6 ms·
That's because this tool has nothing to do with "spying on users". It's a set of tools and a specification for instrumenting applications and collecting logs/m
by sveiss 5y ago
That's because this tool has nothing to do with "spying on users".
It's a set of tools and a specification for instrumenting applications and collecting logs/metrics/traces from them. It's used to ask questions like "why is this page slow to load?" and get answers like "because it talks to the billing microservice which has a really slow SQL query".
This isn't the same sort of telemetry that desktop software vendors collect.
- dmitrygr 5y agoSadly, it seems you are wrong: https://opentelemetry.io/docs/js/ https://opentelemetry.io/docs/js/ "the browser" That means they are running code on my machine and exfiltrating data out.
- rad_gruchalski 5y agoDefine “they”, please.
- robbedpeter 5y agoThey as in "they" who are receiving the data being collected about the user. It isn't hard to see who the bad guys are. If this is implemented in a totally transparent, user controlled, consensual way, and the collected data made ephemeral and subject to user request for deletion and viewing on demand while being stored, then there's nothing bad going on. Anything less is unacceptable - a line is being crossed. Right now a majority of the encounters users have with telemetry is totally opaque and behind the scenes, nonconsensual except for the barest shreds of a EULA or button click fig leaf.
- haswell 5y ago> "they" who are receiving the data being collected about the user I'm curious why you automatically assume data is being collected about the user? OpenTelemetry is about Observability, not user tracking.
- robbedpeter 5y agoIf you're collecting data from software running on someone's device, that's someone else's user data. I think the term of art is metadata. In some ways, such information is just as important as biometrics and passwords and pii. Deanonymizing becomes possible when metadata is cross-referenced. Metadata should be subject to as strict protection and consent rules as documents, health info, or any other "obvious" private data. If it's running on your server and not logging third party activity or metadata, the information belongs to you. Else, you need the third party's consent, etc. "It's just for benign development purposes" doesn't cut it anymore regardless of intentions. We need a cultural and legal area change with regards to privacy and primacy of private data protections.
- bastijn 5y agoNOFI, just to understand if we talk the same thing here, you mean to say that a trace that traces the time it took the product you use to do a query that goes through three different backend services is private data that is owned by you and can only be collected by your consent. Not so much because you are against collecting that information, you may very well accept it to be collected, but because technically the data is collected from your premises and under your usage and thus requires consent as it would otherwise not be generated if not for you. To protect your rights in situations where the data collected would be less harmless, the rules must be strictly enforced. Correct?
- robbedpeter 5y agoProtecting privacy and preventing the weaponization of private data is critically important. Recognizing what constitutes private data seems to be the difficult thing, so I'm trying to clarify it. I understand it seems extreme, but it's really not. Any data generated by or on a user's device is private data. Recording that data is surveillance. No matter how harmless it might seem, data collection should be consensual, transparent, and ephemeral. You should specify, explain, and obtain consent for any and every variable. Anything you do with the data should be reportable to the user. Anything less creates opportunities for abuse. Logging ip address connections is a great example. It's simple and trivial but how many RIAA piracy lawsuits do we have to see inflicted on innocents before we decide keeping those logs might not be a great idea? The misuse of metadata by law enforcement through plausible narrative crafting is ubiquitous. It's not about the developer's intentions, it's about collection of surveillance records that can be seized or stolen and weaponized.
- phillipcarter 5y agoI feel like this is sort of a "you reposted in the wrong neighborhood" moment. OpenTelemetry is a vendor-neutral framework and standard for generating performance data (spans, metrics, logs) about systems, particularly distributed ones where it's impossible to just load up a debugger to figure out why something is failing or slow. It's not a framework for collecting user data. User data and performance data are completely separate things. Your concerns about privacy are important, but not really relevant to the topic.
- FateOfNations 5y agoThe developer of the web app... who is already running all sorts of other code in your browser.
- rad_gruchalski 5y agoSure. Like any JavaScript. As long as the provider of the service is transparent about what is collected, what’s the problem? There’s nothing preventing a system provider from making this collection opt-in. What’s with the assumption that the service provider cannot observe how their system performs?
- marginalia_nu 5y agoIf you are invited to a dinner, you aren't entitled to eating all the food yourself because the hosts put it on the table, you aren't allowed to do anything you feel like in your host's home, use their toothbrush, drill holes in their walls. In a similar way, your software is borrowing time and computing resources from your users. You need to use them sparingly and respect that you do not own their hardware, but are a guest they have invited in. It's not your computer to do whatever you want with.
- haswell 5y agoThis response really strikes me as throwing the baby out with the bath water. The OpenTelemetry project is focused on Observability use cases and not user analytics/tracking/etc. The fact that of all the libraries, a JS browser library exists doesn't automatically mean the parent comment is "wrong". I suggest anyone making snap judgements about OpenTelemetry spend a few minutes reading more about the project. This general pattern of comments surfaces every time this project is posted here.
- deleted 5y ago[deleted]
- jeffbee 5y agoPerhaps you will be surprised to learn that your web browser sends requests all over the place.