Live data from Hacker News

We are sorry

blog.path.com

161–170 of 220 posts

Re: We are sorry

#161

Earlier quoted context omitted.

How does that apparent belief square with their actions though? If they really believed that you should have control over your personal information, and that your trust mattered, they would never have uploaded it without user consent. It's not a "great save", it's a piece of PR flak arse-covering.

I completely agree. The engineers knew what they were doing when they design the app to upload all my info. This behavior should be illegal. I do not care what their BS press release says - they are just covering their a . I will never trust them ever again

This behaviour is illegal in the UK.

Re: We are sorry

#162
So now they have admitted what they have done, is someone in the UK going to prosecute them, I wonder?

It seems they may have broken the data protection act in more than one way.

* First, they collected personal data about UK citizens without their permission (as a 3rd party cannot give that permission),

* Secondly, personal information was kept for longer than is necessary (it should have been deleted after it was used)

* Thirdly, they allowed personal data to leave the EU.

Note that personal data includes name and address, telephone number or Email address.

http://en.wikipedia.org/wiki/Data_Protection_Act_1998

Re: We are sorry

#164
post #119

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened. I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come…

The fact is, there are innumerable factors that affect people's decision-making in situations like this. The ability to decide whether or not a course of action is ethical is greatly affected by what your competitors are doing, groupthink, incentives, time pressures, etc. I could keep going. And yes, your ability to "get away with it" is also a factor.

Now you may say, "Who cares what the factors are? A wrong decision is a wrong decision." And you're right. However, as a practical person who wants to see real change come about, I cannot be satisfied with the run-of-the-mill, "They did it because they're evil and untrustworthy" response.

People are rarely inherently evil. I find it hard to believe that this group of engineers is really so different from you and I. It's likely that all of us grew up in similar environments, have gone through similar experiences, and possess similar moral beliefs. So aren't you the least bit curious why they're capable of making a decision you could never imagine yourself making? I think simply dismissing them as untrustworthy people is an irresponsible and short-sighted reaction. Human beings are more complex than that.

A lot of teachers believed that the only students who cheat are the dishonest ones. Well, some clever psychologists came along and -- lo and behold -- they showed that under the right circumstances, you can convince almost any student to cheat. That's the nature of humans.

Like it or not, we react to situations much more than to our personal moral codes. No amount of shaming greedy bankers, book-padding executives, dishonest politicians, privacy-invading programmers, etc is going to work. If we want to effect real change, we need to change the systems that allow for and incentivize this type of behavior.

I highly recommend reading up on basic human psychology. Influence (by Robert Cialdini) is a good place to start. Charlie Munger's writings, although unorthodox, are also great.

Re: We are sorry

#165
post #132

Earlier quoted context omitted.

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. Well, you can make a mistake intentionally . As in: "I intentionally opted for course A, and I realize it was a mistake".

True. What I meant was that they try to make it sound (at least to me) like the action of stealing the contacts of its users was a mistake. They do this by saying: We believe you should have control when it comes to sharing your personal information. etc. etc. It makes it sound that it somehow was a mistake for those believes to be violated. It wasn't. And if you ask me, that breach of their users trust is not someth…

The action that path says they've taken - which is to delete all the contacts they have so far collected - serves to move me to forgiving them, 'cos that action is the only thing they have going for the contact collection being a "mistake".

"Privacy empathy" (no .. pun not intended I swear) seems hard to come by these days.

Re: We are sorry

#167

Earlier quoted context omitted.

Except for the "and then implement hashing from here on out." part. So, they haven't changed their implementation, they've just added the ability to opt out of the poor implementation.

But hashing doesn't add any protection in this case. There are a very limited number of phone numbers in North America and so those hashes can be pre-computed and rainbow-tabled in a short, reasonable timeframe.

Is this true if they were salted with a very long phrase?

Re: We are sorry

#168

So what changed really? Yesterday morning Path thought it was perfectly OK to scrape user's Address Book behind their back, and now they suddenly acquired moral backbone and ethics? Please give me a break. What they did today is the only sensible thing there was to try and save the company, so they did it, but should they be commended for that? Hell, no. Would you commend a landlord for dismounting a hidden camera in…

I agree with you 100%, and have no idea why your comment is not at the top.

This is a non-apology apology. It's a "you caught us, and we don't want our company to die" apology.

If they actually cared about your privacy, they wouldn't have stored all your personal data on their servers without your permission to begin with.

Re: We are sorry

#169
post #106

Earlier quoted context omitted.

That is incorrect. SHA1 still has no known collisions despite years of research and computing power dedicated to finding just one collision. Edit: Furthermore since the set of valid emails and phone numbers is a very restricted set of input, it is extremely likely that there are literally no two valid email/phone numbers that SHA1 hash to the same value.

I agree that it's practically not a concern, but the local part of an email address[0] is up to 64 characters in an alphabet of size 72, and the domain part is 253+ characters in an alphabet of size 38, giving the valid email space a size of greater than 3e519, which is enough to guarantee collisions in SHA-512 and all of the SHA-3 finalists. [0] http://tools.ietf.org/html/rfc3696

That's irrelevant, since this isn't crypto.

This is matching user email addresses so they can spam you and your friends and grow their company on the back of dodgy practices.

Re: We are sorry

#170

So what changed really? Yesterday morning Path thought it was perfectly OK to scrape user's Address Book behind their back, and now they suddenly acquired moral backbone and ethics? Please give me a break. What they did today is the only sensible thing there was to try and save the company, so they did it, but should they be commended for that? Hell, no. Would you commend a landlord for dismounting a hidden camera in…

They still think it's okay. It's the users' fault this is a problem. Read carefully:

- users brought to light an issue

- we now understand that the way we had designed... was wrong

- we are deeply sorry if you were uncomfortable

Not sorry. Sorry if and only if you took it wrong.

- We want you to feel completely in control of your information on Path.

You won't be in control, but we want you to "feel" you are.

Also:

- stored securely on our servers using industry standard firewall technology

Hmm. My firewall doesn't store data.

- We hope this update clears up any confusion

It's not us, it's you. Stop being confused.

Post reply on HN