Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

201–210 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#202
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

If “Apple would never do this to their users”, then how is it that Apple provided the API which Path used to do this to their users, without requiring the users to give the app permission (as they do with, say, allowing an app access to a user's location)?

Because it requires 2 API's both of which have legitimate uses:

1.) Get the user's address book and 2.) upload it to a server.

Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.

Re: Path uploads your entire iPhone address book to its servers

#203
post #39
post #9

Honest question: Isn't this within the kind of behavior that AppStore reviews are supposed to prevent, at least if there isn't an app specific functional explanation for it? Does Apple have a list of what kind of behavior like this is tolerated or does word just get out about what they don't reject?

Well, since you only ever only submit the compiled application binary to Apple, it'd be pretty darn hard for them to detect behaviour like this. Especially if the code to do so is obfuscated, and/or the data is smuggled out via SSL (or worse, steganography-style piggy-backed on to other data). Sometimes it's tempting to speculate whether the real purpose of the app store review team is just to ensure developers aren'…

Apple would simply tell their SSL library to dump the raw data, I mean they wrote it (or at least have source access to it) and have absolute control of the devices used to test. Nothing hard at all.

Re: Path uploads your entire iPhone address book to its servers

#204
post #202

Earlier quoted context omitted.

If “Apple would never do this to their users”, then how is it that Apple provided the API which Path used to do this to their users, without requiring the users to give the app permission (as they do with, say, allowing an app access to a user's location)?

Because it requires 2 API's both of which have legitimate uses: 1.) Get the user's address book and 2.) upload it to a server. Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.

From the traction this story is getting, it sure looks like address book information is considered sensitive by a lot of people. Possibly on par with location data.

Re: Path uploads your entire iPhone address book to its servers

#205
post #129

I'm pretty sure that Instagram is doing this too as I get push notifications whenever a friend signs up. Can anyone confirm?

I briefly looked into it. Logging in and registering with Instagram apparently won't work behind an http proxy (mitmproxy)

Re: Path uploads your entire iPhone address book to its servers

#206
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Those fuckers should be in jail for this.

Re: Path uploads your entire iPhone address book to its servers

#207

Earlier quoted context omitted.

Wait: What about MY INFORMATION if I've never installed Path? If someone I know with my contact information installs Path, does that mean that my information is stored on their servers? How can I remove my information if I've never installed Path before? It doesn't seem right that my contact information, which I have kept private, because someone I know has uploaded that information. Do I not have a right to keep tha…

Clearly there are a lot of WTFs going on at Path, but this isn't one of them. > Do I not have a right to keep that information private? But you didn't. You gave it to someone else. It's not your information any more. Information about you is not information you own . Privacy and anti-spam laws in various jurisdictions cover what an organisation can do with information they collect about private individuals, but that…

What if I gave someone my silent, protected phone number and that information was stolen by Path like it appears to have done? I may not "own" the information, but I may have rights under law for the information to be protected, and not shared without my permission. Similarly for addresses of people who may be in witness protection programs or escaping violence of some kind. The simple fact is Path stole this information without any kind of consent from the user, information it had no right to access.

Re: Path uploads your entire iPhone address book to its servers

#208
post #126

Earlier quoted context omitted.

That's not a PR move, that's what you do while crossing your fingers that state attorney generals and the FTC doesn't come after you.

Yes, good point. And regarding state attorney generals, how is this not data theft? It seems to go far beyond privacy issues, the program is in every way that matters a trojan that steals personal data. I can't see how it could not be considered so given the details of what was discovered.

If I were an evil-state-attorney-general, I'd be calling up Path and saying "Here's a list of names (unsaid - of suspected drug dealers), please forward all of their details and contacts, and the details and contacts of anyone who lists them as a contact. Thanks"

Re: Path uploads your entire iPhone address book to its servers

#209

Brought to you by: https://path.com/team Their collective decision making has proven to be a huge liability. Would you hire them for your next venture? A 14 year old girl could tell you that her address book is private, private, private!

Umm, hell yes I'd hire them. And so would any major software engineering company in the world. You seriously think that this is out of the ordinary or unusual? How many huge privacy fiascos has Facebook had? And yet, they're about to IPO for $100 billion. The only group who really cares about this is on HN. In a week, most of us will have moved on to the next big drama. In a year, no one will remember this at all. Th…

That doesn't make it right. Privacy is privacy. What happens when their servers get hacked and all of that info is out in the open? This ranks way up there with storing passwords in plain text. OK, sure, the entire team isn't at fault, but one or a few people are. I would not want those people making decisions that could take down my business. No way.

Downvotes me all you want. The fact remains that, if you asked a teenage girl if it would be OK to grab her address book without consent it is very clear what kind of an answer you'd get. Why is it that a bunch of smart adults think that they can get away with it then? The apology is bullshit. They knew what they were doing and got caught.

As far as only HN caring, I'll bet that users of this app would disagree with you on that point. How many people do you know that are OK with a company of strangers secretly downloading their private data onto their servers?

This, in my opinion, is a very serious transgression.

Re: Path uploads your entire iPhone address book to its servers

#210

Earlier quoted context omitted.

I've just: 1) saved their Privacy Policy and Terms of Use 2) requested a complete deletion of our family's account 3) requested deletion of any/all stored information 4) considering contacting our lawyer As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list - that's an insane, willful, and quite unexpected violation o…

As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list Ok, I'm going to pick on you for a second. Hold the downvotes everyone! Let me explain. This seems like a bit of a knee-jerk reaction akin to "think of the children!" or the whole child porn scare-mongering that politicians engage in that we on HN are always critic…

> I'm unclear on why them having the information you cited

First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old.

> along with dozens or hundreds of other contacts from your address book

From path.com/about

  Path should be private by default. Forever. You should 
  always be in control of your information and experience.
I was never once asked, agreed to, or gave consent to allow anyone to collect sensitive information about where are children are schooled at, what buses they ride, where they receive medical treatment at, or OTHER PLACES I LEFT OUT OF THE ORIGINAL LIST BECAUSE THEY ARE PRIVATE TO MY FAMILY. :)

> for millions of users

"kill one, it's murder - kill 1,000,000 it's a statistic" - this isn't about your children - it's about mine. ;)

> constitutes some kind of terrible threat to your children

Where did I say this was a "terrible threat" to my children? Maybe it is, maybe it isn't - bottom line is we did not consent to it. And perhaps we just want to protect our underage children from having behaviorial profiles or credit risk assessments built up on them before they reach kindergarten.

Interestingly enough, according to Path it is VERY reasonable that I should protect my children's information:

  We take reasonable measures to protect your personal information 
  in an effort to prevent loss, misuse and unauthorized access, disclosure, 
  alteration and destruction. Please be aware, however, that despite our efforts, 
  no security measures are perfect or impenetrable and no method of data 
  transmission can be guaranteed against any interception or other type of misuse.
Combined with:

  (You)...accept all risks of unauthorized access to the Registration Data and any other information you provide to us.
My risk, right?

> But maybe there's a specific threat in mind that I'm not thinking of?

Yes, there is. And I acknowledge that you might live in a world where you have no problem allowing anyone in the world to know any detail they can illicitly sneak out of your phone about you, your family, and your friends - but most of the rest of us don't.

For fuck's sake a UIKit dialog box and handler code is less than a dozen lines of code and then NONE OF THIS WOULD BE AN ISSUE.

> Anyway, just thought your response was a little over the top, and more informed by emotion than reason.

I'm curious, do you have a spouse or children?

Post reply on HN