Live data from Hacker News

An open challenge to PandoDaily

scripting.com

31–40 of 72 posts

Re: An open challenge to PandoDaily

#31
post #25

Earlier quoted context omitted.

No, I'm aware of that. What I am saying is that uploading data to an app, no matter what that app may be, is not the same as posting it publicly. When you upload to an app, the makers of that app have access to your data. Don't get me wrong- that's a bad thing. But if you upload your data publicly, anyone in the world has access to your data. Drastically different.

Nothing personal, but I think it's naive to assume that. I once did a deal with a software publisher that required me to turn over the source code. One day I came into the office and found a disk clearly labeled as the source for my product, on the receptionists desk. That was pretty close to public, and I remember that every time I let something sensitive out of my control. Also every few months I have to change my…

Well, the credit card example you give is a good one- you can go through life without paying for anything by credit card, and your credit card will never be stolen. If you do pay for things by credit card, there is a chance that it will be stolen. If you post your credit card details publicly there is a 100% guarantee it will be stolen.

I think the same applies to apps. There is a sensible middle ground in there somewhere, and the new permission request alerts from Apple will go a long way to helping with that. But no, never any guarantees about anything.

Re: An open challenge to PandoDaily

#32

Earlier quoted context omitted.

> Uploading your address book to an app is different than posting it publicly because people trust Path their their data. Are you sure about this? Has every Path user really reviewed Path's data security policies and deemed them satisfactory? Do Path users even have access to that information? And if they did, would most of them be in any position to evaluate it knowledgeably? Or isn't it more likely that they trust…

I'd argue that ven if they read the security policy they wouldn't understand it anyway. When you're surrounded by hackers it's easy to think everyone has some basic understanding of computers but in reality most people are lucky if they know how print a damn Word document. This really is a false comparison. Accessing an address book for the app's use only and accessing the address book for public publishing are so fa…

> People don't seem to care until someone writes a blog post that tells them they should care.

But that's the point, isn't it? They shouldn't have to care! People shouldn't have to be security experts to use a phone. The phone should protect them by default and make them have to jump through hoops to waive that protection, rather than the other way around.

Re: An open challenge to PandoDaily

#33
post #25

Earlier quoted context omitted.

Sorry but I think you're missing some data here. Every app on the iPhone can upload your address book, pictures and calendar data to their servers, whether or not they have anything to do with contacts. Every app. It's worth taking a look at the trivial crap we put on our iPads and iPhones thinking they're harmless, when each of them could be leaking all our private bits everywhere.

No, I'm aware of that. What I am saying is that uploading data to an app, no matter what that app may be, is not the same as posting it publicly. When you upload to an app, the makers of that app have access to your data. Don't get me wrong- that's a bad thing. But if you upload your data publicly, anyone in the world has access to your data. Drastically different.

Because there's no way that your data, once uploaded to the app vendor's servers, can ever leak out. Right?

No way they are running their operation on the cheap and don't have their servers secured against intrusion.

No way they can be inexperienced developers and build an API that leaks information to improperly authenticated requests.

No way they can have a disgruntled employee throw a torrent of it all up when he gets fired.

No way they can get bought by someone with fewer scruples and hand your data over to them as part of the acquisition.

Re: An open challenge to PandoDaily

#35

I think the point of the PandoDaily post was that you're already trusting apps with access to your data. You've granted permission for the app to access it any time. When I grant permissions for an app to access by data, this doesn't mean I am allowing my data to be published for the world to see. That's what privacy policies are for.

...and Dave response's point is that there's no way to guarantee the privacy policy is obeyed, unless it is enforced one way or another. User expectations with regards to the private data were supposed to be guarded by App Store approval process and Apple's iOS access restrictions, however this and now photos somehow slipped through. Pando's mocking of the situation with clipboard example is off the mark. User's expe…

Privacy policies can rarely if ever be enforced or guaranteed. This isn't something new. I can't think of many cases where a third party guarantees adherence to privacy policies. Ultimately if you give someone access to your data, you have to trust that they treat that data appropriately.

Re: An open challenge to PandoDaily

#36
post #28

Earlier quoted context omitted.

why does that matter? I'm judging the content of the article, and it's just accusing another blog of something, just drama.. no valuable content here. just pointless, trivial drama looking for an ego boost.

Hint: scripting.com has a better pagerank than PandoDaily. He's the guy who practically invented blogging.

again, that doesn't matter. Even after knowing who he is now, trivial content is still trivial content. And he might've invented something, but blogging most definitely isn't it. Blogging was going to be come about inevitably once someone invented the internet - that was the hard part. Blogging is just an extension of people expressing themselves.

Re: An open challenge to PandoDaily

#37
post #31

Earlier quoted context omitted.

Nothing personal, but I think it's naive to assume that. I once did a deal with a software publisher that required me to turn over the source code. One day I came into the office and found a disk clearly labeled as the source for my product, on the receptionists desk. That was pretty close to public, and I remember that every time I let something sensitive out of my control. Also every few months I have to change my…

Well, the credit card example you give is a good one- you can go through life without paying for anything by credit card, and your credit card will never be stolen. If you do pay for things by credit card, there is a chance that it will be stolen. If you post your credit card details publicly there is a 100% guarantee it will be stolen. I think the same applies to apps. There is a sensible middle ground in there some…

But this is like someone on the subway reaches into my pocket and takes the credit card, copies the number and then publishes it in a blog post.

Re: An open challenge to PandoDaily

#38
post #18

Earlier quoted context omitted.

This is a little abstract for me, so I'm not sure I understand the objection. Their point is that we are being silly for caring where our personal data goes. If we're being silly, here's an easy way to prove it. Show us how careless you are with your own personal data. If there's a limit, something you won't do to show how casual you are about it, then we found something that we agree on. My belief is they haven't th…

The article referenced an app accessing the clipboard (x) and your challenge involved uploading all of one's contact information and pictures (y).

You missed the bigger story that they were making light of.

Re: An open challenge to PandoDaily

#39

"When you said X, you probably meant Y. But I bet you don't believe Y, thus you were lying about X." How many pointless arguments take this form? He should articulate why he considers the situations comparable, so the Pando people have something to disagree with.

This is a little abstract for me, so I'm not sure I understand the objection. Their point is that we are being silly for caring where our personal data goes. If we're being silly, here's an easy way to prove it. Show us how careless you are with your own personal data. If there's a limit, something you won't do to show how casual you are about it, then we found something that we agree on. My belief is they haven't th…

"My belief is they haven't thought it through, and are just being cute for the sake of being cute"

What I find scary sometimes is if you make challenges like you did to Pando you are assuming they even have the same sense of care and responsibility about their data as you or an average person would.

This reminds me of someone who runs an amusement ride and says "I let my kids ride that ride" as if that is to imply ultimate safety. It doesn't. To wit: There was a story or two recently about parents who let their teenage daughters sail around the world solo. I don't think most parents would do that.

Re: An open challenge to PandoDaily

#40
post #12

This is apples to oranges. Most users, use applications because they find about it from trusted sources. They are more interested in just using the application and moving on. Users have shown time and again that as long as the source is trusted (friends, media, overhyping blogs) then they leave it up to the company to make sure their data is private . Calling to a challenge of posting everything to public is misstati…

Exactly. This 'challenge' has absolutely nothin to do with what PandoDaily is talking about. There's a huge difference between giving your information to a trusted company versus just throwing it out in public.
Post reply on HN