Live data from Hacker News

Path texts my entire phonebook at 6 AM

branded3.com

271–280 of 430 posts

Re: Path texts my entire phonebook at 6 AM

#271

Earlier quoted context omitted.

You are equating "grant access to the address book" with "spam all 'friends' at 6 o'clock in the morning to tell them lies" By your logic, it would be completely useless to even read the fine print, because giving them access to the addressbook would imply my consent for them to do anything technically possible with it.

> ...because giving them access to the addressbook would imply my consent for them to do anything technically possible with it. Well, from a technical perspective that is indeed the case. Once they physically have your contact info they may do as they please. You, as the iOS or Android user, are not giving them permission to use your contacts "properly" or "nicely"--you're giving permission to access them, the raw da…

I agree, there's no easy solution. Maybe public debates like this are the best we can hope for anyway. My approach is to be extremely cautious with apps that depend on network effects to be useful or profitable.

Re: Path texts my entire phonebook at 6 AM

#272
post #230

Earlier quoted context omitted.

>I think it's our jobs to make sure we don't promote poor practice and un-ethical behaviour. No, it's our responsibility as decent people. I don't need to sign some online pledge to keep myself from pushing people in front of trains. If I was the sort to harm others, why would I care about some meaningless online campaign?

> I don't need to sign some online pledge to keep myself from pushing people in front of trains. Neither do doctors really need the Oath of Hippocrates to stop themselves from harming people.

Which is convenient, because the Oath of Hippocrates has not actually stopped doctors from harming people.

Re: Path texts my entire phonebook at 6 AM

#273
post #218

Earlier quoted context omitted.

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

Does this mean that we can't write software for drones anymore? What about software for missile guidance? Is that okay by this oath? Or do we as a community value not texting people at 6AM more than we value not killing people?

While the idea of an oath may be flawed, I do think it's about time some segments of the tech field showed a little less contempt towards users. I don't know how that would happen, but launching your own startup shouldn't give you carte blanche to exploit your users however you see fit.

As a programmer, I don't want a bunch of charlatans in SF to give my career an unsavoury reputation because of these antics.

Re: Path texts my entire phonebook at 6 AM

#274
post #83

Earlier quoted context omitted.

Android doesn't ask for user's permission before accessing the address book, is it?

Android shows the permissions each app is requesting before you install, and even lets you know if they change their permissions between updates. While what Path did is crappy, they didn't subvert the Android permissions system. The thing that burnt the poster is that while a social app asking for access to their contacts might not rise a brow, the user has no way to know what they are going to do with that data with…

But Android also doesn't allow you to deny specific permissions. It's all or nothing at time of install - if it ever gets location, it always gets location. This is one of the reasons I like iOS.

Re: Path texts my entire phonebook at 6 AM

#275

How about another detail -- the fact that the message said the user had photos to share, when he didn't? There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type. Just curious, is there a way to sue/fine a company like this for false advertising, essentially?

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

I'm a member of the Order of the Engineer. Their oath is a pledge of responsibility in engineering, in the interest of the public good: http://en.wikipedia.org/wiki/Order_of_the_Engineer

Re: Path texts my entire phonebook at 6 AM

#276
post #269

Earlier quoted context omitted.

Especially in context, the phrasing is ridiculous, but semantically it no different from "I refused to be bossed around by my phone".

Refusing to be bossed around by an inanimate object still seems somewhat ridiculous to me.

Being bossed around by an inanimate object seems even more ridiculous to me :)

Re: Path texts my entire phonebook at 6 AM

#278

Earlier quoted context omitted.

You presume the app sent it and not their servers or a partner service provider. They already grab your address book, including phone numbers. They don't need you after that.

In that case don't you think we would have seen many more reports of this shady practice? This seems to me a combination of purposefully bad UI and the user not paying attention. Still the same practice spammers use, but very different from "covertly uploading my contacts data and texting everyone without telling me".

Actually the article notes that quite a few other people do seem to have experienced this in the past...

Re: Path texts my entire phonebook at 6 AM

#280
post #67

Earlier quoted context omitted.

This comment is a great example of how people are so quick to rush to judgement with emotional reactions. Let's look at the facts: 1. Path was fined, not for anything involving address books, but for allowing 12 year olds to sign up for the service. 2. Yes... it is proof that Path uploads your phone book. Of course, they ask you. The OS won't even give you access to the phone book without prompting the user. So somew…

Me1000, you should mention to the folks here that you actually worked on the address book stealing code during your time working at Path so you are particularly aware that the statements in your post there are both untrue and self-serving.

I've never hidden that I interned at Path. The address book debacle happened long before I ever joined. The code you're talking about did little more than normalize phone numbers so it could be hashed _before_ it was sent to the server.

It's been about nine months since I've worked at Path and as you may know (although, given how baseless your comment is, perhaps you wouldn't know)... startups move quickly, Path has released many updates since I've left. It's incredibly disingenuous to suggest what I'm saying is untrue (since both statements I made are provable with empirical evidence) or that I had any motive other than trying to get people to think before they go on a witch hunt.

Droithomme, if I know you personally, I would appreciate you contacting me privately.

Post reply on HN