Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Doesn't the fact that companies like Path are exploiting people's address book information illustrate that we do need such strict guidelines?

So Apple didn't make enough rules. That doesn't mean that the existing rules were ineffective. I just don't understand your criticism here.



The rules already prohibited this behavior. The rules were ignored and not enforced. Clearly they were not effective. Adding more rules isn't going to make it any more effective. What we need, and what we're finally going to get, is actual technological controls on access.


Thanks for emphasizing this distinction that neither I nor the post I was reponding to were really making explicit: "rules" as in "guidelines" vs technological rules that are not (normally) possible to break.


Years ago people said that the AppStore approval thing would save us from this. It clearly has not. I do not think more rules will help.


The flaw seems pretty obvious here.

AppStore = lots of "walls/rules", supposed protection, apps have free access to contacts

Market = few "walls/rules", but accessing contacts was a declared and required permission attribute

Apple's walled garden did nothing to prevent apps from freely helping themselves to contacts without user interaction or notification. Android didn't have to curate to solve this problem, they simply implemented it "correctly" at the platform level on the first go.

Frankly, I'm not sure what I think of this criticism of Apple anyway. Where is it declared that your Address Book is absolutely secret information? Windows doesn't protect my Thunderbird contacts, hell, Thunderbird doesn't even try to. Yet I don't blame them for spyware that steals that information. Quite honestly it scares me how much people are totally okay with being dependent on Apple and running to them for protection. It's a losing game this way. There will always be some sort of information, even if acquired via the user or declared permissions, that we won't expect them to want/use/sell. We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.

(My scare quotes aren't commentary so much as they are me trying to stay neutral. I don't know what is the "right" position on these things, frankly I don't worry about this aspect of my privacy that much, and I'm currently with an Android phone.)

edit: I guess my post changes a bit if it really was against the Apple Developer agreement to do this. I guess I would be miffed that they weren't enforcing and protecting against it.


> Quite honestly it scares me how much people are totally okay with being dependent on Apple and running to them for protection. It's a losing game this way.

They build the OS, why shouldn't they protect me? Is there a practical alternative?

> We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.

I agree, but many people expect stuff to be free and ad-driven. As soon as an otherwise honest developer drops in a fishy Ad framework, it's basically game over. I would be surprised if none of them would send AB data over the wires. They certainly send everything else they can get.


It was indeed against the developer agreement to do this.

But more importantly, we simply don't know whether Android is actually protecting customers or not.

If people are just clicking through a warning and having their address book copied against their wishes, that may technically shift responsibility onto them, but it doesn't mean they are 'protected' by a 'correct' platform. It just means that Android is protected from accusations.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: