Anger for Path Social Network After Privacy Breach
Last week, Arun Thampi, a programmer in Singapore, discovered that the mobile social network Path was surreptitiously copying address book information from users' iPhones without notifying them. — David Morin, Path's voluble chief executive …
Context & Ripple Effects
Five days after programmer Arun Thampi documented Path uploading entire iPhone address books to its servers, the story has become a full backlash cycle: Dave Morin is fielding the apology, and the writeup has traveled unusually far for an app-privacy item — Chris Dixon, Ars Technica, The Next Web, parislemon and others all picked it up within days.
The reaction has already split into camps with different fixes: Matt Gemmell argues social apps should hash contact data rather than store raw names, while The Next Web notes Instagram quietly added a contact-list access prompt in the controversy's wake. It lands on a company that had been building toward openness — Path's 2010 integration with Facebook was pitched as connecting people, which makes the undisclosed contact harvesting read as a betrayal of that pitch.
First-order effects
- Path faces immediate reputational damage and user anger over contact data collected without notification, with Morin personally absorbing the apology burden rather than delegating it.
- Every iOS social app that reads the address book is now exposed to the same question from its own users, since Path's practice was common enough that Thampi's finding generalized instantly.
Second-order effects
- Instagram's silent addition of a contact-list access prompt shows competitors pre-emptively adopting disclosure to avoid being next — the cost of the fix is low, so imitation spreads fast.
- Apple comes under pressure because its App Store review process did not catch or require disclosure of address book uploads, putting the platform gatekeeper on the hook for developer behavior.
Third-order effects
- If the pattern holds, silent collection of personal data gives way to explicit permission prompts as the default expectation on iOS, shifting compliance from developer discretion to platform-enforced rules.
- Technical mitigations like hashing contact data before upload — argued for publicly by developers such as Matt Gemmell — could become the accepted engineering norm for social graph features.
The trend: Mobile social apps are being pushed from undisclosed personal-data harvesting toward explicit permission prompts and privacy-preserving data handling, with Apple's gatekeeping role as the deciding force.