4 ms·
I find it outrageous; "Telemetry" is built into most new Microsoft software. For example, they recently released a replacement for powershell and CMD, called "T
by cessor 6y ago
I find it outrageous; "Telemetry" is built into most new Microsoft software. For example, they recently released a replacement for powershell and CMD, called "Terminal 1.0", which also comes with some aggressive telemetry built in:
https://github.com/microsoft/terminal/blob/master/src/host/telemetry.cpp https://github.com/microsoft/terminal/blob/master/src/host/t...
This also applies to newer releases of powershell, aka PS Core. I haven't tried either, but I guarantee you telemetry in both applications is not opt-in but opt out using some obscure method, if that is even possible.
In any case, the claim that telemetry is necessary to improve anything related to customer experience is ridiculous. Not only is a general data collection unnecessary; it would be more efficient to run some experiments, and be it some opt in A/B tests. Surveillance like the above is encroaching and can easily be abused. The data collected are usually fine-grained enough to allow for some nice fingerprinting of individual users. The potential for abuse is high.
- justadudeama 6y agoMaybe I don't understand all the way, but I see this line of code in there: `TraceLoggingUInt32(_rguiTimesApiUsed[GetConsoleAliases], "GetConsoleAliases"),` Is that sending Microsoft all of my bash/zsh aliases? And what about `TraceLoggingUInt32(_rguiTimesApiUsed[GetConsoleTitle], "GetConsoleTitle"),` If it works how most other Terminals I have used - that is going to send the name of the program I am running or host I am connected to to Microsoft. I think that is pretty invasive if you ask me.
- DHowett 6y agoI dunno. The name "_rguiTimesApiUsed" (and that it's a "uint32") suggests that it's a count of times an API was used, not the raw data that went through that API. EDIT: I put together a list of what happens in this file in a sibling comment.
- DHowett 6y agoI'm just gonna recycle the bits I've posted here before about this exact file :) [1] https://news.ycombinator.com/item?id=22331345 https://news.ycombinator.com/item?id=22331345 [2] https://news.ycombinator.com/item?id=19322398 https://news.ycombinator.com/item?id=19322398, https://news.ycombinator.com/item?id=19324538 https://news.ycombinator.com/item?id=19324538 The file you've identified produces a local, opt-in event stream that does not leave your machine unless you literally e-mail it to me. It's just got that unfortunate word in the filename that means we're bad guys. EDIT, upon closer inspection: when this is built as part of the Windows product (which consumes source from this repository) those values may end up in an event stream. In the interest of full disclosure, those events are: 1. Part of the console host (conhost.exe) and covered by the Windows global data collection settings 2. Pertaining to (incomplete, but it's too early in the morning for me to do a full review of this code): 2.a. The number of times each low-level console API was used 2.b. How the legacy Find dialog is being used (long strings, short strings, search direction, number of times) 2.c. Specific settings like font size, how many colors are configured, how big the window and buffer are
- saagarjha 6y agoI should put a disclaimer at the top of this saying that I'm just a regular old Hacker News commenter who skimmed that file and really has no idea what this code actually does, so I'm not trying to scaremonger because I saw something sketchy without following up on it. However, that file seems indicate that Terminal logs process connections. Is there a way that this information might leave the device? Could it include arbitrary processes on my system in that data?
- DHowett 6y agoNow that I'm at my desk, I'll have a look. Thanks for the disclaimer :)
- DHowett 6y agoAlright, with fresh eyes: When the console host (just C:\windows\system32\conhost.exe, not the new Terminal) exits it emits the following information for processes that had connected to it: * How many ANSI/VT sequences they used * How many of the above we understood * How many of them we did not understand * The executable stem name (ConsoleApplication1.exe, wsl.exe, cmd.exe) * How many times we saw that executable ~1-5% of those entries make it into a data pipeline that I believe we stopped looking years ago. These pipelines are usually(?) turned off by the OS, so it's possible that these were rendered inert. Still, though, and because the executable stem name might be a little more exposure than anyone's comfortable with, I've filed https://github.com/microsoft/terminal/issues/6103 https://github.com/microsoft/terminal/issues/6103 to yoink it. (It's been a long time and I still don't know how to format things properly on Hacker News :))
- nickjj 6y agoMonths ago I opened an issue on GitHub asking them if we could get an option to disable / toggle telemetry at https://github.com/microsoft/terminal/issues/5331 https://github.com/microsoft/terminal/issues/5331. It seemed reasonable considering VSCode is also a Microsoft product with an explicit telemetry option that you can opt out of. Within 15 minutes the issue was closed and the idea of adding a telemetry option was dismissed by a contributor. Kind of scary to use something so integral to your day to day as a developer is having that much data being sent out to Microsoft. It's partly why I stick with wsltty (which is equally as fast and has no telemetry).
- nickjj 6y agoIt's too late to edit my original post but since I posted this, a contributor added more comments to the issue. It turns out that as long as you have Basic telemetry settings in Windows then the Terminal app doesn't send anything out to Microsoft by default. This comment goes into more details on what is exactly collected and sent to Microsoft if you use "Enhanced" telemetry (which you don't need to use): https://github.com/microsoft/terminal/issues/5331#issuecomment-632393919 https://github.com/microsoft/terminal/issues/5331#issuecomme...
- waynesonfire 6y agoTelemetry is also built into every web application you interact with. The lessons learned in this space are shifting to non-browser based applications it seems. Sucks.