Founders and Funders: Stop Screwing Users on Privacy

by Ryan Singel on February 13, 2012

Michael Arrington comes to the defense Sunday of one of his Crunchfund portfolio companies, Path, arguing that the New York Times‘s Nick Bilton is just piling on after Path “showed its belly” by apologizing for secretly copying and storing its users’ contacts in a company database.

But Arrington’s just wrong – it’s not piling on – and just because Path apologized, that doesn’t mean that it or the industry should get a free pass.

Bilton’s main point is spot-on: Path CEO Dave Morin, a Facebook veteran, should have known and did know that secretly copying users’ contact information was wrong and that his behavior is becoming all too familiar in the Valley.

Set aside Morin’s tenure at Facebook. Simply look at this exchange with Gawker in regards to the same issue with the first version of Path – where Morin states “Path does not retain or store any of your information in any way.”

Knowing that was an issue, Morin went on to launch a future version that secretly plundered the contacts from users’ iPhones. Path didn’t  even bother to use hashes to protect the data and stored it on their own servers in plain text. Path isn’t even using encryption to keep contact data on their servers, instead saying it’s protected with an “industry standard firewall,” which is just laughable to anyone who has followed the exploits of Anonymous over the last year.

But Arrington says it’s time to let up on Path because the company apologized and deleted the data. After all, Morin thought he could solve the problem by saying Path was being “proactive” in building a consent mechanism into upcoming versions of the app.

Bullshit. It’s time to stop letting start-ups and big companies (I’m looking at you, Google and Facebook) pretend they don’t understand basic fair information practices and then just “apologize” later after backing slightly off a huge insult to user privacy.

For start-ups that don’t know – the rules are really simple and basically boil down to “Don’t be a secretive asshole.”

Fair Information Practices have been around since the early 1970s. There are five of them. Notice, Choice, Access, Security and Redress. Basically that means you tell people why and how you collect data and what you do with it. You give them a choice about whether to provide it and a way for them to see/correct/delete. You use real security (e.g. in Path’s case, if they didn’t use MD5 hashes instead of collecting the plain-text, then the database should be encrypted and access to the database should be extremely limited inside Path). The company should also say what it plans to do if it violates that agreement.

This stuff is extremely basic, and Bilton is right to continue criticizing Path after it showed its belly. Path (and other apps) made the decision to blatantly abuse their users’ trust, *exactly* because it thinks it can be like Facebook and just ride out the storm after an apology, if they got caught.

As Bilton writes:

<blockquote>It seems the management philosophy of “ask for forgiveness, not permission” is becoming the “industry best practice.” And based on the response to Mr. Morin, tech executives are even lauded for it.</blockquote>

Instead of lecturing Bilton on being mean to Path, Arrington ought to be wondering why the hell he invested in a company that has absolutely no respect for its users, their privacy and basic standards of decency. Instead, he penned a column about how the net can become a “mob,” and what a shame it is that you can’t reason with a mob.

While I’ve always appreciated Arrington’s passion for start-ups, I find it very disturbing that he considers the users who raised their voices after being betrayed by Path on its march to the big bucks a “mob”. They aren’t a mob – and while they may not get every detail right, the people we call “users” are usually smart enough to know when they are being screwed.

And they got screwed, intentionally by a company you invested in, Michael. That should worry you more than a column from Nick Bilton.

{ 1 comment }

Facebook Gets Caught Going After Google

by Ryan Singel on May 27, 2011

Facebook recently got caught hiring a PR firm to push stories about a Google social feature that Facebook thought was too deep an invasion of privacy.

The ploy backfired on the social networking giant and its PR firm.

Catch a flavor of the story with these posts (Getting Caught, Getting Caught Covering Up) from my fellow Epicenter writer, Sam Gustin.

{ 0 comments }

Teens See Facebook Differently

May 11, 2011

Parents often think their teenage children will post anything to the web, and that it’s fair game for them to comment on their kid’s status messages. But teens have a different idea of what kind of public space Facebook actually is, according to new research from Microsoft. In restaurants, people often dine close enough to [...]

Read the full article →

Thanks BoingBoing!

April 3, 2011

I love Creative Commons-licensed content. At Wired.com, we rely heavily on photographers who license their photos on Flickr for re-use with credit. And now, I’m launching a data-mining project at the site world-facts.net using 10 years of posts from BoingBoing.net, which they license under a liberal Creative Commons license, allowing re-publishing for non-commercial ventures. Thank [...]

Read the full article →

Bloomberg Game Changers Tackles Twitter

March 12, 2011

A month or so ago, the crew that makes the Bloomberg Game Changers documentaries about entrepreneurs who have transformed our lives stopped by the Wired offices to ask me a bit about Twitter. The 25-minute show is now online and being show on Bloomberg TV. Check out the trailer below, and you can watch the [...]

Read the full article →

Facebook, Faux Dating and Fox

February 22, 2011

A few weeks ago, I wrote a story for Wired.com about how two performance artists had scraped 1 million Facebook profiles to create a fake dating site — the story took off quickly, as did the cease-and-desist letters from Facebook’s lawyers. The site — Lovely-Faces.com — is shut down now, but the duo explains their [...]

Read the full article →

Mark Zuckerberg Does SNL (Thrice)

January 31, 2011

This week’s Saturday Night Live had three versions of Mark Zuckerberg kicking the show off. Not knee-slapping, but actually quite funny.

Read the full article →

In Praise of Twitter

January 11, 2011

In December, Twitter received a court order from the Justice Department seeking details on users connected to Wikileaks, an order that came with a gag order forbidding the site from revealing the existence of the order. Twitter fought that gag order and won the right to tell the account holders about the order, giving them [...]

Read the full article →

Talking Facebook and Parents with Susannah Baldwin

January 10, 2011

Late last year, Susannah Baldwin asked me to be on her parenting show on KWMR radio to talk about Facebook. Thankfully, Susannah asked really good questions and kept away from fear mongering to talk clearly about parents, kids, and Facebook. If you are a parent living in the digital age, it’s worth your time to [...]

Read the full article →

On Glenn Greenwald Distorting My Words

December 30, 2010

In Glenn Greenwald’s recent response to Wired’s explanation of why it is not releasing more of the Bradley Manning/Adrian Lamo chat logs in the Wikileaks controversy, he defends himself by unethically cherry-picking and truncating a quote from an e-mail from me, that he says, erroneously, that I explicitly put on the record. He writes that [...]

Read the full article →