Bart Decrem (Important Friend Book and handshake announcement) said:
First of all, a sincere apology to all of you for this belated response. Second, heartfelt apologies to the people who were affected by this problem.
Here's what happened. The algorithm for matching of address cards was overly relaxed, meaning that matches were made that should not have been made. We did not discover this issue prior to the release because we were unable to test the feature with more than a dozen users (pre-AppStore launch, it was impossible to let outsiders test the app).
Last night, Friend Book was released. Four or five hours after the app was released, we saw the first of the reports above. Within one hour of being made aware of the issue, we removed Friend Book from the AppStore to ensure that no more users would install the app and that we could fully evaluate the issue before making the app available again. Shortly therafter, we disabled the handshaking feature on our web servers to prevent any further exchanges of address cards by the people who had already downloaded the app. Any attempts to exchange address cards after that time would result in the red error screen or a similar error.
In sum:
- The app was available for download for about 5 hours before we pulled it from the AppStore and disabled the handshake feature. We believe it was downloaded by several hundred users, and the handshake feature was used several hundred times
- Users who still have the app installed cannot exchange address cards, so there should not be any residual risk, but we do recommend that users remove the app
- The only address card affected is the Me card selected as part of the handshake feature. No other address cards were ever sent to our servers, and therefore no other addresses were ever jeopardized. No address cards are stored on our servers.
We take this issue very serious, as we hope is demonstrated by the steps we took. We will not release this application again until we are absolutely certain that there is no privacy risk to users. Earning our users' trust and respecting users' privacy is very important to us. We are working on a best-of-breed privacy policy for all of our apps and expect to publish that in the near future. We will also examine our development and QA practices to prevent further privacy related issues.
We apologize again to everyone affected by this.
Sincerely,
Bart Decrem
CEO