Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

271–280 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#271

Earlier quoted context omitted.

An employee at Path might very well decide to start looking through that data. There have been other cases where employees gave in to temptation to access someone's data. Imagine for example if a celebrity is involved and someone decides to leak their address book. Now one would hope that employees wouldn't have unrestricted data to this access, but one would also hope Path wouldn't do this in the first place. The fa…

I don't know any of the Path employees personally, why would they decide to go after me? The possibility seems rather remote.

Maybe not you personally, but think of the NOW scandal going on right now. Information about people's mobile contact info is valuable to a number of organizations in ways not immediately apparent.

Re: Path uploads your entire iPhone address book to its servers

#272
post #21
post #6

I think this is Apple's problem really. Path is just one of many apps that probably do this without asking you. Ideally the OS should prompt you if an app wants access to your address book, just like it does for location.

Android apps must explicitly request a READ_CONTACTS permission. But even there, no one actually reads those permissions lists, and apps routinely ask for far more than they need. User authorization is a very weak security mechanism in the consumer space.

But even there, no one actually reads those permissions lists, and apps routinely ask for far more than they need.

Lots of people do read those permission lists, and they are one of the most commonly referenced complaints in app reviews. A firestorm arose when an Angry Birds update inexplicably added the ability to send SMS'.

Further it focuses a spotlight when an app does request a permission that seems out of place. Ideally when Google evaluates app for their "staff's picks" (the "optional curation") they consider threat surface area.

Re: Path uploads your entire iPhone address book to its servers

#273

Earlier quoted context omitted.

I don't want to rag on you, but the answer to this is really, really obvious--Path certainly screwed up, but that's no reason to lose your head and start making silly claims. iOS doesn't know what's being uploaded by an app. It can't know. They could ask every time an application wants to access your contacts (which, I think, would really suck for UX, and it'd be a context-free question without indication of what the…

Ok, how about asking the first time?

So...what, exactly? "This thing wants to use your contacts." It's a social network. It can be expected to want to use your contacts. It has no bearing on how Apple is supposed to avoid letting Path package up your contacts and send them to Path's servers.

Re: Path uploads your entire iPhone address book to its servers

#274
post #235

Earlier quoted context omitted.

This is false, they do not send a recorded record of your movements to apple, however they do send GPS+WLAN BBSID correlation data back to apple,[1] they claim the processed is anonymized, but there are very powerful deanonymization techniques that can be applied to large data sets. [2][3][4] I live in almost the middle of nowhere, i guarantee nothing like google maps, etc has ever passed this way to map my WIFI poin…

That's circumstantial evidence at best. Here's more useless analytical evidence to suggest that most people don't know everything: when Samy Kamkar[0] first demonstrated geolocation via BSSIDs, I tried out every wireless router in my house, including one that had not been plugged into a wall in over 4 years and never at my current residence, long before Google started wardriving for street maps and well before the fi…

its hardly dismiss-able as circumstantial evidence when apple themselves have said they do it.

Re: Path uploads your entire iPhone address book to its servers

#275
post #175
post #107

Earlier quoted context omitted.

From what I have seen you can only remove those permissions "late". Ie you have to black list permissions, you cannot deny them right away. From my understanding this would not protect me fully since apps could do their thing before I disabled it.

As I understand it: They can't. If you do not open them manually or restart you phone (if they have the permission RECEIVE_BOOT_COMPLETED) They are not executing. You can install them and revoke certain permissions before they are running for the first time.

Nice!

I also remember seeing that permissions were reset on reboot, but that might have been some other setup, not CM.

Re: Path uploads your entire iPhone address book to its servers

#276
This is an accident waiting to happen. Whoever does this is doing it wrong. The case was well-made here by Colin Percival (the tarsnap guy) in his blog: "Playing chicken with cat.jpg" http://www.daemonology.net/blog/2012-01-19-playing-chicken-w...

>> "The answer isn't for (any company) to prove that they can be trusted; the answer is to ensure that their customers don't need to trust them ... The best way to avoid privacy breaches is not to formulate a detailed privacy policy; it's to reduce your capabilities so that you're unable to violate anyone's privacy"

Re: Path uploads your entire iPhone address book to its servers

#277
post #219

Earlier quoted context omitted.

I think you're spot on here mash but I have a disconcerting question. How do you intend to handle this situation with every other app you, and presumably your wife, have ever downloaded? Specifically those that may not be as 'transparent' as Path? I ask because we would be foolish to think the developers of some less then typical quality apps have, or will, certainly exploit this for their own monetary gain.

> How do you intend to handle this situation with every other app you, and presumably your wife, have ever downloaded? Not sure yet. Path is actually the first (and will certainly be the last) social network I've ever joined - and it was precisely because it was supposed to be private and they had a pretty reasonable privacy policy. I remember something of this nature after the App Store was first released but had ho…

I was worried that would be the response. Not that I think it's a bad idea, its just such substantial shift from what I'm used to.

I would be curious for someone to do this with other apps. Even those that aren't social networks. I have a strong inkling that most of the top free apps are doing this without any of us knowing.

Re: Path uploads your entire iPhone address book to its servers

#278
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Apple would never do this to their users.

Perhaps not, but remember that Apple are supposed to have approved all Apps on the AppStore. It's supposed to be for user benefit, to prevent malware, viruses and bad applications. However this app was approved by Apple. What, exactly, is the point of the AppStore approval/walled garden approach if this is acceptable?

Re: Path uploads your entire iPhone address book to its servers

#279
post #241
post #41

Earlier quoted context omitted.

How do you propose to check them client side? :) You still have to send each contact over to the server...

As Matt Gemmell proposed: send over the hash codes of the email addresses or whatever else needs to be compared.

Yeah, but you still have to store the hashes server side in the case where you want to notify people when their friends join (which is how Path was using the data).
Post reply on HN