Seems to me the flaw in the plan here is that we're talking about asking the user for permission, when we should be asking the contact. I don't want Path to have my contact details, but anyone who has me in their address book is able to provide them. Asking the user for address book permission doesn't fix that.
If you give your contact information to another person but what to technologically restrict how that information can be disseminated after that you are asking for DRM.
My comment wasn't asking for anything. I was pointing out that an "allow access to address book" dialog wasn't going to solve the underlying problem, which is that unlike location services, the data you are giving access to is someone else's.