Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

141–150 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#141
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Really? Apple would never do this? http://radar.oreilly.com/2011/04/apple-location-tracking.htm...

This data was never sent to Apple servers.

Re: Path uploads your entire iPhone address book to its servers

#142
post #128

Earlier quoted context omitted.

While I still support Path, the best PR move they could do right now is to pro-actively wipe all non-members' contact info from their servers, and then fast-track approval of the new "opt-in" version to the App Store, so that users can re-upload. Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown o…

If I were involved in this (and I'm not, I just think transparency - not privacy - matters) I would want the CEO and CTO of Path to create a video that is displayed to all relevant users in their mobile app. The first thing they do is apologise, they explain in plain words what people are up in arms about, the CTO reiterates that a) this was dumb and a poor choice but we are all human, b) what this means (eg: we did…

I wouldn't be surprised if there is an engineer there who voiced concerns, but whether they still work there or not would be an open question. Wherever they are, they should be found and put in charge of development.

Re: Path uploads your entire iPhone address book to its servers

#143
Just a quick note to also point out, regarding this from the CEO: "if you'd like your account deleted, including all data, we're happy to do this as well."

I emailed to have my Path account deleted a few weeks ago and was told it had been 'deactivated'. After querying this, it was confirmed that they did not yet have the functionality to delete your data, only hide it. Worrying that he said they can.

Re: Path uploads your entire iPhone address book to its servers

#144
One can fuel a lot of user engagement by scraping the address book and notifying users every time one of their contacts signs up.

The "Beluga" app did this, without user permission or warning, and it boomed ahead of competition that did not. "Kik" did something similar. "Industry best practice" indeed.

Sadly, it's a winning strategy, and will continue to be until someone fixes the rules of the game.

Re: Path uploads your entire iPhone address book to its servers

#145
post #128

Earlier quoted context omitted.

While I still support Path, the best PR move they could do right now is to pro-actively wipe all non-members' contact info from their servers, and then fast-track approval of the new "opt-in" version to the App Store, so that users can re-upload. Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown o…

If I were involved in this (and I'm not, I just think transparency - not privacy - matters) I would want the CEO and CTO of Path to create a video that is displayed to all relevant users in their mobile app. The first thing they do is apologise, they explain in plain words what people are up in arms about, the CTO reiterates that a) this was dumb and a poor choice but we are all human, b) what this means (eg: we did…

I would want the CEO to:

1) Immediately delete all of the non-user data

2) Send an apology e-mail to each Path user explaining the situation

3) Write, by hand, a corresponding apology letter for each Path user

4) Hold a townhall-style meeting in which members of the public can ask him questions

5) Pay, out of pocket, the travel expenses of anyone who attends the townhall meeting

6) Wear an indicator of shame (large necklace or a sign) for as long as he is CEO of the company

Re: Path uploads your entire iPhone address book to its servers

#146

It would be nice to go a single week without seeing how utterly complete the notion of privacy has been destroyed.

Here's a question: was there a concept of privacy 100 years ago? Or 500? Whenever someone had a baby, or bought a cow, or had an affair on their spouse, didn't everyone in town know about it? Did they ask people's permission when the first telephone book was published? Or was the first response, "hey, that's an invasion of my privacy!" I doubt anyone said that before the 1950's. I think privacy is an invention of the…

This is a patently absurd notion.

I haven't heard an assertion so patently foolish and I'll considered since the Path CEO claimed that uploading every users "little black book" onto the Path servers without permission or notification was an "industry standard best practice."

What a bunch of hogwash.

Re: Path uploads your entire iPhone address book to its servers

#147
Can someone explain to me exactly how I could be harmed by this? My contact list is just a list of names and phone numbers of people I contact. Even if I had an escort service in there or something, I don't think anyone on Path's end is individually looking through the data.

Re: Path uploads your entire iPhone address book to its servers

#148
post #44

Dave Morin, Path's CEO just responded in a comment: http://mclov.in/2012/02/08/path-uploads-your-entire-address-... > Arun, thanks for pointing this out. We actually think this is an important conversation and take this very seriously. We upload the address book to our servers in order to help the user find and connect to their friends and family on Path quickly and effeciently as well as to notify them when friends…

If all they care about is matching users up, couldn't they just use hashes of the relevant data? EDIT: possibly even better, they could use a Bloom filter, similarly to how Chrome uses them to filter malicious websites without sharing your entire browsing history with Google.

[deleted]

Re: Path uploads your entire iPhone address book to its servers

#149
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Really? Apple would never do this? http://radar.oreilly.com/2011/04/apple-location-tracking.htm...

The data was stored on the phone, not sent to Apple, and certainly not to advertisers.

The data was used for GPS assistance -- it was a cache that triangulated your location from cell phone towers to help get a faster GPS lock (and to find your location without GPS if you’re getting bad GPS signal).

If you're concerned about the police finding out your moves, they have access to such information from the tellcos themselves with your cell number, whereas to use those stored GPS logs they would need physical access to your iPhone.

Re: Path uploads your entire iPhone address book to its servers

#150

Can someone explain to me exactly how I could be harmed by this? My contact list is just a list of names and phone numbers of people I contact. Even if I had an escort service in there or something, I don't think anyone on Path's end is individually looking through the data.

The question isn't whether or not they are, it's the very possibility of them being able to.
Post reply on HN