Live data from Hacker News

We are sorry

blog.path.com

151–160 of 220 posts

Re: We are sorry

#151
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

How does that apparent belief square with their actions though? If they really believed that you should have control over your personal information, and that your trust mattered, they would never have uploaded it without user consent. It's not a "great save", it's a piece of PR flak arse-covering.

I completely agree. The engineers knew what they were doing when they design the app to upload all my info. This behavior should be illegal. I do not care what their BS press release says - they are just covering their a. I will never trust them ever again

Re: We are sorry

#152
post #64
post #52

Earlier quoted context omitted.

It's crazy that they haven't added this already. Facebook needs to get my permission to find out where I am, but not to scrape a hundred names, phone numbers, and addresses out of my phone? Bizarre.

I realise you might be using Facebook as an example in a theoretical sense (i.e., that Apple believes protecting your location is more important than protecting your contact database), but in case you weren't, Facebook's "find friends" feature does give you an explanation of what is going to happen, asks you to confirm. Here's the explanation: "If you enable this feature, all contacts from your device (name, email ad…

Yes, Facebook was just an arbitrary company/app to use as an example. Nice that they exercise some restraint, though.

Re: We are sorry

#153

Earlier quoted context omitted.

If you put yourself in a user's shoes that doesn't know what the issue was then that is still generic. As a user who doesn't know the story I'd be wondering: - Did they get hacked and now some unknown party may have the contents of my address book? - Were they selling my information to others? - Did something happen as it relates to storage that mixed up or deleted information - Was my data being transmitted in the c…

Paragraph four, which answers questions 2 and 4 in your list and suggests that the answer to 1 and 3 is "No": "In the interest of complete transparency we want to clarify that the use of this information is limited to improving the quality of friend suggestions when you use the ‘Add Friends’ feature and to notify you when one of your contacts joins Path––nothing else. We always transmit this and any other information…

Actually, in the blog post by the guy who discovered that, he said he was able to read the data - meaning that it was transmitted NOT encrypted (please correct me if I am wrong).

Also, I hope that their "industry standard" firewall is better than their "industry best practices" data sharing practices.

Re: We are sorry

#154

Earlier quoted context omitted.

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts." Dave explained the issue well enough in the first paragraph.

If you put yourself in a user's shoes that doesn't know what the issue was then that is still generic. As a user who doesn't know the story I'd be wondering: - Did they get hacked and now some unknown party may have the contents of my address book? - Were they selling my information to others? - Did something happen as it relates to storage that mixed up or deleted information - Was my data being transmitted in the c…

Speaking as someone who has never heard of path before today I have no idea what they are apologizing for, and I'm scanning the HN comments hoping someone will list some background.

For the benefit of anyone else who is confused: http://mclov.in/2012/02/08/path-uploads-your-entire-address-...

Re: We are sorry

#156
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

"Great save for a bad mistake."

I'm not so sure.

The updated iPhone app does the right thing.

What do the apps not updated to the latest version do? Does it re-upload the contacts? If it does, what does the server do with the data?

Re: We are sorry

#157

Earlier quoted context omitted.

There is no proof of that they really deleted all user address book data.

You can't prove a negative. You can only prove the existence of certain data on a particular server, you can not prove that a company does not have certain data unless you are prepared - and they are willing - to give you full access to audit each and every byte on their systems and to wipe any parts that they can't explain and you can't find a way to decrypt. Clearly that is not practical so we'll have to take them…

It probably would help if they had an outside auditor to verify the actions that were taken. Still wouldn't be final proof to anyone who believes that they might still be hiding something but is a step further than just saying "trust us".

Re: We are sorry

#158
post #138

Earlier quoted context omitted.

Facebook is trying to push the responsibility for the privacy of your friends to you with this, and by doing so they are violating EU privacy laws. See: http://en.wikipedia.org/wiki/Data_Protection_Directive This is one of the few areas where the EU is (still...) ahead of the rest of the world. Facebook should not be able to collect data on your friends even at your request unless your friends explicitly consent to t…

Your neighbours to the north also have laws like this that are on par with the DPD. The EU treats PIPEDA as essentially an implementation of the DPD so that DPD compliant orgs can share data with Canadian businesses.

  > Your neighbours to the north
Confused me a bit, b/c I don't think that jacquesm is from the US. I was thinking 'neighbors to the north' meant Scandinavia or Iceland.

Re: We are sorry

#160
"In the interest of complete transparency we want to clarify that the use of this information is limited to improving the quality of friend suggestions when you use the ‘Add Friends’ feature and to notify you when one of your contacts joins Path––nothing else." Is "complete transparency" == me trusting you just because you say so?
Post reply on HN