17 ms·
I suspect the tracking in VSCode is mainly used to improve the product. It's probably in my best interest, and the interest of the community as a whole to leave
by jameskraus 8y ago
I suspect the tracking in VSCode is mainly used to improve the product. It's probably in my best interest, and the interest of the community as a whole to leave tracking on. I mean, I get it, HN is usually a more skeptical and security-focused crowd. At the same time, it's likely MS will just take that information and tailor their bugfixes and features to the things I need most, so by all means I want them to have it.
- jsgo 8y agoI completely agree and I’m in the same boat (I’ll continue to use VS Code). That being said, it’s somewhat amazing we are now in a time when a Microsoft product could have aspects users don’t approve of and rebuild it without it: everyone wins.
- z3t4 8y agoIt maybe starts with simple statistics. But then you want to know what features the user use, then you want to know what other programs they have installed. Then you want to know what the users search for on the web. etc. It's a slippery slope.
- joshschreuder 8y agoYou've literally described a slippery slope fallacy
- jlawson 8y ago"Slippery slope" is not a fallacy. Life is full of slippery slopes in terms of behavior.
- dymk 8y agohttps://en.wikipedia.org/wiki/Slippery_slope#Non-fallacious_usage https://en.wikipedia.org/wiki/Slippery_slope#Non-fallacious_... No, that still falls into fallacious usage. The user doesn't justify why the steps of their assertion follow after the other. Just that they... do.
- steve_taylor 8y agoNo one needs to justify the "why" when we're talking about a very well trodden slippery slope.
- dymk 8y agoFallacies don't just stop applying when it's convenient to elide justification.
- Sir_Substance 8y agoThat's true. However, we also don't collect history for the fun of it. Over the course of the last 20 years, we've seen that once a data collection and digital surveillance framework is put in place, the surveillance tends to expand. Slippery slope arguments, sans good reasoning, tend to be fallacies. However, don't fall into the trap of thinking that an argument backed by historical record is a slippery slope just because it's predicting an outcome. We might call that the "history is all slippery slopes" fallacy. Stating "this has happened before multiple times before, and each time has lead to x" is a very different argument to stating "this has happened, so the logical extrapolation is x".
- justatdotin 8y agoif it can be that well trodden, is it really still a slippery slope?
- mixmastamyk 8y agoOverwhelming empirical data across history.
- johncolanduoni 8y agoThat’s proof of existence of slippery slopes, not of prevelance of hypothetical slippery slopes being realized.
- 8y ago
- asdfasgasdgasdg 8y agoThe fallacy is to assume, without evidence, that the slope is slippery. There are plenty of slopes that aren't. Probably most, just you don't think about those because you know they aren't slippery already. For example, I slept in 'til 8:30 today. OMG, a slippery slope. Next thing you know, I'll be sleeping until 3PM. Til midnight! I will never wake up again. But as it happens, sleeping in isn't a slippery slope. I don't think there's any solid evidence that telemetry is either.
- sitkack 8y agoThis is exactly why I get up a minute earlier each day. As it is, I am waking up tomorrow at 4:39 AM. Mission accomplished.
- TimTheTinker 8y ago(10 years into one possible future) “... and that was me before we had children.”
- iopq 8y agoUmm, it's slippery for me. I haven't had a stable sleeping schedule for over ten years. Send help.
- colordrops 7y agoThat's the "hasty counterexample" fallacy.
- colordrops 8y agoIt's not a fallacy. When a printer driver reporting stats back to the manufacturer made national news in the early 2000s and prompted calls for laws regulating privacy, the argument was that it was a slippery slope fallacy to assert that privacy violations would get worse. Look at where we are now.
- enraged_camel 8y ago>>It's not a fallacy. By itself no, but it is often used fallaciously. Such as in this case, when someone is opposing some good thing on the basis that that good thing might, some day, lead to bad things.
- steve_taylor 8y agoGood things such as trackers ostensibly designed to deliver you relevant content?
- enraged_camel 8y agoNo, good things such as telemetry and automated error reporting so that bugs can be fixed effectively and efficiently and everyone is better off for it.
- wolco 8y agoThat sounds nice. But could they use this data legally in another way?
- jjeaff 8y agoNot realizing that many things actually ARE a slippery slope is what has gotten the world into a lot of messes. Nearly every legitimate privacy concern that we have today started out with a legitimate and we'll meaning purpose. Our entire legal system is predicated on common law precedent. So it is very valid in many cases to argue that allowing something good now, might set us up for something very bad later.
- 8y ago
- deleted 8y ago[deleted]
- DEADBEEFC0FFEE 8y agoIt's a shame we have to assume the worst. What would be better is for Microsoft to be more transparent about the telemetry and to enable more granular control. That said, I wouldn't bother checking as I don't really care. I rub shoulders with infosec issues daily, as most IT folk do these days. When I think about the perceived risk of telemetry from VSCode, now and in the future it's a negligible risk that I accept.
- jakear 8y agoThey are actually very transparent about the telemetry they collect, and they offer granular control. There is a log of all events sent to MS, and a page in settings dedicated to the different types of telemetry they can be enabled.
- felixgallo 8y agoIncorrect. That page has essentially no detail.
- specialist 8y agoFWIW, I'm completely comfortable with telemetry, analytics, whatever so long as 1) there's a complete local log and 2) I can opt-out.
- mkl 8y agoWhere is the log stored? All I can find online are some instructions that seem out of date as they don't refer to the interface I see (or I don't understand them): "You can inspect telemetry events in the Output panel by setting the log level to Trace using Developer: Set Log Level from the Command Palette." [1] The "page" in settings consists of just two options, and the complete descriptions of the types of information they collect are "crash reports" and "usage data and errors". That seems the opposite of transparent and granular. Am I missing something? [1] https://code.visualstudio.com/Docs/supporting/FAQ https://code.visualstudio.com/Docs/supporting/FAQ
- naikrovek 8y ago
- ryder9 8y agoyou should read up on slipper slope fallacy https://en.wikipedia.org/wiki/Slippery_slope https://en.wikipedia.org/wiki/Slippery_slope
- pissfu 8y agodid you read the article you linked? "Logic and critical thinking textbooks typically discuss slippery slope arguments as a form of fallacy but usually acknowledge that "slippery slope arguments can be good ones if the slope is real—that is, if there is good evidence that the consequences of the initial action are highly likely to occur. The strength of the argument depends on two factors. The first is the strength of each link in the causal chain; the argument cannot be stronger than its weakest link. The second is the number of links; the more links there are, the more likely it is that other factors could alter the consequences."" https://en.wikipedia.org/wiki/Slippery_slope#Non-fallacious_usage https://en.wikipedia.org/wiki/Slippery_slope#Non-fallacious_...
- eridius 8y agoWhere's the link between "collecting data on VSCode feature usage" and "gathering a list of all other apps the user has installed on their system and all web searches the user does"?
- nneonneo 8y agoI mean, I can definitely see “all other apps” being collected as a way to check if there are apps conflicting with or interfering with VSCode. Maybe it’s only collected for a small subset of users with particular issues - but it would still be tempting for a dev to try and collect. I can also see them collecting code searches done within the app as a way to check if their search system is working well for real use-cases. Neither is outside the realm of possibility - you just have to put yourself in the mindset of a dev who is assigned to track down a rare crash or to “improve the search experience” who might want a little more data to work with. Not saying I agree with any of this collection - it’s terrible and definitely falls under “the road to hell is paved with good intentions”. Companies should be extremely clear about what they will and won’t collect - and never cross the line even if it would be useful.
- millstone 8y agoI think it sends MS every keypress in search fields - https://github.com/Microsoft/vscode/issues/49161 https://github.com/Microsoft/vscode/issues/49161
- zeusk 8y agoIf you had actually read that issue, > Lol, probably just an oversight because they made the search a lot better. > So I think it only does this on the settings file and not on other files ;) > https://code.visualstudio.com/blogs/2018/04/25/bing-settings-search https://code.visualstudio.com/blogs/2018/04/25/bing-settings...
- kotrunga 8y agoNo matter what, it's an opt-out setting that can only be disabled with: "workbench.settings.enableNaturalLanguageSearch": false That's unacceptable.
- Stuckinsofa 8y agoCan you explain why this search feature is a problem because I don't understand?
- userbinator 8y agoMaybe not understanding the problem with a tool that may be used to work on proprietary code containing trade secret information silently and unexpectedly sending information out to the Internet is the reason for software becoming spyware...
- zeusk 8y agoEmphasizing from my original post, >> it only does this on the (VSCode) settings file and not on other files ;)
- 8y ago
- nwah1 8y agoOne could be totally uncritical about the current or future intentions of Microsoft and still prefer a version with no telemetry. Data breaches are very common. Employees, hackers, or governments could all gain access to the data. The data could be accidentally broadcast or left in a vulnerable place. Even the payroll data for the national security establishment was once reported to be compromised. Everything is vulnerable. Computer science is in such an abysmal state. Even with properly configured servers, OSes, and databases that are up to date, they are still vulnerable to zero-day attacks because they are not formally verified and have enormous and largely unnecessary complexity. Then throw in the crazy complexity of processor instruction sets, creative side-channel attacks, and stuff which exploits the physical properties of the hardware (rowhammer). It is reasons like these why we should never really trust transmission of sensitive data over the internet. The concept of secure voting systems, for instance, is literally a joke. insert obligatory xkcd here
- est31 8y agoYeah, there is a reason why the Kremlin uses mechanical typewriters.
- savant_penguin 8y agoIMO they could get whatever statistics they wanted, as long as they asked before collecting
- chii 8y agoand also, what they intend to use said statistics for.
- eridius 8y agoWhy would Microsoft gathering usage data about VSCode turn into spying on the user's other apps and web searches? There's no connection between the two. Tracking usage of VSCode features has a clear connection towards improving VSCode. Spying on the user's activity outside of VSCode has no connection at all to improving VSCode.
- naikrovek 8y agoEvery time I hear the phrase "it's a slippery slope" uttered by someone arguing against something, I am immediately suspicious of the argument that person is making. There really isn't such a thing, in the way you've used that phrase. Capturing telemetry on how I use a tool from within that tool is perfectly fine, to me. Collecting telemetry on my search history in the browser by that same tool isn't. THERE ARE NO INTERIM STEPS that makes the second of those ok. There is no slope. If there is, it isn't slippery. There is a series of discreet decisions and at some point (which is different for everyone) a line is crossed. There was no slope or slip that brought you there, only a series of mostly unrelated decisions. To think that Microsoft's long-term goal is to install a keystroke logger via a multi-decade and multi-phase plan that begins with application usage telemetry in a free developer tool thanks to "a slippery slope" is just simply not realistic.
- tdesilva 8y agoIt's called a fallacy for good reason.
- wolco 8y agoWhen you walk in the wrong direction the final step off the cliff is the last one. Better to get off of the slope because choices get fuzzier the closer you get to the sun.
- z3t4 8y agoIm not making that up, it was in the TOS for VS/code last time I checked.
- kburman 8y agoI'm ok with until its get used to improve the editor. It would much better if they can share the data they are collecting.
- jakear 8y agoYou can view a real time log of all telemetry events in-editor. Or do you mean you’d like them to share with you all he telemetry from all their users?
- jplayer01 8y agoWell, why not? A bunch of people here are more than happy to defend Microsofts tracking. If telemetry really isn't a big deal, make all that data public. It's our data anyway, collected from how we use their software.
- gmueckl 8y agoThat would be like publishing the recipe to the secret sauce that gives them their competitive advantage. I doubt that theynwant to share that insight.
- millstone 8y agoSo then why keep the telemetry source code secret?
- marquis-chacha 8y agoThe telemetry source code is not secret. In fact, it is annotated thought the code, in order to comply with certain GDPR requirements. Try searching "GDPR" globally in the vscode source.
- prepend 8y agoI think you’re right, but it needs to be a user choice. If presented with an option, I would likely leave it turned on 90% of the time. I hope this project motivates MS to open source the runtime and making tracking a user- selected option. I really like Code and think MS has really helped the dev community by making it so great and free. But I would like to see them embrace f/l/oss for all their non-core products and stay on track for customer/dev-friendliness.
- chipperyman573 8y agoIsn't it? When I opened VS Code on a new computer for the first time today, a message popped up with step by step instructions to opt out
- prepend 8y agoTracking should always be opt-in, not opt-out. I base this on expected user preference and trying to optimize for user happiness and functionality. I don’t think this is as true for non-OSS software where the purpose is likely more toward revenue generation than community and user functionality.
- nurettin 8y agoWhat is the crucial difference between a popup saying "would you like to opt in?" and popup saying "would you like to opt out?"
- _emacsomancer_ 8y agoUser perception of a default state.
- ComodoHacker 8y agoOpt-in telemetry likely won't serve it's purpose. Very few users change the defaults. To the point where you don't get enough data for useful insights.
- swiley 8y agoThe point behind open source software is that the users themselves can make pull requests when there’s something they don’t like. A need for telemetry indicates that contributing is too difficult.
- beefsack 8y agoEven with the best intentions at heart, do you trust them not to accidentally leak sensitive information about you through their telemetry? There are so many places a "phone home" system could either be compromised, or accidentally send more than it should. Telemetry is used either with naivety or malice. There is always some risk to the user.
- pitaj 8y agoThe telemetry code is in the source. You can look at it yourself. It's anonymized.
- zabil 8y agoI agree. As someone who builds product (with opt in tracking) understanding users is key to building a good product.
- tjoff 8y agoAbsolutely, also it is amazing how little tracking does to understand users.
- paulcarroty 8y ago> tracking in VSCode is mainly used to improve the product. Not only, that's the main problem. And I can't simply trust it for company without dark M$ reputation and EEE experience.
- Vinnl 8y agoOne of the more flabbergasting comments I've seen is when Mozilla removed ALSA support from Firefox because nobody stepped up to maintain it, and the metrics showed that it wasn't widely used. There were people complaining about it being removed, and stating that the people who did use it were more likely to have turned off tracking, and thus did not show up. I mean, sure, it might be the case that there were indeed tens of thousands of ALSA users with tracking turned off, but... From my perspective, it seems more likely that it was just a handful, and really there's no way to tell the difference. If you turn off telemetry, and be aware of and accept the downsides. I trust Mozilla, so my telemetry is on, but for many other applications, I often opt to turn off tracking - with the understanding that it's harder for them to tell what my needs are.
- Nullabillity 8y agoSo now we need to allow surveillance, just to prevent the biased data set from ruining the software even more?
- Vinnl 8y agoNo, you don't need to do that, but if you don't, you should realise that that results in biased data, and thus influences the focus of development. If you have an alternative other than "the developers should just magically guess what would make users happy", then I'd be happy to hear it, but otherwise, that's just the way the world works, and thus that's the trade-off you will have to make.
- mmgutz 8y agoDoes anybody else get the sarcasm?
- antpls 8y agoAre the telemetry data made public? If it's not, then it could be manipulated to justify arbitrary decisions from MS
- GordonS 8y agoWhy would they make arbitrary decisions that run contrary to what the telemetry data shows? That just doesn't make sense.
- naikrovek 8y agoYeah, if you're going to just do what you want, you don't need to collect telemetry to do it.
- rum3 8y agoThis may be how they develop Skype hah.
- antpls 8y agoTo gain cheap trust from people by saying "trust us, the data shows it" I can think of two reasons for the data to be made public : - for trust and transparency purposes : It is for the same reason than an election system should be observable and reproducible, from data collection to final decision, including counting methods, etc. Otherwise it would be like "trust us, the data shows it" and you don't show the data to anyone to prove it. - for coordination and sharing knowledge : some people might interpret the data differently, chose to focus on a niche market by doing different bets than MS, and create a complementary editor to the one from MS. MS has no obligation to support minorities, but someone else might be interested, and those minorities are detectable in the data
- dschuetz 8y agoWait a minute, there is tracking involved in a code editor? No, it's not in anyone's best interest. It can't be. Any info collected with tracking could also be used for other, malign purposes, covertly and illegally. I understand your perspective, I wish it was true as a fact. But it isn't. What I've learned in the recent years - don't trust anything that tracks and collects data unless it's your own thing.
- jhall1468 8y agoThere's a pretty wide area between a skeptic and a conspiracy theorist, but this kind of mentality certainly leans toward the latter. Logic dictates it's vastly more likely the data collected is to improve the editor, than a multi-national multi-billion dollar company collecting data to use it illegally.
- dschuetz 8y agoNo, it's an issue of trust. I wasn't implying that Microsoft does such things. Such things could happen without them even knowing about it. With security in mind I just can't take the risk myself or expose my clients to such risks. VSCode is obviously a consumer product, not an enterprise solution, so I advise my clients to use more trustworthy software, without built-in tracking capability.
- fiblye 8y agoGoogle collects far more data than Microsoft does. They have zero problem processing it all. It’s not like it’s human sifting through it by hand.
- caprese 8y agoGreat-grandparent OP was most accurate in that this crowd cares most about privacy regardless of what it is used for, and that it would have little utility outside of this crowd, but your dismissive response is as if you've been in a coma for 10 years. As grandparent OP said, in recent years this has moved waaaaay beyond theory territory and been shown time and time again that <Corporate Sector> + NSA + FBI + CIA + intelligence agencies around the world all employ different ways of collecting analytical data broadcast over the internet. NSA just taps the servers without telling anyone. FBI sends National Security Letters containing gag orders preventing companies from telling you that the federal government is now a data sharing partner. CIA just pays companies for it. FISA court issues secret rulings justifying the legality of it all. Whether that bothers you or not is up to you. Most people don't care. I usually don't. I wouldn't say "logic dictates this won't happen" when it is pretty much only the multi-national multi-billion dollar companies subject to this kind of tampering, and most incentivized to monetize the analytics by allowing these and unknown third parties in. To avoid the security exhaustion, some people would simply prefer their text editor not be "smart", which is a euphemism for internet connected.
- tus87 8y agoSaid by no police state ever. This comment is straight out of 1984.
- progfix 8y ago> It's probably in my best interest, and the interest of the community as a whole to leave tracking on. I hope this is sarcasm. If not, what did I miss? This is the same empty phrase that facebook, google, etc. use. Why is Microsoft more trustworthy in that regard? I am 100% sure they use the data to make money in short terms or in a long run. They for sure use it to make VSCode better, but only to get more people use VSCode and make them dependent on it. VSCode is a prime example of the Embrace, Extend and Extinguish strategy. I already see them grasping for the Python community.
- fiblye 8y agoIt’s possible that MS only uses it for bug fixes. But it’s also known that MS shares data with the NSA and other government agencies. It’d be very unlikely that the NSA would say, “yes, we want your data, but not Visual Studio data. That’s private. :)”