5 ms·
This is actually nothing new. A lot of apps have been doing this for a very long time. However, it is one of the best kept secrets in our space. I kind of have
by corywatilo 15y ago
This is actually nothing new. A lot of apps have been doing this for a very long time. However, it is one of the best kept secrets in our space. I kind of have a feeling no one talks about it because they don't want word to get out. Can you imagine the scandal if this made it on the front page of CNN or Drudge?
Ever since I learned this was possible, I've been very careful about which apps I download, and actually have downloaded very few since, as a result. There are a lot of random iPhone developers that I really don't think need to have access to my entire contact list.
- timjahn 15y agoIf no explicit permission is given by the user, how is this practice not illegal?
- jonknee 15y agoApple doesn't prompt the user to ask for permission when the APIs are used (like what happens with location), so this is the desired behavior. It's very simple: https://developer.apple.com/library/ios/#documentation/AddressBook/Reference/ABPersonRef_iPhoneOS/Reference/reference.html#//apple_ref/c/func/ABAddressBookCopyArrayOfAllPeople https://developer.apple.com/library/ios/#documentation/Addre...
- DrJokepu 15y agoHowever: 17.1 Apps cannot transmit data about a user without obtaining the user's prior permission and providing the user with access to information about how and where the data will be used It's likely that this app will be pulled from the App Store within the next few hours.
- jonknee 15y agoAll that means is that it has to be mentioned in a very long terms of service somewhere. If Apple cared about address book information like they currently do for location data they would make the API query the user.
- Aqua_Geek 15y agoI noticed that Path did this a few weeks ago when I initially installed it. My reaction was much the same: WTF?! I proceeded to file a bug report with Apple that the API should prompt for access just like the Core Location API does (somebody having ALL my contacts' info is more important to me than an app knowing where I currently am). My bug was closed as a duplicate; hopefully a change is in the works.
- alanh 15y agoYep, which makes the address book a hack for (high-latency, obviously) cross-app communication. E.g., last I knew, TextExpander added an entry to your address book with your abbreviations, so that other apps e.g. Simplenote can use those abbreviations as you type. Very well intentioned hack, which shouldn’t be necessary, but is, using an API that really just shouldn’t be open…
- rmc 15y agoThis sort of behaviour is almost certainly illegal in the European Union. You may not store personal information unless you have a clear and legitimate reason to store it. If you affected by this, you should contact your local data protection office.
- dsplittgerber 15y agoWhich apps do that? Do you have a list? Can anything be done about the data after-the-fact?
- frederickcook 15y agoFacebook, Foursquare, Twitter, basically any app that allows you to "search my address book for friends" will do this. All these services require either a email or phone number to sign up, so to search for friends who have also signed up for the service, you need to compare two data sets: emails or phone numbers of users you already have, and those in the person's address book. You obviously wouldn't download your entire database of users contact information to the phone to compare the data sets, so you send the data set up to the server.
- masonlee 15y agoThe addresses from the user's address book should be hashed before sending to the server and compared to hashed addresses on the server. Then only positive matches are registered, and the server doesn't see more private information than it needs.
- azov 15y agoHashing data from address book doesn't work because people write the same addresses and even phone numbers in many different ways. Normalizing it on the client is not really an option either because it requires a lot of data to do decent normalization - not practical to send it all to each client.
- masonlee 15y agoPhone numbers are easy to canonicalize: convert to international form. Email addresses can be effectively canonicalized by lower casing. Not many mail servers are case sensitive these days. Additionally, for the local part, you can generally strip off anything after a "+", and with gmail, you can drop any period in the local part. (Granted, it's not perfect-- so make sure that's not a security concern.) These techniques have been working fine so far in my app for my "Find My Friends" feature.
- achille 15y agoThis was news to me, so I went ahead and submitted a tip to both CNN and Drudge. I hope they pick it up.
- huhtenberg 15y agoWHAT THE FUCK I was operating under the assumption that this is not possible as I am sure many other people were. What sort of imbecile at Apple decided that allowing apps do that was even remotely acceptable to the phone owners?
- sneak 15y agoI haven't MITM'd it to confirm, but it appears from using the app that the Twitter iOS app does this as well.