4 ms·
Well the problem is the privacy bait and switch isn't it? When you install a compiler who's respecting your privacy, and without opt in it starts sending telem
by philprx 4y ago
Well the problem is the privacy bait and switch isn't it?
When you install a compiler who's respecting your privacy, and without opt in it starts sending telemetry, you can't expect that to go well.
Now naming people like this isn't going to help either I think.
- growse 4y ago> When you install a compiler who's respecting your privacy, and without opt in it starts sending telemetry, you can't expect that to go well. Are the currently deployed and used versions of the go compiler going to suddenly start sending telemetry? Or is it just a future version that someone would have to deliberately upgrade to? Personally, when a new version of golang comes out, I like to read the release notes and then adjust my build environments with the necessary environment changes for the new features.
- nishs 4y agoreading release notes for upgrades is the only correct way. regardless i think we should hold open source projects to higher standards, such that telemetry isn’t introduced by default.
- alkonaut 4y ago> Well the problem is the privacy bait and switch isn't it? What is the privacy bait and switch? The whole idea behind "anonymous usage statistics" is that it's statistical and anonymous, so that it by definition has no privacy consequences. If that doesn't hold up (e.g. it leaks a username, a path, anything) then there should be outrage. But this discussion isn't about that. Or about the fact that it could be worse, or have a bug. The interesting question is: is it acceptable to have telemetry that is anonymous and statistical? And if not - why? The argument "it doesn't respect my privacy" can't apply then.
- philprx 4y agoDeconstruction of anonymity is an academic and agencies proven success. It can be called anonymous when it goes through TOR to be sent, etc… which is not even considered afaik. If you rely on the receiving party to not store your IP and other sent details, then it’s not anonymous. Sadly, some companies get evil, get compromised or get internal threats… And yeah, opt-in is minimum or the software is called a spyware. And yes, with this definition recent Windows is a spyware. If you want an argument about privacy, watch the insightful talk by Halvar Flake on security vs. death squads… chilling but sadly true.
- alkonaut 4y agoIf we disregard a small command line utility and look at a larger software package, so that it already does network connections (or won't function) then the key thing is TRUST. That can be achieved by organizational transparency, open protocols, open source. It's hard and slow to build and easy to tear down. But if you use the software, you trust the provider. The simplest argument for this is: if you don't trust the provider then why on earth would you trust that the "no" actually means no!? The compromised or evil organization would send your data anyway. And if they are really evil they wouldn't do it as part of the telemetry they'd just exfiltrate it in whatever way necessary. That's why I think the telemetry thing is a much smaller issue than it seems when it comes to privacy. It's already blind faith.