Live data from Hacker News

We are sorry

blog.path.com

91–100 of 220 posts

Re: We are sorry

#91
post #47

It's not a perfect solution, but I don't understand why Path don't hash the contact details before uploading them, and check against the hashes. You can still infer all kinds of social graph information, of course, but they're at least not consuming raw contact details.

Preface: I will joining Path this Summer, but I do not speak for the company in any way, nor have I spoken with them about the situation. This is a purely technical reply...

You cant guarantee a unique hash. When you hash users' data there is the possibility of collision; this probability grows with every new user. Without identifying data of some sort, it's difficult (impossible?) to get the exact user.

Re: We are sorry

#92
I think they handled it well, much better then Apple handled the Antennagate "saga" However I think they should have led with "We deleted what we had and we are going to work hard to earn back your trust"

Re: We are sorry

#93

This is a welcoming move from Path. However, "industry standard firewall technology" is gibberish.

Yep that sentence, and ones like it always worry me when I see them in companies' documentation about security. If the best thing you can say about your system and application security programme is that you use a firewall, that wouldn't fill me with a lot of confidence...

Re: We are sorry

#95
post #91
post #47

It's not a perfect solution, but I don't understand why Path don't hash the contact details before uploading them, and check against the hashes. You can still infer all kinds of social graph information, of course, but they're at least not consuming raw contact details.

Preface: I will joining Path this Summer, but I do not speak for the company in any way, nor have I spoken with them about the situation. This is a purely technical reply... You cant guarantee a unique hash. When you hash users' data there is the possibility of collision; this probability grows with every new user. Without identifying data of some sort, it's difficult (impossible?) to get the exact user.

It doesn't matter. The purpose of the hash isn't to uniquely identify users, it's to narrow the list of users that need to be sent down to the phone. If Path could send their entire user database to the phone, they wouldn't need to send the contacts to their server.

Re: We are sorry

#97
post #48

Give credit where credit is due. Zynga would never in a million years do this. Facebook probably wouldn't, either. Dave's message is straightforward and sincere.

Facebook actually asks for your permission before sucking up your entire address book.

Even if that weren't the case, "better than Facebook" is a pretty low bar. "Worse than Facebook" is way, way out of bounds.

Re: We are sorry

#98
post #91
post #47

It's not a perfect solution, but I don't understand why Path don't hash the contact details before uploading them, and check against the hashes. You can still infer all kinds of social graph information, of course, but they're at least not consuming raw contact details.

Preface: I will joining Path this Summer, but I do not speak for the company in any way, nor have I spoken with them about the situation. This is a purely technical reply... You cant guarantee a unique hash. When you hash users' data there is the possibility of collision; this probability grows with every new user. Without identifying data of some sort, it's difficult (impossible?) to get the exact user.

Hash collisions aren't a problem for this application and if we were to pretend that they were, that's solvable by using multiple hashing techniques at once.

Re: We are sorry

#99
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

They should prove it by publishing the collection they deleted, otherwise how could we know? :P

Re: We are sorry

#100
post #15
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

I would bold it if I were them. It's a nicely written message, but it reads like a lot of other PR apologies and it's easy to skim over it, deep in its position in the 5th paragraph. Sometimes you need to make actions speak louder than words. :)

I almost wanted to bold it even in the quote. I actually missed it the first time I skimmed the post.
Post reply on HN