Your address book is mine: Many iPhone apps take your data
venturebeat.com
venturebeat.com
Twitter is the only one of these services I use, and when I read that line it took me 5 minutes to decide whether to actually uninstall the Twitter client from my phone. I decided to try to get this bad news from the horse's mouth.
https://twitter.com/privacy contains Twitter's privacy policy. Does it actually say what the article claims?
TL;DR: No.
The number '18' occurs exactly once. It is used in this context:
Log Data: Our servers automatically record information ("Log Data") created by your use of the Services. Log Data may include information such as your IP address, browser type, the referring domain, pages visited, your mobile carrier, device and application IDs, and search terms. Other actions, such as interactions with our website, applications and advertisements, may also be included in Log Data. If we haven’t already deleted the Log Data earlier, we will either delete it or remove any common account identifiers, such as your username, full IP address, or email address, after 18 months.
The word 'contact' appears 5 times, in these contexts:
1. If you have any questions or comments about this Privacy Policy, please contact us at privacy@twitter.com.
2. We may use your contact information to send you information about our Services or to market to you.
3. If you email us, we may keep your message, email address and contact information to respond to your request.
4. If you become aware that your child has provided us with personal information without your consent, please contact us at privacy@twitter.com.
5. Page footer: © 2012 Twitter About Us Contact Blog Status Resources API Business Help Jobs Terms Privacy
The phrase 'address book' appears once, in this context:
Additional Information: You may provide us with additional information to make public, such as a short biography, your location, or a picture. You may customize your account with information such as a cell phone number for the delivery of SMS messages or your address book so that we can help you find Twitter users you know.
Twitter Inc. has acknowledged that after mobile users tap the "Find friends" feature on its smartphone app, the company downloads users' entire address book, including names, email addresses and phone numbers, and keeps the data on its servers for 18 months. The company also said it plans to update its apps to clarify that user contacts are being transmitted and stored.
The company's current privacy policy does not explicitly disclose that Twitter downloads and stores user address books.
It does say that Twitter users "may customize your account with information such as a cellphone number for the delivery of SMS messages or your address book so that we can help you find Twitter users you know."
As with many online social services, Twitter allows users to look for friends that are also registered users. In the case of Twitter's iPhone app, users see a screen noting that the service will "Scan your Contacts for people you already know on Twitter." The short description of the feature does not mention that it also downloads every entry in the address book and stores it.
Twitter's current privacy policy notes that some categories of "Log Data" are stored for up to 18 months.
"Log Data may include information such as your IP address, browser type, the referring domain, pages visited, your mobile carrier, device and application IDs, and search terms," the policy says. "Other actions, such as interactions with our website, applications and advertisements, may also be included in Log Data."
http://www.latimes.com/business/technology/la-fi-tn-twitter-...
Exonerates? Not at all!
My point was just that (contrary to the article) Twitter doesn't make any claims whatsoever about how long they hold your Address Book data.
In fact, since it's mentioned along with other "data with which users may customize their account," that sort of implies that they consider it an integral and permanent part of your customized account profile. If someone told me that the data stays around until I choose to delete my account, I don't see anything in the privacy policy that would contradict that.
* Usually, 'utility' is not the primary driver of these apps, it is more in building a large userbase quickly so VC attention can be garnered.
No point blaming app programmers. The functionality for apps to acquire the address book without asking shouldn't exist.
Dear Apple, thank you for protecting me from adult material in the app store. But, can you... er, this is awkward... can you NOT GIVE MY ADDRESS BOOK AWAY WITHOUT MY PERMISSION? Thanks. And sorry for yelling, it's just, y'know, my address book and all.
I do not know why developers for mobile apps suddenly think that has changed. But they do. That’s certainly a problem and Apple should react to it quickly. The culprit, though, are still the developers who overstepped a pretty clear line.
Well, yes, but unlike on your iPhone you could actively do something against it. E.g. let outlook encrypt your address book, change the addressbook access permissions etc. it was trivial to bar anyone/thing from accessing your address book without having to remove the software you want to use.
On the iphone, you can only chose to install an app or not, if you chose to install, you have to accept anything that comes with it.
If you stick your addressbook into a truecrypt container 100% of programs (i know there is no 100% security, but there is not enough space to spell out all 99.999999s) will not be able to access it anymore without you unlocking/mounting it first. Thus, requiring your permission.
Then, when another person signs up for an account, it's easy to see who they should suggest they should join, but nowhere is any personal data being stored.
Sounds like it'd work to me?
If my problem is that I don't want Facebook to have the phone numbers in my address book, then surely I don't want them to have the SHA1 of each of the numbers in my address book, either?
Isn't it going to be easy for an organisation with Facebook's resources to build a dictionary of the space of SHA1s of phone numbers?
And if they salt the numbers, first, then they can't be compared with each other for suggestions? So whats the point?
Have I overlooked something?
It's true that they could store the hashes and build a graph of mystery contacts, but that's still not as bad as taking the actual contact info.
Same goes for hashing IPv4 addresses. There is no way to make eitther one secure by hashing.
Although what about hardcoding a salt into the app to hash with?
Your lookup table just got a lot bigger.
Feral, Chimp, myEmail, myDeskPhone, myCellPhone
H1 = sha1(Feral-Chimp-myEmail-myDeskPhone-myCellPhone)
H2 = sha1(F-Chimp-myEmail-myDeskPhone-myCellPhone)
H3 = sha1(Feral-C-myEmail-myDeskPhone-myCellPhone)
H4 = sha1(F-C-myEmail-VALUEOMITTED-VALUEOMITTED)
...
...
So flexibility is available, it's just more computationally expensive for the server to do the extra comparisons. The hash calcs use a little extra battery per user, but I'm much happier to donate some of my processor/battery than I am my Address Book contents.
How much extra battery are you willing to spend, and more importantly, how much effort are you willing to spend running your users' batteries down for something that you'd never yourself use?
That's sort of beside the point, though. The question is: How does uploading my Address Book information provide a much more efficient or complete solution to that set of problems? I don't think that it does. In each case, you're dependent on heuristics and sometimes those heuristics are going to miss a match. If I were Twitter, I'd happily accept those misses in exchange for hitting the matches where people spell each other's first names and email addresses consistently (for example).
> how much effort are you willing to spend running your users' batteries down for something that you'd never yourself use?
You lost me there. My point was just that for Twitter, my iPhone CPU/battery are an "externality." So while they might spend more cycles doing server-side comparisons on the hashes my phone sends over, at least they're not paying to compute the hash values.
But as I said, outside of my territory.
[1] I'm not that old, really.
Crypto is actually really cool these days, there's pretty much a solution to every weakness :)
2) if you use some other computationally expensive hash you run into the problem of low powered mobile hardware. Remember you're not hashing 1 thing, but dozens or hundreds of phone numbers or email addresses.
Path stored the data but I know 4sq does a search against it but does not store it. That can make a huge difference...
That's how it knows to suggest people that you should friend once you create an account for the first time and DON'T give it your address book: it stored people that had your email listed in their address books.
Path, to me, was only particularly bad because they'd upload your contacts every time you signed in.
I think we've earned that trust over the past 3 years, and will continue to earn it over and over again into the future by sticking to our word and being transparent about what happens to your data when you send it to us.
I'm not sure how else it could work?
The issue with Path is that they stored the data. Instagram and 4Square do not. They have to re-crunch the "numbers."
HHmmmmm........
1. Hash first on the device (SHA-2, no salt) after converting to common case and removing extraneous characters from contact data. 2. Send hashes over secure connection (SSL, TLS). 3. Hash again on the server (SHA-2, salted with value known only to service provider) 4. Delete all data a reasonable time after comparison / mapping is done.
This way, although it's not unbreakable, there are the advantages of:
- Encrypted, pre-hashed data over the wire. - Easily comparable data on the server. - Reasonably secure server side storage as long as the salt is secured.
Dumb idea?
http://cache.gizmodo.com/assets/images/4/2011/06/ios5twitter...
That must have had close Apple review as part of the official iOS/Twitter integration.
The explanation underneath the 'Update Contacts' button is somewhat reasonable, though it may not register with most people that, barring some unlikely fancy indirection, to 'use' email addresses and phone numbers means they're being reported to Twitter's servers.
Additionally, nobody has touched on the fact that companies can use address books to prevent fraudulent use. For most of the companies listed there isn't too much to be gained from fraudulent use. But you can imagine for services that frequently have to address fraud and, say, don't want a single user to have multiple accounts or that want to make sure all their accounts are owned by real people, doing things like cross-validating address books can be very useful. This can still be done if you hash the names and phone numbers before uploading them, though, which is maybe what everyone should be doing.
tl;dr Data is money/power these days, it's strange that people are shocked by companies making use of all the data they have access to.
Probably not, right? You know they want to gather as much data as possible, but you are angry, because you never gave them permission to go through your thrash.
I think thats how some people feel if an application goes through their phonebook, when they didn't give it permission to; the phonebook is not information people consider public; its privileged. Thats where there's a fuss.
I guess I'm just deflated in that while some aspects of these services enrich my life in some way by exposing me to information I might not otherwise have easy access to ... their primary reason for existence seems misguided from the start. A service built just to advance the quest towards personal or shared wealth feels unnecessarily shallow to me when the ingredients used to generate that wealth are of such a personal nature.
Facebook knows about the connections I've told it about, or others have requested and I've approved.
Yes, it may be useful - but the address book on my phone is quite personal, and not something I would hand over to a 3rd party readily. There are people in there, let's say, who I wouldn't WANT people to know are in there. There may be people in there who hate other people in there.
So.. they can take my address book and do what they want with it? No amount of "cool stuff" adds up to allowing a 3rd party company to have the contents of my personal contact list, sorry. This is really bad.