Live data from Hacker News

We are sorry

blog.path.com

121–130 of 220 posts

Re: We are sorry

#121
post #119

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened. I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come…

You are using a very fine definition of "mistake", more like a synonym for "bug" or "defect".

But it's also possible for management to make a mistaken decision, and that's what Path is meaning here.

Re: We are sorry

#122
post #43

Earlier quoted context omitted.

Except for the "and then implement hashing from here on out." part. So, they haven't changed their implementation, they've just added the ability to opt out of the poor implementation.

So you can opt out then, since they're not doing enough to address your concerns. They're being upfront about it, though, and putting that choice in your hands.

> putting that choice in your hands

They are putting a false choice in your hands that they hope will lead to the status quo while still giving a show of making good on this issue. They could, through sophisticated hashing and matching algorithms, do the user matching without ever learning your contact details. But they aren't bothering to do that. Instead they are just planting a checkbox in front of the user before they go and violate their privacy, and they hope that the vast majority of users will just check it and they'll only lose data from a minority of privacy nuts. Which means Path will end up exactly where they would have been anyway - with a giant database of personally sensitive information sitting unencrypted on their servers, waiting to be exploited, abused or leaked.

Re: We are sorry

#123
So what changed really?

Yesterday morning Path thought it was perfectly OK to scrape user's Address Book behind their back, and now they suddenly acquired moral backbone and ethics? Please give me a break. What they did today is the only sensible thing there was to try and save the company, so they did it, but should they be commended for that? Hell, no. Would you commend a landlord for dismounting a hidden camera in your bathroom? Doubt it.

The fish rots from the head. The company is still under the exact same management it was yesterday morning. Nothing's changed. I wish Path a slow, painful and very public demise to serve as a dire warning to others in similar positions.

Re: We are sorry

#125
Is anyone cataloging public apologies like this for future reference by start ups and other online businesses?

Re: We are sorry

#126
post #119

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened. I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come…

> if they honestly didn't understand that what they did was wrong they don't deserve to be trusted again, not never. And if they did understand that it was unethical, which they undoubtedly did, it is even worse.

This is precisely my reaction to Facebook's Beacon. I decided that they were either completely inept or amoral. In either case I don't trust them.

Re: We are sorry

#127
post #106
post #91

Earlier quoted context omitted.

Preface: I will joining Path this Summer, but I do not speak for the company in any way, nor have I spoken with them about the situation. This is a purely technical reply... You cant guarantee a unique hash. When you hash users' data there is the possibility of collision; this probability grows with every new user. Without identifying data of some sort, it's difficult (impossible?) to get the exact user.

That is incorrect. SHA1 still has no known collisions despite years of research and computing power dedicated to finding just one collision. Edit: Furthermore since the set of valid emails and phone numbers is a very restricted set of input, it is extremely likely that there are literally no two valid email/phone numbers that SHA1 hash to the same value.

I agree that it's practically not a concern, but the local part of an email address[0] is up to 64 characters in an alphabet of size 72, and the domain part is 253+ characters in an alphabet of size 38, giving the valid email space a size of greater than 3e519, which is enough to guarantee collisions in SHA-512 and all of the SHA-3 finalists.

[0] http://tools.ietf.org/html/rfc3696

Re: We are sorry

#128
post #119

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened. I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come…

Only problem is: It was not a mistake. They did this only to cover their asses and that has been the only concern they've ever had.

Well, you can make a mistake intentionally.

As in: "I intentionally opted for course A, and I realize it was a mistake".

Re: We are sorry

#129

If you accept and later decide you would like to revoke this access, please send an email to service@path.com and we will promptly see to it that your contact information is removed. My only qualm is that you can't revoke the permission from within the app. The opt-out should be as easy as the opt-in.

I suspect this is because technically it would be a PITA to allow users to allow/revoke at their own discretion.

While I agree that it would be nice from the users point of view, the impact of pulling data from the kind of analysis I'd expect them to be doing is going to be a data analysts worse nightmare (i.e. holes in your data set can sporadically appear, so nothing is concrete and all analysis must be reverse-justifiable). If you can reduce the frequency this happens but still give the users the option, this seems like the best of both worlds.

Re: We are sorry

#130

I like the "sorry if" comment ...

Yeah, I don't consider an apology that blames ME an apology. You screwed up, full stop. You're shirking your responsibility if you're talking about my response to your mistake.
Post reply on HN