Educause Security Discussion mailing list archives

Re: Dropbox Sales/Legal messages


From: "Barton, Robert W." <bartonrt () LEWISU EDU>
Date: Wed, 12 Aug 2020 17:23:41 +0000

We get them here, but they are hitting a ton of our staff and faculty.  I've already said something about this to them 
and they did not even try to stop.

Robert W. Barton
Executive Director of Information Security & Policy
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Hagan, Sean 
<sean.hagan () YC EDU>
Sent: Wednesday, August 12, 2020 11:46 AM
To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Dropbox Sales/Legal messages

I get those every few months from them.  I find it to be a rather despicable sales tactic, and one that will not elicit 
a positive response from me or my institution.

I suppose it must work though, or they'd stop doing it...



________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Theodore J. 
August <Theodore.August () SALVE EDU>
Sent: Wednesday, August 12, 2020 9:40 AM
To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Dropbox Sales/Legal messages


Hi everyone:

Have you, or someone else in your organization getting messages like these from Dropbox?



Hi X,



I'm hoping you can provide some clarity around X's unmanaged Dropbox deployment. Recent levels of activity across the 
X.edu<https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fX.edu&c=E,1,mxu248GydD-ZbqoAFyC0fqe9hqqeyQIOakBCTOUZfY7_ousODYCvY6WXaHEjrozRuMnK9jnUHdkvva3TdudXQ9Skz7R_C5AByM3dVij7vTiNP-W0yGpeLGU,&typo=1>
 domain are congruent with those of our education customers, but there is no existing contract between X and Dropbox at 
this time.



Given that so many X  users have workflows embedded in Dropbox (over 1000 as a matter of fact!), I wanted to put some 
time down to talk about your options for user/data consolidation.



Do you have 15 minutes to discuss how our education platform can provide value and security in your current environment?



Thanks so much and I look forward to hearing from you!



And…

Following up one last time since I hadn't heard from you. I know this is often an ideal time to purchase potential 
tools for your environment with the year coming to an end. Please let me know which most applies to you:



1. I am not the correct person to discuss this with. Please contact ____.

2. I am authorized to provide consent on behalf of X for the non-IT managed use of Dropbox. I am aware that people in 
my organization are using Dropbox without the presence of a formal Dropbox Business agreement and I have confirmed 
internally that this adoption aligns with our IT policies and data governance posture.

3. I would like more information before making a formal evaluation. Please set up a 15 minute call.



We know people use Dropbox with their institutional e-mail addresses, despite the University’s lack of support for that 
product.  Our response to the first one is that we have no interest in any services, and that Dropbox can contact 
end-users directly if they are violating any terms of service. We have no interest in purchasing services from Dropbox 
regardless of the number of accounts being used in our domain.  I feel like #2. is some sort of informal legal 
indemnification for Dropbox for users on our domain, and I’m not willing to provide them one on behalf of our 
University.



If Dropbox has some sort of issue with our users using free accounts, they can reach out to them directly and tell them 
so.



We see these as a “legal” leaning sales pitch… they did come from someone who is working in enterprise sales…



Thoughts?



--

Ted August
Assistant Director of Cybersecurity and Compliance
Office of Information Technology
Salve Regina University

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fwww.educause.edu%2fcommunity&c=E,1,QLR2txWxlWBK-XYtmaqlBildWtVZrDhfrtOC2APwFFpND4Wx0ADris_Q5o_N8En2WXar6IWrmks437_p7M8FUpoNqsgnnpIPJ8Rdeo4ndFKGcSWQN2aC&typo=1>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: