4 ms·
I don't understand the almost religious opposition to the telemetry the Go team are proposing. It involves no PII data, would be easy to disable for those who w
by room271 4y ago
I don't understand the almost religious opposition to the telemetry the Go team are proposing. It involves no PII data, would be easy to disable for those who want to do so, is minimal in scope, and the use cases are well articulated.
- deleted 4y ago[deleted]
- daneel_w 4y agoIt doesn't have to involve PII data to be invasive. The heuristics applicable can be used to, in a roundabout way, fingerprint the type of software. And since it's being shipped to Google through the Internet they also know where the software is being developed and where it's being used. And this is just for starters. Once they've tackled the hurdles of people's resistance; having one foot through the door; it's easier to slide more and more telemetry functionality in. You may recognize this behavioral pattern from, uh, well, almost all of their other products.
- vorpalhex 4y agoIt only takes them screwing up once for them to send my PII data. "Oops, we accidentally included ~.ssh"
- titaniczero 4y agoObjectively speaking, how valuable would that information be if it were to be leaked? Random weekly aggregated and sampled machine data associated to random IPs that in most cases would no longer be yours (and that’s in the worst case that both servers were compromised or misused by an employee during a specific time window, because IP is not stored in the analytics server but temporally in a proxy to prevent abuse). I don’t know, I’m all for privacy but people get passionate too easily the moment someone even mentions the word telemetry and I think we should focus on actual privacy issues, like analytics in the context of ads, social networks (tiktok, fb, ig…), etc.
- jeroenhd 4y agoData collection always starts out like that. An independent company may get away with that approach. However, this is Google. The problem is, we've seen it all before. When Microsoft added telemetry to dotnet, they stated the following: > The feature collects the following pieces of data: > > The command being used (e.g. “build”, “restore”) > The ExitCode of the command > For test projects, the test runner being used > The timestamp of invocation > The framework used > Whether runtime IDs are present in the “runtimes” node > The CLI version being used > > The feature will not collect any personal data, such as usernames or emails. It will not scan your code and not extract any project-level data that can be considered sensitive, such as name, repo or author (if you set those in your project.json). We want to know how the tools are used, not what you are using the tools to build. If you find sensitive data being collected, that’s a bug. Please file an issue and it will be fixed. All very useful information that doesn't tell them anything about you or your machine. Since then, Microsoft has been steadily increasing the amount of data it's been collecting, including personal identifiable information in the form of a pseudonym based on unique machine identifiers. Once data collection starts, it only ever gets worse.
- deleted 4y ago[deleted]
- mindslight 4y ago"PII" is often a straw man based on a few narrow categories defined by corporate interests. I consider IP addresses and what code I'm working with much more personal and sensitive than say the association between my name and my social security number.
- yamtaddle 4y agoDoesn't matter, someone looking over your shoulder while you're using your own machine, without asking first, is spyware. Period. Doesn't matter a bit what they're collecting.