Live data from Hacker News

We are sorry

blog.path.com

11–20 of 220 posts

Re: We are sorry

#11
post #3

I was hoping to see that they would just drop the entire database, and then implement hashing from here on out. Otherwise, the apology feels sincere and I appreciate it.

"So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers." That sounds like exactly what you were hoping for.

Except for the "and then implement hashing from here on out." part.

So, they haven't changed their implementation, they've just added the ability to opt out of the poor implementation.

Re: We are sorry

#12
I'm kind of sick of this "let's revolt against everybody using my data" mentality. They don't persist your contact data to their server. What exactly is it that you're afraid of?

Moreover, how on earth did you think the "Add Friends" feature worked? I'm assuming at least some of you program software, and you should know that data doesn't just appear out of nowhere. Do you really expect a software startup to move every piece of data sorting & analyzing to the client side that has potential to piss off its userbase?

I understand that it's easy to just encrypt the information, or some other X remedy. I'm just saying there's a line between a software mistake and the let's-grab-the-pitchforks rhetoric that inevitably stems from stories like this.

Re: We are sorry

#13
post #4

Surprise: an actual apology, followed by an explanation and how they're going to do it slightly better in future, plus a remedy of sorts. Better than ATT, VZW, MS, TW, Comcast, or any national US bank.

The fact that they've already deleted all user address book data, and have an updated version of the app available today with a privacy option, is a big deal. I don't know how they managed to get an update to the app approved so quickly (24-48 hours?), they must have worked directly with Apple. A good sign, either way.

Re: We are sorry

#14
post #2

I have a question about how they store the contacts. Can't they encrypt each of the phone numbers before they get sent to the server? This way there's no breach of privacy and the friend suggestion feature still works for everyone.

Do you mean hash instead of encrypt?

Re: We are sorry

#15
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

I would bold it if I were them. It's a nicely written message, but it reads like a lot of other PR apologies and it's easy to skim over it, deep in its position in the 5th paragraph.

Sometimes you need to make actions speak louder than words. :)

Re: We are sorry

#16
post #10

Good for the most part, but does anyone feel like they deliberately left out what it was they're apologizing for? I can imagine a user unaware of the recent event stumbling across this article and leaving confused about what wrong was committed. They sort of just assume you knew what happened, instead of explicitly explaining what they'd been doing. But, they're taking steps to resolve the issue, apparently; so good…

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts."

Dave explained the issue well enough in the first paragraph.

Re: We are sorry

#17
It's a step in the right direction, but doesn't clear up all of the confusion. I can't update to 2.0.6 (it's not an option on my device, a 4th gen iPod touch running 2.0.5). In addition, how will adding friends work going forward -- Facebook Connect, or manual searches by name?

Will hashing be implemented?

Re: We are sorry

#19

I'm kind of sick of this "let's revolt against everybody using my data" mentality. They don't persist your contact data to their server. What exactly is it that you're afraid of? Moreover, how on earth did you think the "Add Friends" feature worked? I'm assuming at least some of you program software, and you should know that data doesn't just appear out of nowhere. Do you really expect a software startup to move ever…

I agree in general, but they do actually store your data on the servers.

Re: We are sorry

#20
post #2

I have a question about how they store the contacts. Can't they encrypt each of the phone numbers before they get sent to the server? This way there's no breach of privacy and the friend suggestion feature still works for everyone.

How would one carry out the friend suggestion feature with encrypted phone numbers?

instead of comparing the phone numbers you'd compare the hashed phone numbers.
Post reply on HN