing written on that page you cited says otherwise... The 10GB limit only applies to files uploaded through the web interface. Files uploaded through the OS/mobile client have no file size restriction. [0]
Last year a friend couple uploaded photos of their one-year son (I understand it were those "bathtub photos" parents like taking to embarrass the children when they grow up) just to get their paid account blocked. They panicked because they used Skydrive to "securely" store lot of pictures, including their travels, honeymoon, etc. The husband was a bit tech-savvy, but I failed to convince him to always PGP-encrypt the files and rename them to non-significative names before uploading. At least, I made them never trust these services again.
I, personally, never use these file storage services to hold anything but encrypted data assuming that such data can disappear overnight without any warning.
Hmm what you describe conflicts with what u/m0dest mentioned above. I'd like to hear word from him/her about the matter. If your friend's content wasn't shared, the the image must have been someone processed for known nudity patterns
I suppose Microsoft started using some fuzzy/NN/heuristic/etc. pattern matching algorithm to identify pornography, so it caught the photos my friends uploaded even if they didn't came from a know database.
I just use GnuPG with some specific temporary keys (eg. "Project P File Transfer Key"). All transfer are among desktop/laptop machines, so mobile apps are not a requirement. And I don't use GDrive to sync data to my phone.
I wasn't sharing it. To be honest if they're checking for CP then they're messing with your files. There isn't a sudden distinction when you bring in "think of the children"...
I think there's a clear distinction between possessing child porn, which is illegal and subject to a jail term, and so-called "piracy", which is a civil dispute.
There are very few digital things that are illegal to possess (and no, a digital copy of The Matrix is not illegal to possess), and I believe Microsoft has both a legal and moral obligation to ensure the files on its servers are not child porn.
Putting aside the obligation(s), the mere fact they (and to be fair, likely other clouds) have an automated deletion process for unwanted content reduces their reliability. There may be bugs, possibly poor hash distributions, malicious misreporting, erroneous classifications, or misappropriation of the tool for other purposes.
I don't think this measure is effective (it's trivial even for non-techies to circumvent hash-based detection) nor proportional to the likely incidence/impact of this crime. While I cannot speak to what their legal obligations are, I don't think we should encourage invasion of privacy for no particularly good reason. As such, I strongly object to the notion they have a moral obligation to commit this particular harm. Facetiously claiming that doing so somehow protects children is just a joke in particularly bad taste.
Child porn is a "everything must be done against it" topic and while that is what should be done, it means that it makes a perfect "no arguments against it" argument for snooping.
But it is my belief that file hosters have a legal and moral obligation not to know what they are hosting for their customers. It is not the obligation of a host to look at a customer's files and decide what is ok and what is not. It is the same thing with Tor nodes or if you decide to encrypt files. I actually think that any online sync host like this or like Dropbox should not have any chance of knowing what I store with them. That's my private business and there is zero reason for them to know, is there?
Your belief doesn't have any grounds on reality and/or current laws. Once notified of child pornography, Microsoft cannot keep that content stored in its network. Period. Otherwise the next request they will get from a judge is to close the service down.
I actually think that any online sync host like this or like Dropbox should not have any chance of knowing what I store with them
Cryptography is readily available to anyone who cares to use it.
1. It doesn't sound like anyone is "notifying" Microsoft in any way. They're almost certainly just using the NCMEC hash set (which they helped develop) to identify known images.
2. You ought to provide some kind of legal citation for your claim that a judge can order a service like Onedrive to shut down after just two allegations of illegal content.
Truecrypt is far from done. But wouldn't be the fact that it's open source be enough for you to deem it trust worthy? Of course not, as recent events have demonstrated.
Although we all have reason to believe every single encryption tool out there is compromised, where does that leave us? Paralyzed. IMHO, we won't have 100% trustworthy software ever and we're better off using what we have then not using anything at all. Remember, in this thread we're talking about our privacy, not some top-secret project for which developing a encryption tool from scratch would be affordable (that'd be cool though).
Well, there might actually be value in knowing the content for e.g. searching, analysis, compression, deduplication, and advertising purposes. I'm not terribly in favor of exploiting these uses, but there certainly are conceivable reasons for the online service to examine the content of the stored files.
There was also some discussion about metadata being changed once the files were uploaded to OneDrive. So if you plan to use it just for plain file storage then it might be an issue.
That was something completely different, and a result of Microsoft's naming screwup: Sharepoint adds/changes some metadata of MS Office files (for collaboration, etc.). OneDrive for Business is essentially Sharepoint in the cloud.
This OneDrive does not change metadata, it's a 'simple' cloud storage.
BTW: interesting, I've submitted this link an hour or so ago, and it was immediately flagged as dead. :)
That's only OneDrive for Business [1], a product that (fortunately) shares nothing but branding with the consumer product. Not so say the latter doesn't have its own warts...simply that it doesn't have that particularly egregious one.
I uploaded a legit Office ISO I downloaded from MSDN to SkyDrive (as it was called back then) to test throughput up and down.
After 3-4 hours it was gone.
My data isn't going near it.
Edit: just to clarify... I think they hash incoming files and delete known ones as part of a takedown system. This was an ISO that had been shared on TPB as well as MSDN. Of course their policy allows these measures but I'm not happy putting something up there on the basis that they can arbitrarily delete it.