They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened.
I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come out stronger than ever before). And they have tried to do that, for that I give them credit.
But. It was not a mistake. And this sentence really shows why:
"Through the feedback we’ve received from all of you, we now understand that the way we had designed our ‘Add Friends’ feature was wrong."
They did it deliberately, there was not a mistake anywhere when implementing this nor with their intentions, and if they honestly didn't understand that what they did was wrong they don't deserve to be trusted again, not never. And if they did understand that it was unethical, which they undoubtedly did, it is even worse.
Their trust is not worth anything more than what they think they can get away with. The only thing that is different today from yesterday is that they think they can get away with less.
This desperately highlights why both android and iOS needs a way to spoof contacts for apps (return an empty list). Some android developers have solved this by having two apps in the market, one "private" version that requires fewer permissions. But that's a kludge (that I really appreciate) that almost noone uses.
You seem to define a mistake as 'an error in the code'. However, their use of the term mistake to be 'an error in judgement' or 'an error in the value of user's privacy', is also valid. When someone does something immoral, saying that it was a mistake because they didn't think it was immoral at the time (but now they realise it is) can, in many situations, be a good response.
Of course, there are some things for which no amount of apology could ever bring about true forgiveness (think godaddy). I personally don't feel this is one of those times, but everyone is entitled to their opinion.
Sorry to pick on semantics, but wanted to clarify this because I initially was confused when reading your post: you meant "immoral," correct? "Amoral" does not mean "morally wrong," but rather refers to things which are morally agnostic. It actually seems to me that Path believed their actions were amoral, that is, not registering anywhere on the moral spectrum (neither right nor wrong).
Well, as long as we're picking on semantics, that's not what amoral means. Amoral means lacking _regard for_ morality. You use it to describe a person or other entity that is unconcerned with the morality of their actions. Which fits Path pretty well.
I think Wikipedia is in the wrong here. In fact, if you read the article linked from the disambiguation page, it strongly supports the definition shown in all dictionaries, and makes no mention of rocks or chairs being 'amoral'. Regardless, none of this bears out the idea of 'amoral' meaning morally agnostic, ie actions having no moral component, and your initial semantic nitpick was itself incorrect.
Dictionary.com: having no moral standards, restraints, or principles; unaware of or indifferent to questions of right or wrong: a completely amoral person.
Merriam-Webster: lacking moral sensibility <infants are amoral> | being outside or beyond the moral order or a particular code of morals <amoral customs>
Apple dictionary: lacking a moral sense; unconcerned with the rightness or wrongness of something : an amoral attitude to sex.
thefreedictionary.com: Lacking moral sensibility; not caring about right and wrong.
Admittedly, some of these do mention definitions along the lines of "having no moral component", so it looks like everyone was wrong. Hurray!
I suspect, if you probe more deeply, that some of the Path developers where familiar with how this problem is normally solved and just copied a common design pattern. A large number of IOS applications supposedly upload the contact list to make it easier to find friends server side - I further suspect that many, many of the popular social apps do this.
Hopefully at least Five good things will come out of this:
1) Social Apps immediately remove the "upload contact list code from their
apps"
2) Social Apps come up with a more privacy clueful way of searching for
your friends.
3) Social Apps (all apps, ideally) focus more on user privacy.
4) Apple requires permission to be granted before allowing an app to read
your contact list.
5) Apple is more explicit about what app developers are _not_ allowed to do
when transmitting information off the IOS Device
6) The App review process adds a check to see if certain user private fields
are accessed, (Contact, Photos) - and ensures (through audit, or
confirming with the developers) that private information is not
being uploaded without opt-in.
If some or more of these things happen, then I'm actually happy what Path did was publicized. They've deleted 100% of the contact information off their servers - people now have to opt-in to add it back in.
It seems to me to be more a case of developers taking the easiest option, rather than spending some time considering a more secure, less creepy way of doing what they wanted to do.
The fact is, there are innumerable factors that affect people's decision-making in situations like this. The ability to decide whether or not a course of action is ethical is greatly affected by what your competitors are doing, groupthink, incentives, time pressures, etc. I could keep going. And yes, your ability to "get away with it" is also a factor.
Now you may say, "Who cares what the factors are? A wrong decision is a wrong decision." And you're right. However, as a practical person who wants to see real change come about, I cannot be satisfied with the run-of-the-mill, "They did it because they're evil and untrustworthy" response.
People are rarely inherently evil. I find it hard to believe that this group of engineers is really so different from you and I. It's likely that all of us grew up in similar environments, have gone through similar experiences, and possess similar moral beliefs. So aren't you the least bit curious why they're capable of making a decision you could never imagine yourself making? I think simply dismissing them as untrustworthy people is an irresponsible and short-sighted reaction. Human beings are more complex than that.
A lot of teachers believed that the only students who cheat are the dishonest ones. Well, some clever psychologists came along and -- lo and behold -- they showed that under the right circumstances, you can convince almost any student to cheat. That's the nature of humans.
Like it or not, we react to situations much more than to our personal moral codes. No amount of shaming greedy bankers, book-padding executives, dishonest politicians, privacy-invading programmers, etc is going to work. If we want to effect real change, we need to change the systems that allow for and incentivize this type of behavior.
I highly recommend reading up on basic human psychology. Influence (by Robert Cialdini) is a good place to start. Charlie Munger's writings, although unorthodox, are also great.
>The ability to decide whether or not a course of action is ethical is greatly affected by what your competitors are doing, groupthink, incentives, time pressures, etc.
No, its not. You do not kill a person over any of these. You do not kill someones trust in you over any of these.
>I cannot be satisfied with the run-of-the-mill, "They did it because they're evil and untrustworthy" response.
Then how about that they are shitty crappy company who are unconcerned about ethical matters of things and more concerned about what they can get away with. You know that they must have spent considerable time and effort to enable their app and service to steal all Contact data in the first place, right?
>I think simply dismissing them as untrustworthy people is an irresponsible and short-sighted reaction. Human beings are more complex than that.
irresponsible, irresponsible? What shit are you smoking chief? I have zero responsibility for their actions, or the pubic outrage against it, or my own reaction to crap. Let them rot in hell for all I care.
>convince almost any student to cheat. That's the nature of humans.
I am alarmed, you are now equating cheating under the right circumstances, to planned and intentional thieving under business as usual.
>I highly recommend reading up on basic human psychology
No, its not. You do not kill a person over any of
these... they are shitty crappy company who are
unconcerned about ethical matters of things
You're oversimplifying human behavior. It's not as simple as "bad people do bad things." There are COUNTLESS examples in which large groups of decent people have acted in horrifying, deplorable ways. And our psychologists know enough to reproduce this type of behavior in a lab. Read about the Milgram experiments, in which researchers were able to convince average American citizens to knowingly torture each other for almost no reason.
I am alarmed, you are now equating cheating under
the right circumstances, to planned and intentional
thieving under business as usual.
Circumstances are circumstance, whether we're talking about business or school. In this particular circumstance, you have Path participating in a market where "the police" Apple simply allows this behavior to go on. And where there's tremendous social proof, because everybody else is doing it. And where there is tremendous groupthink, because the only people they consulted with were themselves. And where there was tremendous incentive, because they want their company to be successful. And where they can attempt to rationalize their decision by saying, "Well we won't use the data for anything bad" without any oversight. All the ducks are in a row. It's just the type of perfectly disastrous environment that could entice even the most noble of people to make bad decisions.
irresponsible, irresponsible? What shit are you
smoking chief? I have zero responsibility for their
actions, or the pubic outrage against it, or my own
reaction to crap. Let them rot in hell for all I care.
It's simple: Either you care more about verbally abusing people who behave poorly, or you care more about preventing poor behavior in the future. If you claim to belong to the former group then fine, keep doing what your'e doing. But it never fixed anything in the past, and it won't do so in the future. But if we want to bring about real change, then we're going to have to concentrate on the immoral systems that allow and incentivize bad behavior.
The facts in this case are simple. The judgement is clear. You seem to be justifying their actions. There is no moral justification.
>type of perfectly disastrous environment that could entice even the most noble of people to make bad decisions
see, because of this incident we can now clearly tell which companies are noble and which were pretending to be so. "ducks in a row" is not a moral argument.
>Either you care more about verbally abusing people who behave poorly, or you care more about preventing poor behavior in the future
I am sorry, it is not an either-or, and not the way you put it too. You admonish people for __bad__ behaviour because you care about preventing it in the future.
You seem to be justifying their actions.
There is no moral justification.
You can't simply assert that you are right and I am wrong. I gave you clear examples under which normal people can be influenced to do bad things. If you don't think that's possible, then cite errors in the evidence. But if you're going to simply ignore the evidence, I can't take your responses seriously. There's no point in continuing.
because of this incident we can now clearly
tell which companies are noble and which were
pretending to be so.
...
You admonish people for __bad__ behaviour because
you care about preventing it in the future.
Humanity has been admonishing the immoral behavior companies/politicians/etc for millennia, and yet it still continues to this day. Appealing to morality does not work, has never worked, and never will work. Unless you fix the system, you are accomplishing nothing in the long run. What you're doing is the equivalent of blowing on a pot of boiling water to try and cool it off. Sure, it may get a degree or two colder for a few seconds. But unless you take the pot off the fire, the water will keep boiling.
> if they honestly didn't understand that what they did was wrong they don't deserve to be trusted again, not never. And if they did understand that it was unethical, which they undoubtedly did, it is even worse.
This is precisely my reaction to Facebook's Beacon. I decided that they were either completely inept or amoral. In either case I don't trust them.
I, like many others in this thread, think this is a fairly gross over-reaction. As engineers, we're trained to dig up problems and create solutions -- and a big part of this process is understanding what data can be made available to you and how you can use it to make your product better. I sincerely believe that they saw the immense potential of having this information available to them and ran with it under the excitement-induced delusion to the effect of, "who could be unhappy with this when it brings so much value to the table?"
I think their flaw was either in not polling their user base before hand or making it opt in to begin with, but I also think that this oversight happened because they truly believed in the usefulness of what they were doing.
Then again, I still believe that Google isn't trying to be evil (nor do I really think they ARE particularly evil for the time being), so take my opinion with a grain of salt.
Yeah this is like BP making excuses for the oil spill. Anyway, it's every iPhone owner's fault that they give away their privacy that easily without even caring. On the other hand it's Path's fault that they seem to have done this without a real plan (what are we keeping the data for? what are we going to do in case of "PR nightmare"?).
You are right. And I am not touching Path with a ten foot pole. Not in hell. What annoys me is that Apple has caused a few hours of my life to be wasted on this shit. And has me deeply worried about what other crap is uploading all my contacts information into their hush hush secure database. And also that they allowed this piece of free advertisement seeking shit company to get through their fabled review system. Heck, I want an apology from Tim Cook, and maybe one from the heavens where a visionary soul probably rests forever now.
If the going is so bad, I will soon end up using a clam shell that I put up with all these years before an eventful day that I fell in love with an "are you getting it?" product. Makes one wonder what all those jerks making the rounds on SOPA and PIPA are doing to protect us from these Path like shit makers.
This illustrates rather than you should think twice before using a service you do not know much about. You can always make rules and there will always be ways to go around them. Personal responsibility and awareness is what makes the difference in the end. Would you eat just anything given to you if you ignore where it comes from and how it's made?
I don't think the developers behind the product were thinking about it in a bad way when they did it that way. It was probably more practical to do it that way at that moment and they didn't give it more thoughts, like they would never have considered selling those informations.
I get that now it's a big deal since it became a huge product. I wouldn't call that a mistake though, the problem with personal information on internet is pretty recent (facebook, google+...) and developers don't really know how to deal with it yet.
I guess the more we see problems like that, the more developers will educate themselves on the matter.
True. What I meant was that they try to make it sound (at least to me) like the action of stealing the contacts of its users was a mistake. They do this by saying: We believe you should have control when it comes to sharing your personal information. etc. etc. It makes it sound that it somehow was a mistake for those believes to be violated. It wasn't.
And if you ask me, that breach of their users trust is not something that you can just turn around. If they didn't understand that their users might get upset that only makes it worse (when it comes to trusting them).
The action that path says they've taken - which is to delete all the contacts they have so far collected - serves to move me to forgiving them, 'cos that action is the only thing they have going for the contact collection being a "mistake".
"Privacy empathy" (no .. pun not intended I swear) seems hard to come by these days.
Ironically, this was exactly the kind of apologetic but side-stepping rhetorics used by still German president Christian Wulff so I call shenanigans and nothing but modern rhetorics and modern PR-management. This is very alike to catching someone red-handed, with the hand still on the murder weapon stuck in the body... and then they make a public apology along the lines of "Through the feedback I’ve received from all of you, I now understand that the way I handled this dispute over $20 million, which are clearly mine by the way, was wrong. But I deeply care about ethics, human life and I honestly believe that body should be allowed to live and as a clear signal to my commitment to human rights, I will immediately retreat my serrated blade from their chest."
> They did it deliberately, there was not a mistake anywhere when implementing this
Exactly - so that's why those "oh I realize that now and really want you all to understand my deeeep commitment to the exact opposite moral values of what I actually did" apologies make me so sick. It completely side-steps the fact that it was done deliberately, 100% on purpose and they basically cover that up by trying their hardest to scrape it under the rug as an "oopsy-daisy!" now and let users feel as if thousands of phonebooks beamed themselves totally magically into their servers and they really had no idea that was happening!
You can simply not be so detached from reality that you do not worry about reading people's phone books like that.
Want to apologize and really speak through actions? Dave Morin, Co-Founder and CEO, step down immediately because you have deliberately violated human rights and now you are just trying to get away with it, IMHO. And as CEO, you are ultimately responsible.
Human rights? If I'm correctly understanding the issue, their software monitored your contact list so they could notify you when one of your contacts joined the service. You seem ready to throw him before the International Court.
That they've wiped their user data and are giving people the opportunity to use their product in a setting with opt-in sharing seems to demonstrate to me, at least, that they still believe that hosting your contact information would add value to their product, but they now realize that concerns regarding privacy are significant enough to warrant using the product without this feature. To reference a parallel thread, I don't think this is a reflection of morality/amorality/immorality, but rather that this never registered in their engineering oriented brains.
IMHO privacy should become a human right in these surveillance-ridden times but that was ahead of time - replace with "privacy", if you ask me it was a huge intrusion into the privacy of the users.
Sure, privacy should become a human right. I personally am a very private person. What you need to understand is we live in a world where there is no such thing as privacy. We need to clearly define what is right and what is wrong. What needs to be opt-in and what needs to be opt-out. What we, as a community, need to do is set a standard. We need to establish boundaries so that we can regain our privacy.
Outside of establishing boundaries there needs to be a way to deal with those who break the rules. Sending CEOs straight to the slaughter house doesn't accomplish anything. Companies need an opportunity to react and do the right thing. Especially when intentions were good, and the reaction from the Company is as responsible as Path's.
+1 Paths Owned their mistake
+1 Deleted all the data
+1 Fixed the mistake by publishing an opt-in feature.
They did everything they could to right their wrong.
You also need to realize they didn't commit murder. They weren't 'caught red handed with the murder weapon'. They had some digital data, and then deleted it. It's not like they raped and murdered your wife and family. They didn't commit genocide. They made a minor mistake and fixed it.
They did this only to cover their asses and that has been the only concern they've ever had. That they already tried to push the opt-in was of course only in fear of what just happened.
I'm sorry, I'm all for public apologies and I truly believe that it is in times like these companies have a chance to really prove themselves and really make a mishap something positive (and come out stronger than ever before). And they have tried to do that, for that I give them credit.
But. It was not a mistake. And this sentence really shows why: "Through the feedback we’ve received from all of you, we now understand that the way we had designed our ‘Add Friends’ feature was wrong."
They did it deliberately, there was not a mistake anywhere when implementing this nor with their intentions, and if they honestly didn't understand that what they did was wrong they don't deserve to be trusted again, not never. And if they did understand that it was unethical, which they undoubtedly did, it is even worse.
Their trust is not worth anything more than what they think they can get away with. The only thing that is different today from yesterday is that they think they can get away with less.
This desperately highlights why both android and iOS needs a way to spoof contacts for apps (return an empty list). Some android developers have solved this by having two apps in the market, one "private" version that requires fewer permissions. But that's a kludge (that I really appreciate) that almost noone uses.