7 ms·
Can anyone explain to me why I should be concerned about vs code telemetry? I have zero personal information in the IDE and all the code I work on is already in
by cachestash 6y ago
Can anyone explain to me why I should be concerned about vs code telemetry? I have zero personal information in the IDE and all the code I work on is already in the public domain with an open source license, so why should I care?
- nightowl_games 6y agoI value silence in my network traffic.
- DoingIsLearning 6y agoIt's interesting, if we look at the size of webpages in everyday browsing, which can go from tens of megabytes to a few kilobytes when blocking tracking/analytics scripts. I wonder what would be the back of the napkin calculations for network traffic and energy savings (local and server side) of regulating tracking and telemetry? Is there an environmental case to be made against modern web practices on tracking and telemetry?
- luckylion 6y agoI've really come to dislike Google over the past decade or so, but I do like that their Speedtests, Lighthouse etc don't hide this fact from you. Pretty much all sites I've been asked to look at were getting low scores because of Google Tag Manager, Adsense and the like. It has a very measurable impact, and yeah, removing it speeds up the page. The environmental case will probably not fly for regulation, but it just might in public shaming of large companies. "Hey, $company, your usage of $trackingTech uses as much power per year as an average family of four. Is that really in line with your green approach?"
- gdmka 6y agoThank you! This is exactly one of the reasoning pillars i'm using in arguments about the "innocuous" nature of telemetry and tracking. Any new product that collects telemetry/does tracking requires storage that is bought and connected to a power source with high availability given it performs I/O all the time.
- oaiey 6y agoI agree to that. I also do not care too much about the telemetry, but silence (on the network not the telemetry) should be the default.
- 0x0 6y agoBecause maybe developers in your bank or hospital are using IDEs with nasty telemetry that might expose data on you? Maybe they are editing a branch called "workaround-for-mr-cachestash-bankrupcy-account-bug"?
- aspyct 6y agoNever say never, but still, this is super unlikely and not at all what telemetry is. They report on things like button usage, time spent in app etc. Possibly personal information about the developer, although unlikely. But your code? No no, they're probably not looking at your buggy code...
- Xelbair 6y agoand how do you know that? did you check the source? oh wait..
- aspyct 6y agoAnd how exactly do you think they would look at all the source code in the world? Humans are too expensive. So probably AI. How would AI tell the difference between valuable banking software full of bugs and your side project full of bugs? Also from there, why would you include a customer's personal information in your code, or even have it on your own machine? Really, the chances of vscode's telemetry leaking personal user information is super extra low, unless you're obviously doing something wrong with your code. Ah, and finally, if you're using github, they have a much more efficient way of getting your code anyway.
- 0x0 6y agoMicrosoft has been known to do things like log all command line arguments in dotnet, for example https://docs.microsoft.com/en-us/dotnet/core/tools/telemetry https://docs.microsoft.com/en-us/dotnet/core/tools/telemetry And then they post the results publicly. https://devblogs.microsoft.com/dotnet/what-weve-learned-from-net-core-sdk-telemetry/ https://devblogs.microsoft.com/dotnet/what-weve-learned-from...
- sneak 6y agoTelemetry tells your ISP and national military your usage patterns, too. When, where, and how often you use the tools is itself private. Imagine a private journal that reported to the government every time you wrote in it, and what city you were in when you did so. Furthermore, VS Code is specialized software. Using it in certain places allows a specific user to be tracked and identified out of millions of more "normal" traffic patterns, as developers are still a tiny minority in society.
- robalni 6y agoHow right or wrong it is to collect information about people and what they do is not entirely determined by how much personal information there is to get. Just like how right or wrong it is to break into someones house is not entirely determined by what they take, or how much personal information you have in your house. But yes, if you don't have anything valuable in your house, maybe you don't need to be concerned about people breaking in, but that doesn't make it more right.
- stinos 6y agoSuch analogies really depend on what the telemetry contains (granted, I don't know in this case). I.e. you describe it as stealing from inside the house. Say, VSCode figuring out your email adress and reporting it. But it might as well actually be pretty anonymous non-personal data i.e. more like looking at the outside of a house and taking note of that. Say, VSCode reporting the theme you use, and just that.
- robalni 6y agoMy point is that it's not just what information is being taken that matters. Even if you don't take anything it's still wrong to do things inside someone's computer or home without permission. Maybe VS Code asks for permission properly and gives the user sufficient control and has good defaults, I don't know, but it's difficult to do that properly because people don't understand computers as well as they understand the rest of life.
- ulisesrmzroche 6y agoThis (Vscode) is a product for developers, so are you saying that if you use VScode you don’t understand computers? That’s very arrogant of you
- robalni 6y agoBy "computers" I really meant "the complexity in the software that computers run". Computers do very complex things and most of those things can't be directly seen. So if you want to tell someone about what some software is doing, it's not always easy.
- Nextgrid 6y agoBecause some other people might be working with code that is not in the public domain, or code whose mere existence should be kept hidden (so even relatively innocent things like project, file or branch names should be kept secret)? I personally prefer tools that don't spy on me. In 99% of cases I probably won't care, but I don't want to take the chance of the 1% where a telemetry request would send out something I'd rather keep private which is why I want tools that are private by design. My screwdriver doesn't spy on me and report what kinds of screws I use it with, the hammer doesn't either, I want my text editor to behave in the same safe and predictable manner.
- The_Colonel 6y agoAs an application developer it's quite frustrating to be left completely in the dark about how people actually use my applications. All I can do is guess. Those guesses are most probably incorrect and the app won't be as good as it could. Just a simple button click heat map would be very useful info to have. But then sending click heat map is the same thing as stealing credit card info in the minds of many ...
- Nextgrid 6y ago> to be left completely in the dark about how people actually use my applications You don't have to be left in the dark. You can ask people for feedback (yes that used to be a thing) or run user testing sessions (yes that used to be a thing too but seemingly not anymore when we look at the quality of modern software). > the app won't be as good as it could I have yet to see any evidence that telemetry improves software quality enough to warrant the privacy trade-off. If there is a correlation it seems to be opposed; telemetry started becoming popular in the last decade, and the last decade is also the time around which software started declining in quality or usability (see Windows 8+, certain changes to macOS and iOS, bloated or user-hostile websites, etc). > Just a simple button click heat map would be very useful info to have. That heatmap thing will also at least leak my IP address, software version and a persistent UID that will allow the backend server (whether self-hosted, or powered by a nasty ad-tech company like Google analytics) to keep a log of my IP changes and usage patterns.
- chii 6y ago> Can anyone explain to me why I should be concerned about vs code telemetry? why do you close the door when you go to the toilets? It's not like what you do in there is really not known.
- mekster 6y agoBecause it makes others uncomfortable if you don't. Wrong analogy.
- thinkingemote 6y agoIf you have nothing to hide you have nothing to fear.
- mekster 6y agoGoogle/Apple maps where you live and go, Facebook knows who you deal with, Microsoft knows how you use your computer and Amazon knows what you buy. It's ok if you're a boring type for your whole life.
- gdmka 6y ago>>I have zero personal information in the IDE and all the code I work on is already in the public domain with an open source license, so why should I care? Off the top of my head: API tokens and other credentials that live right in the file while you develop and debug. Those are quite sensitive. To put more wight on the issue[0] [0] https://medium.com/@stestagg/stealing-secrets-from-developers-using-websockets-254f98d577a0 https://medium.com/@stestagg/stealing-secrets-from-developer...
- mekster 6y agoSince when does the telemetry even send out any contents of any files? That's called stealing not telemetry.
- gdmka 6y ago>> Since when does the telemetry even send out any contents of any files? To me it's not evident otherwise until i'm capable of observing bare data itself. Not obfuscated, not in some proprietary format to secure it in-transport but the raw stuff. MS states there's no reliable way to let people see the data being collected (even under GDPR) as there's no sing-in experience provided.[0] While a part of the statement is true, most of privacy conscious VSC users aware that every installation of the product has a unique `machineId` property. Can be located at Output -> Log (Shared). The [0] provides some elaboration: "We do send information that helps us approximate a single user for diagnostic purposes (this is based on a hash of the network adapter NIC) but this is not guaranteed to be unique. For example, virtual machines (VMs) often rotate NIC IDs or allocate from a pool. This technique is sufficient to help us when working through problems, but it is not reliable enough for us to 'provide your data'." So, given the premise the user can be identified by a NIC plus a machineId (which looks to be an UUID) — it's easy to get access to collected data. As soon as ability to verify no really critical data is collected, i'll switch back from VSCodium. [0]https://code.visualstudio.com/docs/getstarted/telemetry https://code.visualstudio.com/docs/getstarted/telemetry
- Silhouette 6y agoSince when does the telemetry even send out any contents of any files? Since pretty much forever? At the very least, many programs with built-in telemetry have included things like memory dumps of key areas at the time of a crash, which could include data the user was working on at the time. More seriously, I invite you to read Microsoft's extensive privacy policies and try to satisfy yourself that they don't grant themselves the right to upload your code. They are sufficiently nebulous and ambiguous that they could probably be interpreted that way.
- teddyh 6y agoThe Eternal Value of Privacy https://www.wired.com/2006/05/the-eternal-value-of-privacy/ https://www.wired.com/2006/05/the-eternal-value-of-privacy/
- heyoo 6y agoI choose to trust MS are using the telemetry for improving VS Code, which I genuinely love, and accept the "risk" that MS somehow abuses the telemetry. I see this risk way lower than e.g. Google or Facebook abusing data they can collect about me.
- riejo 6y agoFYI, to see what's being send do this: "F1 > Log Level > Trace" and then "View > Output > Log (Telemetry)"