Live data from Hacker News

We are sorry

blog.path.com

1–10 of 220 posts

Re: We are sorry

#2
I have a question about how they store the contacts. Can't they encrypt each of the phone numbers before they get sent to the server? This way there's no breach of privacy and the friend suggestion feature still works for everyone.

Re: We are sorry

#3
I was hoping to see that they would just drop the entire database, and then implement hashing from here on out. Otherwise, the apology feels sincere and I appreciate it.

Re: We are sorry

#4
Surprise: an actual apology, followed by an explanation and how they're going to do it slightly better in future, plus a remedy of sorts.

Better than ATT, VZW, MS, TW, Comcast, or any national US bank.

Re: We are sorry

#5
Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path."

Great save for a bad mistake.

Re: We are sorry

#6
Path should come up with a Privacy Protection Program that commit them not to repeat their mistake. It's too easy to do something and ask for forgiveness later on. That would distinguish themselves from Facebook's way of doing things.

Re: We are sorry

#7
Nice to see a transparent and timely response to this issue. I get the feeling that the startup world learned some serious lessons in crisis management after seeing the Airbnb nightmare unfold. At the end of the day, the customers/users are the real winners here.

Re: We are sorry

#8
post #3

I was hoping to see that they would just drop the entire database, and then implement hashing from here on out. Otherwise, the apology feels sincere and I appreciate it.

"So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers."

That sounds like exactly what you were hoping for.

Re: We are sorry

#9
post #2

I have a question about how they store the contacts. Can't they encrypt each of the phone numbers before they get sent to the server? This way there's no breach of privacy and the friend suggestion feature still works for everyone.

How would one carry out the friend suggestion feature with encrypted phone numbers?

Re: We are sorry

#10
Good for the most part, but does anyone feel like they deliberately left out what it was they're apologizing for?

I can imagine a user unaware of the recent event stumbling across this article and leaving confused about what wrong was committed. They sort of just assume you knew what happened, instead of explicitly explaining what they'd been doing.

But, they're taking steps to resolve the issue, apparently; so good on them.

Post reply on HN