Live data from Hacker News

We are sorry

blog.path.com

211–220 of 220 posts

Re: We are sorry

#211
post #119

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened. I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come…

I suspect, if you probe more deeply, that some of the Path developers where familiar with how this problem is normally solved and just copied a common design pattern. A large number of IOS applications supposedly upload the contact list to make it easier to find friends server side - I further suspect that many, many of the popular social apps do this. Hopefully at least Five good things will come out of this: 1) Soc…

I could not agree more. I think they've set a reasonable precedent for dealing with such oversights.

Re: We are sorry

#212
post #206

Earlier quoted context omitted.

Ironically, this was exactly the kind of apologetic but side-stepping rhetorics used by still German president Christian Wulff so I call shenanigans and nothing but modern rhetorics and modern PR-management. This is very alike to catching someone red-handed, with the hand still on the murder weapon stuck in the body... and then they make a public apology along the lines of " Through the feedback I’ve received from al…

Human rights? If I'm correctly understanding the issue, their software monitored your contact list so they could notify you when one of your contacts joined the service. You seem ready to throw him before the International Court. That they've wiped their user data and are giving people the opportunity to use their product in a setting with opt-in sharing seems to demonstrate to me, at least, that they still believe t…

IMHO privacy should become a human right in these surveillance-ridden times but that was ahead of time - replace with "privacy", if you ask me it was a huge intrusion into the privacy of the users.

Re: We are sorry

#213
post #190

Earlier quoted context omitted.

Both uses of "amoral" are correct. http://en.wikipedia.org/wiki/Amoral "Amorality, the absence of morality; for example, a stone, a chair, or the sky may be considered amoral" , http://dictionary.reference.com/browse/amoral "not involving questions of right or wrong; without moral quality; neither moral nor immoral."

I think Wikipedia is in the wrong here. In fact, if you read the article linked from the disambiguation page, it strongly supports the definition shown in all dictionaries, and makes no mention of rocks or chairs being 'amoral'. Regardless, none of this bears out the idea of 'amoral' meaning morally agnostic, ie actions having no moral component, and your initial semantic nitpick was itself incorrect.

If by "all dictionaries" you mean no dictionary I've ever read, nor the one quoted for you right here. You're wrong.

Re: We are sorry

#214

Earlier quoted context omitted.

But hashing doesn't add any protection in this case. There are a very limited number of phone numbers in North America and so those hashes can be pre-computed and rainbow-tabled in a short, reasonable timeframe.

Is this true if they were salted with a very long phrase?

But the app would need to contain the salt in order to send it to Path's servers hashed and salted. So a hacker could decompile the app to determine the salt.

Re: We are sorry

#215
post #213

Earlier quoted context omitted.

I think Wikipedia is in the wrong here. In fact, if you read the article linked from the disambiguation page, it strongly supports the definition shown in all dictionaries, and makes no mention of rocks or chairs being 'amoral'. Regardless, none of this bears out the idea of 'amoral' meaning morally agnostic, ie actions having no moral component, and your initial semantic nitpick was itself incorrect.

If by "all dictionaries" you mean no dictionary I've ever read, nor the one quoted for you right here. You're wrong.

Dictionary.com: having no moral standards, restraints, or principles; unaware of or indifferent to questions of right or wrong: a completely amoral person.

Merriam-Webster: lacking moral sensibility | being outside or beyond the moral order or a particular code of morals

Apple dictionary: lacking a moral sense; unconcerned with the rightness or wrongness of something : an amoral attitude to sex.

thefreedictionary.com: Lacking moral sensibility; not caring about right and wrong.

Admittedly, some of these do mention definitions along the lines of "having no moral component", so it looks like everyone was wrong. Hurray!

Re: We are sorry

#216
Bah, "We are deeply sorry if you were uncomfortable with how our application used your phone contacts." Is still a non-apology. We're sorry that YOU feel this way. Not, we're sorry that WE screwed up.

Re: We are sorry

#217
Companies make mistakes. In the rush to develop great products decisions are made rather quickly. When your intentions are pure, the fact that you might be doing something wrong simply doesn't cross your mind.

Unfortunately, these things happen.

What you have to do now is look at how Path reacted. The second the article exposing their mistake was published Path became very open and honest. Above that they offered reassurance to their users, deleted the data (I never expected that), and pushed a feature to opt-in to sharing your private data.

In my opinion they couldn't have handled this any better. For that reason, I give Path all the trust and respect in the world.

Re: We are sorry

#218
post #212

Earlier quoted context omitted.

Human rights? If I'm correctly understanding the issue, their software monitored your contact list so they could notify you when one of your contacts joined the service. You seem ready to throw him before the International Court. That they've wiped their user data and are giving people the opportunity to use their product in a setting with opt-in sharing seems to demonstrate to me, at least, that they still believe t…

IMHO privacy should become a human right in these surveillance-ridden times but that was ahead of time - replace with "privacy", if you ask me it was a huge intrusion into the privacy of the users.

Sure, privacy should become a human right. I personally am a very private person. What you need to understand is we live in a world where there is no such thing as privacy. We need to clearly define what is right and what is wrong. What needs to be opt-in and what needs to be opt-out. What we, as a community, need to do is set a standard. We need to establish boundaries so that we can regain our privacy.

Outside of establishing boundaries there needs to be a way to deal with those who break the rules. Sending CEOs straight to the slaughter house doesn't accomplish anything. Companies need an opportunity to react and do the right thing. Especially when intentions were good, and the reaction from the Company is as responsible as Path's.

+1 Paths Owned their mistake +1 Deleted all the data +1 Fixed the mistake by publishing an opt-in feature.

They did everything they could to right their wrong.

You also need to realize they didn't commit murder. They weren't 'caught red handed with the murder weapon'. They had some digital data, and then deleted it. It's not like they raped and murdered your wife and family. They didn't commit genocide. They made a minor mistake and fixed it.

Re: We are sorry

#219

I see a trend of pushing the envelope of what is admissible. If users don't like it they are quick to apologize (lusers..., we'll iterate over this...) If they do it often enough, in the end one of them will even claim they're using the "standard industry practice"

"Standard industry practice" in the second paragraph. I can't believe it:

http://uncrunched.com/2012/02/13/we-are-better-than-this/

Re: We are sorry

#220
post #212

Earlier quoted context omitted.

IMHO privacy should become a human right in these surveillance-ridden times but that was ahead of time - replace with "privacy", if you ask me it was a huge intrusion into the privacy of the users.

Sure, privacy should become a human right. I personally am a very private person. What you need to understand is we live in a world where there is no such thing as privacy. We need to clearly define what is right and what is wrong. What needs to be opt-in and what needs to be opt-out. What we, as a community, need to do is set a standard. We need to establish boundaries so that we can regain our privacy. Outside of e…

If this was such a minor little mistake, why does the congress suddenly deal with it?

http://www.macrumors.com/2012/02/15/congress-weighs-in-on-io...

Post reply on HN