Anger for Path after Privacy Breach: So Many Apologies, So Much Data Mining
bits.blogs.nytimes.com
bits.blogs.nytimes.com
When Path states they didn't realize users would feel deceived and that they only intended to use the information to make better suggestions for the user's contact list, well, I don't want to sound cynical, but I think anyone who blindly believes these kinds of statements (from Path, Facebook, or any other company) is either personally/financially interested or extremely naive.
I reckon the more likely truth is that the Path folk genuinely saw nothing wrong with what they were doing. There are a group of people (call them the Facebook crowd, if you want) who think that excessive privacy is unnecessary, extending that thought to sharing people's address books.
No one ever says "I'll be evil". Instead, they come up with ways to justify the evil that they do.
The only reason for giving someone who "meant well" a pass is if it's likely that the bad outcome was fairly unexpected. If, as is usually the case, the bad outcome was likely, they should be held accountable for intending it, just as we do with drunk drivers. No, "meaning well" isn't an excuse for ignoring reality.
Remember, most of the world's horrors are caused by folks who claim that they're trying to do good.
A child would know that this was wrong. It's that simple.
Gawker's Ryan Tate reports that he specifically confronted the CEO Dave Morin about the address stealing behavior last year and he officially denied that they were doing it.
http://gawker.com/5883549/dont-forgive-path-the-creepy-iphon...
The intractable problem is there's no way to verify what's being done with that data once it's accessed.
> "The answer isn't for ... the company ... to prove that they can be trusted; the answer is to ensure that their customers don't need to trust them. ... The best way to avoid privacy breaches is not to formulate a detailed privacy policy; it's to reduce your capabilities so that you're unable to violate anyone's privacy."
Just think of what target companies like this will make for hackers. It's an accident waiting to happen.
It'll be a shitstorm when a large set of address books gets leaked to the internet (à la AnonOps, etc.).
(Though it would be a lot of fun to run some graph-theoretic metrics on the dataset (closeness, centrality, etc.). I've often lusted over getting an anonymized version of the Facebook graph (32-bit ID for each person, assume average of 100 friends, 700 million users, gives a total size of about 300 GB uncompressed), but a leak of a couple million address books now seems not far-fetched.)
in both cases, a clued-up governmental agency could read the data. as the article says, this can be a big fucking deal.
tldr: if you're going to abuse people's privacy, at least do it right.
[it's possible that the tls case involved loading a new trusted certificate onto the phone before the attack; i did check for that when i read the description and couldn't find any mention, but if that's the case then the loading would be secure - although even then, it might have been possible for path to hard code details of which ca they trust.]
i agree that, if it was done, then the transfer is more secure, but, as i said, that does not appear to be the case.
If they are willing to sell these to private organizations, who's to say that one of the many certificate authorities have not sold such devices or certificates to repressive governments?
SSL is basically a joke at this point. Because it requires you to trust every single certificate authority for every single domain, it basically means that you are only protected against the average script kiddie, not a dedicated attacker. There have been plenty of CAs compromised, who continued to issue MD5 signed certificates well after it was broken, who are within the control of authoritarian governments, or who are willing to sell subordinate root certs for the purpose of snooping to any company who is willing to pay enough.
And that's not to mention that even if the information is properly protected in transit, putting this information on your servers makes you that much more vulnerable to attackers who may want access to this information, the government of the country in which it is hosted, legal process, or any number of other threats. Even if they had properly secured the information in transit, and SSL were secure, it still vastly increases your customers exposure to upload this information to your servers.
It would have taken programmers weeks to write the code
necessary to copy and organize someone’s address book.
"Weeks" seems a little far-fetched, no? (Especially given the apparent lack of sophistication in the import process.)"Lawyers I spoke with said that my address book — which contains my reporting sources at companies and in government — is protected under the First Amendment."
What does this even mean? Does he mean the fourth amendment? If so, lawyers would have told him "not once it leaves your phone". What do you mean by "protected"? That you can't be compelled to divulge it at all? That police need a warrant to get at it? That you can sue if someone else exposes it?
So I flipped the bozo bit. If the author plunks a meaningless but frightening sounding paragraph in the middle of an article, I just don't really put a high value on anything he has to say.
Isaac Newton wasted the last decade of his life trying to turn stuff into gold, but his physical model of the universe was still quite correct, at least as a first approximation at the meso-scale (the best you could do at the time). You may find that one statement to be crazy, but I think the author still makes some important points about the flippant attitude toward privacy in the tech industry, which is supported by a thousand data points across dozens, perhaps hundreds of companies.
http://www.rcfp.org/first-amendment-handbook/introduction-le...
And, as others have suggested, you might want to flip the "bozo bit" on the entire notion of a "bozo bit", because it's a funny metaphor but a lousy rule for real life. Everybody is a bozo some of the time.
I don't think disregarding someone's opinion because you've found a significant fault in some of their opinions. I'm not an expert on everything, but then I don't post articles on things I'm not an expert on. If the parts of an article I can can evaluate turn out to be incorrect, then I can reasonably infer that the rest of the article is of similar accuracy, even if I can't personally evaluate it.
That means he's not only a sloppy journalist for not explaining his First Amendment point, but he's doubly sloppy for implying that he talked to any lawyers while writing this article. Because if he did, they'd have said "Go check out jaylevitt's excellent comment on HN explaining why that's irrelevant."
> it was also transmitting the data in “plain text.” This would be like mailing a private letter to someone without the envelope.
My understanding is that the data was transmitted over https, which is decidedly not like mailing a letter with no envelope.
Why is the New York Times incapable of writing headlines in one of the variants of English spoken on Earth?
But the New York Times headline writing style is a variety of English, familiar to English-speaking readers of newspapers. As I wrote earlier in response to a similar question,
http://news.ycombinator.com/item?id=3358744
"Newspapers all over the world use different grammatical conventions in headlines from articles. I read Chinese, and Chinese-language newspapers also have headlines that look quite bizarre in isolation. As the first kind reply here said, this convention probably began to save space for banner headlines in large type."
When I install an application on my computer, I do not expect it to upload arbitrary information from my disk to the developer's servers. If an application did, I would be quite upset, even though any application that I run on my computer will generally have access to all of my data with no substantial platform-provided protection.
Why should I suddenly give the developers a break because the application is running on the computer I carry around in my pocket, instead of the computer I put in my lap?
Would you forgive a company if their application grabbed your cookies, and uploaded those to their server, so that they could log into your Gmail account to find your contact information? Decided to upload all of your documents to their servers and convert them to a convenient HTML format to make it easy for you to share them with one click to your friends? Rooted around your hard disk, uploading your tax information to their servers?
So why do you say that we should forgive companies for making the deliberate decision to grab private information from your phone, and upload it to their servers, just because the platform vendor never implemented a feature to explicitly forbid that?
No. It's Apple's fault for failing to protect their customers that buy into their walled garden, but even then, there isn't exactly a hugely black and white list of things that Apple considers to be "fair use" and "evil" in privacy contexts.
The app developers CHOSE to use, upload, store and reuse this data, not Apple. Shifting the blame to Apple is making extreme excuses for app developers.
>Until then, lets leave the app developers alone.
I can't begin to wrap my head around this viewpoint. At all. Let's give them a free pass. Despite them violating my implicit privacy, they can't be blamed. If they can, they should be able to, that's what you're saying...
On the other hand, if an app was able to forcibly allow itself access to Location Services and ignore the iOS setting, I would argue that is unauthorized.
Granted, I have absolutely no idea what the context of unauthorized is from a purely legal standpoint.
I am really upset by this. Most executives (I'm looking at you BP) have had very inconsiderate versions of "I'm sorry" that are literred by play on words, media spin, and disgrace.
Human beings are not flawless and I respect the companies (I'm looking at you Facebook, Dropbox, Path, etc) that are willing to treat me like a human being and say they're sorry.
In the seventies it was "At this time, Senator, I do not recall."
In the eighties and nineties it was "there's nothing new here."
Now we're sorry.
SSDD.
It's not like they were using the data for something other than convenience for the user. When the users were upset, they reacted accordingly.
Facebook looks at all your data for targeted ads, and Google uses all your data to refine their algorithms. All Path did was try to use your data to help you, and when they were met with resistance they back tracked on their decision.
Mistakes like this are made all the time, and this isn't even that big of a mistake. It's not like the data was leaked. People need to seriously calm their nerves and look at what Path did right.
Stop looking for a story where there isn't one. The real story is Apple's privacy policies. Path should have been forced to ask for access to the data, but they weren't.
I think having some sort of permission guard for contacts is totally worth doing, but to put Path's sending of your contacts to a remote server in the same category as Apple not asking before allowing something to see your contacts is misleading at best.
1) Put in their detailed rules that this (uploading entire address books) is not allowed.
2) Remove apps from the Apple App Store if they are found to violate this rule.
Apple could also remove such apps from phones after the fact as if they were hostile malware. This may be going too far, but it can be done: http://cybernetnews.com/apple-can-remotely-remove-bad-apps-f... I mention this since by saying "What is Apple supposed to do to prevent.." you may be asking if there's anything Apple can do at all. Yes, of course there is. It's not hard to do something when you own the app store and have control over all the devices.
This is the same reason Facebook apps have to explicitly ask for permission to certain data.
It is Apple's platform, and Apple's app store. They own more of this issue in my eyes. They are the ones that make the rules and review the apps.
Well, that too. But eropple (the parent poster)'s point is that social networking apps are the kind that would typically ask for this permission. Controls on this behaviour before and after the fact can work together.
Now that I think about it, doing the "find your friends" thing without uploading address book data at all would be tricky.
I'm sure you've heard. How would you like to have shown up in his address book? Or should we all rest assured that the all-powerful people at Path would refuse governmental threats?
>All Path did was try to use your data to help you
You don't really buy that...do you? These companies all make money from our data, in some form or another. I understand that Path isn't solely to blame here, but they played the game like everyone else and happened to get caught. I feel no pity.