1. I’ve heard rumors that lots of apps have been uploading user contact lists for years. One person who knows the iOS world well told me “if you download a lot of apps, your contact list is on 50 servers right now.” I don’t understand why Apple doesn’t have a permission dialog box for this (that said, I’m not sure that’s the best solution – see #4 below). Apple has dialogs for accessing location and for enabling push notifications. Accessing users’ contact lists seems like an obvious thing to ask permission for.
2. I don’t know what the product design motivations are for uploading contacts, but I assume there are legitimate ones. [commenters suggest it is mainly to notify users when their friends join the service]. If this or something similar is the goal, you could probably do it in a way that protects privacy by (convergently?) encrypting the phone numbers on the client side (I’m assuming the useful info is the phone numbers and not the names associated with the phone numbers since the names would be inconsistent across users).
3. Many commentators have suggested that a primary security risk is the fact that the data is transmitted in plain text. Encrypting over the wire is always a good idea but in reality “man-in-the-middle” attacks are extremely rare. I would worry primarily about the far more common cases of 1) someone (insider or outsider) stealing in the company’s database, 2) a government subpoena for the company’s database. The best protection against these risks is encrypting the data in such a way that hackers and the company itself can’t unencrypt it (or to not send the data to the servers in the first place).
A bad outcome from this controversy would be to have companies encrypt sensitive data over the network and then not encrypt it on their servers (the simplest way to do this is to switch to https, a technology that is much more about security theater than security reality). This would make it impossible for 3rd parties (e.g. white-hat hackers) to detect that sensitive data is being sent over the network but would keep the data vulnerable to server side breaches / subpeonas. Unless Apple or someone else steps in, I worry that this is what apps will do next. It is the quickest way to preserve product features and minimize PR risk.
4. I worry that by just adding tons of permission dialogs we are going back to the Microsoft IE/Active X model of security. With lots of permission popups, users get fatigued and confused and just end up clicking “Yes” to everything. And then the security model says: If the user says “yes”, and the app uses “best practices” like https, it can do whatever it wants. We saw how this played out with the spyware/adware epidemic on the web from 2001-2006 and it wasn’t pretty.
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | TechCrunch
Pingback: Some thoughts on the iPhone contact list controversy and app security — nPost
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Kantier
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Champlin News | Champlin Local News
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Vadnais Heights News
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Robbinsdale News
Pingback: iPhoneNation.com: Apple News and Technology Insiders – “We’re So So Sorry”: An Apology Form Letter For Startups
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups « Go Digital Apps
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Minnetonka News
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | New Brighton News
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups |
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | iyaan.info
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | PRO-BTC
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | TechDiem.com
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Bitmag
Pingback: “We’re So So Sorry”: An Apology Form Letter For Startups | Startup Help
Pingback: Social apps & doing the right thing — Tech News and Analysis
Pingback: Mobile Address Book—Much Heat, Little Light | TechCrunch
Pingback: Mobile Address Book—Much Heat, Little Light | Montevideo News
Pingback: Mobile Address Book—Much Heat, Little Light | Новости мобильных технологий
Pingback: iPhone Games » Mobile Address Book—Much Heat, Little Light
Pingback: Mobile Address Book—Much Heat, Little Light | PRO-BTC
Pingback: Mobile Address Book—Much Heat, Little Light | | AdWords WhizAdWords Whiz
Pingback: Mobile Address Book—Much Heat, Little Light - The Review Blog
Pingback: Mobile Address Book—Much Heat, Little Light | NokiaBattery
Pingback: Mobile Address Book—Much Heat, Little Light | Startup Help
Pingback: Mobile Address Book—Much Heat, Little Light | iyaan.info
Pingback: Mobile Address Book—Much Heat, Little Light | Digital Gadget dan Selular
Pingback: Social apps & doing the right thing | Freeex Blog
Pingback: Apps uploading address books is a privacy side-show compared to DPI
Pingback: Controversy, journalism, disclosures and the future of web content - KyleLibra.com
Pingback: Apps Uploading Address Books Is A Privacy Side-Show Compared To DPI | iyaan.info
Pingback: Apps Uploading Address Books Is A Privacy Side-Show Compared To DPI - SocialEnterprise.com Beta
Pingback: Inside the iPhone Contact List Scandal | Startups