{"id":4254,"date":"2012-02-08T15:26:52","date_gmt":"2012-02-08T20:26:52","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=4254"},"modified":"2020-03-05T09:01:57","modified_gmt":"2020-03-05T14:01:57","slug":"path-uploads-your-entire-iphone-address-book-to-its-servers","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2012\/02\/08\/path-uploads-your-entire-iphone-address-book-to-its-servers\/","title":{"rendered":"Path Uploads Your Entire iPhone Address Book to Its Servers"},"content":{"rendered":"<p>In 2010, <a href=\"http:\/\/mjtsai.com\/blog\/2010\/10\/01\/curated-doesnt-necessarily-mean-secure\/\">I wrote<\/a>:<\/p>\n<blockquote cite=\"http:\/\/mjtsai.com\/blog\/2010\/10\/01\/curated-doesnt-necessarily-mean-secure\/\"><p>I don&rsquo;t understand why iOS makes such a big deal about permission to access location data, when any random app, even one that shouldn&rsquo;t need network access at all, can access my address book, photos, and clipboard and upload them to who-knows-where.<\/p><\/blockquote>\n<p>Yesterday, <a href=\"http:\/\/mclov.in\/2012\/02\/08\/path-uploads-your-entire-address-book-to-their-servers.html\">Arun Thampi<\/a> wrote:<\/p>\n<blockquote cite=\"http:\/\/mclov.in\/2012\/02\/08\/path-uploads-your-entire-address-book-to-their-servers.html\"><p>Upon inspecting closer, I noticed that my <strong>entire address book (including full names, emails and phone numbers) was being sent as a plist to Path<\/strong>. Now I don&#8217;t remember having given permission to Path to access my address book and send its contents to its servers, so I created a completely new &#8220;Path&#8221; and repeated the experiment and I got the same result &#8211; my address book was in Path&#8217;s hands.<\/p>\n<\/blockquote>\n<p><a href=\"http:\/\/daringfireball.net\/linked\/2012\/02\/08\/path\">John Gruber<\/a> notes that the <a href=\"http:\/\/mclov.in\/2012\/02\/08\/path-uploads-your-entire-address-book-to-their-servers.html#comment-432202082\">response from Path<\/a> is not very satisfying. Is this <a href=\"http:\/\/dcurt.is\/stealing-your-address-book\">really<\/a> &ldquo;currently the industry best practice&rdquo;? See, for example, these questions from <a href=\"http:\/\/mclov.in\/2012\/02\/08\/path-uploads-your-entire-address-book-to-their-servers.html#comment-432211641\">Matt Gemmell<\/a>. There&rsquo;s no automated way to get them to delete your data. Rule 17.1 of the App Store Review Guidelines seems to prohibit this sort of behavior without the user&rsquo;s consent, yet <a href=\"http:\/\/itunes.apple.com\/us\/app\/path\/id403639508?mt=8\">Path<\/a> has been in the curated App Store for over a year and Apple doesn&rsquo;t seem to have noticed that it&rsquo;s sending this information back to the server <strike>in cleartext<\/strike>. Now that the news has broken, Apple has neither pulled the app nor approved the update that asks users to opt in. As <a href=\"https:\/\/twitter.com\/petermaurer\/status\/167315253812666368\">Peter Maurer<\/a> says, &ldquo;No technology will ever protect us from Trojan horses. Rules that destroy functionality are mere security theater.&rdquo;<\/p>\n<p>Update (2012-02-08): The <a href=\"http:\/\/blog.path.com\/post\/17274932484\/we-are-sorry\">official response from Path<\/a>:<\/p>\n<blockquote cite=\"http:\/\/blog.path.com\/post\/17274932484\/we-are-sorry\"><p>We are deeply sorry if you were uncomfortable with how our application used your phone contacts.<\/p><\/blockquote>\n<p>That could have been phrased better. Also, <a href=\"http:\/\/gawker.com\/5883549\/dont-forgive-path-the-creepy-iphone-company-that-misled-us-once-already\">Gawker<\/a> quotes Path CEO Dave Morin, in November 2010:<\/p>\n<blockquote cite=\"http:\/\/gawker.com\/5883549\/dont-forgive-path-the-creepy-iphone-company-that-misled-us-once-already\"><p>Path does not retain or store any of your information in any way.<\/p><\/blockquote>\n<p>Good thing they will &ldquo;continue to be transparent.&rdquo;<\/p>\n<p>Also, in 2010, <a href=\"http:\/\/scripting.com\/stories\/2010\/11\/15\/theTechIndustryIsAVirus.html\">Dave Winer<\/a> noticed that something wasn&rsquo;t right, but he&rsquo;d forgotten about it until <a href=\"http:\/\/scripting.com\/stories\/2012\/02\/08\/take3.html\">now<\/a>.<\/p>\n<p>Update (2012-02-09): <a href=\"http:\/\/gawker.com\/5883549\/dont-forgive-path-the-creepy-iphone-company-that-misled-us-once-already\">Gawker<\/a>:<\/p>\n<blockquote cite=\"http:\/\/gawker.com\/5883549\/dont-forgive-path-the-creepy-iphone-company-that-misled-us-once-already\"><p>The official version from Morin is that the statement was technically accurate, at the time he made it. He just changed his mind.<\/p><\/blockquote>\n<p><a href=\"https:\/\/twitter.com\/petermaurer\/status\/167522277141909504\">Peter Maurer<\/a> links to this screenshot of <a href=\"http:\/\/twitpic.com\/8hagc6\">Path&rsquo;s new opt-in alert<\/a>, <a href=\"http:\/\/twitter.theinfo.org\/167522277141909504\">noting<\/a> that it isn&rsquo;t very transparent. It just asks whether you want to invite your friends, without explaining what this entails for your personal data. However, Ole Zorn links to <a href=\"http:\/\/yfrog.com\/h7ttsgp\">this screenshot<\/a> in which the alert actually says &ldquo;Path needs to send contacts to our server.&rdquo;<\/p>\n<p><a href=\"http:\/\/inessential.com\/2012\/02\/09\/super-quiet_non-understanding\">Brent Simmons<\/a> on <a href=\"http:\/\/dcurt.is\/stealing-your-address-book\">Dustin Curtis&rsquo;s<\/a> &ldquo;quiet understanding&rdquo; that it&rsquo;s OK to do this with people&rsquo;s address books:<\/p>\n<blockquote cite=\"http:\/\/inessential.com\/2012\/02\/09\/super-quiet_non-understanding\"><p>I know a ton of developers, and I&rsquo;ve never, ever heard this.<\/p><\/blockquote>\n<p>Update (2012-02-10): In the comments, <a href=\"http:\/\/mjtsai.com\/blog\/2012\/02\/08\/path-uploads-your-entire-iphone-address-book-to-its-servers\/#comment-638874\">CF<\/a> quotes Steve Jobs at D8:<\/p>\n<blockquote cite=\"http:\/\/mjtsai.com\/blog\/2012\/02\/08\/path-uploads-your-entire-iphone-address-book-to-its-servers\/#comment-638874\"><p>We take privacy extremely seriously. That&rsquo;s one of the reasons we have the curated apps store. We have rejected a lot of apps that want to take a lot of your personal data and suck it up into the cloud. Privacy means people know what they&rsquo;re signing up for.<\/p><\/blockquote>\n<p>Update (2012-02-15): <a href=\"http:\/\/www.readwriteweb.com\/archives\/twitter_is_the_latest_company_to_admit_it_uploads.php\">Dave Copeland<\/a>:<\/p>\n<blockquote cite=\"http:\/\/www.readwriteweb.com\/archives\/twitter_is_the_latest_company_to_admit_it_uploads.php\"><p>But Twitter, <a href=\"http:\/\/www.latimes.com\/business\/technology\/la-fi-tn-twitter-contacts-20120214,0,5579919.story\">as reported by the Los Angeles Times<\/a>, seems to be the biggest name to make a revelation so far. The company told the newspaper it is making changes to make the policy clearer to users of its app. The current policy does not clearly state that Twitter downloads the entire address book of users who use the &ldquo;Find Friends&rdquo; feature on the app, including names, email addresses and phone numbers, and stores the data on its servers for 18 months. <\/p><\/blockquote>\n<p><a href=\"http:\/\/venturebeat.com\/2012\/02\/14\/iphone-address-book\/\">Venture Beat<\/a> (via <a href=\"http:\/\/kottke.org\/12\/02\/ios-apps-and-your-address-book\">Jason Kottke<\/a>):<\/p>\n<blockquote cite=\"http:\/\/venturebeat.com\/2012\/02\/14\/iphone-address-book\/\"><p>Facebook, Twitter, Foursquare, Instagram Foodspotting, Yelp, and Gowalla all upload either your contacts&rsquo; phone numbers or email addresses to their servers for matching purposes. Some of these applications perform this action without first requesting permission or informing you how they long they plan to store this data. Foodspotting is the worst of the bunch, as it appears to transmit your data over an unencrypted HTTP connection (in plain text), making it even easier for mischievous parties to intercept.<\/p><\/blockquote>\n<p><a href=\"http:\/\/allthingsd.com\/20120215\/apple-app-access-to-contact-data-will-require-explicit-user-permission\/\">John Paczkowski<\/a>:<\/p>\n<blockquote cite=\"http:\/\/allthingsd.com\/20120215\/apple-app-access-to-contact-data-will-require-explicit-user-permission\/\"><p>&ldquo;Apps that collect or transmit a user&rsquo;s contact data without their prior permission are in violation of our guidelines,&rdquo; Apple spokesman Tom Neumayr told AllThingsD. &ldquo;We&rsquo;re working to make this even better for our customers, and as we have done with location services, any app wishing to access contact data will require explicit user approval in a future software release.&rdquo;<\/p><\/blockquote>\n<p>Not mentioned: (1) the other types of personal data that apps can access without permission, and (2) the difference between letting the app access your address book and letting the app transmit it.<\/p>","protected":false},"excerpt":{"rendered":"<p>In 2010, I wrote: I don&rsquo;t understand why iOS makes such a big deal about permission to access location data, when any random app, even one that shouldn&rsquo;t need network access at all, can access my address book, photos, and clipboard and upload them to who-knows-where. Yesterday, Arun Thampi wrote: Upon inspecting closer, I noticed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2020-03-05T14:02:01Z","apple_news_api_id":"4660a044-0002-4a16-acc4-156b93d86b5b","apple_news_api_modified_at":"2020-03-05T14:02:01Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/ARmCgRAACShasxBVrk9hrWw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,1930,31],"class_list":["post-4254","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-app-store-review-guidelines","tag-ios"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=4254"}],"version-history":[{"count":35,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4254\/revisions"}],"predecessor-version":[{"id":4326,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/4254\/revisions\/4326"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=4254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=4254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=4254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}