Live data from Hacker News

Your address book is mine: Many iPhone apps take your data

venturebeat.com

51–56 of 56 posts

Re: Your address book is mine: Many iPhone apps take your data

#51
post #6

I really think Apple needs to do something here with their next update. For every company that does the right thing by asking permission first, who knows how many are being sneaky.

Agreed. But you're being too kind on Apple. This is the worst privacy breach from Apple in iPhone's history. No point blaming app programmers. The functionality for apps to acquire the address book without asking shouldn't exist. Dear Apple, thank you for protecting me from adult material in the app store. But, can you... er, this is awkward... can you NOT GIVE MY ADDRESS BOOK AWAY WITHOUT MY PERMISSION? Thanks. And…

The app programmers do have to take the blame. Those breaches of privacy have always been possible on desktop PCs but app programmers usually didn’t do them because that would make them a pariah.

I do not know why developers for mobile apps suddenly think that has changed. But they do. That’s certainly a problem and Apple should react to it quickly. The culprit, though, are still the developers who overstepped a pretty clear line.

Re: Your address book is mine: Many iPhone apps take your data

#52

Earlier quoted context omitted.

And the likelihood that you'll match somebody got a lot smaller. Names have different spellings, phone numbers have different spellings (to say nothing of different numbers), people have multiple emails. You can't canonicalize some of these either.

The engineer in me says you could soundex/metaphone the names before adding them to the hash. The rest of me says apps just shouldn't be doing this.

I'm probably out of my territory (I don't have a phone right now[1]), but my first UI instinct would be to allow address book entries to be grouped (or tagged or labelled, the actual mechanism is secondary), and on first request from the app being asked what groups I'd like to allow it access to. Bonus points for the option to create a per-app group and put some users in right there and then.

But as I said, outside of my territory.

[1] I'm not that old, really.

Re: Your address book is mine: Many iPhone apps take your data

#54
post #51

Earlier quoted context omitted.

Agreed. But you're being too kind on Apple. This is the worst privacy breach from Apple in iPhone's history. No point blaming app programmers. The functionality for apps to acquire the address book without asking shouldn't exist. Dear Apple, thank you for protecting me from adult material in the app store. But, can you... er, this is awkward... can you NOT GIVE MY ADDRESS BOOK AWAY WITHOUT MY PERMISSION? Thanks. And…

The app programmers do have to take the blame. Those breaches of privacy have always been possible on desktop PCs but app programmers usually didn’t do them because that would make them a pariah. I do not know why developers for mobile apps suddenly think that has changed. But they do. That’s certainly a problem and Apple should react to it quickly. The culprit, though, are still the developers who overstepped a pret…

"Always been possible on desktop PCs"

Well, yes, but unlike on your iPhone you could actively do something against it. E.g. let outlook encrypt your address book, change the addressbook access permissions etc. it was trivial to bar anyone/thing from accessing your address book without having to remove the software you want to use.

On the iphone, you can only chose to install an app or not, if you chose to install, you have to accept anything that comes with it.

Re: Your address book is mine: Many iPhone apps take your data

#55
post #54
post #51

Earlier quoted context omitted.

The app programmers do have to take the blame. Those breaches of privacy have always been possible on desktop PCs but app programmers usually didn’t do them because that would make them a pariah. I do not know why developers for mobile apps suddenly think that has changed. But they do. That’s certainly a problem and Apple should react to it quickly. The culprit, though, are still the developers who overstepped a pret…

"Always been possible on desktop PCs" Well, yes, but unlike on your iPhone you could actively do something against it. E.g. let outlook encrypt your address book, change the addressbook access permissions etc. it was trivial to bar anyone/thing from accessing your address book without having to remove the software you want to use. On the iphone, you can only chose to install an app or not, if you chose to install, yo…

Trivial? No, not at all. Not in the slightest.

Re: Your address book is mine: Many iPhone apps take your data

#56
post #55
post #54

Earlier quoted context omitted.

"Always been possible on desktop PCs" Well, yes, but unlike on your iPhone you could actively do something against it. E.g. let outlook encrypt your address book, change the addressbook access permissions etc. it was trivial to bar anyone/thing from accessing your address book without having to remove the software you want to use. On the iphone, you can only chose to install an app or not, if you chose to install, yo…

Trivial? No, not at all. Not in the slightest.

I think I did not make my point clear enough. It is trivial to make it inaccessible to programs who assume that it is easily accessible. I did not mean to include solely malicious programs.

If you stick your addressbook into a truecrypt container 100% of programs (i know there is no 100% security, but there is not enough space to spell out all 99.999999s) will not be able to access it anymore without you unlocking/mounting it first. Thus, requiring your permission.

Post reply on HN