Path texts my entire phonebook at 6 AM
branded3.com
branded3.com
There's annoying spam, and then there's straight-out-lying spam -- the "x has sent you a message, you need to create an account to view it" type.
Just curious, is there a way to sue/fine a company like this for false advertising, essentially?
Another app doing similar spamming is Circle: http://discovercircle.com - surprised no one talked about that...
(your winnings, sir.)
Still the same practice spammers use, but very different from "covertly uploading my contacts data and texting everyone without telling me".
http://arstechnica.com/tech-policy/2012/11/how-lawsuit-again...
> The case originated with two lawsuits claiming that Classmates.com had sent out millions of deceptive e-mails telling users that an old friend was trying to contact them, and had viewed their profile or signed their "guestbook." For the great majority, that wasn't true; no one at all had shown an interest in their profile. About 60 million users were contacted, and about 3 million actually took the bait, paying between $10 and $40 to Classmates.
http://arstechnica.com/tech-policy/2010/03/classmatescom-set...
Maybe it's time to create a Hippocratic Oath for developers to publicly commit to?
A future Path developer could then refuse to implement an unethical "feature" by pointing out that the company had hired them with the full knowledge that the oath had been undertaken.
I don't think the company would pink slip the developer, as they would probably want to avoid any attention being drawn to the unethical "feature" in a tribunal or other legal setting.
Path is young (and building a service, not a device/OS) and it can be abandoned for something similar since all they're keeping is data. Once you buy a gadget, that's an investment on your part which will make a lot of people hesitant to give it up and the culture it that surrounds it.
And I wouldn't bet that Apple will be able to survive scandal after scandal and still survive unscathed. Cook is no Jobs.
If a developer refused to implement a feature due to their ethics then the company would do the following:
* Move engineer to different project
* Set unrealistic goals/deadlines/expectations
* After engineer fails, voice concern about performance
* Set up performance review and improvement plan
* After causing engineer to fail a second time due to unrealistic expectations, fire them due to poor performance
Even if that engineer writes a blog post, enough has happened between his initial refusal and termination as to make conclusive proof impossible. The discussion will be a he-said-she-said affair as his former employer makes a counter-blog post explaining the engineer's poor performance.
A lawsuit is similarly out of the question as most companies have sufficient funds to cause delays in court, thereby causing you to spend all your money on attorney fees and bleeding you dry.
It's not like hospitals haven't contended with this exact thing for a very long time. The wills of surgeons/doctors and their hospital administrators do not always match up.
"The Turing Oath" is on Github (https://github.com/maxmackie/Turing-Oath/blob/master/README....) and I recommend people contribute and we grow this to become something people recognize.
But I'm not sure if Turing, who is not well known for having had anything to do with privacy is the right person for this oath.
Though admittedly, no technology was involved in the whole matter.
Also, Turing’s wartime exploits involved a breach of privacy in the service of a good cause.
Actually, come to think of it, if viewed in that way, he's the perfect name for an ethics oath regarding privacy. I hadn't considered it that way.
For developers who have undertaken the Oath, the challenge would then be to write the best code, so that it sees widespread adoption. This might potentially make it harder for companies like Path to engage in activities which break the Oath.
This is silly. Stop trying to add grandeur to writing some code at X,Y startup/company.
People don't die or get harmed when some social-messaging application spams someone. Code is a way to implement an idea. Most applications exist to make money. If this a shock to you, read the user agreement before installing/upgrading, uninstall the application, or realize that in social networking, your personal data what the company uses to make a profit.
Ethics in computer-science-related fields are important and I think we do need a set of rules we can dogmatically follow like the Hippocratic Oath. Of course, the HO is different in that failing to follow can cause physical harm. However, the world is progressing quickly and more and more information is hosted online -- personal information.
I think it's our jobs to make sure we don't promote poor practice and un-ethical behaviour.
Seriously. I hope that you'll see this in time!
>>>> I think we do need a set of rules we can dogmatically follow like the Hippocratic Oath.
So you don't actually have to employ your own brain and your own moral judgement, because somebody already did it for you and wrote this nice set of rules, that you swore by Apollo to faithfully execute, without thinking, not unlike that box of wires and silicon chips you are paid to play with? Nice arrangement, I suppose.
>>>> I think it's our jobs to make sure we don't promote poor practice and un-ethical behaviour.
And you need to sign an explicit oath to do that?
Also, I think you're sort of merging the HO with the Code of Ethics for engineers in Canada -- two very different documents and I suggest you give them a read. And no, no one still thinks they're swearing to Apollo.
Why you need an oath for that - shouldn't it be always the default behavior?
>>>> and to act in the interest of the public.
"Interest of the public" is a very dangerous thing. I can remember a lot of very bad things that were done "in the interest of the public". You can make almost anything pass as "in the interest of the public" if you want to. Murder? Millions were murdered "in the interest of the public", because they were of the wrong ethnicity, class, physical features or just in the wrong place in the wrong time. Robbery? Millions were stripped of their property and reduced to utter poverty because it was claimed it is "interest of the public" to do so. And so on, and so forth.
I would rather steer clear of anything that has "interest of the public" written on it, at least until it's very clear what is underneath. Too many things that were underneath such writing proved to be a disaster.
>>> no one still thinks they're swearing to Apollo.
Swearing to a document composed by a faceless bureaucracy is no better. If you have code of ethics, live by it, if you do not - get one. What Apollo or his modern equivalent, the almighty bureaucracy, has to do with it?
bookoutlines.pbworks.com/w/page/14422685/Predictably%20Irrational
One more variation: Nina, On, and Ariely conducted a similar experiment. But, one group was asked to write down 10 books they had read in high school, and the other group was asked to try to recall and write down the 10 Commandments. When cheating was not possible, the average score was 3.1 When cheating was possible, the book group reported a score of 4.1 (33% cheating) When cheating was possible, the 10 Commandments group scored 3.1 (0% cheating) And most of the subjects couldn't even recall all of the commandments! Even those who could only remember 1 or 2 commandments were nearly as honest. "This indicated that it was not the Commandments themselves that encouraged honesty, but the mere contemplation of a moral benchmark of some kind." Perhaps we can have people sign secular statements--similar to a professional oath--to remind us of our commitment to honesty. So Ariely had students sign a statement on the answer sheet: "I understand that this study falls under the MIT honor system." Those who signed didn't cheat. Those who didn't see the statement showed 84% cheating. "The effect of signing a statement about an honor code is particularly amazing because MIT doesn't even have an honor code."
So I assume you never use any open source code in any of your programming projects, since you are fundamentally opposed to adopting any ideas that are not exclusively your own?
No, it's our responsibility as decent people. I don't need to sign some online pledge to keep myself from pushing people in front of trains. If I was the sort to harm others, why would I care about some meaningless online campaign?
The Oath is there to remind you to act in the best interest of the user. There are no formalities and although it seems common sense to people like you and me, others might not see it so clearly.
Neither do doctors really need the Oath of Hippocrates to stop themselves from harming people.
Well, yes. But there is a reason that every profession that has tackled this problem has used a system of oaths and certification. Engineers, Doctors and Lawyers are the canonical examples.
You need something that is given and can be taken away for bad behaviour in order to change behaviour at this level. Damn human brains.
Anyway, the issue at hand is bad corporate behavior, not bad programmers. I don't see why we need to start licking our chops about the prospect of forming a blacklist against individual programmers.
So go ahead and try and stop bad corporate behaviour, everyone else can use a proven system so that programmers can easily say "no" when asked to do something unethical and not be fired for it.
I'm often confused by how often programmers completely reinvent the wheel when faced with social problems. The idea of looking to other similar industries never comes up, even if the problem is exactly the same.
So what if they lose their license? They can still write code and do harm.
Yes, indeed. As it stands right now, the reality of the engineer's license is such that it doesn't fit very well the software world. The vast majority of companies couldn't give less of a damn whether you are licensed or not. However, it depends.
Regulations might eventually come in place to force software producers to hire only licensed engineers if the nature of their business is prone to put the public in danger. And as technology grows ever deeper into our lives, the danger that consumer apps can cause on the public is ever growing as well. For instance, breaching a user's privacy can be enough info to grant an ill-intended operator access to the user's e-mail through social engineering, from which it is then often trivial to gain access to that user's bank informations. You don't need that much imagination to figure out a scenario where a user's life can be turned to shit by some software abuse.
Given that this risk is ever growing, the possibility of a code of ethic on software business is plausible. Say in X months, the government of country Y decides that companies hoping to run a social network available on their territories must hire licensed software-engineers, and have them all sign-off any code that is presented to the public. That software engineer they'd hire would have to put their license and career in jeopardy if they were to implement some evil feature.
Before Québec's bridge, engineers didn't need a license to build infrastructure. The parallel between the current situation and the past isn't too hard to make.
Of course they get harmed: their time is wasted, and perhaps their concentration disturbed. This is a small harm to each victim, no doubt about it, but if you write code that makes your social-messaging application spam people then you're delivering that small harm to a large number of people. If your code wastes 10 seconds each, just once, for a million people, that's about three person-months of aggregate time you've stolen that will never come back.
It's quite true that "in social networking, your personal data what the company uses to make a profit". But if it were near-universal practice for new software engineers to swear a solemn oath not to use their powers for evil, who knows? perhaps some other business model for social networking might have had a chance to succeed.
I'm not justifying either approach, by the way, just observing what I regard as a strange disconnect.
What happens if an app for job seekers texts your boss? What if a casual hookup site texts your new girlfriend--even though you signed up a year before meeting her? What happens if your app calls an old person and they crack a hip trying to answer a phone--when everyone that knows them personally knows not to call until they're awake and their caretaker is in?
These may sound far-fetched, and we all mostly don't pretend we're as disciplined as structural engineers, but "we do it for the money lulz" is a shitty and stupid argument.
I'm okay with this. I'd rather be calculating than have my head in the sand about the business models of social networking what-have-you applications.
>What if a casual hookup site texts your new girlfriend--even though you signed up a year before meeting her?
While I don't and won't have to experience this, your imagined relationship suffers more from lack of trust and honesty than "some dumb app does some dumb, annoying thing."
>"we do it for the money lulz" is a shitty and stupid argument.
Don't Straw Man me. If my code was going to be used for something I perceive as evil, I'd leave the job.
Our industry doesn't need yet another pointless, embarrassing ethics/integrity campaign when the people writing the code don't care.
When was the last one?
I disagree. This case reminds me of Geni. You would put a relative's email address in to invite them, and they'd then receive a torrent of spammy "updates", until they registered to unsubscribe.
My less tech-savvy father added many relatives from his address book to Geni. Lots of hate from deranged relatives, and some less technically-inclined relatives are probably still being spammed, 6 years later-it made family gatherings awkward for a while. There are real-world, harmful consequences to this kind of scummy, unethical tactic.
http://www.telegraph.co.uk/news/worldnews/europe/russia/8284...
People want validation. Line-level employees want praise from coworkers and bosses. Executives want praise from their peers, investors, industry, and press. Concepts like ethics, "right," or even this-is-good-for-thie-world isn't a concern when faced with "X will increase my social status and happiness with my peer brogrammers." What's X? It's anything possible, regardless of legal, right, wrong, or ethical.
A nontrivial number of companies use unethical methods (spam, false invites, false installs, phone and email address book capture, fake attractive profiles) to increase their vanity metrics. Employees see those methods as either: "this is bad, but it's sooooo good for us — look at all the lame n00bs who fall for our tricks" or "this is bad, and I'm ashamed to work here."
The ones who feel shame would take the Hippogrammer Oath. Those who revel in manipulating others and standing on their broken bodies will rake in all the profits while the good guys just sit around and "play nice."
Even the tech darlings of today used spammy methods to grow their initial user base. How do you grow your userbase to ten million when you're growing at a constant 5,000 per day? Obviously you want to "go viral." How does one just on a whim "go viral?" You can either become a meme, a social phenomenon, or spam and manipulate unsuspecting people. Spam is less work than creativity.
http://blogs.msdn.com/b/oldnewthing/archive/2006/11/01/92244...
I often find myself saying, "I bet somebody got a really nice bonus for that feature."
"That feature" is something aggressively user-hostile,...
Things are going to look different to me now when I'm on a windows machine.
I remember having to put my job on the line a few times for refusing to program / setup something awful.
One of the worst was when I was asked to combine all divisions email lists and send out a marketing email selling some overpriced book, this was against the Privacy Act (AU), against our privacy policy and highly unethical to boot, refused and was given a written warning.
It was a contract web development company I was working for, about ten years ago. One of our clients wanted some SEO work done, and my supervisor had recently been reading a lot about SEO. He started out reading white-hat stuff, but by this point he was delving into some black-hat research, and he essentially asked me to program a message-board spam-bot. I just told him straight up that I believed that would be unethical and I refused to do it, knowing full well that simply refusing to do assigned work could cost me job.
Thankfully, not only did this not cost me my job, it caused my supervisor to re-evaluate his own position and he decided to go back into completely white-hat SEO. And in the end, he actually thanked me for refusing to do that work.
I feel like lucked out on that one.
I think it is important that we should realize this kind of mentality won't work. You might see bad people making money, but eventually it will be no good for them. Either they don't sustain, or the money is no good for them, or they can't sleep with all that money under their pillow. You will see lot of examples of this from history.
I have seen people who are ethical and right also make a lot of profits. May be not in the short term, but in the long term. The idea is, you don't go behind money, instead you do what you do best, and money will come behind you.
The patent language says it's "a commitment from Twitter to our employees that patents can only be used for defensive purposes." Extending this more broadly would say "a commitment to our employees that the code they write can only be used for non-spamming purposes."
The problem, of course, is that it's pretty easy to tell whether a patent is being used defensively or offensively. Defining spam (or more difficult yet, privacy) is a bit more slippery.
> Who would knowingly submit themselves to a doctor, knowing that they might give you a secondary, curable disease, just to ensure they got paid?
FTFY
What about software for missile guidance? Is that okay by this oath?
Or do we as a community value not texting people at 6AM more than we value not killing people?
If it does, it would never get mainstream acceptance; if it doesn't, but does cover the topic of this post, it will be ethically absurd.
I don't see how this is a straw man; when building a professional code, one has to choose what actions to allow or disallow, and this seems like a topic that would obviously come up. What do you think about this scenario misrepresents the idea of a developer's professional code?
I've never had to actually face the ethical dilemma of developing weapons, but what if the development improved precision on a missile? If we can ignore the question as to whether a missile is ethical or not, developing a better guidance system for a missile will help limit collateral damage, but could increase the "comfort-level" of using the weapon for those who decide such things, therefore increasing overall death/destruction. Utilitarianism is hard, because taking all factors into account is impossible. Kind of like machine learning.
I will never scoff at someone who turns down work for ethical objections, but some people are more pragmatic than others.
Both of Williams examples are really hard to wrap your head around if you accept the situations as presented. They are similar to a Sophies Choice [1]
[0]: http://plato.stanford.edu/entries/williams-bernard/#Day [1]: http://en.wikipedia.org/wiki/Sophie%27s_Choice_(novel)
As a programmer, I don't want a bunch of charlatans in SF to give my career an unsavoury reputation because of these antics.
Some folk tried to create a pacifist version of the GPL[1].
Others are using the RMPL (RobotGroup-Multiplo-Pacifist-License)[2] - basically a MIT license, but with a restriction that bans military projects.
[1] http://arstechnica.com/uncategorized/2006/08/7511/
[2] http://multiplo.com.ar/soft/Mbq/Minibloq.Lic.v1.0.en.pdf
I generally agree with this, which is why I find the idea of a "developer's code" somewhat ridiculous.
//It should be noted that no ethically-trained software engineer would ever consent to write a DestroyBaghdad procedure. Basic professional ethics would instead require him to write a DestroyCity procedure, to which Baghdad could be given as a parameter.
http://www.codinghorror.com/blog/2007/05/your-favorite-progr...
We need them to change their ways, not disappear.
Once Congress puts a bill forward to deal with this issue, it will be the beginning of the end for this type of behavior. I'm sure Obama will get behind it as well, as it will help the computer market immensely.
You don't need an official Oath or for the company to know or base their employment on such an Oath. Either way, the bottleneck is the employee drawing attention to the company doing something unethical; no Oath has to get in the way of that. There's already a sub-thread on top-secret/weapons/armaments jobs. What about political ethics? And religious? Marriage / gay rights? Porn? "Sexism?"
I think the system should be licensing and involve losing that license if you commit an ethics violation.
There would be unlicensed developers of course, but connecting the incentive to not do unethical things with the incentive to be part of the elite class in your profession has worked pretty damn well for Engineers, Doctors and Lawyers.
... and has pretty much screwed over the rest of society, at least in the latter two cases. The legal and medical cartels have done incredible harm to their customers over the years.
See http://mises.org/freemarket_detail.aspx?control=51 (law) and http://mises.org/daily/4276 (medicine) for details.
Even if there was some bad "allopathy" back in the day, there is more bad eclictics and homeopathy right now. And to practice medicine you have to understand scientific method, especially falsifability.
And I also have to say that the "free market" idea isn't falsifable. "Let it to free market" rarely works.
They assume rational actors (people making decisions based on their own self interest). That's been falsified (when applied to humans).
Most variations of the efficient market hypothesis have been disproved as well, for the same reasons:
Humans have cognitive biases and other types of irrational behaviour.
But anyone linking to mises.org is probably a follower of the church of the free market. And they generally strongly disagree with the idea that humans have cognitive biases (because their faith requires it not to be true).
I'm glad someone else laughed at the pro-homeopathy / conspiracy theory around the history of snake oil salesmen content on there.
> on their own self interest).
That's untrue of some schools of economics that advocate free markets, e.g. Austrian.
> But anyone linking to mises.org is probably a follower of
> the church of the free market. And they generally
> strongly disagree with the idea that humans have
> cognitive biases (because their faith requires it not to
> be true).
That's an ... interesting ... claim. Care to justify it?
I took the term "free market 'idea'" to be specifically talking about those for which it's true. That seemed to be the point, and the site linked to was Austrian. Both articles make the assumptions in question about the ability to self-regulate that assumes rational actors. So yes, my statement was not true of all schools, but it seemed like those types of Austrians were not in the scope of the discussion.
> That's an ... interesting ... claim. Care to justify it?
Subjective opinion. I read economics news and neuroscience news because it's interesting. Comment threads, especially here, frequently have two types of subjects that start the vocal libertarians arguing and proclaiming: government regulation and the phrase "humans are irrational".
Example: P.E. certified people should have no problem creating weapons systems for a nation-state at war. Does that make it ethical? Depends on who writes the history books afterward.
Example: P.E. certified people might refuse to participate in experimental, unorthodox methods. But especially in software these often become the runaway successes.
In other words _you_ have to own _your_ personal ethics. You won't be able to point and say "I was just following orders!" The pointy-haired boss who gave the orders isn't going to be able to exonerate you of the guilt. Often he doesn't even congratulate you for "doing the right thing." Maybe he'll fire you or give you a bonus – or join you in prison! – but my point is: it's orthogonal to your personal ethics.
Ethics may sometimes appear to conflict with rapid progress. That doesn't necessarily imply an existential crisis, just a lack of forethought. So many ethical problems arise due to overflowing ignorance / lack of forethought combined with a sudden rash of malice (when it comes time to pay the piper). Ethics are a way of expressing realities about the world that conflict with the general Adam Smithian "enlightened self-interest." I view ethics as meta-enlightened self interest – like how Apple is more than just industry-leading, they carved new niches where no one thought to go.
Engineers (software engineers or otherwise) have untangled things much more complicated than this. It's only overwhelming if it blows up in your face.
Path seems like a classic case of all of the above.
If you believe that standing up for your strongly-held beliefs will get you fired, you should look for a new job _now_. Sure, that incurs the trouble and uncertainty of a job switch, and possibly a pay cut (though perhaps less of that than you think). But if it means that you don't have to be ashamed of what you do all day --- it's generally worth it.
Furthermore, whistleblowers are often unemployed for extended periods of time, due to corporations not wanting to hire them as they could be a liability.
At one time, it was cooperative multitasking and memory management. Programs were supposed to behave themselves and get out of one anothers' way. Except that, due to bugs or malice, some didn't. We called this world "DOS" (or pre OSX Macs).
Microsoft still attempts to allow vendors to install programs whereever the hell they want, and to, pretty please, not overwrite other program's infrastructure or system-level DLLs. Yeah. Right.
In the Linux world, we've solved this problem, if done right, though distro-managed, well, distributions. Any program can be included if it meets qualifications (generally limited to licensing requirements), and a sponsor steps up. Once included, the package gets the benefits of being included in the package lists, distributed over archive mirrors, and included in bugtracking and support systems. However it's also got to play along with the requirements of Debian Policy as to how it behaves on a system.
The proper way to address the issues of app privileges is to control privileges centrally on the device and grant them to specific apps. If a user doesn't wish to give an app, say, addressbook access, then they can deny it (or feed it a bogus addressbook). The app vendor can decide what they're going to do at this point, but what they can't do is override the user's explicitly stated limits.
Perhaps the guy checked a box that said "Please notify all of my contacts via text message".
Then all the messages went into queue that was delayed a bit.
Then the phone companies converted text messages to voice calls.
This approach might burn them completely but also can get them to some significant number of users (after which they will issue an apology and pay all fines if needed).
Shitty behavior does not stop being shitty behavior because you have bills to pay. And it's not even in the "understandable under duress" area of shitty; Path isn't a person with a starving child and that dude's contact list isn't a loaf of bread.
If your company can't exist without being shitty, your company shouldn't exist.
I can't figure out what you mean by this. Are you saying that this behavior is only alright when you need the money?
[edit]To be clear: I do not have dependents, but I also don't have an employer (who isn't me), and I do have people that depend on me. What I also have is a lot of experience in a lot of situations that are very much "gray" in terms of what less-experienced people seem to consider moral/ethical absolutes, which simply do not exist. That last part is what you don't understand but are likely to figure out as life teaches you the things your parents and teachers would like to but simply can't.[/edit]
Doing the right thing is sometimes difficult. That's not an excuse to do the wrong thing. Indiscriminately spamming hundreds of contacts is always the wrong thing.
But the standard for acting like an asshole has to be greater than simple expediency. The necessity of breaking the social contract has to be roughly proportional to the community inconvenience; that's why firemen get to use the siren and everyone is supposed to yield when they are headed to, well, fight a fire, but I don't get to use one when I'm headed to the grocery store.
If I bang on a stranger's door at 6am because their house is on fire and I'm trying to warn them, then that's great, because the "don't harass strangers at six in the freaking morning" social norm is less important than the "OMG THE FLAMES THEY BURN!" social norm. In contrast, if I bang on someone's door at 6am trying to sell Amway products, then I'm an asshole. Finally, If I bang on someone's door at 6am, insist that their buddy, whose name I found by going through the trash, has photos to share with them, and only later reveal that there never were any photos, then I'm an unbelievable jackass.
banging on door <=> text/phone call, which likely causes an audible alert stranger <=> contact/acquaintance/vendor/client/boss/relative/lover/ex-lover/dentist of a new user 6am <=> 6am their buddy <=> their contact the trash <=> a new user's cell phone contacts has photos to share <=> has photos to share there never were any photos <=> there never were any photos unbelievable jackass <=> unbelievable jackass
Seems close enough.
But my real question for you is which is it? Did a developer/Path act unethically, but you believe those actions are justified because people have families they need to care for? Or do you believe that Path/the developers did nothing wrong and I'm just applying my own morals to the situation? One or the other is a legitimate position to take (though I may disagree with your view), but you can't have both.
We can bitch at Path all day, but there exists strong incentive to do this, and people who don't do this will have unilaterally disarmed and be at a disadvantage. We need to encourage the first group to not do this, and encourage the second group to keep it up and not feel like suckers for respecting their users.
But you can get on TechCrunch, so it's gotta be okay, right? :(
[0] Note that jail time also serves to rehabilitate the offender in case of serious crimes. That obviously doesn’t really work with companies, and unfortunately, carelessness with other people’s data is not considered a serious crime in many places.
[1] Basically anything above a parking ticket.
It also discourages the searching of flaws in the system because even if you get away with it once (net-positive) you know the next time the fine will make unviable.
BTW this is similar to how already the civil justice system works in many countries, where after repeated minor offenses you go to jail.
Ethical justification isn't easy, but it's also not this hard. The entire point of being ethical is that you might lose out as a result of being ethical. If you opt to discard ethics in order to get ahead, you are being unethical. That is what it means to be unethical.
This. Is. Unethical.
UPDATE: That appears to be related to collecting info on minors. Looks like they need to be fined again for this.
They will claim it's a "bug"... albeit one of those "viral bugs" that seems to lead to topping the App Store download charts. These tactics make me think there's no such thing as organic growth within the app stores.
You can sue for anything; just not always successfully. That said ...
This appears to be trespass which I think is a tort (entering a part of property, the phone, that was off limits and without consent). You can sue for that.
It's also in the same respect contrary to the UK Computer Misuse Act (crime) AFAICT [story appears to be in the UK, or is it just UK entries in the addressbook]. That would probably hinge on the consent to access the particular files duplicated.
Then there's database rights (tort?), a sort of copyright for databases. [Copyright wouldn't apply as it's not a creative work].
Harassment (tort I think) and infringement of the right to a private life as enshrined in the ECHR (crime) seem to be causes to object as well.
As the calls were business motivated then failure to check against a telephone cold-call blacklist could also generate extra fines.
Seems there's much that could be sued for.
Still bad, but quite a different perspective.
Yes. It's illegal to use someone else's likeness for advertising without their permission.
LinkedIn keeps asking me to share my mail user/password so I can connect with more people, and says that X and many others already did it. I can't tell about others, but X is my wife and I'm certain she didn't do it.
So well, as I said I think that this is just a matter of incompetence (ie. automated message gone wrong).
EDIT: typo
I incline towards the opinion that these sharks do it quite deliberately. They just don't care how many people they embarrass and annoy, as long as some of those tech-innocent grannies and plumbers join up and thus put figures on their business projection sheets that get these sharks closer to cashing in big on an FB style IPO.
And the messages Facebook sends me telling me about an event and letting me know that one of my friends is a guest, when they've been invited but haven't actually confirmed.
It is, but his stated reason for doing so is nothing if not totally insane.
For the CEO of a business that sends phone spam to other people at 6AM, it’s also rather telling behavior, though.
[0] - http://jesuschristsiliconvalley.tumblr.com/post/48596551224/...
Here's to hoping the next fine will exceed their cash reserves and we can put an end to this madness.
The post is proof positive that path still uploads phonebooks from the app to their servers right after installing it.
1. Path was fined, not for anything involving address books, but for allowing 12 year olds to sign up for the service.
2. Yes... it is proof that Path uploads your phone book. Of course, they ask you. The OS won't even give you access to the phone book without prompting the user. So somewhere along the way, the user knowingly gave Path access to their contacts.
It would be rather trivial for a real reporter to do some research here. Does Path actually say "We're going to invite all your friends via SMS", even in fine print? It might be sleazy, but it would certainly change a lot. But instead, we're just going to sit here and speculate about things and irrationally talk about a fine that didn't have anything to do with this.
The thing that burnt the poster is that while a social app asking for access to their contacts might not rise a brow, the user has no way to know what they are going to do with that data without looking at the reviews or around the internet for complaints/testimonials.
Yes and no. Google often hides the most offensive permission requests under that "see more" arrow. And the permission requests (and accompanying explanations) are too vague and ambiguous. For example: Does "request access to network" mean they're able to sniff all my incoming/outgoing data, granting the app access to everything?
It's got the title and button at the top, taking up a large chunk of space (1/3rd on my Nexus 4), and then a vague list of - to most users - technical-sounding "stuff".
My guess is a large majority of users never look past the button.
<uses-permission android:name="android.permission.READ_CONTACTS"/>
and the installer will prompt the user for that permission when they install the app.Go to play.google.com. Search for path. First result in the app store. Click on Permissions.
"This application has access to the following:
... blah blah blah ...
This permission allows the app to use the camera at any time without your confirmation.
... blah blah blah ...
read your contacts Allows the app to read data about your contacts stored on your tablet
... blah blah blah ...
read call log Allows the app to read your tablet's call log, including data about incoming and outgoing calls.
... blah blah blah ...
Now users have been trained to click "yes" to all requests without even reading them, so I you can get into philosophical arguments about if the "really" have permissions. Just like most users randomly click thru "click thru licences".
I'd assume the reason Google is somewhat hesitant to offer this officially is that many apps don't deal well with this -- some do degrade gracefully, while others end up throwing task-ending exceptions because the app code just never planned for not being able to do some task which requires permissions declared in the manifest.
Every app already has to consider the case of GPS being unavailable indoors, the contact list only having one person (yourself) in it, or the camera picture being black in darkness.
I'm sure some apps will fail anyway because they just never expected a contact list of 0 entries, but the list should be much smaller in that situation (mostly limited to those who do virtually no QA).
It would be easy enough for developers to catch security exceptions that Google would find little or no developer fall-off due to a requirement like this.
>Does Path actually say "We're going to invite all your friends via SMS", even in fine print?
Should it? More importantly, will anyone download the app in the first place if it did?No one -- in their right minds -- would suddenly want to share (non-existent) photos with all their contacts. Seems like an odd way to say "We're going to invite all your friends via SMS". Your address book doesn't consist primarily of your Twitter followers. It doesn't matter if they intended it to be a feature; someone at the company should have raised a Big Red Flag and made any such SMS feature explicitly opt-in-only. With a big fonts, high-contrast colors, dancing bananas or whatever else you can use to grab attention to that fact.
This is an order of magnitude beyond sleazy.
Many users just mash on the "next" button on app intro screens. Again, it's all just speculation until someone takes the time to start researching and documenting the facts instead of just yelling "KILL IT"! :/
I'm not unsympathetic when someone says "oh, I didn't read that bit" (I'm guilty of that too), but surely they have usability experts who would have warned them about it. The original author is technically inclined to make an informed decision. That's a big deal to me. That tells me, they never gave the guy any settings options to begin with or hid it in an obscure panel.
What's worse, according to the author, texts were sent possibly after he uninstalled the app. Which means they still keep the data!
For what it's worth, I disagree with Path and Me1000's arguments. Doesn't mean us here at HN should be attacking him or ignoring his points because of that, nor does it mean that doxing him is acceptable.
Really disappointed with HN in this thread :/
I don't know what the details are on those audits, but if these texts were sent without consent it seems like the kind of misuse of personal information that they would be concerned about.
That's not true, is it? According to the FTC[1], they were fined for "collecting personal information from their mobile device address books without their knowledge and consent."
2. Yes... it is proof that Path uploads your phone book. Of course, they ask you. The OS won't even give you access to the phone book without prompting the user. So somewhere along the way, the user knowingly gave Path access to their contacts.
Giving them permission to read the address book (which might be useful and perfectly legitimate) and giving them permission to send everyone in that address book spam is two very different things.
> The OS won't even give you access to the phone book without prompting the user. So somewhere along the way, the user knowingly gave Path access to their contacts.
The introduction of address book privacy in iOS was in large part prompted by the publication of Path's behavior. Up until the Path and eventually iOS update after the controversy first arose, Path didn't explicitly ask the user for access to their address book.
http://www.engadget.com/2012/02/15/iphone-address-book-issue...
> Path was fined, not for anything involving address books, but for allowing 12 year olds to sign up for the service.
Path was fined for the 12 year old signup thing specifically, but they were still charged with privacy violations regarding the address book kerfuffle.
For example, I'd want to be able to use the facebook app and many users might even want to have it scan their address books in order to find friends. However, if the app attempts to read my address book when I'm just checking someone's status update that is clearly not okay and I want to be able to block it.
The free pass to pillage my phone upon installation doesn't sit well with me.
Most definitely. This has always been my argument against the whole system: installing apps that need excessive permissions is basically blackmail. Just like "Do you agree to the terms of service?", you hardly have a choice. I was very surprised to see people not even glance at the permissions before clicking Accept.
But as I said, it's blackmail anyway whether you look or not. You don't want them to have all your contacts, your exact location, all data on your sdcard, and full network access? Fine then, you won't get [whatsapp] (or pretty much any other app), that what everyone else has and that you're almost socially obliged to have (at least in my age category).
It even goes so far that the android user has no permissions to use the permission manager to deny or allow permissions for apps. There are commands ("pm grant x" and "pm revoke y") that lets you change apps' permissions... but you can't use it by default, even as root ("java.lang.SecurityException: Neither user [your uid] nor current process has android.permission.GRANT_REVOKE_PERMISSIONS"). It's totally messed up.
Same odious behavior, just a bit different this time.
By your logic, it would be completely useless to even read the fine print, because giving them access to the addressbook would imply my consent for them to do anything technically possible with it.
Well, from a technical perspective that is indeed the case. Once they physically have your contact info they may do as they please.
You, as the iOS or Android user, are not giving them permission to use your contacts "properly" or "nicely"--you're giving permission to access them, the raw data of all of them, and once that's done all bets are off. If the app is untrustworthy it is free to go crazy (one of the reasons I always say "no" to that question).
I don't see how Apple or Google can stop this in a technical way without making the permissions more fine grained which in turn makes it more confusing to users (who probably mostly click "OK" anyway).
Apple could, however, make better app policies so that they can pull apps when they attempt this kind of shady crap. I'm not familiar with the Android app store policy, so I won't speculate there.
It's been about nine months since I've worked at Path and as you may know (although, given how baseless your comment is, perhaps you wouldn't know)... startups move quickly, Path has released many updates since I've left. It's incredibly disingenuous to suggest what I'm saying is untrue (since both statements I made are provable with empirical evidence) or that I had any motive other than trying to get people to think before they go on a witch hunt.
Droithomme, if I know you personally, I would appreciate you contacting me privately.
Lots of people know Randy. He's had posts on the front page of HN.
As much as a developer can be a "public figure", I think he is one.
If John Resig posted about DOM libraries and someone mentioned that he wrote jQuery, I don't think anyone would suggest he'd been doxed.
Is it? The texts were coming from his phone number, which suggests they were sent from his phone (not necessarily, I know, but you said "proof positive").
I don't know how Android text message sending works, but there is likely some rate limiting to how many texts you can send so they certainly could have been queued up to be sent later.
If Path grows, I hope they just die (two strikes is enough for me!) more and more people will look under the hood.
It's a fun device. But it's a spy, outside my control, in my pocket.
I've rooted it, but haven't yet modded it (and if anyone cares to point me at a gentle introduction for CyanogenMod or another option that works on an HTC Incredible, I'm all ears).
I've been reasonably conservative in what apps I place on my phone, and several (Pandora specifically comes to mind) were removed when permissions were extended to include contacts (Pandora, you listening?).
I'm waiting eagerly for the following capabilities:
To define at the phone level what information I'm willing to share. Existing "privacy controls" make a mockery of any semblance of either "privacy" or "control" by distributing vague and conflicting access among a great many applications with no ability to centrally audit them.
To specifically grant to specific applications specific rights. My location is something I'll disclose very guardedly (I disable GPS functions on my phone). Other rights generally shouldn't be shared.
To request and audit ALL information a given application has of me in a convenient electronic format (such as a database dump accessibly by MySQL or Postgresql). Such functionality is of course a three-edged sword, as what information the vendor has and I wish to request a third party might also request pretending to be me. Or having legal authority to make the request (though that's already the case), via subpoena or warrant.
My contacts list is off limits. Full stop. Specific contacts might be contacted by way of an application if specifically designated by me, but no other use may be made of their information. Hell, it's not even mine to give.
The existing state of smartphones is interesting, but it's also a little shop of horrors. And if application authors, smartphone manufacturers, and telecom providers don't get their act together on this Real Soon Now, we're going to see some horror stories.
Then whenever the app attempted to use those revoked permissions, android would do something logical for certain cases (like providing an empty contacts list for the contacts permissions), or even just crash the app if it couldn't do anything else. I would totally be willing to accept a certain amount of instability for a feature like this.
You can, you can! Only Google went ahead and disabled it for you. The commands are "pm revoke x" and "pm grant y", but if you ever try it (even running as root), you'll get this message:
Operation not allowed: java.lang.SecurityException: Neither user [your uid] nor current process has android.permission.GRANT_REVOKE_PERMISSIONS
> "Then whenever the app attempted to use those revoked permissions, android would do something logical for certain cases (like providing an empty contacts list for the contacts permissions), or even just crash the app if it couldn't do anything else. I would totally be willing to accept a certain amount of instability for a feature like this."
Exactly! Same for me. If this made it into stock android, developers would be forced to put phone book access in a try{} block so that permission revoking doesn't crash the entire app. Your solution with returning an empty phone book sounds even better, but that's also more work so I don't know whether that'll ever make it... Then again, it's a much nicer solution, so who knows.
This kind of behavior doesn't just go away after a bit of bad publicity or a few fines. It's part of the DNA of a company. Such a lack of ethics permeates everything from strategic decisions to technical choices to hiring.
Expect more of the same.
Edit: Here's when they flubbed a year ago.
http://news.cnet.com/8301-19882_3-57373474-250/path-ceo-we-a...
Edit2: Er... apparently, I suffered a seizure of some sort (and an aneurism and a stroke simultaneously). Reworded.
"... Your trust matters to us and we want you to feel completely in control of your information on Path. ..."
So they want you to feel in control.
I get the feeling that either those in charge are hopelessly detached from society to see how privacy is perceived by the rest of us (like Zuckerberg) or there's little to no vetting when it comes to implementation decisions.
That non-apology is corporate communications at its most typical.
More here: http://terribleapologies.com/ and http://en.wikipedia.org/wiki/Non-apology_apology#Examples and http://jezebel.com/sorry-not-sorry-how-to-non-apologize-5993...
If you aren't Captain Picard, you're not engaging anything. Shut up and talk human, folks.
So, google cache: http://webcache.googleusercontent.com/search?q=cache%3Ahttp%...
1. if you don't have sudo, use the W3 Total Cache plugin http://wordpress.org/extend/plugins/w3-total-cache/
2. if you have sudo:
2a. the easy way: apt-get install memcached, add the pecl memcache extension, and use object-cache.php http://plugins.svn.wordpress.org/memcached/trunk/object-cache.php and batcache http://wordpress.org/extend/plugins/batcache/
2b. the hard way: varnish https://www.varnish-cache.org/ https://github.com/pkhamre/wp-varnish # /var/spool/cron/crontabs/apache
*/2 * * * * ( cd /var/www/htdocs && [ ! -e .mlan.lock ] && touch .mlan.lock && wget -q -O tmp.html http://www.mywebsite.com/blogs/my-long-article-name/ && mv -f tmp.html my-long-article-name.html && rm -f .mlan.lock )
Post HN story http://www.mywebsite.com/my-long-article-name.html and it'll get refreshed every 2 minutes. Pretty simple hack. (Edit: add lock file) rm -rf /var/www/wordpress
FTFYI'll make sure to never install Path
There are some abuses that can't be solved by an apology.
Not installing Path is not a solution here. You gotta look critically at the permissions an app uses and their terms of service (at least skip to the privacy related issues, though they usually try to hide and obfuscate them). If there is something you don't entirely trust, wonder why you really need that app. Perhaps it's an improvement for your life, but can't you really live without? You've gone without that app for the past how many years? Is it worth giving up your phone book and all sdcard contents?
Here's what I would like: for Android to allow me to deny or ask for a confirmation for each permission of these.
However, if the story is indeed cut and dry:
1) Path sent messages that qualify as spam both because they had no permission to send them and they were false.
2) If this was intentional, this should be a red flag to investors not just of the company but the kind of people that run it.
3) This is nothing new. Tagged did the same thing, with e-mail, which to some degree falls afoul of less laws than using text messages or the telephone (other commentators pointed out that land line carriers convert SMS to voice calls, which is news to me.)
4) Using spammy methods to acquire users is a red flag for any web service. While arguably Facebook used and uses extremely aggressive e-mail notifications (sending out an e-mail for every minor thing, and whenever a new feature is added opting in the user to receive notifications by default), using spammy techniques means that your service will skew toward the bottom of the market that actually "falls" for these techniques (poor and illiterate) early on and actually scare away early adapters for multiple reasons.
5) In the short term, Path's metrics will look really good, but in the long term it could result in serious problems, least of which will be another news story with FTC settlement in it.
(Do they charge you 15¢ for the privilege? Can you reply?)
(You can also contact your phone company and ask them to please remove this "feature" - but usually you have to be subjected to it before you know the phone company even does this!)
Obviously such an action should be more clearly labelled. If it was, could they whitelist the times it sends out text messages to not do it at 6am? How easy is it to lookup an approximate region for a mobile number?
"Do not send SMS, email, or other messages on behalf of the user without providing the user with the ability to confirm content and intended recipient."
An app generally needs a backend and it is clear some of the policies are directed towards not the app itself but how it interacts with the backend. These same guidelines are meant to be used to stop apps such as malware games that collect contacts and send them to the backend to be used as spam email lists.
Contact them via their Desk service portal here http://service.path.com/customer/portal/emails/new and ask them to remove your data after deactivating.
Not deleting your content, though. I hate that.
“Deactivating your account will remove your content from Path.”
The ‘Path’ in the sentence refers to the social network, not the company’s servers.
This privacy policy is a joke. It basically says "we can do anything we like with your data".
Under the "What Information Do We Share With Third Parties?" section there are some classic deceptions. This one is great (as in evil genius):
>with certain social networking services, if you allow such sharing through our services; //
Not consent, allow. As in if you don't actively prevent it we'll do it.
>with service providers who are working with us in connection with the operation of our site or our services //
We'll sell you out to anyone who we can describe as "working with us".
>"in connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition, or in any other situation where personal information may be disclosed or transferred as one of our business assets."
So when doing business-y stuff, blah, blah oh yeah and any time we want to use your info as a business asset. They're covering themselves, again, to sell all data to anyone who'll buy it.
Why? Having worked on a semi social app last year, deleting a user and all their content was a huge undertaking. Marking them and their content as deleted was simple and had the exact same effect--user and content never get returned from DB queries. Guess which one we implemented?
I guess I'm trying to say sites don't (always) do the deactivate thing because of some nefarious scheme to steal your content/identity at a later date. Sometimes it's just a technical call (or lazy programmers, depending on your point of view).
But more generally: one of the most interesting parts of startups is the tension between "Don't Be Evil" and "Don't Fail". It would be good to be able to discuss this more openly -- "Don't Be Evil" by itself is too utopian. Many of the most successful companies in the world did things in their early days -- or later -- that new entrepreneurs would never even consider -- until of course their own backs are up against the wall.
However, problems arise when startups begin to think that behaving this way is 'normal'. During the previous furore over Path grabbing address books, the CEO claimed it was "industry best practice". Just because (nearly) everyone does it, doesn't make it "best practice". It actually belongs on the 'list-of-dodgy-things' and therefore should be treated with the appropriate caution.
This is one reason I have a gripe with the "Move fast and break things" bandwagon. It's not really appropriate if you're stumbling around in a minefield.
After reading this I don't think I will join anytime soon. I don't really get the reasoning behind this. Path is marketed for the use case I had in mind. Sharing stuff with only a handful of people you know well. Why on earth are they trying to lure all of your contacts in. This would make sense for facebook, not for path.
Anyone knows an alternative to path using my data more responsibly?
But besides the fact that my friends aren't really into the whole tech thing (lot of them are still using their old non-smartphone) Inlining videos, photos and threading conversations is something I really like for such a software to have.
The thing is it doesn't matter.
When you're dancing on the line of ethical behavior, you are one bug, one mistake, one oversight from crossing it. When you cross it, it might not be "your fault", but generally it never is: your fault was to be so close that such a thing could happen in the first place.
You have to explicitly hit "unselect all" first :(
Obviously, this is really bad UX design (for the user), and it really surprises me that Path would do this just to get a few more users, especially considering that they used to market themselves as a social network for a limited number of close friends.
http://gawker.com/5883549/dont-forgive-path-the-creepy-iphon...
Path seems to be taking especially egregious steps. All the UI polish in the world can't hide shady business practices.
As it stands, $800k is a line item equal to only 2% of the money Path has raised. As such, I doubt that anybody who invested in it cares or views this as anything other than a triviality that a few nerds will care about.
1. Was the feature designed badly? Yes. Friends should be unchecked by default.
2. Did Path call anyone? No. That's a service from phone providers when a text is sent to a landline.
3. Did Path sent texts without permission of the user? No. But the feature was designed in a way that many people just tapped yes and didn't uncheck their contacts.
No?
The permissions screen is shown in the verge article. It's labelled: "Find Your Friends: Path is more fun with friends. Find out who's already on Path."
I interpret that as asking permission to run my contacts against its database and tell me who else is already on Path. Not as asking permission to text people who aren't.
Permission to do some X with a contacts list is not permission to do anything with a contacts list.
http://www.reddit.com/r/Android/comments/16tavj/warning_be_c...
https://play.google.com/store/apps/details?id=com.path&f....
"I decided the best place to contact them would be Twitter"
Why would anyone contact someone on Twitter first? Their contact page (usefulness unknown) is easy to find on their website.
I just deleted Path; I recommend others do the same.
When a company is this small and shows no regard for privacy we better hope that it falls in the deadpool because if they get to scale, we are going to get to hear a lot more of these invasive tactics. I really hoped for path to put a dent into Facebook's growth but not anymore!
Exploits should be used on targeted individuals where you can serve a trojaned app just to that individual, vs. something like the App Store where that would require either Apple's permission or some crazy proxy. (A carrier could probably do it with phones the carrier sells, though, particularly on Android, but even on Apple by pre-jailbreaking phones sold in sketchy areas like rebel-held Syria, if that were the goal)
This is why I hate install-time permissions. It means you have to trust an app until uninstall do you part, which generally happens well after abuses.
Android developer here: I would have to say a mix of permission types would be best. Sometimes a feature of an app is crucial to its design (or, to be blunt, to its monetization).
A few things -- using the camera on the phone, accessing the address book, sending text messages, maybe a few others -- would be great to request as "optional permissions," or even better, "runtime-granted permissions," so that an app that only 5% of the time needs that permission could ask for it LATER instead of making everyone who installs the app agree to using a permission that they may not want the app to have.
As it stands, you'd have to break your app up into several different downloads in order to have optional features. Not impossible, but neither is it a good user experience.
LinkedIn's signup flow is similar.
http://blogs.wsj.com/digits/2013/04/25/path-a-social-diary-a...
Path, a more intimate social-networking app that’s like a personal journal, is now growing by 1 million registered users a week after its most recent launch.
The newest version of Path includes a way to message your friends — for which Path limits to 150 — and send them stylized stickers like other top messaging apps. Around half of Path’s registered users (now at 9 million) are regularly using the app on a monthly basis, CEO Dave Morin said.
This may not be the reason but surely helps many in our industry to reach those dark spots of ethics and faithfulness.
If your users are customers, that is, they pay you, then you will care about their privacy, as you know that otherwise, you will loos them.
If they don't, and yet consume your bandwidth and CPU, you may find yourself end up sniffing their address-books, claiming copyrights on their images or selling their clicks and choices to campaigners.
Did OP give this permission? I'm not defending Path (at all!), just trying to get full details. I've in fact accidentally given address book permission to apps by tapping too fast.
Update: OP is using Android, which is different.
On iOS, for reference, one could install Path but then deny it notification permission (or limit what types of notifications at a very granular level), allow/deny access to photos, and allow/deny access to the address book. You could deny all of those and still use the app just fine, though obviously without the ability to upload things from your photo roll.
Yup, here’s an article about it, from February of last year: http://allthingsd.com/20120215/apple-app-access-to-contact-d...
However, according to Apple, even before iOS6 came along (which asks permission whenever an app requests access to Contacts) it had already been against Apple’s dev guidelines to use Contacts info without users’ permission:
“You and Your Applications may not collect user or device data without prior user consent, and then only to provide a service or function that is directly relevant to the use of the Application, or to serve advertising. You may not use analytics software in Your Application to collect and send device data to a third party.”
> We're sorry to hear of your issues.
Well I don't have issues, you have issues. And you should be sorry that you screwed up, not to hear about anything.
After getting a "smartphone" I've had 50x more spam calls. I never had this problem pre-Android. Coincidentally, spam peaks when I'm using my phone, which makes me wonder if these apps are telling spammers I'm near the phone.
On top of all of that, why wouldn't the phone provide a setting to restrict all personal/identifying information from being accessed by the app?
They can change later and spam your list or use it for some other purpose. You can shame them publicly if you find it out. But then, it's already too late by that time.
This is my personal favorite app permission that you can request: http://developer.android.com/reference/android/Manifest.perm...
Translation: "Your blog post detailing our scuzzy spammery is getting seen by lots of people. We're uncomfortable with that, and would like to get you to say we're not so bad after all."
CALLING A FREAKING LANDLINE?!? DIE PATH
I've been so dumb to not have tried this kind of bad publicity stunt yet.
If you can't send anything except this daft, goofy, unbelievably annoying tweet, maybe you need to find a different way to "engage" with upset users.
The Play store definitely has a more laissez fair approach to apps, but spamming like this is pretty a pretty blatant violation. Google might want to consider suspending their app.
For "bit.ly/PathHelp" the underlying url is "t.co/B4lOWrDqyr" and it redirects to "service.path.com/customer/portal/emails/new"
I'm sure there is a reason for it, but just having service.path.com or help.path.com would be more beneficial for the company to both have as a url and to tweet to (former) customers/users.
Overreaching use of customer data, check ("But everyone else was doing it!"), and then saying "it turned out the customers didn't understand this", spamming contacts, a CEO who come across as somewhat of an arse at multiple opportunities.
If I was a VC I'd be so nervy about investing money in a business that's repeatedly getting caught out doing some seriously shady business practises.
"The Director of Privacy and Legal will be responsible for positioning Path as a leader in the protection of user privacy."
They are showing the world what could happen if your data lands in the wrong hands. I hope people now become more aware of privacy and security issues thanks to Path. Tell me which other company is directly working for this cause? FB and Google keep telling that they won't use our date for bad purposes. Path is showing what can be done with the data they already have.
So this is why I like Path. They are setting an example of what bad companies can do.
Which is essentially what they did. It's still a break in even if you leave your door unlocked.
Might even cover that 800k fine easily.
Someone built a tool. And someone else used that tool to do an unethical thing. I doubt a software language exists that can control the choices of its users.
Never ascribe to malice that which is adequately explained by incompetence.
This does not seem like the most likely scenario to me.
Recently fined by the FTC: http://www.pcworld.com/article/2026985/ftc-fines-maker-of-pa...
if another dozen of cases like this happen, maybe, just maybe, people will wake up and stop installing apps with ridiculous permissions.
That's one of the reasons i use CyanogenMod. i can disable permissions from apps. For example, i removed internet access from swype. It does crash everytime i reboot my phone, because it's probably trying to check for updates, and i know it will crash if it tries to connect while i'm typing. and i rather that then be in the dark if my data is secure.
Anyone got a mirror?
say i install an app, but i want that app to see exactly 0 contacts when i actually have more contacts than that.
"Path is really best with friends and we really want to help users invite the people that they care about to their Path as quickly as possible," said Nate Johnson, VP of marketing for Path. Johnson said the Path customer service team has reached out to Kenwright, but right now it looks like nothing went wrong with the app.
Maybe I'm not in the target demographic, but I'm guessing that most people have a mix of contacts in their contact list that conform to different social situations. Not all of them would care to know I had photos to share.
They are betting that they become so big that these shenanigans don't matter later on.
It's a Catch-22 of ethical misconduct!
I'm not sure the shenanigans won't come back to haunt them. Less trendy apps have been booted from Apple's App Store for a lot less.
No, you didn't. You decided that you could score some quick internet drama points using Twitter.