Live data from Hacker News

Path texts my entire phonebook at 6 AM

branded3.com

201–210 of 430 posts

Re: Path texts my entire phonebook at 6 AM

#203
I don't know the exact details of this story, may be the blogger accidentally pressed a button in the app and the messages were queued up for the following day.

However, if the story is indeed cut and dry:

1) Path sent messages that qualify as spam both because they had no permission to send them and they were false.

2) If this was intentional, this should be a red flag to investors not just of the company but the kind of people that run it.

3) This is nothing new. Tagged did the same thing, with e-mail, which to some degree falls afoul of less laws than using text messages or the telephone (other commentators pointed out that land line carriers convert SMS to voice calls, which is news to me.)

4) Using spammy methods to acquire users is a red flag for any web service. While arguably Facebook used and uses extremely aggressive e-mail notifications (sending out an e-mail for every minor thing, and whenever a new feature is added opting in the user to receive notifications by default), using spammy techniques means that your service will skew toward the bottom of the market that actually "falls" for these techniques (poor and illiterate) early on and actually scare away early adapters for multiple reasons.

5) In the short term, Path's metrics will look really good, but in the long term it could result in serious problems, least of which will be another news story with FTC settlement in it.

Re: Path texts my entire phonebook at 6 AM

#204
post #142

Earlier quoted context omitted.

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

>Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? This is silly. Stop trying to add grandeur to writing some code at X,Y startup/company. People don't die or get harmed when some social-messaging application spams someone. Code is a way to implement an idea. Most applications exist to make money. If this a shock to you, read the user agreement before installing/upgrading, uninstall t…

You really come off as an amoral jerk here.

What happens if an app for job seekers texts your boss? What if a casual hookup site texts your new girlfriend--even though you signed up a year before meeting her? What happens if your app calls an old person and they crack a hip trying to answer a phone--when everyone that knows them personally knows not to call until they're awake and their caretaker is in?

These may sound far-fetched, and we all mostly don't pretend we're as disciplined as structural engineers, but "we do it for the money lulz" is a shitty and stupid argument.

Re: Path texts my entire phonebook at 6 AM

#205
post #98

Earlier quoted context omitted.

Well we know they don't keylog, they can't act outside of their sandbox. Curious if they'd try if they could though.

Unless they've found an exploit. Even companies that are generally law-abiding (Sony) have distributed applications specifically designed to circumvent OS-level protections, to do things the user doesn't want. Given what we know about these creeps, why wouldn't they? You have to have trust to install closed-source software, and that trust should be based on something besides "oooo, shiny".

Putting a keylogger exploit into an app that you, as named identifiable rich people and a US company distribute through the app store, would be pretty crazy risk profile for the developer. All it takes is one person finding it.

Exploits should be used on targeted individuals where you can serve a trojaned app just to that individual, vs. something like the App Store where that would require either Apple's permission or some crazy proxy. (A carrier could probably do it with phones the carrier sells, though, particularly on Android, but even on Apple by pre-jailbreaking phones sold in sketchy areas like rebel-held Syria, if that were the goal)

Re: Path texts my entire phonebook at 6 AM

#206
post #169

Earlier quoted context omitted.

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

Twitter essentially created a Hippocratic Oath for patent usage (that is, for its employees who are developers concerned about unethical offensive use of software patents): https://blog.twitter.com/2012/introducing-innovators-patent-... The patent language says it's "a commitment from Twitter to our employees that patents can only be used for defensive purposes." Extending this more broadly would say "a commitment to…

Used that in some contract work last year--it's a good thing.

Re: Path texts my entire phonebook at 6 AM

#207

How about another detail -- the fact that the message said the user had photos to share, when he didn't? There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type. Just curious, is there a way to sue/fine a company like this for false advertising, essentially?

Maybe that's why we've been seeing Path more in App Store top charts recently? Another app doing similar spamming is Circle: http://discovercircle.com - surprised no one talked about that...

Growth hacking through grey-hat tricks? This is an outrage!

(your winnings, sir.)

Re: Path texts my entire phonebook at 6 AM

#208
post #142

Earlier quoted context omitted.

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

>Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? This is silly. Stop trying to add grandeur to writing some code at X,Y startup/company. People don't die or get harmed when some social-messaging application spams someone. Code is a way to implement an idea. Most applications exist to make money. If this a shock to you, read the user agreement before installing/upgrading, uninstall t…

[deleted]

Re: Path texts my entire phonebook at 6 AM

#209
post #150

Earlier quoted context omitted.

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

A "Hippocratic Oath for developers" sounds like a great idea, but we vastly underestimate the number of jerkbags in the world. People want validation. Line-level employees want praise from coworkers and bosses. Executives want praise from their peers, investors, industry, and press. Concepts like ethics, "right," or even this-is-good-for-thie-world isn't a concern when faced with "X will increase my social status and…

Haven't seen this mentioned yet, but ...

http://blogs.msdn.com/b/oldnewthing/archive/2006/11/01/92244...

I often find myself saying, "I bet somebody got a really nice bonus for that feature."

"That feature" is something aggressively user-hostile,...

Re: Path texts my entire phonebook at 6 AM

#210
post #142

Earlier quoted context omitted.

>Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? This is silly. Stop trying to add grandeur to writing some code at X,Y startup/company. People don't die or get harmed when some social-messaging application spams someone. Code is a way to implement an idea. Most applications exist to make money. If this a shock to you, read the user agreement before installing/upgrading, uninstall t…

I disagree. As a computer engineer in Canada, I must swear by the Code of Ethics because what I do (or potentially don't do) can cause harm. Ethics in computer-science-related fields are important and I think we do need a set of rules we can dogmatically follow like the Hippocratic Oath. Of course, the HO is different in that failing to follow can cause physical harm. However, the world is progressing quickly and mor…

So in Canada, software engineers never cause harm to anyone? Nice to know.

>>>> I think we do need a set of rules we can dogmatically follow like the Hippocratic Oath.

So you don't actually have to employ your own brain and your own moral judgement, because somebody already did it for you and wrote this nice set of rules, that you swore by Apollo to faithfully execute, without thinking, not unlike that box of wires and silicon chips you are paid to play with? Nice arrangement, I suppose.

>>>> I think it's our jobs to make sure we don't promote poor practice and un-ethical behaviour.

And you need to sign an explicit oath to do that?

Post reply on HN