Earlier quoted context omitted.
Like FB apps, even legit Android apps ask for the moon, with no option to dole out granular permissions. "The Weather Channel" is a default icon suggesting a free download on the Kindle Fire. It asks for: Set the wallpaper Send SMS messages Write to external storage Access info about Wi-Fi networks Access coarse location Initiate a phone call without going through the Dialer user interface for the user to confirm the…
Why does a weather channel app require recording audio?
Path uploads your entire iPhone address book to its servers
111–120 of 283 posts
Re: Path uploads your entire iPhone address book to its servers
#112Earlier quoted context omitted.
I think the simplest explanation is that he's playing dumb.
He almost certainly is either playing dumb or is dumb. If you're not dumb, you have to play dumb, because otherwise you'll be crucified.
Re: Path uploads your entire iPhone address book to its servers
#113Earlier quoted context omitted.
A postdoc in my lab published an academic paper that did exactly this: automated static analysis of iOS compiled binaries for privacy violations. As far as I know Apple was not interested. Here's the paper if you want to take a look: http://seclab.cs.ucsb.edu/media/uploads/papers/egele-ndss11....
Interesting. Quick question, how would you deal with things that call APIs via, for example, NSSelectorFromString, where the String is built in an obfuscated way? (I'll go back and read the paper in more detail soon)
So the analysis would fail to determine the method and class of a obfuscated string.
Re: Path uploads your entire iPhone address book to its servers
#114Earlier quoted context omitted.
You really don't need to upload address book for that. Sending just hash sum of each of phone, address, name, and email would be enough to make the matching.
Hashing phone numbers doesn't do much since the space is so small.
I would be more comfortable with this than giving them my entire address book, anyway.
Re: Path uploads your entire iPhone address book to its servers
#115Earlier quoted context omitted.
He almost certainly is either playing dumb or is dumb. If you're not dumb, you have to play dumb, because otherwise you'll be crucified.
Playing dumb. Hashing the information is such an obvious choice, there's really no plausible explanation for the developers to have not to consider it. They probably just figured "everyone else is doing this so what's the harm?"
Re: Path uploads your entire iPhone address book to its servers
#116I think this is Apple's problem really. Path is just one of many apps that probably do this without asking you. Ideally the OS should prompt you if an app wants access to your address book, just like it does for location.
Android apps must explicitly request a READ_CONTACTS permission. But even there, no one actually reads those permissions lists, and apps routinely ask for far more than they need. User authorization is a very weak security mechanism in the consumer space.
Re: Path uploads your entire iPhone address book to its servers
#117I think this is Apple's problem really. Path is just one of many apps that probably do this without asking you. Ideally the OS should prompt you if an app wants access to your address book, just like it does for location.
Android apps must explicitly request a READ_CONTACTS permission. But even there, no one actually reads those permissions lists, and apps routinely ask for far more than they need. User authorization is a very weak security mechanism in the consumer space.
For their Facebook Connect permissions, they ask for all the permissions… (that was true beginning of November, not sure they changed it since)
Re: Path uploads your entire iPhone address book to its servers
#118It would be nice to go a single week without seeing how utterly complete the notion of privacy has been destroyed.
Or was the first response, "hey, that's an invasion of my privacy!" I doubt anyone said that before the 1950's.
I think privacy is an invention of the late 20th century. I am truly curious if any real notion of "invasion of privacy" existed for most of man's history.
Re: Path uploads your entire iPhone address book to its servers
#119Earlier quoted context omitted.
Like FB apps, even legit Android apps ask for the moon, with no option to dole out granular permissions. "The Weather Channel" is a default icon suggesting a free download on the Kindle Fire. It asks for: Set the wallpaper Send SMS messages Write to external storage Access info about Wi-Fi networks Access coarse location Initiate a phone call without going through the Dialer user interface for the user to confirm the…
CyanogenMod allows the user to remove specific permissions frmo specific apps. If more users used CyanogenMod, more app developers would become compatible.
Re: Path uploads your entire iPhone address book to its servers
#120I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…
Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown over.