Live data from Hacker News

We are sorry

blog.path.com

31–40 of 220 posts

Re: We are sorry

#31
post #13
post #4

Surprise: an actual apology, followed by an explanation and how they're going to do it slightly better in future, plus a remedy of sorts. Better than ATT, VZW, MS, TW, Comcast, or any national US bank.

The fact that they've already deleted all user address book data, and have an updated version of the app available today with a privacy option, is a big deal. I don't know how they managed to get an update to the app approved so quickly (24-48 hours?), they must have worked directly with Apple. A good sign, either way.

Any dev can appeal to Apple to expedite a review when there is a good reason. I've done it several times and they generally have it reviewed within a few hours and out within 24. It's good that they've done this though and deleted all the data.

Re: We are sorry

#32
post #17

It's a step in the right direction, but doesn't clear up all of the confusion. I can't update to 2.0.6 (it's not an option on my device, a 4th gen iPod touch running 2.0.5). In addition, how will adding friends work going forward -- Facebook Connect, or manual searches by name? Will hashing be implemented?

If you can run Path 2.0.5, you can run Path 2.0.6. I think you're confused because the AppStore hasn't actually updated yet to show 2.0.6. Try again later today.

Re: We are sorry

#33
post #13
post #4

Surprise: an actual apology, followed by an explanation and how they're going to do it slightly better in future, plus a remedy of sorts. Better than ATT, VZW, MS, TW, Comcast, or any national US bank.

The fact that they've already deleted all user address book data, and have an updated version of the app available today with a privacy option, is a big deal. I don't know how they managed to get an update to the app approved so quickly (24-48 hours?), they must have worked directly with Apple. A good sign, either way.

IIRC, Path's CEO commented on the post that initially reported this behaviour saying that an update had been submitted that would make it an optional feature prior to the report.

Re: We are sorry

#34
Honestly, I keep hoping Apple adds a permission check for the contact list (like they do for GPS location). If the user says no, they should just return a blank contact list (to keep old apps happy that aren't expecting the call to fail).

Re: We are sorry

#35
post #2

I have a question about how they store the contacts. Can't they encrypt each of the phone numbers before they get sent to the server? This way there's no breach of privacy and the friend suggestion feature still works for everyone.

That wouldn't add any real protection. Phone numbers is a very small set (100 million possible in the U.S. and Canada). A rainbow table of all possible combinations can be created in only a week or two.

Re: We are sorry

#36
post #13
post #4

Surprise: an actual apology, followed by an explanation and how they're going to do it slightly better in future, plus a remedy of sorts. Better than ATT, VZW, MS, TW, Comcast, or any national US bank.

The fact that they've already deleted all user address book data, and have an updated version of the app available today with a privacy option, is a big deal. I don't know how they managed to get an update to the app approved so quickly (24-48 hours?), they must have worked directly with Apple. A good sign, either way.

You are entitled to a number of expedited reviews per app

Re: We are sorry

#37
Note to PR dicks: never include a mission statement in an apology if that very mission statement is the reason you were hired to write an apology.

Note to app builders: never hire a PR firm to do your dirty work.

Re: We are sorry

#39

Earlier quoted context omitted.

"So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers." That sounds like exactly what you were hoping for.

Except for the "and then implement hashing from here on out." part. So, they haven't changed their implementation, they've just added the ability to opt out of the poor implementation.

But hashing doesn't add any protection in this case. There are a very limited number of phone numbers in North America and so those hashes can be pre-computed and rainbow-tabled in a short, reasonable timeframe.

Re: We are sorry

#40
"It is also stored securely on our servers using industry standard firewall technology."

Undoubtably in plaintext. Having "industry standard firewall technology" didn't do jack for Zappos, why would Path's data be any more secure?

Post reply on HN