Live data from Hacker News

Path texts my entire phonebook at 6 AM

branded3.com

121–130 of 430 posts

Re: Path texts my entire phonebook at 6 AM

#121

How about another detail -- the fact that the message said the user had photos to share, when he didn't? There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type. Just curious, is there a way to sue/fine a company like this for false advertising, essentially?

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

I think that's a great idea. Drafting a version of it right now.

Re: Path texts my entire phonebook at 6 AM

#122
post #98

I think the moral of this story is to do a little Googling about a company or product before trusting them with all the contact information (at least) in your phone. You know, to find out first if they're criminal scumbuckets. For all you know their app keylogs your transactions with your bank.

Well we know they don't keylog, they can't act outside of their sandbox. Curious if they'd try if they could though.

Unless they've found an exploit. Even companies that are generally law-abiding (Sony) have distributed applications specifically designed to circumvent OS-level protections, to do things the user doesn't want. Given what we know about these creeps, why wouldn't they? You have to have trust to install closed-source software, and that trust should be based on something besides "oooo, shiny".

Re: Path texts my entire phonebook at 6 AM

#123
post #118

How about another detail -- the fact that the message said the user had photos to share, when he didn't? There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type. Just curious, is there a way to sue/fine a company like this for false advertising, essentially?

This is proven (and risky) way to grow. I really cannot blame them: they have to pay their rent and VCs are nervous. This approach might burn them completely but also can get them to some significant number of users (after which they will issue an apology and pay all fines if needed).

> I really cannot blame them

Shitty behavior does not stop being shitty behavior because you have bills to pay. And it's not even in the "understandable under duress" area of shitty; Path isn't a person with a starving child and that dude's contact list isn't a loaf of bread.

If your company can't exist without being shitty, your company shouldn't exist.

Re: Path texts my entire phonebook at 6 AM

#125
post #9

The just got fined $800,000. I guess it should have been $800,000,000.

We'd see a lot less abusive behavior from startups if investors went to zero when it happened.

As it stands, $800k is a line item equal to only 2% of the money Path has raised. As such, I doubt that anybody who invested in it cares or views this as anything other than a triviality that a few nerds will care about.

Re: Path texts my entire phonebook at 6 AM

#126
that is great! really!

if another dozen of cases like this happen, maybe, just maybe, people will wake up and stop installing apps with ridiculous permissions.

That's one of the reasons i use CyanogenMod. i can disable permissions from apps. For example, i removed internet access from swype. It does crash everytime i reboot my phone, because it's probably trying to check for updates, and i know it will crash if it tries to connect while i'm typing. and i rather that then be in the dark if my data is secure.

Re: Path texts my entire phonebook at 6 AM

#127
post #115

Earlier quoted context omitted.

Android doesn't ask for user's permission before accessing the address book, is it?

This doesn't sound very difficult to verify. Go to play.google.com. Search for path. First result in the app store. Click on Permissions. "This application has access to the following: ... blah blah blah ... This permission allows the app to use the camera at any time without your confirmation. ... blah blah blah ... read your contacts Allows the app to read data about your contacts stored on your tablet ... blah bla…

Can you actually prevent an app from using one or more of those permissions? Like can I give it permission to my camera but not to the call log?

Re: Path texts my entire phonebook at 6 AM

#128

Earlier quoted context omitted.

I just noticed, in that apology letter, the line: "... Your trust matters to us and we want you to feel completely in control of your information on Path. ..." So they want you to feel in control.

"We are deeply sorry if you were uncomfortable with how our application used your phone contacts." That non-apology is corporate communications at its most typical.

Path's customer service replied to this article's author on Twitter saying they'd "love to engage."

If you aren't Captain Picard, you're not engaging anything. Shut up and talk human, folks.

Re: Path texts my entire phonebook at 6 AM

#129
post #38
post #20

FYI, you can deactivate your Path account by visiting their website ( https://path.com/ ), signing in and clicking 'Deactivate' on the 'Settings' page.

Notice that is says "Deactivating your account will remove your content from Path. If you reactivate your account, your content will come back." Not deleting your content, though. I hate that.

It's also a bald-faced lie. If it removes the content, then there is no way for it to come back.

Re: Path texts my entire phonebook at 6 AM

#130
post #48

Earlier quoted context omitted.

Address book access is a permission just like anything else (internet access, for example), so it can fly under the radar. Android has been trying to make things like "send text messages" stand out a tad more than "write to local storage", but they may need to go even further. This is my personal favorite app permission that you can request: http://developer.android.com/reference/android/Manifest.perm...

Wow. I wonder what the use-case for that is?

An app that lets you brick your phone remotely if it gets stolen maybe? Depends on how it works.
Post reply on HN