Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

231–240 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#231
post #229

Earlier quoted context omitted.

> I'm unclear on why them having the information you cited First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. > along with dozens or hundreds of other contacts from your address book From path.com/abo…

> They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. What are you talking about? Do you expect them to perform complex data analysis to figure out that certain contacts are young children, and then explicitly ask permission to share those? Or do you expect them to preemptively ask for any potential sensitive conta…

> What are you talking about? Do you expect them to perform complex data analysis to figure out that certain contacts are young children, and then explicitly ask permission to share those? Or do you expect them to preemptively ask for any potential sensitive contact information? "Can we use your children's information?" "Can we use your in-laws' information?" "Can we use the address of the President's safehouse?" Etc.

Just a "Can we upload your entire address book?" would have worked. Or perhaps listing "Your entire address book" in the "What personal information do we collect?" section of their Privacy Policy.

Re: Path uploads your entire iPhone address book to its servers

#232
post #219

Earlier quoted context omitted.

> I'm unclear on why them having the information you cited First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. > along with dozens or hundreds of other contacts from your address book From path.com/abo…

I think you're spot on here mash but I have a disconcerting question. How do you intend to handle this situation with every other app you, and presumably your wife, have ever downloaded? Specifically those that may not be as 'transparent' as Path? I ask because we would be foolish to think the developers of some less then typical quality apps have, or will, certainly exploit this for their own monetary gain.

> How do you intend to handle this situation with every other app you, and presumably your wife, have ever downloaded?

Not sure yet. Path is actually the first (and will certainly be the last) social network I've ever joined - and it was precisely because it was supposed to be private and they had a pretty reasonable privacy policy. I remember something of this nature after the App Store was first released but had honestly thought it was a fixed issue.

On our lap/desktops we use prompting firewalls and on occasion will even watch suspicious apps or behaviors, if you will, where on iOS this is much harder.

I have an idle FreeBSD box and may start mitm'ing like OP did, but seriously pouring through the kind of output a home network produces doesn't sound like fun at all and I already know that going back to a dumb phone would probably be just as easy.

Re: Path uploads your entire iPhone address book to its servers

#233
post #229

Earlier quoted context omitted.

> They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. What are you talking about? Do you expect them to perform complex data analysis to figure out that certain contacts are young children, and then explicitly ask permission to share those? Or do you expect them to preemptively ask for any potential sensitive conta…

> What are you talking about? Do you expect them to perform complex data analysis to figure out that certain contacts are young children, and then explicitly ask permission to share those? Or do you expect them to preemptively ask for any potential sensitive contact information? "Can we use your children's information?" "Can we use your in-laws' information?" "Can we use the address of the President's safehouse?" Etc…

That still wouldn't be specific permission to share children's information specifically, which is what it seemed like your were requesting.

Re: Path uploads your entire iPhone address book to its servers

#234

Can someone explain to me exactly how I could be harmed by this? My contact list is just a list of names and phone numbers of people I contact. Even if I had an escort service in there or something, I don't think anyone on Path's end is individually looking through the data.

An employee at Path might very well decide to start looking through that data. There have been other cases where employees gave in to temptation to access someone's data. Imagine for example if a celebrity is involved and someone decides to leak their address book. Now one would hope that employees wouldn't have unrestricted data to this access, but one would also hope Path wouldn't do this in the first place. The fa…

Also, for apps with private messaging systems like Path, I'd be far more concerned about rogue employees looking through the messages I send than contact list data. I'm far more likely to have sensitive information in there.

Re: Path uploads your entire iPhone address book to its servers

#235
post #141

Earlier quoted context omitted.

This data was never sent to Apple servers.

This is false, they do not send a recorded record of your movements to apple, however they do send GPS+WLAN BBSID correlation data back to apple,[1] they claim the processed is anonymized, but there are very powerful deanonymization techniques that can be applied to large data sets. [2][3][4] I live in almost the middle of nowhere, i guarantee nothing like google maps, etc has ever passed this way to map my WIFI poin…

That's circumstantial evidence at best.

Here's more useless analytical evidence to suggest that most people don't know everything: when Samy Kamkar[0] first demonstrated geolocation via BSSIDs, I tried out every wireless router in my house, including one that had not been plugged into a wall in over 4 years and never at my current residence, long before Google started wardriving for street maps and well before the first iPhone came out. He was able to accurately map it to my old residence. That means that sometime before December of 2006, someone or something was able to snatch my BSSID from someplace, accurately note it's physical location in the world, and store that away in some database that was used almost 4 years later. I can guarantee you it was not Apple, and I'd be damned surprised if it was Google at that time.

[0] http://samy.pl/mapxss/

Re: Path uploads your entire iPhone address book to its servers

#237
post #183

1. I just changed my phone # 2. I notified all of my contacts to change their phone #s 3. I contacted both Apple and my State senator. I am outraged by this scandal, and I still can't bring myself to believe that Path has been collecting this sensitive personal information. My 6-month old's pediatrician's # is in my phone. If this were EVER exposed or shared with a 3rd party, I can only image what kind of damage coul…

You can contact Path and they will remove the data for you.

Re: Path uploads your entire iPhone address book to its servers

#238
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

The problem is any site that decides to grab this data gets an advantage over any site that does not, and the regular users simply don't care enough.

About four years ago, a new trend just started emerging. Sites would ask user's for their Gmail passwords and scrape all the users' contacts to invite them for their service. I remember this because I was at a company where I refused to implement a service that requested a user to enter their Gmail password. They got someone else to do it. The issue was that we had competitors using this tactic and they were gaining a lot of users. Unless you have a way to level the playing field, you'll end up just punishing the ethical companies.

Re: Path uploads your entire iPhone address book to its servers

#239

Can someone explain to me exactly how I could be harmed by this? My contact list is just a list of names and phone numbers of people I contact. Even if I had an escort service in there or something, I don't think anyone on Path's end is individually looking through the data.

"I don't think anyone on Path's end is individually looking through the data."

Oh, really? You'd be surprised. http://gawker.com/5637234/

Re: Path uploads your entire iPhone address book to its servers

#240
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

> we believe users need further transparency on how this works, so we've been proactively addressing this

I feel like shooting someone every time I see them (or for that matter, anyone else) doing things 'proactively' (at least three times in the comments of original blog post). My BS meter goes all red on that. What does 'proactively addressing issue of transparency' mean? Even the sentence itself is not transparent.

I seriously wonder why so many companies communicate using language like that. Is it because of law? If instead, he'd say "well, we really screwed that one up and we want to apologize; right now we're trying to figure out how to fix those issues, please be patient" - could that get them sued, or what?

Post reply on HN