Live data from Hacker News

Path texts my entire phonebook at 6 AM

branded3.com

351–360 of 430 posts

Re: Path texts my entire phonebook at 6 AM

#352
And this is why I fundamentally don't trust my smartphone.

It's a fun device. But it's a spy, outside my control, in my pocket.

I've rooted it, but haven't yet modded it (and if anyone cares to point me at a gentle introduction for CyanogenMod or another option that works on an HTC Incredible, I'm all ears).

I've been reasonably conservative in what apps I place on my phone, and several (Pandora specifically comes to mind) were removed when permissions were extended to include contacts (Pandora, you listening?).

I'm waiting eagerly for the following capabilities:

To define at the phone level what information I'm willing to share. Existing "privacy controls" make a mockery of any semblance of either "privacy" or "control" by distributing vague and conflicting access among a great many applications with no ability to centrally audit them.

To specifically grant to specific applications specific rights. My location is something I'll disclose very guardedly (I disable GPS functions on my phone). Other rights generally shouldn't be shared.

To request and audit ALL information a given application has of me in a convenient electronic format (such as a database dump accessibly by MySQL or Postgresql). Such functionality is of course a three-edged sword, as what information the vendor has and I wish to request a third party might also request pretending to be me. Or having legal authority to make the request (though that's already the case), via subpoena or warrant.

My contacts list is off limits. Full stop. Specific contacts might be contacted by way of an application if specifically designated by me, but no other use may be made of their information. Hell, it's not even mine to give.

The existing state of smartphones is interesting, but it's also a little shop of horrors. And if application authors, smartphone manufacturers, and telecom providers don't get their act together on this Real Soon Now, we're going to see some horror stories.

Re: Path texts my entire phonebook at 6 AM

#353

How about another detail -- the fact that the message said the user had photos to share, when he didn't? There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type. Just curious, is there a way to sue/fine a company like this for false advertising, essentially?

We need to nip this in the bud. Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken. I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn…

Computers attempted various guises of "can't we all just get along".

At one time, it was cooperative multitasking and memory management. Programs were supposed to behave themselves and get out of one anothers' way. Except that, due to bugs or malice, some didn't. We called this world "DOS" (or pre OSX Macs).

Microsoft still attempts to allow vendors to install programs whereever the hell they want, and to, pretty please, not overwrite other program's infrastructure or system-level DLLs. Yeah. Right.

In the Linux world, we've solved this problem, if done right, though distro-managed, well, distributions. Any program can be included if it meets qualifications (generally limited to licensing requirements), and a sponsor steps up. Once included, the package gets the benefits of being included in the package lists, distributed over archive mirrors, and included in bugtracking and support systems. However it's also got to play along with the requirements of Debian Policy as to how it behaves on a system.

The proper way to address the issues of app privileges is to control privileges centrally on the device and grant them to specific apps. If a user doesn't wish to give an app, say, addressbook access, then they can deny it (or feed it a bogus addressbook). The app vendor can decide what they're going to do at this point, but what they can't do is override the user's explicitly stated limits.

Re: Path texts my entire phonebook at 6 AM

#354
post #182
post #142

Earlier quoted context omitted.

>Maybe it's time to create a Hippocratic Oath for developers to publicly commit to? This is silly. Stop trying to add grandeur to writing some code at X,Y startup/company. People don't die or get harmed when some social-messaging application spams someone. Code is a way to implement an idea. Most applications exist to make money. If this a shock to you, read the user agreement before installing/upgrading, uninstall t…

> People don't die or get harmed when some social-messaging application spams someone. Of course they get harmed: their time is wasted, and perhaps their concentration disturbed. This is a small harm to each victim, no doubt about it, but if you write code that makes your social-messaging application spam people then you're delivering that small harm to a large number of people. If your code wastes 10 seconds each, j…

Its also true that in search, your personal data is what the company uses to make a profit. And yet, one hears less complaints about that.

I'm not justifying either approach, by the way, just observing what I regard as a strange disconnect.

Re: Path texts my entire phonebook at 6 AM

#355
post #18

Why is it even possible for this to happen? Did someone really think it was a bright idea to provide an API to access people's personal data, and if so, why doesn't the phone tell them that before letting them install the app? On top of all of that, why wouldn't the phone provide a setting to restrict all personal/identifying information from being accessed by the app?

All of the smartphones I have used ask you before allowing access to your contacts. But many apps want to use these for legitimate purposes -- for example, Vine uses them to find people you're already friends with.

It's all about trusting what that company is saying "now".

They can change later and spam your list or use it for some other purpose. You can shame them publicly if you find it out. But then, it's already too late by that time.

Re: Path texts my entire phonebook at 6 AM

#360

Earlier quoted context omitted.

Engineers have this system already and have had it forever. In Canada (the one I'm familiar with) it is the P.Eng (Professional Engineer) license. I think the system should be licensing and involve losing that license if you commit an ethics violation. There would be unlicensed developers of course, but connecting the incentive to not do unethical things with the incentive to be part of the elite class in your profes…

> has worked pretty damn well for Engineers, Doctors and Lawyers. ... and has pretty much screwed over the rest of society, at least in the latter two cases. The legal and medical cartels have done incredible harm to their customers over the years. See http://mises.org/freemarket_detail.aspx?control=51 (law) and http://mises.org/daily/4276 (medicine) for details.

I have to say that your link about medicine is short of laughble.

Even if there was some bad "allopathy" back in the day, there is more bad eclictics and homeopathy right now. And to practice medicine you have to understand scientific method, especially falsifability.

And I also have to say that the "free market" idea isn't falsifable. "Let it to free market" rarely works.

Post reply on HN