Stealing Your Address Book
dcurt.is
dcurt.is
Here's one reason why we don't scan people's system for interesting private files and secretly upload it for our economic benefit:
1. It violates the user's trust, expectations and privacy.
Here's a second reason:
2. It is a criminal act to do so.
I don't buy these discussions about how it is Apple's fault. It's not. It's illegal to steal private data like this. The companies doing this should be raided and shut down by the FBI immediately. All of them. Whether or not they issued a tearful apology.
Alternatively, Apple could spend a few thousand dollars and properly secure their MULTI billion dollar platform so the problem couldn't occur in the first place.
I guess you're saying don't blame Apple, blame the criminals. Okay, I blame the criminals. Crime is always the criminal's fault.
But I'd also like Apple to protect me from them. Especially since the App Store is advertised as a safe place and this view is reinforced by protecting access to other types of private data in the system.
I'm not blaming Apple for the behavior of criminals, but I am blaming Apple for failing to deliver a product that will protect me from them.
Nobody is suggesting it should be impossible to integrate with contacts. The suggestion is it should be impossible to do so without asking my permission, as is the case with other private data. Requiring that apps ask approval before accessing my private data is not at all like waiting in line for bread in the USSR.
> The argument that it's apple's fault
Is one that nobody is making, so you don't need to debunk it. Or at the very least, I'm not making it, in fact, I very explicitly stated I wasn't making that argument in the post you replied to.
http://en.wikipedia.org/wiki/Data_Protection_Act_1998
I naively thought that iOS Apps wouldn't do this, in part, because it was illegal.
Because no-one ever checks up on them.
Agreed with your outrage on a company taking files off of my system (address book or otherwise) and uploading them. And, from reading the dcurt.is entry - it sounds like 85%+ of social apps do this as common practice.
Does Apple provide application level permissions system where users can see what permission application require, and where users can choose if they will grant application permission the right to read address book or choose not to install it?
If Apple doesn't do this, than it's Apples fault that it didn't sandbox applications enough in order to protect its users.
If you upload personal data (which, I agree, is wrong unless explicitly requested and authorized) you are having much more data to protect.
Maybe its because mobile developers mostly come from web development where it is normal for the server to store such data. For a lot of web applications (web-mail, Facebook) it is part of the service.
The world is certainly 'not' always ideal, and as a phone owner when I download apps, I would like to be able to defend my privacy at the OS level
If you pull my CEO's private contact info off my phone, or pull a high-level contact from some company we've been privately looking to acquire, you best pray that theft doesn't result in a leak of privileged business information.
Right, because the presence of some contacts at company B immediately implies "oh, we're going to acquire them."
What people really aren't mentioning is that people give out the information likely stored in your address book to pretty much any service that even looks to be interesting based on a screencast, or even a splash page. Do you read the terms of service and privacy policies of all random websites you sign up for? Do the people whose contact information you are protecting do so?
You're missing a "some" in that sentence, and the difference between "all people" and "some people" sort of renders your point moot.
My social/business network, particularly as contained in my address book is absolutely private data and it should be my choice whether or not it's shared.
> ...this issue is a failure of Apple and a breach of trust by Apple, not by app developers.
That's a cop-out, of course. There is no lesser responsibility on the part of an app developer to "do no evil" if you've simply bent your definition of evil to "whatever Apple DOESN'T let me do to their users".
Let's look at this statement:
> ...there's a quiet understanding among many iOS app developers that it is acceptable to...
That should be a big red flag to the writer. Quiet understandings have led to all sorts of problems - certain financial collapses come to mind.
Ultimately, this is something Apple needs to confront. Consistency is far more important that any specific moral position - for users and app developers. But that's not a get out of jail free card for the developer.
That's arguable. Privacy is all about "expectation of privacy," which means there's really no predictable, testable methodology other than implementing a feature and finding out if people are outraged. In fact, it's almost certainly different for apps with different target audiences. Path probably gets a lot of tech-savvy 20- and 30-something users who are outraged by address book sharing, but the average Facebook user probably wouldn't care even if they found out it was happening.
Obviously, this just means that developers should err on the side of openness (e.g. in your privacy policy) and explicitness (e.g. popup dialog asking for permission). But that's often only apparent in hindsight, since a developer may never think that something could even be interpreted as a privacy issue, since the developer knows he or she will never misuse the data or even use it all in any personally-identifiable way.
Presumably, for better or for worse, many developers either consciously or subconsciously trust Apple to have a pulse on the community of users when it comes to privacy. It would be nice to be able to do so, but apparently that can't be trusted. Of course, from the user's perspective, it means they can't trust any app to not be abusive (according to their own definition of "abuse").
I wonder if Apple's tight control over app approval has made them actually legally responsible for this kind of thing. Not that it would absolve the app seller/author, but it seems Apple might share significantly in responsibility.
Apple clearly does not enforce the the guidelines 17.1 strictly - but some developers are rejected for this. I can imagine it being possible (and I have no idea) that Apple turns a blind eye to developers that break this rule on the assumption they are doing it as a reputable company and doing it for "clear" value to the end user. (e.g.: not just acquiring all your contacts despite being a fart app.)
> 17.1: Apps cannot transmit data about a user without obtaining the user's prior permission and providing the user with access to information about how and where the data will be used.
Apple traditionally will happily leave functionality users or developers deem critical out of iOS until it is done right - push notifications, geo-location, background applications. It seems to make so much sense that "contacts" are part of something that Apple would want to do right - after all - it can create significant value for the user. (as discussed here: http://parislemon.com/post/11647475506/your-true-social-netw...)
But that doesn't explain why allow it in the first place in its current state? Its a really odd thing to simply offer developers on a whim (all their SDK blurb says is "Your application can create new Address Book contacts and get existing contact info.") Why can I import all of a users' contacts but it is not possible to populate an iMessage with a recipient and content?
(I mean, Game Centre, the nearest thing to an Apple "social network" uses contacts to find your friends but in a truly terrible - albeit more ethical - manner. Which is both parts fascinating and infuriating as GameCentre is mostly crippled by being incapable of finding your friends.)
At a guess: internally Apple iOS development is under resourced and they have a todo list a mile long. This simply has not been a severe enough problem that it has warranted being fixed yet.
Whatever the reason, I hope it gets fixed.
It was relaxed later. I don't recall exactly when, but I'm thinking around 3.2 or so. Before whatever update, you had to have silos of contacts. After it, all apps could use your address book.
You can pop up an SMS sheet like you do for sending emails now.
I once considered the possibility of uploading the entire address book to my servers, too. In fact, I even considered email/sms spamming everyone in those address books with "invitations" from the address book owner to download my app. Of course, I did not end up doing any of that nefarious stuff. Not even uploading the address book for innocent "Add Friends" features. But the fact remains that given the freedom to do so, almost every developer will be, at least, tempted to take advantage of it. Most will.
I honestly don't think Path did anything wrong and I'm sure they kept the information secure on their servers. It's Apple that somehow let this one slip through.
Oh and by "let it slip through," I didn't mean the app itself, but the fact that the SDK requires no authorization from the user for any app to access the address book. Like the author of the article said, it requires it for location. Why on earth doesn't it require it for your contacts? They're arguably much more valuable.
What is the basis for that claim?
Ah, Internet.
Most app developers are just trying to get a job done as quickly as they can, and are in that hustle are choosing the path of least resistance, rather than thinking, "I really want to exploit this data as much as possible and invade as much privacy as possible."
It seems to me that the biggest complaints are that Apple doesn't popup a permission dialog before allowing an app to access your address book, and that Path's privacy policy seemed to omit that they were using your address book.
I've seen rainbow tables claiming 100% coverage of all <14 lowercase characters. I'd bet reasonable money that there's a rainbow table specifically generated for email-address-like strings and another for name-like-strings. I'm pretty sure both names and email addresses have a lot less entropy than random lowercase letter for the same lengths.
Using hashes to obfuscate while still maintaining comparison ability of low entropy data really doesn't help security much…
There are still plenty of sites storing plaintext passwords. I doubt there's a data mining conspiracy there (although I bet you could make some interesting guesses about people based on their password choice). It's just a poor design that accomplishes its task in the simplest way possible.
I don't care whether or not it was done with malicious intent. What bothers me is that copies of my address book are floating around out there without my permission.
If not, then I can see why this might be Apples fault for allowing developers to abuse this.
If yes, then how can this possibly be Apple's fault? It seems almost absurd to blame them. The buck stops with the end user for not protecting their Address Book. If you allow some weather app to download your Address Book, why should Apple care? You cannot trust every developer (turns out we are all data hungry), and they even asked to peak in there too.. You explicitly gave them permission!
I think you're overgeneralizing...
- location (only accessible via permissions dialog)
- existing photos and videos (only accessible via apple-provided picker dialog)
- reading email or SMS (never accessible)
- sending email or SMS (only accessible via apple-provided compose dialog)
- any data or settings for other apps (never accessible)
- push notifications (only allowed after permissions dialog)
- Safari history, cache, cookies, etc (never accessible)
In fact, the only thing apps can access without permission that's really problematic are the contacts. And yes, I expect Apple will be closing this very soon.You could maybe argue that accessing the live camera and microphone feed are an issue?
Are you sure about that? I was under the impression that the Asset Library framework (https://developer.apple.com/library/ios/#documentation/Asset...) would allow one to build their own picker and thus access the existing photos and videos. But I didn't go far enough into iOS yet to try it and see what it really does…
That being said, I can't find an app that allows me to select multiple pictures at once. (you'd think the Facebook app would let you do that) Which is weird because I'm fairly certain that Picasa Web Albums allowed that at some point. (http://itunes.apple.com/us/app/web-albums-a-picasa-photo/id3...) I remember because I specifically bought the app to upload a couple of folders at a time and I don't see myself choosing them one by one… In any case, while the description implies it can, the current version won't let me.
FlickStacker supports batch select, as do many other up loaders or photo vaults.
I guess they could just make all the "get" functions return empty data sets if the user doesn't agree for apps using the current functions.
They'll need to maintain backward compatibility to at minimum iOS 4, there's not many new apps that are iOS 5 only at the moment.
I really thought iOS did ask for permission. I know I have had to grant it before, but perhaps it was just some nice app developers doing the moral thing.
http://cache.gizmodo.com/assets/images/4/2011/06/ios5twitter...
(It's possible they're scraping Twitter handles/photos in some way that doesn't link the 'email addresses and phone numbers' to the requester's Twitter handle... but almost any straightforward way of implementing this has the de facto effect of informing Twitter of all your contacts' emails and phone numbers.)
Everyone's at it.
Apps, should just work.®
Constant permission prompts just train users in to muscle memory to accept these dialogs without thinking. Instead Apple sees it better make developers justify their needs to the APIs when they submit. Then Apple tests the app and looks for anything fishy. In the end, they reserve the right to pull them when they violate their terms.
The article is wrong in that the camera roll is secure. It's technically not. Through the asset library API you can get at it. See docs here: https://developer.apple.com/library/ios/#documentation/Asset...
One of the issues Android had up until recently was that you couldn't update all apps in one shot. The reason is that app update may have required permission changes from a pervious version. You would have to acknowledge each of these before installing the update. This was a crappy user experience and it's still the current experience when you install 3rd party APKs and update them.
The problems with these "list of permissions wanted" screens is they don't let the developers justify to the user why they need access to these different features inline with the request. The users see it at install or update often.
There are often very simple reasons why I need access to data on the device on Android in my app. I had people not install my app because I asked to send SMSs (which tells the user I can charge them money that way) in my music app, but it's only because I had a share button that is user invoked and clearly is sending a text message to user.
Sure, be clear with your intent with your users, but these permission models don't always scale for the everyday users.
Why can I not query each and every application vendor for all data held on me, and either modify or correct this as I see fit?
I've enjoyed playing with my Android phone for the past while, but I'm increasingly very unhappy carrying a persistent snitch in my pocket.
I'm waiting for the Perl Harbor / 9/11 day for this stuff. It's going to happen, it's a matter of when.
So the companies that willfully ignore Apple's app rules and normal ethics are in no way to blame?
It's easier to send the raw data. It's foolish to send the raw data. It's a lazy mistake. We all know it happens. We all know WHY it happens. Stop fucking with our data. Pay attention because sometimes you should not be quite so lazy.
Path gets off easy because they're Path. I'm ok with that. But I would fire your ass if you did this under my watch because I know for a fact that this is a stupidly easy problem to resolve. Don't be so damned lazy when it matters.
Persons wishing to bring this issue to Apple's attention might wish to engage an Australian lawyer or bring the matter to the attention of the Attorney-General's department.
I don't have an iPhone, so I'd have no standing. Fellow Australians, call your lawyers and start raising a stink.
(IANAL, TINLA).
[1] http://www.privacy.gov.au/materials/types/infosheets/view/65...
A while back I casually nuked my iPhone 3G back to factory to give to a friend. I did so without realizing there were some contacts on there that failed to backup to my Mac.
What are the odds some startup or other company out there has my contacts? Do any of them offer personal data dumps? Sadly, these contacts never made it to Google, where I can dump the data.
Just curious.
1. Permission to access a resource just locally for the benefit of the user;
2. Permission to transmit the data about a resource for social purposes.
I use my address book for everything. I have my contacts' names, phone numbers, email addresses, addresses, IM usernames, birthdays, anniversaries, websites, workplace and other info stored in mine (not to mention some personal info jotted in the notes section).
Until today, I believed that information was secure. I had no idea an app could upload all of that information to their server WITHOUT MY KNOWLEDGE, much less consent.
Because of Google's approval process (or lack thereof), Android users have always been paranoid of the apps they install and what permissions they give them. As an iOS user, I never thought I had to worry about that because of Apple's approval process.
Does it make a little more sense why some of us are furious about this now?
Recently it seems it's been coming to light that their curation process is not nearly as thorough as they would have us believe.
Are you sure all the people in your address book are as careless about that data? The friend with the restraining out against their ex? The minor celebrity with the unlisted phone number?
Are you happy with the possibility that a connection between you and someone else might be implied without being true? What if a known drug dealer* had your phone number in their address book? (Perhaps via a room mate or child using the landline to have called them once? Or through reuse of an expired disposable cellphone number?)
* or child pornographer, or political dissident, or terrorist, or…
This is not a "mistake". Why would anyone want to have anything to do with such people, much less be their customer?
This warrants punishment, not forgiveness.
I say misguided because there are many ways that your personal information, behaviours, interests and usage history can be fettered away from you all outside of Apple's control, this is a privacy and transparency issue.
Not only should there be some level of respect for the information you possess (especially information you possess on others), but many countries already have legislation that address these privacy concerns specifically.
This means that there are real legal consequences to this address book saga, but contrary to the article's spin this is again not directed at Apple.
In short: Apple can do more to protect users, but shovelling them with the full blame over apps that are deliberately designed to gather and produce results from your contact information to provide is misguided.
More like...the people who built your house and are guarding it allowed thieves to break in.
I believe I might hold them responsible.