Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

221–230 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#221
post #183

1. I just changed my phone # 2. I notified all of my contacts to change their phone #s 3. I contacted both Apple and my State senator. I am outraged by this scandal, and I still can't bring myself to believe that Path has been collecting this sensitive personal information. My 6-month old's pediatrician's # is in my phone. If this were EVER exposed or shared with a 3rd party, I can only image what kind of damage coul…

Your child's pediatricians phone number will somehow cause inconceivable damage if this number gets out? I bet calling up all of the pediatricians in your town phishing for this info would be much more productive than worrying about it being stolen off of a database from Path.

Re: Path uploads your entire iPhone address book to its servers

#222
I wrote a MobileSubstrate (jailbreak only, sorry!) tweak to block the use of ABAddressBookCopyArrayOfAllPeople, the most common method of stealing contacts in this manner.

It's rough around the edges, but check it out: http://news.ycombinator.com/item?id=3564968

It should be available in the BigBoss repository as "Address Book Privacy" sometime tomorrow.

Re: Path uploads your entire iPhone address book to its servers

#223

Earlier quoted context omitted.

This appears to be a sound response to a sensitive issue. Certainly handled far better than some others have handled their PR (debacles) recently.

You should not have been downvoted for your opinion on this, but I have to respectfully disagree. There MUST have been somebody at some point who mentioned that they were storing the details of non-users and making a massive database of connections without authorization, and as the CEO he must have been aware of this, and as the CEO he made a bad decision to go ahead and do it anyway. He didn't even respond that they…

I'll admit I only really superficially followed this through HN, and it seems you're more informed than I am - but my point was this was handled FAR better than AirBnB's debacle.

Re: Path uploads your entire iPhone address book to its servers

#224
Such a blatant and fundamental failure to be transparent in regards to user privacy should make everyone doubt Path's ability to function as a private social network. Whether this incident is a reflection of their technical incompetence or a lack of actually caring about their user's privacy (as their Values would otherwise have you believe) the expectation that their product can live up to its purported goal is misplaced.

This is pretty basic stuff.

Re: Path uploads your entire iPhone address book to its servers

#225
post #141

Earlier quoted context omitted.

Really? Apple would never do this? http://radar.oreilly.com/2011/04/apple-location-tracking.htm...

This data was never sent to Apple servers.

This is false, they do not send a recorded record of your movements to apple, however they do send GPS+WLAN BBSID correlation data back to apple,[1] they claim the processed is anonymized, but there are very powerful deanonymization techniques that can be applied to large data sets. [2][3][4]

I live in almost the middle of nowhere, i guarantee nothing like google maps, etc has ever passed this way to map my WIFI point's BSSID onto a physical location, yet the week a member of my family got an iphone, plugging the BSSID into a location api gives the exact location of my house...

[1]http://www.wired.com/gadgetlab/2011/04/apple-iphone-tracking...

[2]http://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf

[3]http://www.cs.utexas.edu/~shmat/shmat_oak09.pdf

[4]http://www.iseclab.org/papers/sonda-TR.pdf

Re: Path uploads your entire iPhone address book to its servers

#226
So I have read the responses and it seems that there are a few schools of thought here and I just want to make sure that I understand the possible solutions.

Per user Steko is this the ultimate solution to the problem -

(0) we get your permission (is this in the ULA, the in app screen? The privacy page of the app?)

(1) we check for your contacts in our database (hashing your contacts). The method of hashing yet to be determined or what info to hash and match if anything other than the email address or maybe the phone number.

(2) we let you know if any matches are found.

(3) we throw away all your data afterwords.

My question is - do you go through steps 1,2,3 each time that you boot up the application or click the add connections button. Compare the hash, report on the matches and dump the rest? Rinse and repeat?

Is the issue more the keeping the address book for later matching, or the passing it in the clear part?

If you were going to have an opt-in or disclosure what would you want it to say?

Re: Path uploads your entire iPhone address book to its servers

#227
In our Q platform, we specifically upload only the hashes of the address book. There is absolutely no need to have the actual email or phone number of people in order to find "who is on the service". However, when you INVITE people, we specifically download the full email address because we send them an invitation ourselves.

This is just one out of 100 things that our platform does while solving the usual stuff of apps: user signups, importing address books, invites, etc. However, we applied for a patent on some of the stuff we do. Even though I personally don't like patents, it's the thing to do in the current environment. Going to write a blog post about it soon.

Re: Path uploads your entire iPhone address book to its servers

#229

Earlier quoted context omitted.

As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list Ok, I'm going to pick on you for a second. Hold the downvotes everyone! Let me explain. This seems like a bit of a knee-jerk reaction akin to "think of the children!" or the whole child porn scare-mongering that politicians engage in that we on HN are always critic…

> I'm unclear on why them having the information you cited First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. > along with dozens or hundreds of other contacts from your address book From path.com/abo…

> They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old.

What are you talking about? Do you expect them to perform complex data analysis to figure out that certain contacts are young children, and then explicitly ask permission to share those? Or do you expect them to preemptively ask for any potential sensitive contact information? "Can we use your children's information?" "Can we use your in-laws' information?" "Can we use the address of the President's safehouse?" Etc.

Re: Path uploads your entire iPhone address book to its servers

#230
post #130
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Mind-blowing level of arrogance. Path just ensured that I will never use their product and that I will actively discourage all my friends, colleagues, co-workers, and users that I support (who number 100 or so) from ever using Path, too. "This is currently the industry best practice"? That's the biggest bullshit line I have ever heard. No, it's most certainly NOT a "best practice", and even if it were, it shouldn't b…

  >> No, it's most certainly NOT a "best practice"
Apparently they meant to say 'industry lowest common denominator'.
Post reply on HN