Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

121–130 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#121
post #99

I begin to understand what Richard Stallman has been saying all those years. Although I don't like the guy on the personal level, this incident make him completely right - running closed source software can compromise your rights. (rights to privacy in this case). I also want to thank the author of this post to discover this! I wanted to try Path some time ago, now I can safely avoid it without regret.

open source software can collect exactly the same information on you.

there was a furor recently where it was revealed that OS X and Windows collect data on what access points you have associated with. what was omitted was that linux does exactly the same thing: the wireless subsystem has a debug print (at a debug info level turned on in all major distributions) that will log the MAC address of the AP you just associated with.

it's still there, afaik.

Re: Path uploads your entire iPhone address book to its servers

#122
post #44

Dave Morin, Path's CEO just responded in a comment: http://mclov.in/2012/02/08/path-uploads-your-entire-address-... > Arun, thanks for pointing this out. We actually think this is an important conversation and take this very seriously. We upload the address book to our servers in order to help the user find and connect to their friends and family on Path quickly and effeciently as well as to notify them when friends…

>we proactively rolled out an opt-in for this on our Android client a few weeks ago and are rolling out the opt-in for this in 2.0.6 of our iOS Client, pending App Store approval. "Proactively?" How do you get into the Social Networking business and not see this issue coming before the first line of code is written? [re: hashing] >This is a good alternative solution which we'll look into. Thanks for the idea. Again,…

> "Proactively?" How do you get [...]

was about to say exact the same. the only thing I can add here is that if this wouldnt make headline, noone would have thought of opt outs.

Re: Path uploads your entire iPhone address book to its servers

#123

Earlier quoted context omitted.

Like FB apps, even legit Android apps ask for the moon, with no option to dole out granular permissions. "The Weather Channel" is a default icon suggesting a free download on the Kindle Fire. It asks for: Set the wallpaper Send SMS messages Write to external storage Access info about Wi-Fi networks Access coarse location Initiate a phone call without going through the Dialer user interface for the user to confirm the…

FWIW, if you have a rooted Android phone, you can install an app called "LBE Privacy Guard". It lets you install apps which require permission to send SMS, make calls, read contacts, access the network and a bunch of other things, but then prompts you when an app tries to do any of these things and lets you block/allow it temporarily/permanently.

[deleted]

Re: Path uploads your entire iPhone address book to its servers

#124

Earlier quoted context omitted.

Like FB apps, even legit Android apps ask for the moon, with no option to dole out granular permissions. "The Weather Channel" is a default icon suggesting a free download on the Kindle Fire. It asks for: Set the wallpaper Send SMS messages Write to external storage Access info about Wi-Fi networks Access coarse location Initiate a phone call without going through the Dialer user interface for the user to confirm the…

FWIW, if you have a rooted Android phone, you can install an app called "LBE Privacy Guard". It lets you install apps which require permission to send SMS, make calls, read contacts, access the network and a bunch of other things, but then prompts you when an app tries to do any of these things and lets you block/allow it temporarily/permanently.

Thanks for the tip - I'm going to go install that now and probably do a writeup.

Re: Path uploads your entire iPhone address book to its servers

#125

Earlier quoted context omitted.

You can access the Picture/Video library since iOS 4. It does prompt at least once for location access (apparently since they can contain GPS metadata), but it does not mention anything about why it's asking for that location access. https://developer.apple.com/library/ios/#documentation/Asset...

Really? It asks for location access to get access to your asset library? That is pretty stupid. Thanks for the heads up. I was unaware of the AssetLibrary framework.

This is because the photos contain GPS data about where they were taken.

Re: Path uploads your entire iPhone address book to its servers

#126
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

While I still support Path, the best PR move they could do right now is to pro-actively wipe all non-members' contact info from their servers, and then fast-track approval of the new "opt-in" version to the App Store, so that users can re-upload. Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown o…

That's not a PR move, that's what you do while crossing your fingers that state attorney generals and the FTC doesn't come after you.

Re: Path uploads your entire iPhone address book to its servers

#128
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

While I still support Path, the best PR move they could do right now is to pro-actively wipe all non-members' contact info from their servers, and then fast-track approval of the new "opt-in" version to the App Store, so that users can re-upload. Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown o…

If I were involved in this (and I'm not, I just think transparency - not privacy - matters) I would want the CEO and CTO of Path to create a video that is displayed to all relevant users in their mobile app. The first thing they do is apologise, they explain in plain words what people are up in arms about, the CTO reiterates that a) this was dumb and a poor choice but we are all human, b) what this means (eg: we did this not for our value but to deliver the best experience by matching you to your friends effortlessly) and c) why this matters on a macro scale for the industry.

I would respect a company that did this because they are not only addressing users that are aware of it but also users that are not aware (but are affected.)

Wiping data is fine but it feels like it doesn't solve the crux of this problem -- communication and transparency. Companies make mistakes and they can fix them, sure, but communicating about them? that's much cooler. (I suspect this is overkill unless mainstream news catches on this - which seems unlikely)

Re: Path uploads your entire iPhone address book to its servers

#130
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Mind-blowing level of arrogance. Path just ensured that I will never use their product and that I will actively discourage all my friends, colleagues, co-workers, and users that I support (who number 100 or so) from ever using Path, too.

"This is currently the industry best practice"? That's the biggest bullshit line I have ever heard. No, it's most certainly NOT a "best practice", and even if it were, it shouldn't be, and as a CEO, you're supposed to be bright enough to know this. And if you don't know this, you're supposed to be bright enough to make up a better excuse when you get caught. Hint: This ain't it.

Post reply on HN