"The Address Book framework provides access to a centralized contacts database, called the Address Book database, that stores a user’s contacts."
It has been there since iOS 2.0
201–210 of 283 posts
"The Address Book framework provides access to a centralized contacts database, called the Address Book database, that stores a user’s contacts."
It has been there since iOS 2.0
I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…
If “Apple would never do this to their users”, then how is it that Apple provided the API which Path used to do this to their users, without requiring the users to give the app permission (as they do with, say, allowing an app access to a user's location)?
1.) Get the user's address book and 2.) upload it to a server.
Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.
Honest question: Isn't this within the kind of behavior that AppStore reviews are supposed to prevent, at least if there isn't an app specific functional explanation for it? Does Apple have a list of what kind of behavior like this is tolerated or does word just get out about what they don't reject?
Well, since you only ever only submit the compiled application binary to Apple, it'd be pretty darn hard for them to detect behaviour like this. Especially if the code to do so is obfuscated, and/or the data is smuggled out via SSL (or worse, steganography-style piggy-backed on to other data). Sometimes it's tempting to speculate whether the real purpose of the app store review team is just to ensure developers aren'…
Earlier quoted context omitted.
If “Apple would never do this to their users”, then how is it that Apple provided the API which Path used to do this to their users, without requiring the users to give the app permission (as they do with, say, allowing an app access to a user's location)?
Because it requires 2 API's both of which have legitimate uses: 1.) Get the user's address book and 2.) upload it to a server. Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.
I'm pretty sure that Instagram is doing this too as I get push notifications whenever a friend signs up. Can anyone confirm?
I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…
Earlier quoted context omitted.
Wait: What about MY INFORMATION if I've never installed Path? If someone I know with my contact information installs Path, does that mean that my information is stored on their servers? How can I remove my information if I've never installed Path before? It doesn't seem right that my contact information, which I have kept private, because someone I know has uploaded that information. Do I not have a right to keep tha…
Clearly there are a lot of WTFs going on at Path, but this isn't one of them. > Do I not have a right to keep that information private? But you didn't. You gave it to someone else. It's not your information any more. Information about you is not information you own . Privacy and anti-spam laws in various jurisdictions cover what an organisation can do with information they collect about private individuals, but that…
Earlier quoted context omitted.
That's not a PR move, that's what you do while crossing your fingers that state attorney generals and the FTC doesn't come after you.
Yes, good point. And regarding state attorney generals, how is this not data theft? It seems to go far beyond privacy issues, the program is in every way that matters a trojan that steals personal data. I can't see how it could not be considered so given the details of what was discovered.
Brought to you by: https://path.com/team Their collective decision making has proven to be a huge liability. Would you hire them for your next venture? A 14 year old girl could tell you that her address book is private, private, private!
Umm, hell yes I'd hire them. And so would any major software engineering company in the world. You seriously think that this is out of the ordinary or unusual? How many huge privacy fiascos has Facebook had? And yet, they're about to IPO for $100 billion. The only group who really cares about this is on HN. In a week, most of us will have moved on to the next big drama. In a year, no one will remember this at all. Th…
Downvotes me all you want. The fact remains that, if you asked a teenage girl if it would be OK to grab her address book without consent it is very clear what kind of an answer you'd get. Why is it that a bunch of smart adults think that they can get away with it then? The apology is bullshit. They knew what they were doing and got caught.
As far as only HN caring, I'll bet that users of this app would disagree with you on that point. How many people do you know that are OK with a company of strangers secretly downloading their private data onto their servers?
This, in my opinion, is a very serious transgression.
Earlier quoted context omitted.
I've just: 1) saved their Privacy Policy and Terms of Use 2) requested a complete deletion of our family's account 3) requested deletion of any/all stored information 4) considering contacting our lawyer As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list - that's an insane, willful, and quite unexpected violation o…
As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list Ok, I'm going to pick on you for a second. Hold the downvotes everyone! Let me explain. This seems like a bit of a knee-jerk reaction akin to "think of the children!" or the whole child porn scare-mongering that politicians engage in that we on HN are always critic…
First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old.
> along with dozens or hundreds of other contacts from your address book
From path.com/about
Path should be private by default. Forever. You should
always be in control of your information and experience.
I was never once asked, agreed to, or gave consent to allow anyone to collect sensitive information about where are children are schooled at, what buses they ride, where they receive medical treatment at, or OTHER PLACES I LEFT OUT OF THE ORIGINAL LIST BECAUSE THEY ARE PRIVATE TO MY FAMILY. :)> for millions of users
"kill one, it's murder - kill 1,000,000 it's a statistic" - this isn't about your children - it's about mine. ;)
> constitutes some kind of terrible threat to your children
Where did I say this was a "terrible threat" to my children? Maybe it is, maybe it isn't - bottom line is we did not consent to it. And perhaps we just want to protect our underage children from having behaviorial profiles or credit risk assessments built up on them before they reach kindergarten.
Interestingly enough, according to Path it is VERY reasonable that I should protect my children's information:
We take reasonable measures to protect your personal information
in an effort to prevent loss, misuse and unauthorized access, disclosure,
alteration and destruction. Please be aware, however, that despite our efforts,
no security measures are perfect or impenetrable and no method of data
transmission can be guaranteed against any interception or other type of misuse.
Combined with: (You)...accept all risks of unauthorized access to the Registration Data and any other information you provide to us.
My risk, right?> But maybe there's a specific threat in mind that I'm not thinking of?
Yes, there is. And I acknowledge that you might live in a world where you have no problem allowing anyone in the world to know any detail they can illicitly sneak out of your phone about you, your family, and your friends - but most of the rest of us don't.
For fuck's sake a UIKit dialog box and handler code is less than a dozen lines of code and then NONE OF THIS WOULD BE AN ISSUE.
> Anyway, just thought your response was a little over the top, and more informed by emotion than reason.
I'm curious, do you have a spouse or children?