5 ms·
Telemetry by default should be illegal. They should be required to obtain owner permission.
by Crontab 3y ago
Telemetry by default should be illegal. They should be required to obtain owner permission.
- antoineMoPa 3y agoThat would make any site using mixpanel/google analytics/sentry/etc. illegal. Not so easy to enforce.
- Aerroon 3y agoBut these are two very different scenarios though. When I use a website I'm actively interacting with that website. I want something from their web servers. When I'm using an Nvidia graphics card I'm not actively looking to use their web services. I want the graphics card that I bought to work and that's it. The graphics card doesn't improve as a device by connecting to the internet.
- antoineMoPa 3y agoBut metrics could help nvidia fix issues and add features in the next driver update? I'm mostly playing devil's advocate here, what I truly think is that all monitoring and analytics should require user approval a bit like cookies. E.g.: you visit a website and it would ask for permission to send monitoring data to listed sites.
- unethical_ban 3y agoPerhaps they meant locally installed software. And EU has tried making sites classify and ask for permission for cookie storage. And maybe mixpanel and Google and cross site tracking should be opt-in for users.
- danaris 3y agoAnd wouldn't that be a terrible shame.
- TheRoque 3y agoTrue. I'm surprised this doesn't go against GDPR.
- zerkten 3y agoYou don't understand the GDPR then. The focus is on controlling where data goes (not out of the EU), but your point is about telemetry in general. If you keep the data inside the EU and manage it in a way that's compliant with the GDPR then then that telemetry doesn't put you in jeopardy. If you want to be protected for telemetry then you need to advocate for better legislation. Stating that something is covered by the GDPR ultimately masks the issue because it's not against the GDPR and you lose an opportunity to advocate for better legislation to reduce, or kill telemetry.
- TheRoque 3y agoGDPR is not only about where the data goes, it's also about asking for the user explicit consent for their data collection [0], this is what I was referring to. Not the telemetry collection. I just thought it worked for other stuff than cookies. https://www.privacyaffairs.com/cookie-consent/ https://www.privacyaffairs.com/cookie-consent/
- bootsmann 3y agoCollecting data is not against GDPR. GDPR is about consent, processes etc. Whether or not this is compliant depends on the way their installer is set up.
- nicbou 3y agoAs far as I know, it is required.
- patrakov 3y agoThe question here is not telemetry itself, but the infinite over-reach in what data is collected. Categorized websites have nothing to do with driver crashes or performance issues.
- JohnFen 3y agoIt's also about telemetry itself. That this telemetry is obviously overly expansive just increases how objectionable the practice is.
- MereInterest 3y agoAnd not just “permission” as a mandatory click-through, but freely-given permission. The permission may not be bundled with any other agreement, and the product must remain usable regardless of the telemetry settings.
- JohnFen 3y agoThis is why I prefer "informed consent" over "permission". And even "informed consent" is redundant, as it's not possible to provide real consent if you're not fully informed about what you're being asked to consent to.
- sirius87 3y agoI wish we could all pool money and buyout politicians in some tiny corner of the globe to pass laws that made all telemetry illegal for any device that entered their geography and allowed hefty fines for even basic data collection.
- LeoPanthera 3y ago> Telemetry by default should be illegal. Is it not?
- hunson_abadeer 3y agoI'm not aware of any laws in the US or in Europe that generically prevent "phoning home". There are laws that limit your ability to collect certain types of sensitive information without some quasi-meaningful user consent, but most telemetry goes around this by notionally not collecting PII. The gotcha is that in practice, most companies don't put a whole lot of effort into making sure there's no incidental PII in the telemetry, and no other way to infer who you are. Browsers automatically collect crash reports that, for a good while, might have contained your cookies, URLs, and other goodies in the logs or memory dumps... cars collect "anonymized" telemetry that shows you driving from your single-family home to wherever you're headed... etc.
- Nextgrid 3y ago> but most telemetry goes around this by notionally not collecting PII. The problem is that an IP address is considered PII and is inherently sent in any HTTP request, so you could argue that any non-essential request to any third-party should be opt-in since it contains PII.
- rrobukef 3y agoUnless you have a contract stating the non-collection of PII, the you can wash your hands. OTOH, it's just as easy to be willfully blind about that.