11 ms·
> We also collect a few anonymous data (CLI errors, most frequently used commands and count of resources). Looks cool, but this is an instant no for me. Sorry
by heartsucker 10y ago
> We also collect a few anonymous data (CLI errors, most frequently used commands and count of resources).
Looks cool, but this is an instant no for me. Sorry guys.
- hbbio 10y agoProject creator here (but obviously not the OP). Yes, we do collect minimal anonymised statistics in the sole goal of improving awless. All the statistics code is here: https://github.com/wallix/awless/blob/master/stats/stats.go https://github.com/wallix/awless/blob/master/stats/stats.go As the project is Apache licensed, you're free to modify it if you don't want this. Also, if you're conscious about privacy you should use application firewalls on your client side like Little Snitch etc. since many software that you install on your machine also do this.
- scaryclam 10y agoI like the look of this, so on the software side it's a thumbs up. However, the fact that the code is active at all will rule it out for some companies (firewall or not). Perhaps make it something users can turn off in a config file? Not everyone can code in go, especially if their job is as a sysadmin, which isn't unlikely given that this is an infrastructure tool, so it might not be as simple as forking and editing the code for them.
- mbreese 10y agoOr make it turn-off-able (?) with an environmental variable. There are a couple of ways to make the tool default to report and allowable in non-reportable environments. The key thing is to make what is happening transparent.
- frugalmail 10y agoMust be an explicit "turn-on" option.
- deleted 10y ago[deleted]
- ezekg 10y agoWhat does the data payload look like? I'd like to see the actual data you're sending, even if it's just a mock. From digging around in the code, it looks like you're sending infra data, including instance IDs. How do I know you aren't sending my AWS access tokens[0]? [0]: https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6f4850c52e57d5d77c9/stats/stats.go?ts=2#L159-L184 https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6...
- the_duke 10y agoYou should at least provide a prompt on first start that asks if participating in analytics collection is acceptable.
- gigatexal 10y agoA toggle at least would be nice to turn all data collection off.
- frugalmail 10y agoI appreciate that your folks released this OSS tool. However: Where I work, as long as the data collection code is in there, whether I can modify it or not, they won't allow it on our computers. I know this is not uncommon. Dismissing this concern by saying "other software does this" while awless falls into a different category (small CLI tool) is also problematic.
- fxaguessy 10y agoThanks for the feedback. Until we provide a way to allow/disable data collection, we have disabled completely the data sending (see https://github.com/wallix/awless/commit/f6389e75787390bd779773a5e253bdb7a5947ddc https://github.com/wallix/awless/commit/f6389e75787390bd7797...).
- godgod 10y agoHow bout you NOT collect this information. It's just creepy that this is turned on by default.
- heartsucker 10y agoWow, and your website isn't even HTTPS for what appears to be a security company. Get it together.
- bdcravens 10y agoSeems like a non sequitur when discussing an open source project they have released.
- heartsucker 10y agoThe tool phones home. Their website doesn't have HTTPS. It's plausible that the tools phones home over an unencrypted channel (I didn't look, so I could be wrong). My overall impression is that they don't do security very well.
- deleted 10y ago[deleted]
- bdcravens 10y agoAnyone can release a project on Github; the project should be based on its merits, not how well an unrelated project is implemented. (and vice versa) A quick search of the repo of https:// https:// and then http:// http:// shows that the stats collection is apparently https.
- heartsucker 10y agoSure, and if we imagine a hypothetical entity that has 10 products with security holes and then releases and 11th, it might be worth looking at the 11th more suspiciously. Things don't happen in a vacuum.
- hbbio 10y ago@heartsucker If you want to judge on previous things, we are the team that created http://opalang.org http://opalang.org and have no tie at all with the company static and outsourced portal. Also, will be in Berlin soon, contact me will gladly meet there.
- matthewmacleod 10y agoInstead of bitching about it, you could very simply and easily fork this entirely open-source project and remove the code. It's literally a single line-change.
- ceejayoz 10y agoThat "bitching" is both constructive criticism and helpful to highlight here in the comments so others may take note.
- tequila_shot 10y agoWell, I think it's not constructive criticism. If there were a closed source project, then yes, it would be a very helpful highlight.
- rlpb 10y agoThis kind of functionality is generally frowned upon in the Free Software world. For example, in Debian, it'd be treated as a bug and patched out. So I disagree; calling it out to inform others is entirely appropriate.
- matthewmacleod 10y agoMaybe you're right and I'm being unfair. It just seems kind of dick-ish - what's wrong with even "Cool, but I don't like stats being collected, please make this opt in"?
- kl4m 10y agoThat's how I interpreted the OP.
- dsmithatx 10y agoNo need to fork. Just clone and comment the line.
- yeukhon 10y ago
- NotHereNotThere 10y agoAnd for some reason, this (in my eyes useless) data collection is bundled inside the version check: https://github.com/wallix/awless/blob/master/stats/stats.go#L82 https://github.com/wallix/awless/blob/master/stats/stats.go#...
- chews 10y agoNot useless, gives them usage numbers.
- edsouza 10y agoAlso upload the a hash of the userid and accountid. Hashed with non-random salt so it's not really anonymous as the function says. userid and accountid stored in database here: https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6f4850c52e57d5d77c9/database/db.go#L83-L102 https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6... retrieved by stats here: https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6f4850c52e57d5d77c9/stats/stats.go#L159-L167 https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6... Added to stats payload here: https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6f4850c52e57d5d77c9/stats/stats.go#L175-L176 https://github.com/wallix/awless/blob/e2bf4f2cad37b011c5b3b6...
- fxaguessy 10y ago(I'm one of the core developpers of awless) The hash functions are totally unrevertable, so it is impossible to come back to the original identifiers. We added these anonymous ids, in order to know which commands are the most used per users. Anyway, if you have better ideas on how to manage this, feel free to make a pull request or create a Github issue. And if you prefer to disable it, you can also do it easily with the source code (you just need to comment a few lines). Edit: We opened an issue for this topic on our Github repo: https://github.com/wallix/awless/issues/38 https://github.com/wallix/awless/issues/38 . Feel free to continue the discussion there.
- pavelmelnichuk 10y agoYou can create a randomly generated cookie of sorts instead of doing anything with a users' credentials. The supposed accomplished task and end goal would be the same, and yet, people would feel more comfortable. Your claim that you are using an irreversible hash is not comforting. Your forced data collection is also not comforting.
- yourapostasy 10y ago> You can create a randomly generated cookie of sorts instead of doing anything with a users' credentials. That throws off their statistical analysis. Random cookies generates a new cookie for each new install or re-install, inflating the "users" count. If someone installs this on five different servers, the stats under random cookies will show five separate streams of data, and they will draw improper conclusions that a particular operation used on all of those servers if five times more popular than it really is. A configuration flag to disable the data collection is reasonable, but using a well-known hash like Whirlpool to anonymize the data stream is also reasonable. If someone doesn't like data collection, then they shouldn't use cloud products, and they should just as vociferously declaim cloud services. With cloud services, whether or not the usage data collection is anonymized is at vendor discretion, but here, you control the source. Using a utility for a cloud service, and complaining about usage data collection, is ironic, considering AWS surely collects the same data.
- samx18 10y agoAgreed! Cant run it on our environment as well :(
- hbbio 10y agoComing soon: https://github.com/wallix/awless/issues/38 https://github.com/wallix/awless/issues/38
- nunez 10y agoIs it opt-out?