8 ms·
Apple will require apps to ask users for permission to address books
- siculars 15y agoYou had to see this coming. Nice to see Congress stepping in and up for the consumer. Can't wait for Apple's detailed reply.
- bradleyland 15y agoReally, because frankly, I don't want Congress mucking about in this matter. There's been tremendous consumer backlash over this issue. Application developers and Apple are forming a response that looks pretty positive. The Congressional involvement, from my perspective, is just a meaningless dog & pony show. It won't have any bearing on the outcome. I really dislike the line of reasoning that the government should step in any time a company makes a mistake. If something egregious is happening, then let's get the government involved, but what we don't need, is Washington getting their panties in a wad and trying to craft some new legislation. We all know how that turns out.
- Aaronontheweb 15y agoLaw should always be the option of last resort for fixing a problem, never the go-to under most circumstances. Laws do not go away in the United States - they can get overridden or re-interpreted by judges, but they never leave the books once they're on them. Part of the reason why our legal system has so many pitfalls is that laws written in bygone eras intended for use-cases that no longer exist can be interpreted and applied to modern scenarios. Consumers should vote with their feet and wallets by using different apps that don't misuse their contact information or perhaps a different mobile platform altogether.
- vl 15y agoI think in this case Congress involvement was a bit uncharacteristic and populistic. We see so many issue in this area, and they are stepping in for a relatively minor issue on a platform which is generally most resrictive and protective? I would rather see them stepping in and kicking AT&T (and friends) for 20c cost per SMS, non-free incoming SMS and abolishment of bulk SMS plans. Just recently I wanted to sign up for 100 for $5 plan, it's not there anymore, the only bulk plan left if $20 unlimited. This is ridiculous oligopoly and consumer exploitation.
- SimHacker 15y agoCongress will soon pass a law that makes it illegal for consumers to get brain damage from cell phones.
- jackalope 15y agoWould it make sense to store addresses in the Keychain?
- dan1234 15y agoWell, better late than never. I still don't get why this wasn't in from the very beginning, considering the protection covering the location and camera roll.
- brudgers 15y agoThe cynical side of me thinks it was to foster the development of free and low cost apps in lieu of encouraging development of a mobile web accessible to devices from many manufacturers...the business side of me does as well.
- gurkendoktor 15y agoApple has previously erred on the side of the web too when their Safari form autocomplete leaked address data. I don't think we need a conspiracy theory for everything.
- brador 15y agoCan users who were affected by this still sue them for anything?
- monochromatic 15y agoSue Apple?
- ary 15y agoA few years ago developers were bemoaning all the arduous controls as hurdles. Today people cry out for them. I, for one, am thankful that people are at least expecting a higher standard.
- rmc 15y agoAnd a few years ago people were telling us that we needed Apple's strict guidelines to prevent rouge apps for doing this sort of evil behaviour. Apple's rules are ineffective.
- ambler0 15y agoDoesn't the fact that companies like Path are exploiting people's address book information illustrate that we do need such strict guidelines? So Apple didn't make enough rules. That doesn't mean that the existing rules were ineffective. I just don't understand your criticism here.
- mikeash 15y agoThe rules already prohibited this behavior. The rules were ignored and not enforced. Clearly they were not effective. Adding more rules isn't going to make it any more effective. What we need, and what we're finally going to get, is actual technological controls on access.
- ambler0 15y agoThanks for emphasizing this distinction that neither I nor the post I was reponding to were really making explicit: "rules" as in "guidelines" vs technological rules that are not (normally) possible to break.
- rmc 15y agoYears ago people said that the AppStore approval thing would save us from this. It clearly has not. I do not think more rules will help.
- 15y ago
- billpatrianakos 15y agoI'm torn on this issue. A part of me fears for developers. The practice of uploading address books is not a new phenomenon but suddenly over the past week everyone has jumped on it as if it's some brand new conspiracy to invade our privacy. It didn't hurt anyone before this became a hot news story and I'm confident that more than a handful of people knew about it before then too. But there's a very valid concern about it nonetheless so putting aside the issue of whether it's alright to upload the user's address book at all in any way this issue still makes me fear for developers. I'm afraid because it seems like these days everyone wants their apps for free with absolutely no strings attached. There's an entitlement on the web that you don't see anywhere else. On the web we expect to get the best, coolest, most entertaining, problem-solving, pain-point-eliminating products and services free and we expect the providers of those products and services to bend to our will in the way they operate too. So let's give the critics this one and say that yeah, it's absolutely necessary to ask permission first before accessing the iOS address book. Okay but what's next? We're used to going nuts about slippery slopes when it comes to the user but what about some companies? They're not all evil like some would make them out to be. Are we going to demand that Google stop showing ads because they're confusing or annoying when mixed with organic results? Will we demand the ability to post to Facebook and Twitter.. anonymously? Will we band together and force companies to add features that muddy already good products because a noisy few were, well, really noisy? That's what I fear. I fear that the balance of power between users and developers will swing too far I'm the user direction. Make no mistake, I'm not saying a service provider should be able to do whatever it pleases with no say from users. I do believe, however, that there needs to be a balance of power (or influence, whatever you want to call it) and that balance should never swing too far in either direction. Its not often that I hear "I don't like that company/developer/service provider X is doing Y so I quit using them". Instead I often hear "they're doing X and I hate it do come complain with me and let's make them change that". That's fine a lot of times but I'm afraid that at some point people's sense of entitlement will grow too large and there will be outrage where none is needed and where the best course of action for a small minority would be to quit using X while the majority who are alright with it continue. In some cases like Google and Facebook the service has become so ingrained in our lives that it's hard to just quit using it and in those cases I'm willing to forgive a lot of seemingly frivolous outrage but in other cases it wouldnt be that awful to find an alternative. I just wonder if one day the frivolous outrage of a noisy minority will ruin a product or service for the very content majority.
- tferris 15y agoAndroid has this feature for years or call it a very granular and understandable permission system for apps. (Don't want to start a flame war and I am not really an Android fan)
- functionform 15y agoThis is a clear marketing opportunity for the Android platform, of course since no one really governs its course, it's completely being missed. I suppose cheaper/more features/hotter phones is the way they want to go.
- nigelsampson 15y agoI'm also surprised Microsoft hasn't taken advantage of this in marketing Windows Phone since it has a capabilities model similar to Android.
- sehugg 15y agoWP7 is even more secure when it comes to contact info -- you can only access contacts from an app via UI control, and then you can only return email/phone number from one person at a time (whichever the user has selected).
- nigelsampson 15y agoMango added the ability to query contact and calendar data without the chooser UI. However it does require a declared capability in the app manifest.
- lawnchair_larry 15y agoAndroid's permissions model doesn't work at all. Every app asks for a ton of permissions at install time. You can't install the app without saying yes, and every app asks for far more than it needs. In theory, it is good, but in practice, it's broken. The iOS way installs the app, but denies access to the resource.
- funkah 15y agoSo, developers will do their contact stealing with Mac or Windows apps instead. Better than nothing.
- watty 15y agoThere are much more valuable files to steal off a computer than a phone. The reason you won't see it (often) is because it's so much easier to watch traffic on your computer. Any company doing this would be taking a huge risk and would likely be caught within a day.
- jinushaun 15y agoI'm an iOS developer and I can't believe it has taken Apple so long to implement a security popup when accessing the address book, or that adding address book support doesn't require the developer to declare in the info.plist that this app needs access to it.
- smackfu 15y agoThis kind of thing really requires good faith efforts from both Apple and the developers. A system-generated prompt for your address book is not particularly useful if it comes up on first launch of the app with no explanation why the app wants the data, like a lot of apps do with location services today.
- nimblegorilla 15y agoIf an app asks for location information I usually deny it. I would do the same thing for my address book and photos if I had the ability. Almost all of the apps I use have no reason to need my addressbook data so it would be nice to know that none of those are secretly stealing it.
- Francisc 15y agoOh they caught on to this minor security issue. Well done Apple.
- ugh 15y agoThat’s really annoying. If so many developers weren’t so stupid and evil, strict guidelines from Apple and social pressure could easily solve this. Isn’t that how it’s solved on the desktop (minus the guidelines)? Yes, I can see that an App Store makes it easier for people to install all kinds of apps. (I can also see that more people are going to have more extensive address books on their mobile phones compared to their PCs.) There isn’t really a handful of developers anymore (like there were on the Mac for the longest time) who you know you can trust. And yes, spyware was also a problem on the desktop – but usually not one for high profile apps. If the developer was big and had something to lose you could be somewhat certain that they were not going to sell you out. But no. More dialogs everyone will ignore anyway. Not a real solution by any stretch of the imagination.
- feralchimp 15y agoWelcome news, and hopefully the existing entitlements system will allow this change to be made quickly and clearly. More granularity might be nice also. They could have a separate "names only" entitlement, or allow users to identify address book contacts / fields that should never be shared; that are redacted in content returned by the underlying APIs. Important to note that this still does not address the wholesale detailed export and persistence of contact data by developers. Could be opp for a new provider there.
- sshumaker 15y agoGranularity comes with a cost: complexity. Complexity which would be foisted on the end-users. It's a slippery slope - you can quickly end up with android-style permissions, where the user has to understand (and usually doesn't) dozens of options. I doubt Apple will go this route.
- feralchimp 15y agoSpot on.
- moe 15y agoAndroid's permission system would be great if it wasn't for the one fatal flaw: Some idiot decided to make it declarative instead of deductive. This is one of these fundamental bugs where you can only wonder what they are smoking at google. Instead of automatically scanning the code for actual API calls ("Ah, trying to send SMS here") they require the developer to manually declare their desired permissions in a separate manifest-file. Unsurprisingly this has led to the current situation where every little "wallpaper clock" app demands every permission under the sun, and then some, without ever actually using them. Developers are just dumb and lazy like that, go figure... So, my point is, android-style permission granularity is not a problem at all. Just make sure "can read phonebook" translates to will actually read your phonebook (hopefully soon in iOS) instead of developer is probably incompetent (Android).
- commandar 15y ago
- st3fan 15y ago"After a week of silence, Apple has finally responded to reports..." "Better late than never..." Why do people expect that Apple respond realtime to these kinds of things? These are complex issues and tough decisions that need lots of thought and discussion within the iOS teams at Apple. These things take time. Remember, iOS is deployed to how many devices now? 100 million? Do you think they can come to conclusions in between two tweets? Honestly, having an answer ready in a week is not bad at all I think.
- mikeash 15y ago"Better late than never" is saying that this protection should have been in the OS from the very beginning, years ago, rather than being tacked on now. It's not related to taking a week to respond to the latest fluff.
- pja 15y agoWhy do people expect that Apple respond realtime to these kinds of things? I think people believe that Apple should have considered the privacy implications of allowing Apps unfettered access to user contact data years ago, rather than only reacting when it becomes a PR issue that user-data is being misappropriated by shady App developers who appear to believe that making money is more important than the privacy of their users. (My personal guess is that they did think about it, after all they introduced Location access permissions with iOS 2.0, but decided that an Android-style permissions matrix would put off end-users. In other words, I suspect that Apple made exactly the same decision that their App developers did: ease-of-use was more important than user privacy.)
- Tyrannosaurs 15y agoI think you're absolutely right, but I the point kind of still stands - when evidence appears that challenges your agreed position, you should still consider it properly before responding rather than make a knee jerk reaction.
- reddit_clone 15y agoAlso, asking for forgiveness is far easier than asking for permission.
- richardlblair 15y agoIt's about time. It is their platform, their OS, and their users. It is their responsibility to respond to potential threats accordingly. This is the right thing to do. Good decision Apple.
- hockeybias 15y agoLet me join the chorus of "Better late then never".It is pathetic that this privacy breach occured - not to imply that Apple is anything short of God's final incarnation of perfection. :) Like hockey? Go to http://HockeyBias.com http://HockeyBias.com
- cewawa 15y agoSeems to me the flaw in the plan here is that we're talking about asking the user for permission, when we should be asking the contact. I don't want Path to have my contact details, but anyone who has me in their address book is able to provide them. Asking the user for address book permission doesn't fix that.
- huhtenberg 15y agoThe issue you describe is not "fixable" in principle.
- cewawa 15y agoYou can discover friends using a service without allowing wholesale access to address books.
- harryh 15y agoYou're basically asking for DRM on your contact details. That's not going to work.
- cewawa 15y agoUm, you proposed "DRM on your contact details", not me.
- harryh 15y agoIf you give your contact information to another person but what to technologically restrict how that information can be disseminated after that you are asking for DRM.
- cewawa 15y agoMy comment wasn't asking for anything. I was pointing out that an "allow access to address book" dialog wasn't going to solve the underlying problem, which is that unlike location services, the data you are giving access to is someone else's.
- dredmorbius 15y agoAnd how is Apple going to go about securing the permission the people LISTED in the address book for their personal data to be harvested. Address books are out of bounds. End discussion. Permission fail.
- artursapek 15y agoConsidering all the apps that like to use the phone numbers and emails to help new users find their friends using the app it's a difficult decision. I think a good compromise would be allowing an app access to phone numbers or emails without the rest of the information, eg whose number that is, their street address, etc. Then, giving your own number when you sign up could be an option. That way a new user's app could connect them to those friends of theirs who have opted to attach their name to their number.
- deleted 15y ago[deleted]
- reddit_clone 15y agoJesus Christ. With so many people syncing with their corporate groupware with their iPhones, how is this not a howling, category 10, shitstorm yet?
- polemic 15y agoWill existing [installed] apps be required to ask for permission if it has not previously been explicitly granted? Or will they effectively be exempt?
- zak_mc_kracken 15y agoThe question is: why wasn't this permission asked since version 1.0 of iOS? Android has had it since day one, isn't it common sense to assume that users might want to approve such access? <shakes head>
- antonyh 15y agoWhat Android doesn't have is the ability for the user to deny permissions. It does inform the user when installing the software, but there's still no way I can control permissions of Application X and disable it's access to contacts, SMS, and so on. iOS gives every app the same rights, Android presents a list of permissions without the ability to disable any of them. What's the difference? I suspect that the vast majority of users don't read that list anyway and just click through. Those that do read it and understand it have only two options - ok to everything, or don't use the app.
- buff-a 15y ago17.1: Apps cannot transmit data about a user without obtaining the user’s prior permission and providing the user with access to information about how and where the data will be used 3.3.9 You and Your Applications may not collect user or device data without prior user consent, and then only to provide a service or function that is directly relevant to the use of the Application, or to serve advertising. You may not use analytics software in Your Application to collect and send device data to a third party. So. These apps will be removed from the app store immediately, yes? It is my understanding that a person's address book can be a trade secret, and is protected by law.
- xsmasher 15y agoI'm surprised that Apple didn't do this four years ago, when an iPhone game was found doing the same thing (and transmitting the data in cleartext.) http://isource.com/2008/07/23/aurora-feint-removed-from-app-store-over-privacy-concerns-hopefully-to-return-soon/ http://isource.com/2008/07/23/aurora-feint-removed-from-app-... The game was removed, but the (obvious) policy change wasn't made.
- sutro 15y agoWith Congressional involvement this disturbance has now been upgraded to a Category 4 Shitstorm.
- frankus 15y agoThe whole Address Book framework on iOS seems to have gotten the shit end of the doody stick when they were handing out skilled programmer-hours at Apple. For example it's inexplicably implemented as a bunch of low-level Core Foundation calls even though it's not remotely a performance bottleneck in any conceivable use case and 90% of the apps using it immediately wrap every query result in some kind of half-baked Objective-C container. And although 99.9% of the code using it wants to use it a simple contacts database, the APIs are designed to be as general as possible and thus are even more needlessly hard to use. My guess is there has been a "Do something about Address Book on iOS" item on Apple's to-do list for the last couple of years and this permission business always got pigeonholed under that item, until this latest shitstorm demanded a short-term fix. It's going to be interesting how they implement this for existing apps, since there is no "The user said 'No'" return value for any of the APIs. I guess they're just going to have to return an empty address book or a "record deleted" result code when the user declines access for an app.
- antonyh 15y agoIt would be interesting to see what might happen in either of those use-cases for an app which syncs address books with a remote service, such as Google, Yahoo! or CRM tools. It's entirely conceivable that if a user hits no it could have rammifications to other systems which wouldn't expect either of these results.
- ansy 15y agoAbout time. Long overdue. But how soon is actually soon? 5.0.2 soon? Or 5.1 soon? I can only wonder how many app developers need to update their apps to remove unnecessary and shady looking address book access. Even worse, I wonder if any popular libraries are slurping address book data that developers don't even know about. Analytics and advertising companies in particular surely couldn't have resisted taking a peek could they? How can you even tell if someone zips up and encrypts your address book? Maybe if you have a jail broken phone modified to detect that, but that's pretty unlikely. Look how many people use Path and we're just now getting wind of it.
- yabai 15y agoIt is ironic that Apple is supposed to be protecting us by having very rigid policies for what and what does not enter the app store but they let an app access contact data without permission from the user!