Live data from Hacker News

We are sorry

blog.path.com

81–90 of 220 posts

Re: We are sorry

#81
post #15

Earlier quoted context omitted.

I would bold it if I were them. It's a nicely written message, but it reads like a lot of other PR apologies and it's easy to skim over it, deep in its position in the 5th paragraph. Sometimes you need to make actions speak louder than words. :)

>We are deeply sorry if you were uncomfortable with how our application used your phone contacts Better would have been 'we are sorry we misused your phone contacts', rather than trying to make the users responsible by invoking their feelings. Aside: interesting how the concept of theft seems meaningless when applied to copyrighted material, but meaningful when applied to private data.

I don't think that you should assume that they are sorry that they "misused your phone contacts". This, like a lot of companies' efforts, is emblematic of their efforts to find out what people's (ever-expanding) comfort zone is when it comes to giving up their privacy. They (Path) are not looking at this as a philosophical failure (which would be cause for the apology you put forth)...they simply see it as an A/B test result ('sorry about making you uncomfortable').

Re: We are sorry

#82
how do you know they actually deleted all? I'm not saying they did not, but at some point, I expected you to say "pics or it didn't really happen" Many people are getting emotionally attached with companies, apps etc. so that it hinders their ability to even think about whether there is evidence or not.

Re: We are sorry

#83
post #73
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

I completely agree. I'm happy they actually took action and didn't just say sorry.

Well they didn't really say sorry, not for what they actually did:

"We are deeply sorry if you were uncomfortable with how our application used your phone contacts."

Should have been:

"We are deeply sorry that we appropriated your personal contact information and uploaded it to our servers without authorization or consent"

No real admission of wrongdoing or responsibility, only a fool would go back to trusting this company.

Re: We are sorry

#84

Earlier quoted context omitted.

Hashing phonenumber+userid does absolutely nothing for them, though. The purpose of uploading your contacts is so that if Jack's phone number is (555) 555-5555, and Sam uploads a contact list saying that he is friends with a guy whose phone number is (555) 555-5555, Path can match up those two phone numbers (or hashed versions of them) and tell Sam that Jack is a member. That match-up doesn't work if the phone number…

They could take the phone numbers, sort them and hash them together. So if Sam is 5 and Jack is 6, they both upload the hashed social relationship 56 to the system and it can match them up. It wouldn't keep someone with access from checking if a social relationship existed in the database, but it should make recovering phone numbers and the like from the hashes quite a lot harder.

That only works though if you have both Jack & Sam's phone books (and they have each other in their books) so the hit rate would go down, possibly significantly.

Re: We are sorry

#85
There was a great discussion about hashing strategies as an alternative to storing all of this contact info. Did any specific code/examples follow?

It'd be great to see a new "best practice" emerge from this discovery. If it's easy to use, everyone building an app will just default to comparing hashes vs. matching phone numbers.

Re: We are sorry

#86
post #15
post #5

Key paragraph: "We believe you should have control when it comes to sharing your personal information. We also believe that actions speak louder than words. So, as a clear signal of our commitment to your privacy, we’ve deleted the entire collection of user uploaded contact information from our servers. Your trust matters to us and we want you to feel completely in control of your information on Path." Great save for…

I would bold it if I were them. It's a nicely written message, but it reads like a lot of other PR apologies and it's easy to skim over it, deep in its position in the 5th paragraph. Sometimes you need to make actions speak louder than words. :)

I would bold it too. That's at the heart of how sorry they really are. If they didn't delete the info, it would be PR blah.

Re: We are sorry

#87
Its very surprising that no one who was involved with the implementation of the feature thought that they were doing something wrong.

Only when someone caught them "in a compromising position" they said sorry.

Its like Bill Belichick saying "I misinterpreted the rule" :)

Re: We are sorry

#88

I'm kind of sick of this "let's revolt against everybody using my data" mentality. They don't persist your contact data to their server. What exactly is it that you're afraid of? Moreover, how on earth did you think the "Add Friends" feature worked? I'm assuming at least some of you program software, and you should know that data doesn't just appear out of nowhere. Do you really expect a software startup to move ever…

The issues are that they sent address books in plain text without opt in. Two fundamental, I'd-sack-him-if-I-employed-him mistakes.
Post reply on HN