5 ms·
What you are stating is incorrect. Each of the calls you link to sets a boolean here: https://github.com/microsoft/terminal/blob/57c3953aca49f68acc480ca27533fd
by Genbox 4y ago
What you are stating is incorrect.
Each of the calls you link to sets a boolean here: https://github.com/microsoft/terminal/blob/57c3953aca49f68acc480ca27533fdc7aad78b43/src/host/telemetry.cpp#L24-L55 https://github.com/microsoft/terminal/blob/57c3953aca49f68ac...
It does not transmit what you copy, search for or when you clicked/resized/closed the window. It simply stores a true/false value saying "feature X was used". In some cases, like with find/replace, it also stores the average length of things you searched for. That is a common way for developers to get an idea if performance characteristics due to the longest common substring problem[1]
You are trying to spread misinformation here to make Microsoft look like a bad guy. There is nothing sinister going on here, it is just ordinary metric collection.
But don't take my word for it. Take for example the "we can see it log every time you resize a console window" statement. In the link it calls SetWindowSizeChanged()[2] which again calls SetUserInteractive()[3] and it just sets a boolean to true.
So there is no "log every time it resize a console window". It simply sets a variable to true, which presumably the Windows Terminal dev team use to see how many users use the console with interactive sessions.
[1] https://en.wikipedia.org/wiki/Longest_common_substring_problem https://en.wikipedia.org/wiki/Longest_common_substring_probl...
[2] https://github.com/microsoft/terminal/blob/57c3953aca49f68acc480ca27533fdc7aad78b43/src/host/telemetry.cpp#L137 https://github.com/microsoft/terminal/blob/57c3953aca49f68ac...
[3] https://github.com/microsoft/terminal/blob/57c3953aca49f68acc480ca27533fdc7aad78b43/src/host/telemetry.cpp#L71 https://github.com/microsoft/terminal/blob/57c3953aca49f68ac...
- jiggawatts 4y agoEvery group implements their own telemetry. Every group goes through the same “learning process” of making it asynchronous and correctly dealing with proxies, firewalls, etc… Inevitably mistakes are made that either slow down computers or outright freeze apps that can’t connect to some telemetry endpoint. Security teams around the world feel like they’re holding back the tide with a broom because EVERY piece of software is contributing to a veritable firehouse of information sprayed all over the Internet from every endpoint on the network. This is not okay. It’s not Microsoft’s computer. It’s not their network. It’s not their data. How is this not clear? How can you be so apologetic?
- what-the-grump 4y agoJust FUD? You are running an operating system made by Microsoft, they could monitor how often you click your mouse just like every website on the planet at this point but dont. Boolean telemetry on feature use is somehow the end of the world? Get out.
- jiggawatts 4y agoLook at it this way: PowerShell sends telemetry. The Terminal in which it runs sends Telemetry. The "dotnet core" framework PowerShell uses in turn also sends telemetry. The PowerShell modules you load (from Microsoft!) send telemetry. In effect, ONE application has at least four independent sets of telemetry. This is the console, the kind that you would use on servers. High-security servers in DMZs. Servers hosting police records, health records, or even military secrets. FUD my arse. It's a torrent of information that seeks every crack it can find to "get out", purposefully designed to circumvent mitigations by security teams. Two examples: Microsoft regularly changes which environment variables disable telemetry. Just about every major release means that I have to check if it is now "DOTNET_TELEMETRY=Off" or "NET_TELEMETRY_CORE=0" or whatever. This isn't an accident. Nobody's "finger slipped". The old telemetry started to tail off and someone "fixed it" in Microsoft to get 100% coverage, against the will of their privacy concious customers. Similarly, some Windows telemetry uses "microsft.com" instead of "microsoft.com" to bypess firewall rules blocking the latter. You can't tell me that this is "nothing to worry about" when it feels an awful lot like the enemy is inside the gates and is actively hostile to any measures taken to stop them progressing further into the network.
- majkinetor 4y agoTelemetry is essential thing to understand how service is used. It leads to better service for all users. In the case you mention, it should be IMO up to you to prevent this, probably via firewall. Having standard telemetry environment variable might be for the best. There is a risk in this case to disable telemetry systematically though, even if you want to just block it in one app, which is also not something I as vendor of many tools would want. This is probably not easy to fix for everybody to be happy. And its probably not that important for security - there are FAR easier way to deduce something about someone then to 1) hack microsoft telemetry servers or transit 2) look into the patterns of use of specific programs. Besides, telemetry data is anonymous. So I guess even in the case you get the data, what could you do with it ? I can send you billion of telemetry data of government services I make, you can only deduce that people start working at 7AM and get lots of passwords wrong before first coffee.