Martijn Vreugde's Hangout

About this site

Hi, I'm Martijn Vreugde this is a collection of my rambling thoughts on modern media, inspirational design and... well pretty much anything I found interesting enough to share with you fine upstanding folks of the internet.

This is shocking that such top notch apps and web savvy companies would do something so reckless as pulling a users private contact list info without the users knowledge never mind consent.

Path

Even the @Scobleizer was shocked (From Google+) :

  -  1:55 AM  -  Public
Yes, +Path and +Dave Morin really screwed up here. They should have realized that uploading data without transparency would bite them in the ass sooner or later (I wish I had known).

Yes, Dave says they only use that data to try to find friends of yours who are already on the system, but that’s beside the point.

Developers have to be very careful to do the following:

1. Offer an opt-out.
2. Be transparent about what’s being sent.
3. Be transparent about what will be done with the data.
4. Offer a way to delete that data after it’s been sent.

What do you think?

markchang:

Inspired by this post (which you should all read), I looked at the apps on my own iPhone for information leakage by other apps. I figured this would be common practice, and lo and behold, when booting up Hipster, it seems like parts of my iPhone address book were being uploaded to Hipster. Here’s the breakdown, done in the style of Arun Thampi (the author of the first post).

Creating an Account

Hipster starts with a POST to api.hipster.com/v1/people

Worth noting, this is not over HTTPS, and it sends your info, including password and iPhone UID in plaintext. Ugh.

Okay, not terrible.

Several other transactions happen here, giving us acknowledgment of your login and creation of an account and user ID, and the public “Popular” feed is returned.

Sadly, the badness happens when you go to add your friends from the More > Find Friends menu option.

Badness

The Hipster app, in an unsecured HTTP GET request, sends a big chunk of your iPhone address book in the form of an email param that includes a comma-separated list of email addresses. WAT. Here it is, with the big block of email addresses redacted.

Okay, that’s enormous. Let’s just get the important bits. The HTTP GET goes to:

api.hipster.com/v1/me/friends_lookup?auth_token=[redacted]&emails=[…]

Boy. Thanks, Hipster.

The Issue

As was addressed in the other post, this is offensive for a few reasons:

  1. Hipster never asked me for permission to send my address book emails to them.
  2. Hipster does not say anything (AFAIK) about if they are storing those emails or what.
  3. The Hipster app allows you to deselect the “Contacts” button when looking for new friends, but it is enabled by default. Therefore, there is no way to avoid sending address book emails to Hipster, as far as I can tell.

Thanks to the original article on Path. While it is up for debate how much of a negative impact this has on an individual’s privacy, I feel these two examples (which were easy to come by) point toward a state of lax privacy attitudes among some of the leading edge of socially-minded consumer applications.

Time to clean up a bit, right?

Comments below, or hit me up on Twitter, @mchang

Recent comments

Blog comments powered by Disqus

Notes

  1. commercial-trucks reblogged this from markchang
  2. mattress-toppers reblogged this from markchang
  3. thefeastx reblogged this from markchang
  4. whatisadhd101-com reblogged this from markchang
  5. lawn-and-garden-tools reblogged this from markchang
  6. top10-lists reblogged this from markchang
  7. wordpress-review-theme reblogged this from markchang
  8. wedding-gowns-in-kenya reblogged this from markchang
  9. laptoprepair-cobham reblogged this from markchang
  10. cheapelectronic-cigarettes reblogged this from markchang
  11. social-networking-marketing reblogged this from markchang
  12. apple-macbook-pro-reservedele reblogged this from markchang
  13. classipress-plugins reblogged this from markchang
  14. acer-extensa-powersupply reblogged this from markchang
  15. acer-laptop-reservedel reblogged this from markchang
  16. acer-aspire-notebook reblogged this from markchang
  17. acer-aspire-keyboard reblogged this from markchang
  18. in-the--news reblogged this from markchang
  19. stephen-pierce-blog reblogged this from markchang
  20. stephenpierce-mrmi reblogged this from markchang
  21. stephen-pierce-review reblogged this from markchang
  22. stephen-pierce-fraud reblogged this from markchang
  23. stephen-pierce-mrmi reblogged this from markchang
  24. stephen--pierce reblogged this from markchang
  25. stephen-pierce-international reblogged this from markchang
  26. stephen-pierce reblogged this from markchang
  27. facebook--covers reblogged this from markchang
  28. im600 reblogged this from markchang
  29. best-credit-card-review reblogged this from markchang
  30. canadian-secured-credit-card reblogged this from markchang
  31. indoor--gardening reblogged this from markchang
  32. make-money-taking-surveys reblogged this from markchang
  33. eheim-shop reblogged this from markchang
  34. partyguide reblogged this from markchang
  35. echuca-deals reblogged this from markchang
  36. two-player-games reblogged this from markchang
  37. what-is-workers-comp-insurance reblogged this from markchang
  38. cheap-laptops-for-sale reblogged this from markchang
  39. glass-pumpkins reblogged this from markchang
  40. flip-toronto-new-condos reblogged this from markchang
  41. first-time-home-buyers reblogged this from markchang
  42. cottages-ontario reblogged this from markchang
  43. luxury-condo-homes reblogged this from markchang
  44. flat-fee-mls-gta-toronto reblogged this from markchang
  45. movie-reviews-1smartinvest reblogged this from markchang
  46. beverlyhills-plastic-surgeon reblogged this from markchang
  47. china-reisen reblogged this from markchang
  48. gay-straight-alliances reblogged this from markchang
  49. self-directed-real-estate-ira reblogged this from markchang
  50. world-of-warcraft--gold reblogged this from markchang