Live data from Hacker News

We are sorry

blog.path.com

51–60 of 220 posts

Re: We are sorry

#51
post #6

Path should come up with a Privacy Protection Program that commit them not to repeat their mistake. It's too easy to do something and ask for forgiveness later on. That would distinguish themselves from Facebook's way of doing things.

The could set up a company in the European Union, and hence be subject to EU Data Protection Law, which is stronger than the USA. They would then be risking fines and court orders for things like this. It would show that they don't think it'd happen again.

It would be a bit of an beaurocratic pain in the ass though.

Re: We are sorry

#52

Honestly, I keep hoping Apple adds a permission check for the contact list (like they do for GPS location). If the user says no, they should just return a blank contact list (to keep old apps happy that aren't expecting the call to fail).

It's crazy that they haven't added this already. Facebook needs to get my permission to find out where I am, but not to scrape a hundred names, phone numbers, and addresses out of my phone? Bizarre.

Re: We are sorry

#53
post #10

Good for the most part, but does anyone feel like they deliberately left out what it was they're apologizing for? I can imagine a user unaware of the recent event stumbling across this article and leaving confused about what wrong was committed. They sort of just assume you knew what happened, instead of explicitly explaining what they'd been doing. But, they're taking steps to resolve the issue, apparently; so good…

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts." Dave explained the issue well enough in the first paragraph.

I don't think that explains anything to someone not familiar with the scenario. It doesn't say how they handled transmission and storage of phone contacts, just that they did it in a bad way.

I don't think it's intentional, though. When writing this I doubt the audience in their minds were the people who don't know about the issue.

Re: We are sorry

#54

Earlier quoted context omitted.

How would one carry out the friend suggestion feature with encrypted phone numbers?

a cryptographic hash of a phone number on their server should match a cryptographic hash of a phone number in a contact list on a phone. The app sends the hash to the server, the server looks up users via the hash and responds with user data for matches. To be honest this should be a third party service, since it sounds like every major social networking app is doing the same exact thing.

In my opinion, giving out your number, along with the hash of each phone number in your address book to an authority with millions of such hashes isn't appreciably better than giving them in plaintext.

(Hi Dan?)

Re: We are sorry

#55

This is a welcoming move from Path. However, "industry standard firewall technology" is gibberish.

Agreed. That specific sentence reminded me all too much of snake-oil and charlatanry, and it coloured my reading of the rest of the apology.

Re: We are sorry

#56
post #10

Good for the most part, but does anyone feel like they deliberately left out what it was they're apologizing for? I can imagine a user unaware of the recent event stumbling across this article and leaving confused about what wrong was committed. They sort of just assume you knew what happened, instead of explicitly explaining what they'd been doing. But, they're taking steps to resolve the issue, apparently; so good…

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts." Dave explained the issue well enough in the first paragraph.

If you put yourself in a user's shoes that doesn't know what the issue was then that is still generic. As a user who doesn't know the story I'd be wondering:

- Did they get hacked and now some unknown party may have the contents of my address book?

- Were they selling my information to others?

- Did something happen as it relates to storage that mixed up or deleted information

- Was my data being transmitted in the clear

- Was mt data being transmitted without my knowledge or approval?

Two of those things did happen but the user doesn't know for sure. To be fair though, I think their statement was enough. They really don't have to go into more details unless the situation calls for it and it doesn't right now. Those who know get the apology they deserve and those who don't continue using Path as if nothing ever happened. Win win.

Re: We are sorry

#57
It reads like standard PR damage limitation, but it ticks all the right boxes:

* They've admitted responsibility.

* They've shown they understand why they were wrong.

* They've explained what they've done to put it right now.

* They've explained how they intend to proceed in the future.

Re: We are sorry

#58
post #10

Good for the most part, but does anyone feel like they deliberately left out what it was they're apologizing for? I can imagine a user unaware of the recent event stumbling across this article and leaving confused about what wrong was committed. They sort of just assume you knew what happened, instead of explicitly explaining what they'd been doing. But, they're taking steps to resolve the issue, apparently; so good…

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts." Dave explained the issue well enough in the first paragraph.

That was a deliberate mistake. at the first they said it's not a big deal (just like Airbnb did) but then when they saw the social media getting on fire they apologized. Better they should not have done it, but good they took measures.

Re: We are sorry

#59

Earlier quoted context omitted.

"We made a mistake. Over the last couple of days users brought to light an issue concerning how we handle your personal information on Path, specifically the transmission and storage of your phone contacts." Dave explained the issue well enough in the first paragraph.

I don't think that explains anything to someone not familiar with the scenario. It doesn't say how they handled transmission and storage of phone contacts, just that they did it in a bad way. I don't think it's intentional, though. When writing this I doubt the audience in their minds were the people who don't know about the issue.

Given that they've removed all the data and updated the app, I'm not sure it's necessary that they give highly granular details as part of the apology.

Re: We are sorry

#60
Isn't it unfair that Path gets all this press for making a mistake and apologizing? What about all the apps that didn't make this mistake?
Post reply on HN