4 comments
> Uploading your address book to an app is different than posting it publicly because people trust Path their their data.
Are you sure about this?
Has every Path user really reviewed Path's data security policies and deemed them satisfactory? Do Path users even have access to that information? And if they did, would most of them be in any position to evaluate it knowledgeably?
Or isn't it more likely that they trust Path because they don't know the full scope of what Path has access to? Blind trust is easier to extend to someone the less information you're trusting them with, after all.
Are you sure about this?
Has every Path user really reviewed Path's data security policies and deemed them satisfactory? Do Path users even have access to that information? And if they did, would most of them be in any position to evaluate it knowledgeably?
Or isn't it more likely that they trust Path because they don't know the full scope of what Path has access to? Blind trust is easier to extend to someone the less information you're trusting them with, after all.
Yes, I think it is quite a clear statement. Uploading to an app is not the same as posting it publicly.
Other points that you are mentioning have more to do with user's willingness to take privacy seriously. Most don't take it seriously because a) it's tedious and time-consuming b) they probably don't understand it c) it is easier to trust the company like everyone else and get onto using the app and 4) ... as long as it does not include criminal, financial, health or their telephone records, everything is pretty much a go go for a user.
Users don't care about their privacy unless it has elements of the 4 categories stated above. Users hate hassle and they have pretty much resigned from the fight for privacy mainly because they have found that the benefit of sharing things with others outweighs the willingness to be clear of a trouble that rarely every shows up in their conscience anyway .... think about it ... when was the last time a major security breach occurred that compromised so many millions and devastated so many thousands that it has left a blip or a bad mark on users conscience.
We maybe very techi ... but average users are far more occupied with other concerns. So blind trust plays a strong role for them.
Other points that you are mentioning have more to do with user's willingness to take privacy seriously. Most don't take it seriously because a) it's tedious and time-consuming b) they probably don't understand it c) it is easier to trust the company like everyone else and get onto using the app and 4) ... as long as it does not include criminal, financial, health or their telephone records, everything is pretty much a go go for a user.
Users don't care about their privacy unless it has elements of the 4 categories stated above. Users hate hassle and they have pretty much resigned from the fight for privacy mainly because they have found that the benefit of sharing things with others outweighs the willingness to be clear of a trouble that rarely every shows up in their conscience anyway .... think about it ... when was the last time a major security breach occurred that compromised so many millions and devastated so many thousands that it has left a blip or a bad mark on users conscience.
We maybe very techi ... but average users are far more occupied with other concerns. So blind trust plays a strong role for them.
I didn't read all the disclosure documents on my mortgage, but I bought the house anyway.
I'm not saying Path is right for what they did, but neither do I think it's the same as publishing everything where identity thieves can get at it. Such black & white thinking is of little use in creating policy.
I'm not saying Path is right for what they did, but neither do I think it's the same as publishing everything where identity thieves can get at it. Such black & white thinking is of little use in creating policy.
"I didn't read all the disclosure documents on my mortgage, but I bought the house anyway."
You should have read them. All those people who got stung by Adjustable Rate Mortgages? Didn't read the terms either.
Now imagine that an app has terms that are a bit like Adjustable Rate Mortgages.
You should have read them. All those people who got stung by Adjustable Rate Mortgages? Didn't read the terms either.
Now imagine that an app has terms that are a bit like Adjustable Rate Mortgages.
I'd argue that ven if they read the security policy they wouldn't understand it anyway. When you're surrounded by hackers it's easy to think everyone has some basic understanding of computers but in reality most people are lucky if they know how print a damn Word document.
This really is a false comparison. Accessing an address book for the app's use only and accessing the address book for public publishing are so far apart it's ridiculous. Security policies don't mean anything. If data is stored digitally there will always be a way to compromise its security no matter how much encryption, SSL, etc. you use. Security, especially on the web is a total misnomer. All you can really do is make it inconvenient to access.
Trusting a company isn't about their data privacy and security policies. It's about their brand to a large degree. Their track record and other peoples' experiences with the app. I'm in the camp that understands these policies and what they mean but thats not the reason I trust the company behind an app. I trust Google with my docs because they have a good track record. Facebook I trust as a necessary evil. Scratch that, I don't trust Facebook but I use it anyway because I'm banking on the odds. I think that's what it boils down to for most average folks. If the odds are that they'll have no trouble then that's a risk they're willing to take. If there's a breach of security and a bunch of people have their data exposed (but I'm not affected) well that makes me think twice not because of the breach itself but because of all the pile-on press coverage.
I'm one who firmly believes that people don't make their own minds up about this stuff. The average person's view of this whole app uploading address books thing is based purely in whichever side of the manufactured debate is the loudest and seemingly most expert-y. After watching how people use the web, their computers, and their smartphones for some time now I've become really cynical when it comes to this stuff. People don't seem to care until someone writes a blog post that tells them they should care.
This really is a false comparison. Accessing an address book for the app's use only and accessing the address book for public publishing are so far apart it's ridiculous. Security policies don't mean anything. If data is stored digitally there will always be a way to compromise its security no matter how much encryption, SSL, etc. you use. Security, especially on the web is a total misnomer. All you can really do is make it inconvenient to access.
Trusting a company isn't about their data privacy and security policies. It's about their brand to a large degree. Their track record and other peoples' experiences with the app. I'm in the camp that understands these policies and what they mean but thats not the reason I trust the company behind an app. I trust Google with my docs because they have a good track record. Facebook I trust as a necessary evil. Scratch that, I don't trust Facebook but I use it anyway because I'm banking on the odds. I think that's what it boils down to for most average folks. If the odds are that they'll have no trouble then that's a risk they're willing to take. If there's a breach of security and a bunch of people have their data exposed (but I'm not affected) well that makes me think twice not because of the breach itself but because of all the pile-on press coverage.
I'm one who firmly believes that people don't make their own minds up about this stuff. The average person's view of this whole app uploading address books thing is based purely in whichever side of the manufactured debate is the loudest and seemingly most expert-y. After watching how people use the web, their computers, and their smartphones for some time now I've become really cynical when it comes to this stuff. People don't seem to care until someone writes a blog post that tells them they should care.
> People don't seem to care until someone writes a blog post that tells them they should care.
But that's the point, isn't it? They shouldn't have to care! People shouldn't have to be security experts to use a phone. The phone should protect them by default and make them have to jump through hoops to waive that protection, rather than the other way around.
But that's the point, isn't it? They shouldn't have to care! People shouldn't have to be security experts to use a phone. The phone should protect them by default and make them have to jump through hoops to waive that protection, rather than the other way around.
The phome ismt what's insecure though in this case. We're talking about the security of the servers that these apps are sending data to. For some reason people think about phones differently than any PC running whichever OS. If the app store didn't exist and we got smartphone apps the way we all used to (and to large degree still do) download PC programs I doubt anyone would be upset with Apple. All the blame would be solely on the app developers. Apple polices the app store and locks down iOS a lot as it is. If Path were a native Mac or Windows program and it was accessing data from other programs we'd all be screaming that it's some kind of spyware. We'd probably sayng that Path itself should be asking permission to access data, not the OS. But because we have the app store and have come to have this strange relationship with Apple where we bitch about how locked down the devices are but at the same time want them to protect us from apps like Path we're placing some responsibility on Apple. I don't think it's right. We need to decide if we like our locked down devices or if we want Apple to stop playing babysitter for us.
Amen to that. I couldn't have said it any better. I have been arguing the same thing - history of the web and these companies have been a pretty clean one.
It's different in that having your address book uploaded without your permission is actually being the victim a crime in most countries. At least posting it publicly is a voluntary act.
Putting yourself in a situation where you are very likely to get mugged would be better comparison. Winer is being mild in his challenge.
So yeah, I agree it's not in the same league, but not in the way you mean.
Putting yourself in a situation where you are very likely to get mugged would be better comparison. Winer is being mild in his challenge.
So yeah, I agree it's not in the same league, but not in the way you mean.
Sorry but I think you're missing some data here. Every app on the iPhone can upload your address book, pictures and calendar data to their servers, whether or not they have anything to do with contacts. Every app. It's worth taking a look at the trivial crap we put on our iPads and iPhones thinking they're harmless, when each of them could be leaking all our private bits everywhere.
No, I'm aware of that. What I am saying is that uploading data to an app, no matter what that app may be, is not the same as posting it publicly.
When you upload to an app, the makers of that app have access to your data. Don't get me wrong- that's a bad thing. But if you upload your data publicly, anyone in the world has access to your data. Drastically different.
When you upload to an app, the makers of that app have access to your data. Don't get me wrong- that's a bad thing. But if you upload your data publicly, anyone in the world has access to your data. Drastically different.
Because there's no way that your data, once uploaded to the app vendor's servers, can ever leak out. Right?
No way they are running their operation on the cheap and don't have their servers secured against intrusion.
No way they can be inexperienced developers and build an API that leaks information to improperly authenticated requests.
No way they can have a disgruntled employee throw a torrent of it all up when he gets fired.
No way they can get bought by someone with fewer scruples and hand your data over to them as part of the acquisition.
No way they are running their operation on the cheap and don't have their servers secured against intrusion.
No way they can be inexperienced developers and build an API that leaks information to improperly authenticated requests.
No way they can have a disgruntled employee throw a torrent of it all up when he gets fired.
No way they can get bought by someone with fewer scruples and hand your data over to them as part of the acquisition.
These are all perfectly valid critiques of the notion that "my data is protected by Path's privacy policy", and they are excellent reasons why Path was right to apologize and correct a genuine problem with their app's behaviour.
But they aren't really relevant to the parent comment's point, which is that, even with these (potential) holes giving your address book to Path is fundamentally different than posting it publicly. In one instance, your data is public, immediately and unconditionally. In the other, there is potential for abuse that could result in your data becoming public if an arguably unlikely sequence of events were to occur.
So it doesn't make any sense at all for Winer to be challenging PD to engage in a behavior that is simply not analogous to the issue at hand. All that Winer's post does is distort the issue, intentionally or not, and distract from the important debate/conversation that Path's policies initiated. I honestly don't see how that's helpful at all.
[UPDATED: Minor correct for clearer syntax]
But they aren't really relevant to the parent comment's point, which is that, even with these (potential) holes giving your address book to Path is fundamentally different than posting it publicly. In one instance, your data is public, immediately and unconditionally. In the other, there is potential for abuse that could result in your data becoming public if an arguably unlikely sequence of events were to occur.
So it doesn't make any sense at all for Winer to be challenging PD to engage in a behavior that is simply not analogous to the issue at hand. All that Winer's post does is distort the issue, intentionally or not, and distract from the important debate/conversation that Path's policies initiated. I honestly don't see how that's helpful at all.
[UPDATED: Minor correct for clearer syntax]
Nothing personal, but I think it's naive to assume that.
I once did a deal with a software publisher that required me to turn over the source code.
One day I came into the office and found a disk clearly labeled as the source for my product, on the receptionists desk.
That was pretty close to public, and I remember that every time I let something sensitive out of my control.
Also every few months I have to change my credit card number because a charge appears that I didn't make. Luckily the credit card companies have developed good algorithms for detecting these. Now you might assume that every company that you give your CC to is being careful not to make it public, but if you believe that, you aren't reading the news.
I once did a deal with a software publisher that required me to turn over the source code.
One day I came into the office and found a disk clearly labeled as the source for my product, on the receptionists desk.
That was pretty close to public, and I remember that every time I let something sensitive out of my control.
Also every few months I have to change my credit card number because a charge appears that I didn't make. Luckily the credit card companies have developed good algorithms for detecting these. Now you might assume that every company that you give your CC to is being careful not to make it public, but if you believe that, you aren't reading the news.
Well, the credit card example you give is a good one- you can go through life without paying for anything by credit card, and your credit card will never be stolen. If you do pay for things by credit card, there is a chance that it will be stolen. If you post your credit card details publicly there is a 100% guarantee it will be stolen.
I think the same applies to apps. There is a sensible middle ground in there somewhere, and the new permission request alerts from Apple will go a long way to helping with that. But no, never any guarantees about anything.
I think the same applies to apps. There is a sensible middle ground in there somewhere, and the new permission request alerts from Apple will go a long way to helping with that. But no, never any guarantees about anything.
But this is like someone on the subway reaches into my pocket and takes the credit card, copies the number and then publishes it in a blog post.
I trust Path with some of my data -- most of it generally created for the specific use within Path.
Uploading your address book to Path is not the same as an app locally reading the contents of your clipboard and asking if you want to use that data. It's not even in the same league.
And, loathe though I am to defend PandoDaily, the OP misses the point of their article. Uploading your address book to an app is different than posting it publicly because people trust Path their their data. If they didn't then the really shouldn't be using it in the first place.