5 ms·
> OSS should have opt-in error reporting only. I'm curious what's different about OSS in this regard? I thought this was an argument about the user's privacy,
by Griffinsauce 5y ago
> OSS should have opt-in error reporting only.
I'm curious what's different about OSS in this regard?
I thought this was an argument about the user's privacy, so what does it matter how the software was built?
Also a sidenote: this whole thread feels quite pedantic and counterproductive to me. Sentry is an error reporting tool that helps solve issues in software, the alternative is your software having many, many more bugs that never get fixed. It's not used for tracking or "spying".
I feel that blowing your stack about a tool like this weakens your argument against true privacy invasions. It trains people to stop listening because we whine about things that are not actually a problem.
- dgan 5y agoWhen you need to report errors from offline product, you create a dump file, zip it, and ask user to send it if he wants the problem investigated File creation can be done automatically as a segfault handler for example
- yarcob 5y agoI have some experience developing desktop apps. Less than 1% of crashes are reported by users. And only around 50% of users who do report a bug will provide follow up info such as crash reports or diagnostic information. Before I had automatic crash reporting, I was blissfully unaware how bad my app was.
- dgan 5y agoWell what you said is correct, but there is a difference between a commercial product, and free software I would expect users to care more about the latter. For example, I am specifically talking about open source games, where often users report errors with zipped stacktrace attached
- duckmysick 5y agoIn my experience it's the other way around - but the difference is not that big anyway. Commercial programs typically imply paid support, which can tease out more details when the user contacts them. The users themselves are also more invested, as they already committed their money. Open source software faces the same problems about a lack of bug reports. Check out this article and the related HN discussion: https://pointersgonewild.com/2019/11/02/they-might-never-tell-you-its-broken/ https://pointersgonewild.com/2019/11/02/they-might-never-tel... https://news.ycombinator.com/item?id=21427996 https://news.ycombinator.com/item?id=21427996
- yarcob 5y agoYes, there are some users that are really helpful. I also thought that my users are great at reporting bugs. But when I added an automatic crash reporter, I was shocked how many crashes happened that nobody bothered to report. Maybe 1 in 10 crashing bugs was reported at all. A serious bug that made the app all but unusable was reported by 2 or 3 people (out of at least 100 people who were affected before I pulled the broken update).
- duckmysick 5y agoWhy should users go out of their way to fix something that wasn't their fault?
- dgan 5y agoBecause they actually care about a program?
- skybrian 5y agoOften they don’t because they are running hundreds of programs and don’t particularly care about this one. Not everything is a high-profile app that a lot of people pay attention to.
- duckmysick 5y agoMost users actually don't care about the particular program itself. They care about the problem said program claims to solve. If the program gets in the way, they get frustrated and they may even move on. Only a fraction of users will voluntarily report bugs. Even less will do it in a meaningful and detailed way.
- Griffinsauce 5y agoThis is truly the core problem here. Nearly all users are about solving a problem, not about the method. So we can philosophize all we want here about the "correct" way but if it simply does not manifest that way in practice it's all moot.
- gorgoiler 5y agoIf you don’t know the history: most open source software is freely available and built as a community effort by volunteers. FOSS has, by necessity, had a strong liberal culture from the outset. The genesis of many projects has been about sticking it to the man and winning back the freedoms taken away by big companies, especially hardware manufacturers. I’ll pay you to build me a minicomputer, but I’m damned if I’m letting you dictate what I can and can’t do with it. Telemetry is about gathering data and sending it to a single place. Having a central focus point of potentially personally identifying information, controlled by one entity more privileged than the others, is anathema to the idea of many of traditional open source projects.
- perl4ever 5y ago>a strong liberal culture Are you American? I would have said (small-l) "libertarian" not "liberal" in the American sense. For better or worse.
- aksss 5y ago“Liberal” today basically is the man. The word in American politics is associated with very illiberal policies, ironically.
- duckmysick 5y ago> The genesis of many projects has been about sticking it to the man and winning back the freedoms taken away by big companies I'm not sure it's working as intended. The current trend is for big companies to take FOSS, put it on a server, and run it as a service with extra quality-of-life trinkets on top - like GitHub or AWS.
- Griffinsauce 5y ago> Telemetry is about gathering data and sending it to a single place. Having a central focus point of potentially personally identifying information, controlled by one entity more privileged than the others, is anathema to the idea of many of traditional open source projects. This is the most clear eyed description I've seen yet, thanks. I guess my angle is not that of a FOSS developer but a regular user out in the world who has to get shit done. Most people (rightly, in that context) do not care about this one iota. This kind of absolutism limits the reach of the software, preventing it from reaching the stated goal of "sticking it to the man and winning back the freedoms taken away by big companies".
- javajosh 5y agoI will assume your questions are in good faith. OSS is code is generally made by unpaid volunteers. There may be some operational effort behind it, too, in terms of building and distributing binaries. But gathering remote telemetry is NOT typically something I would expect to be part of typical project operations. After all, who is gathering the data? What is the organization, what is the locus of control? That's easy to answer for a business, but hard for an OSS project. The "telemetry" mechanism I have come to expect from OSS is the "bug report", where telemetry will be produced explicitly by me. I understand exactly what this means, what the data is, and why it's being collected. Moreover, I have expectations about how it will (and will not) be used (although, now that I think about it, I think those expectations need to be examined. I can see how bad actors could be using the data in these bug trackers for nefarious ends!) This is a material privacy invasion because it violates the norms around what we expect from our software. I don't expect Audacity to phone home, and I don't expect the entity that distributes binaries to include functionality designed to satisfy the Russian government's need for data, for example. The fact that Audacity is used to gather and process sound data makes this particularly concerning, as this can be very sensitive data, and they are clearly serving more than one master here. Hope that clears it up.
- gentleman11 5y agoIs that still true? Iirc, most contributions to the notable foss projects I know about are industry sponsored, whether by companies or trade organizations
- the_other 5y agoI think at this point it's clear we need to stop calling those OSS, and instead call them "volunteer-developed" (or some other euphemism for the owner externalising the cost of dev and test).
- jfrunyon 5y agoI'm not sure what you're getting at. Do you think that most not-hobby FOSS projects are somehow 'profiteered' by freeloading companies who own them but don't invest any time or labor into them?