Now Apple just needs to do something about the address book and we're good. I don't particularly like any random app having silent, unrestricted access to my entire address book. It's only a matter of time before we find out some super popular free app has been sucking down contact lists and I don't trust the Apple review process to protect users.
There should be a "this app is trying to access your address book" notification and per app permissions in Settings just like Locations and Push Notifications.
> It's only a matter of time before we find out some super popular free app has been sucking down contact lists
I believe that moment already came and went when people discovered the sync feature on the iPhone Facebook App sent all of your friends' phone numbers to Facebook. (https://www.facebook.com/friends/edit/?sk=phonebook)
For the record, finding this didn't particularly bother me and I did approve it -- however unwittingly. (I thought I was just pulling info from facebook, not sending info back.)
Facebook has a responsibility to do the right thing or lose a lot. It has executives, investors, and assets which are all exposed to lawsuits and criminal investigation.
A dude in Thailand that makes a free "Angry Birds Cheats" app does not have a lot to lose. In fact he could probably get away with putting something up on the app store with a stolen identity. The app could suck down millions of people's address books with real names, real birthdays, real phone numbers, real addresses, a network graph, and maybe more completely silently. You know the network activity indicator doesn't even activate unless it's flipped on and off programmatically? Best case scenario Apple finds out, takes the app down, and tells the Thai police to go find the guy? Good luck with that. Worst case scenario nobody even notices and the app disappears after sinking off the charts.
There is zero consumer protection against the latter and quite frankly the former shouldn't be an issue to begin with either. Facebook was getting away with it without getting caught. How many of those other high throughput apps that aren't from Facebook receive the same scrutiny from the public and researchers?
"Facebook has a responsibility to do the right thing or loose a lot. It has executives, investors, and assets which are all exposed to lawsuits and criminal investigation."
Couldn't care less. The fact that they did this without being clear and honest about it is more than enough to completely obliterate any trust they might inherit for having much to loose. Especially since this alone should be more than enough for them to "loose a lot".
There is absolutely zero consumer protection against facebook as well.
And then you take into account that people most likely have had secret phone numbers in their contact list, what facebook did/do should be a criminal offence, especially considering they are a large corporation and exploits the inherited trust from that.
If you use the Facebook app and enable contact syncing, it prompts:
"If you enable this feature, all contacts from your device (name, email address, phone number) will be sent to Facebook and be subject to Facebook's Privacy Policy, and your friends' profile photos and other info from Facebook will be added to your iPhone address book. Please make sure your friends are comfortable with any use you make of their information."
I work at Facebook, but I am not involved in that team and from my perspective it looks like an honest attempt is being made to help people understand what is going to happen, and I don't see any "getting away with it without getting caught" going on.
I'm totally with you on how much of a problem this could be when someone is actually attempting to be malicious. I think Apple should probably protect the contact database in a similar way to how it protects your location from applications. It doesn't prevent an app that ostensibly is using your contacts for some good purpose (and getting your permission) from using it for bad ones, but it does reduce the likely distribution/success of the application.
The increasing prevalence of warnings and confirmations when signing up for a site, when downloading/connecting applications, or when enabling features has encouraged people to skim these attempts to educate them about what it going to happen without reading them. Trying to effectively communicate and emphasize the importance of the information contained in warnings and confirmations is a growing problem that I don't think anyone has cracked just yet, but I know people are concerned about it and working on it.
There should be a "this app is trying to access your address book" notification and per app permissions in Settings just like Locations and Push Notifications.