Earlier quoted context omitted.
Though it's quite a difference whether the contacts are checked client-side or all sent over to THEIR server including all (unnecessary) info.
How do you propose to check them client side? :) You still have to send each contact over to the server...
Path uploads your entire iPhone address book to its servers
241–250 of 283 posts
Re: Path uploads your entire iPhone address book to its servers
#242Re: Path uploads your entire iPhone address book to its servers
#243Earlier quoted context omitted.
If “Apple would never do this to their users”, then how is it that Apple provided the API which Path used to do this to their users, without requiring the users to give the app permission (as they do with, say, allowing an app access to a user's location)?
Because it requires 2 API's both of which have legitimate uses: 1.) Get the user's address book and 2.) upload it to a server. Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.
1) Get the user's address book 2) upload _something_ to a server.
A user could give permission to both.
Re: Path uploads your entire iPhone address book to its servers
#244Earlier quoted context omitted.
That's not a PR move, that's what you do while crossing your fingers that state attorney generals and the FTC doesn't come after you.
I've just: 1) saved their Privacy Policy and Terms of Use 2) requested a complete deletion of our family's account 3) requested deletion of any/all stored information 4) considering contacting our lawyer As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list - that's an insane, willful, and quite unexpected violation o…
Don't really like this kind of argumentation.
Re: Path uploads your entire iPhone address book to its servers
#245I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…
"Proactively" doesn't mean acting after you've been caught.
Actually, it means exactly the opposite.
Re: Path uploads your entire iPhone address book to its servers
#246Earlier quoted context omitted.
As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list Ok, I'm going to pick on you for a second. Hold the downvotes everyone! Let me explain. This seems like a bit of a knee-jerk reaction akin to "think of the children!" or the whole child porn scare-mongering that politicians engage in that we on HN are always critic…
> I'm unclear on why them having the information you cited First of all, my wife and I actually read and attempted to analyze Path's Terms and Privacy Policy before joining. They did not in ANY WAY have our permission, either implicitly or explicitly to collect private information about our children, who are, 3 and 4 years old. > along with dozens or hundreds of other contacts from your address book From path.com/abo…
What for an argument is this. So if he doesn't have a spouse or children he can't be right. What kind of populist are you?
Re: Path uploads your entire iPhone address book to its servers
#247Earlier quoted context omitted.
[deleted]
One of my kids has special needs. This means he rides a certain bus and goes to a certain school. It would be trivial to uniquely identify him for the rest of his LIFE with only the information contained in my contacts list. So now, without consent, this "private" "friends and family"-based app I installed on my phone, plus it's company, plus any other company they choose to do business with, or any entity that acqui…
Do you also buy snake oil if it comes with a document using lots of difficult sounding words but ends saying it cures everything?
Re: Path uploads your entire iPhone address book to its servers
#248Earlier quoted context omitted.
Wait: What about MY INFORMATION if I've never installed Path? If someone I know with my contact information installs Path, does that mean that my information is stored on their servers? How can I remove my information if I've never installed Path before? It doesn't seem right that my contact information, which I have kept private, because someone I know has uploaded that information. Do I not have a right to keep tha…
Clearly there are a lot of WTFs going on at Path, but this isn't one of them. > Do I not have a right to keep that information private? But you didn't. You gave it to someone else. It's not your information any more. Information about you is not information you own . Privacy and anti-spam laws in various jurisdictions cover what an organisation can do with information they collect about private individuals, but that…
Re: Path uploads your entire iPhone address book to its servers
#249Earlier quoted context omitted.
Yes, good point. And regarding state attorney generals, how is this not data theft? It seems to go far beyond privacy issues, the program is in every way that matters a trojan that steals personal data. I can't see how it could not be considered so given the details of what was discovered.
If I were an evil-state-attorney-general, I'd be calling up Path and saying "Here's a list of names (unsaid - of suspected drug dealers), please forward all of their details and contacts, and the details and contacts of anyone who lists them as a contact. Thanks"
Re: Path uploads your entire iPhone address book to its servers
#250Earlier quoted context omitted.
Because it requires 2 API's both of which have legitimate uses: 1.) Get the user's address book and 2.) upload it to a server. Installing an application implies a higher level of trust than a web application. You can't prompt the user for every API that might have a nefarious use. Location data is also much more sensitive so it makes sense to prompt the user for that.
I guess it's more like 1) Get the user's address book 2) upload _something_ to a server. A user could give permission to both.
You'd have solved the problem, but created a horrible user experience instead.