14 ms·
Intel's GPU Drivers Now Collect Telemetry, Including 'How You Use Your Computer'
- opan 3y agoHow will this affect GNU/Linux? They mention an installer and a yes/no prompt, which to me implies Windows. If it can be disabled, I suppose distro packagers will likely make the choice for the user when they create the package. Or is this a driver that would be included in the kernel itself?
- ladyanita22 3y agoIt will not affect Linux
- anotherhue 3y agoSix months later: Our analytics show very little uptake in Linux use so we are reallocating investment towards windows users.
- steeleduncan 3y agoWhile AI companies are buying high end GPUs by the truckload to run on their Linux fleets this is unlikely to be a problem
- steeleduncan 3y agoIntel provides open source drivers GPU drivers for GNU/Linux. As long as that remains true it is unlikely they'd try to collect telemetry through those drivers. If they do, it would get stripped out long before it reaches the kernel.
- acqq 3y agoThis is definitely not what I'd be ready to approve: "Intel provides a long list of the types of data it collects" ... "Those include the types of websites you visit, which Intel says are dumped into 30 categories and logged without URLs or information that identifies you, including how long and how often you visit certain types of sites." Emphasis mine. I surely don't expect that from a GPU driver company. Damn.
- aport 3y ago[flagged]
- NekkoDroid 3y agoI surely wouldn't call Intel a "GPU driver company" (like how I'd call American Megatrends a BIOS/Firmware company), but rather a Processor company that is also making drivers (but that is neither here nor there). This is still so weird of them (not weird in the sense I wouldn't put it past them, but weird in a sense that someone even had the idea), even if they make it optional. Like, I don't care if you want to use that information to try to make better drivers by knowing which sites break the GPU, I will report that to you if I feel so inclined to it. I'd understand if it were "We wanna know what programs are using hardware acceleration", but it's not limited to that...
- acqq 3y agoI never had a goal to reduce Intel to a single role in today's world. Instead: For a company Y, where Y produces GPU driver, I can't believe there's a plausible explanation for Y to globally collect information about the web sites visited by all users in order to improve the GPU driver code. The reason behind must be something else.
- nopassrecover 3y agoSo depending on the categories it would potentially not be sensationalist to say “Intel GPU drivers are recording how much you watch porn”. And this potentially covers a lot of people if integrated video is covered by the same drivers. I suspect I won’t be the only person to adopt a principled position and avoid Intel devices from now on after a lifetime of choosing only Intel. How are we 2023 and there still not legal protections against this sort of thing. It’s basically the tech version of peeping tom.
- TheAceOfHearts 3y agoMy understanding is that Nvidia GPUs require GeForce Experience to enable all of the advertised features, which also includes telemetry that tracks your windows and URLs. Only one good player remains.
- titzer 3y agoWhat is the thought process that goes into thinking such a thing is a good idea, then proposing it, arguing for it, and then it being approved (presumably) by product managers and executives? It's just a downward spiral at this point as each new generation of software and each new year brings a worse and worse privacy default with even more self-justification and half-assed anonymization. Drivers need to know website usage statistics. Are we really here now?
- fnordpiglet 3y agoThe process that is motivated by profits. Here’s the thing. It not only got approved but it almost certainly got some people promoted.
- BLKNSLVR 3y agoAdd to this a total and utter lack of any interest from any political parties with any chance of being elected to govern a country. User-hostility in the privacy realm is open slather. It's (more than?) likely to be encouraged by political parties because they can buy and use the data for their, inarguably worse for society, constituent-hostile political gaming. The pirates are the corporates and there is no law under which the pillaged can seek protection.
- saiya-jin 3y agoYeah, you can't say a big no-no to private companies doing this and in the same time collect everything on everybody without any good law to back it up, even about hobo half around the world as long as they leave any kind of data trail (or somebody else does on their behalf). Somebody may connect the dots and uses it against you in election campaigns. So we are where we are, all politicians are well aware of this topic, all pros and cons, but nobody wants to touch it with 10m pole unless they can somehow spin it into their advantage. But then again, politicians have supporters, donations etc. Can't bite the hand that feeds you, can you. And there is always that cheap argument about 'think about the children...' when terrorists don't terrorize general population enough.
- 3y ago
- BLKNSLVR 3y agoThe time seems to be getting closer to the ubiquitous need for an 'allow list' for outbound internet connections. OpenSnitch or equivalent (per device) + Pi-Hole / Adguard (per network). Inverse WEI. Sorry, this request fails our Web Environment Integrity validation, you will not be receiving any data from this device.
- WirelessGigabit 3y agoThat used to work in the past with different IPs. Now an IP might have hundreds of DNS records pointing to it. But fine, installing AdGuard works great. But now we're fighting against 2 things: Things smashed together on the same domain, so no longer separate subdomains. And DNS of HTTPS, so we can't even get all our traffic to go over the same DNS server.
- JohnFen 3y ago> And DNS of HTTPS, so we can't even get all our traffic to go over the same DNS server. I bet there's a market for something like a user-friendly mitmproxy variant to plug that hole. It might even be able to be a part of pi-hole for pi-hole users.
- donmcronald 3y agoI bet there would be, but I'd also make a big bet that MS, Google, and Apple will make "trusted TLS chains" or some BS part of the trusted computing model "for your safety".
- rolandog 3y ago> Things smashed together on the same domain, so no longer separate subdomains. We can refine the regexps so that we approve certain subfolders within a same address.
- WirelessGigabit 3y agoYou can't due to more and more software (ab)using certificate pinning.
- xnx 3y agoA terrifying side-effect of AI is that everything is now potential "training data" and there's financial incentive to vacuum up any and all possible data. The situation on Windows is much worse than Chrome extensions (which have been attempting this for awhile) because of the near non-existent permission limits on Windows. I was shocked to learn just yesterday that Nvidia drivers were doing this. It feels extremely gross, like someone has broken into your home.
- bogwog 3y agoThis might actually be a good thing. For the longest time, very few people cared about privacy issues, which is why we live in a privacy hellscape today. If AI fears can motivate people to start taking privacy issues seriously, then we might actually see some strong privacy legislation, or more privacy-focused businesses to meet new demand. (or maybe I'm just being overly optimistic)
- distant_hat 3y agoThese are really niche issues and most people aren't even aware, let alone care about this. The only real solution to this is some kind of legislation that makes it difficult to carry on with business as usual. I wonder how this data collection squares with GDPR?
- bogwog 3y ago> These are really niche issues and most people aren't even aware, let alone care about this. Everyone seems to be aware of the protests in Hollywood, and I don't think it's too much of a stretch to tie that to privacy issues. Those AI models taking artists' jobs were trained with data scraped from the internet. Even if you aren't an artist, there's a risk that the data these companies collect on you will be used to train an AI model that will take your job, so you shouldn't be giving it away for free.
- ollien 3y agoI do think that's a bit of a stretch. Regardless of your opinions on the ethics of AI companies training on scraped data, how is scraping publicly available artistic works a privacy issue? Me, personally, I might call it unethical and undesirable, but I wouldn't call it an issue of "privacy" on its face.
- pptr 3y agoI don't understand the need to include "the types of websites you visit" in GPU driver telemetry. AMD's telemetry doesn't seem to include that: https://www.amd.com/en/legal/privacy/user-experience-program.html https://www.amd.com/en/legal/privacy/user-experience-program... I couldn't figure out what telemetry is collected by Nvidia.
- Dalewyn 3y ago>I don't understand the need to include "the types of websites you visit" in GPU driver telemetry. Do you visit Youtube and Twitch other streaming services often? Focus on video decoding. Do you visit sites that heavily utilize graphics[1]? Focus on 3D acceleration. There are reasons this data can be useful, especially since Intel wants to unfuck their otherwise imperially fucked drivers. Websites aren't just plain text with window dressing anymore, they are entire programs unto themselves. [1]: https://news.ycombinator.com/item?id=37026592 https://news.ycombinator.com/item?id=37026592
- AnonCoward42 3y ago> Do you visit Youtube and Twitch other streaming services often? Focus on video decoding. > Do you visit sites that heavily utilize graphics[1]? Focus on 3D acceleration. This is almost cynical. Why not track your user's eyes and record the screen to see where or if visual fidelity at certain parts is necessary? You know, to optimize the architecture.
- timw4mail 3y agoI guess I'm glad I noticed this when it appeared on a driver update. Another box to uncheck on each update: arc control and telemetry.
- steeleduncan 3y agoI'm not familiar with the details of such things, but would it be possible to "port" the Intel's open source Linux GPU driver to Windows? That would make for a working driver without this junk
- fluoridation 3y agoEven if you were to overcome the massive hurdle of porting a driver between two completely different kernel architectures, you would not be able to load it without enabling driver testing mode at boot time, or without buying a code signing certificate.
- yomlica8 3y agoIts the wrong priority anyway. Windows is utterly infested with far worse telemetry at this point so it would be like fixing pinhole hull leaks in the titanic after the ship had snapped in half.
- fluoridation 3y agoSomeone might be comfortable with Microsoft telemetry but not with Intel telemetry. That's not wrong. Weird, sure, but not wrong.
- JohnFen 3y ago> Even if you were to overcome the massive hurdle of porting a driver between two completely different kernel architectures Hmm, would that be a massive hurdle? I haven't looked at that driver code, but I have done a lot of driver development for both Windows and Linux, and have ported a number of drivers between the two. Sight unseen, it's not obvious to me that this would be a huge hurdle. The code signing is an issue, but that's a manageable one.
- fluoridation 3y agoI can't imagine it's easy, but if you say you've done it I'll have to defer to you.
- snapplebobapple 3y agoI assume I am safe using linux and the linux drivers?
- Dah00n 3y agoYes.
- aboringusername 3y agoOne question I don't see asked in the various threads covering this: why does windows freely offer such data? At least Intel does give you an opt out (should be opt in really), but other applications can freely collect this data without you knowing. Windows needs to have much better control maybe a "telemetry" setting to control each apps access to the data, but that would most likely require some serious reengineering. Just use an app like Simplewall and block outbound connections, you should be doing that anyway as windows sends so much data off to the NSA anyway.
- api 3y agoEven if it had better isolation a video driver is going to have system permissions.
- Dalewyn 3y agoA big part of what makes Windows so free and powerful is that it was architected during a time when security simply wasn't a concern. This is good because it enpowers users to use their computers as they see fit, but also bad because with great powers come great responsibilities that are often thrown to the wind. So to answer your question of why, the answer is simply that Windows doesn't care.
- AnonCoward42 3y ago> A big part of what makes Windows so free and powerful is that it was architected during a time when security simply wasn't a concern. Wouldn't that be true for BSD and Linux as well? Windows seems to be slow with implementing meaningful security/privacy features to the end user. Windows also has a good track record with backwards compatibility (compared to Linux at least), but that might also be the underlying problem here.
- JohnFen 3y ago> Wouldn't that be true for BSD and Linux as well? Depends on how it's done, I think. The security story in the unices is better than in Windows, but you can't lock down any system too tightly or it becomes unbearable for most to use. But if we're talking system-level drivers, they are in effect extensions of the kernel and largely have administrator rights, whether we're talking Windows or *nix.
- amelius 3y agoThis kind of thing should be opt-in not opt-out. And not the kind of opt-in where you can still accidentally press "OK" in an inattentive moment.
- Espionage724 3y agoYeah that kind of silly selfish behavior is exactly why NVIDIA buries the telemetry deep in their drivers and doesn't offer an option. Most people have no reason to limit or even be concerned with this. Intel is adding telemetry to improve the GPU drivers. Who would be against improving GPU drivers? Why are you considering Intel hostile?
- amelius 3y agoOn Linux, can I run drivers inside a sandbox already?
- speed_spread 3y agoNo, because monolithic kernels are unequivocally superior to microkernels /s
- fsflover 3y agoNo, but you can do it on Qubes OS.
- binary132 3y ago“Nonfree drivers are totally fine bro!”
- mastax 3y agoI know that Nvidia does extensive telemetry with GeForce Experience (the optional but heavily pushed companion software to the driver) but do they do it in the driver package also? The article makes no distinction and says there's no opt out. I thought choosing to not install GeForce Experience was the opt out (though that is not communicated to you at all during installation).
- daneel_w 3y agoI never install it myself, since I don't need it for anything. Would love to get a confirmation that tossing "GFE" disables their telemetry drone.
- Eisenstein 3y agoYou can use NVCleaninstall to remove the telemetry package. * https://www.techpowerup.com/download/techpowerup-nvcleanstall/ https://www.techpowerup.com/download/techpowerup-nvcleanstal...
- WirelessGigabit 3y agoAnd it's the only way to get auto software updates.
- daneel_w 3y agoMicrosoft provides updates for just the GPU driver through Windows Update if you tick the box for that.
- TimeBearingDown 3y agoNVCleanstall linked in another comment will also notify you of updates.
- dangus 3y agoMy takeaway from this was that Nvidia is the only GPU manufacturer that doesn’t even have an opt-out for telemetry and seems to be the least transparent about it.
- nine_k 3y agoThe problem is that the driver is closed-source. Even if the driver sent data in a format which is easily inspectable by user, and with only benign-looking data, it would be really hard to prove that something nefarious and underhanded is not being sent instead under that guise.
- hasmanean 3y agoHard for a human.
- yeck 3y agoIf you see where the packets are going you might be able to block at the DNS level.
- TacticalCoder 3y ago> If you see where the packets are going you might be able to block at the DNS level. There are many DNS blocklists out there and some of them do indeed block domain names from known telemetry (aka "spying") services. But if some telemetry directly report to specific IP addresses then blocking at the DNS level won't help. FWIW my firewall blocks some companies' known IP CIDR blocks (like FB/Meta) and my DNS (unbound) blocks all known malware, porn and telemetry services (among others). In addition to that the only process allowed to emit ongoing traffic to port 443 is the process running my browser. All hope is not lost yet.
- Tokumei-no-hito 3y ago> In addition to that the only process allowed to emit ongoing traffic to port 443 is the process running my browser. How did you get this configured?
- Dah00n 3y agoUnless they circumvent the system set DNS and use a hard coded one, which many that collect telemetry seem to do. On Android I see lots of traffic to Google's DNS even though I do not use their DNS servers (and it is in fact blocked).
- daneel_w 3y agoWhile Nvidia's driver installer doesn't ask permission, does anyone happen to know if there's a way after installation to disable their telemetry collection?
- unknown_user_84 3y agoBest guide I found https://old.reddit.com/r/privacy/comments/euud7u/how_to_prevent_nvidia_from_spyingphoning_home/ https://old.reddit.com/r/privacy/comments/euud7u/how_to_prev... I updated their blocks to cover all the IPs in the range, windows firewall rules accept CIDR notation ala 72.25.64.0/18. All the ranges for their backend stuff I've found so far: 72.25.64.0/18 216.228.112.0/20 8.36.80.0/24 8.36.113.0/24 I leave mapping out the rest of their IP space as an exercise to the reader. Found using `whois` against the IPs and domain from that reddit post. Their primary website appears to be on EC2, so nothing terribly useful there. I'm personally expecting companies that do this nonsense to move all their collection infra to EC2 or similar to make it harder to do simple blocks. Those that haven't already.
- LinuxBender 3y agoA few of tools you may find useful to aid in your searches [1][2][3] if you did not already have them. [1] - https://bgp.he.net/ https://bgp.he.net/ [click on the AS then the IPv4/IPv6 prefixes] [2] - https://bgp.tools/ https://bgp.tools/ [3] - https://www.robtex.com/ https://www.robtex.com/
- Eisenstein 3y agohttps://www.techpowerup.com/download/techpowerup-nvcleanstall/ https://www.techpowerup.com/download/techpowerup-nvcleanstal...
- el_duderino 3y agoPrevious discussion from a couple of days ago: https://news.ycombinator.com/item?id=37033475 https://news.ycombinator.com/item?id=37033475
- soraminazuki 3y agoAll the more reason to avoid Windows I guess. MS is busy crippling the user experience in exchange for short-term profits and now this. I'm glad Linux has good driver support and maintainers who would say no to BS like this.
- Espionage724 3y agoLmao. Anyone who cares about this likely isn't using Windows to begin with, and has already fallen into some Parabola Trisquel rabbit hole. Microsoft isn't crippling their user experience considering that doesn't benefit them; it's bad-actors cultivating that idea to push people on less-secure platforms, and/or naive Arch Linux first-time installer bros that want to push the idea of a worst desktop experience everywhere for no deep reason. Microsoft doing whatever they're doing to Windows benefits the average person who otherwise isn't going to deep lengths to improve their security and experience. I want more people to be as-secure as possible considering they'll become bot net contributors otherwise, or leak data that I share with them in some manner.
- JohnFen 3y ago> Microsoft isn't crippling their user experience considering that doesn't benefit them I have to use Windows at work, and have done so for decades. From where I sit, Microsoft is absolutely crippling the user experience. Every release after Win 7 has been a degradation in that.
- shrimp_emoji 3y agoCompare KDE's Dolphin with Windows's Explorer (tabs, split view, dark theme a decade ago, file size/mod date under filename...) Ten Dutch guys can make for free a better piece of software than a multi-billion dollar corporation can because better UX isn't profitable when you've already captured 99% of the market. :p
- Espionage724 3y agoKDE is not relevant or even heard of aside from people on Arch forums and more isolated communities. Heck the rare times I've seen Linux in the wild, guess what DE they were using? It's the one that's actually used by mainstream Linux distros, and even outside of GNOME, I even saw a wild Ubuntu terminal running Unity about a week ago. KDE should stop assisting with fragmenting Linux, or get the DE up-to-par for mainsream distros to use :p Meanwhile, guess what's the most popular operating systems for workstation use is. You're implying everyone using Windows willingly is dumb and being inefficient. Dolphin works, so does Explorer, Nautilus, and even Thunar. Only two of those are relevant for most people.
- tycoon666 3y agoGreat. The next generation finally gets a dedicated porn accelerator
- Espionage724 3y agoGreat! I want Intel to improve the driver stack I use on my hardware, and if information how I use their graphics stack is useful for that, cool. I continue on my usual usage, and Intel gets data on how to improve the experience for free. How does anyone expect software to improve if nobody gives feedback? Ya'll know those website surveys, bug report apps in GPU control panels? If people used those, maybe secret telemetry wouldn't be required. It's easier to complain vaguely online in random communities. Data collection isn't going away. Nor is it inherently harmful, unless you feed into the idea you're intentionally using hostile hardware and software for some reason.
- JohnFen 3y ago> If people used those, maybe secret telemetry wouldn't be required. That argument is simple extortion. Secret telemetry is never required, period. If people are unwilling to volunteer such data, then the devs simply have to do without. If that means that software won't improve[1], too bad. [1] Which isn't what that means. Software has always been improving even back when spying on people wasn't a feasible thing to do at scale, so spying is clearly not necessary. It's just cheaper than the old ways.
- Espionage724 3y agoIt's not spying. Spying implies being observed without consent, and that the adversary is gaining information to use against you. The average person who is using Windows and likely the only ones to see this do not fall under this. People were unwilling to volunteer the data exactly because of this fear-mongering. Ya'll act like Intel is sitting in a back room watching flowing logcats of your activity and cherry-picking ones to target you personally, as if some of ya'll are that important lmao :p
- JohnFen 3y ago> Spying implies being observed without consent It doesn't imply it, that's what it means. If data is being collected about me, my machine, or my use of my machine without my consent, it's spying. > and that the adversary is gaining information to use against you. I disagree that this is required in order for it to be spying. The reason it's collected is irrelevant. If I didn't give consent, it's spying. > Ya'll act like Intel is sitting in a back room watching flowing logcats of your activity and cherry-picking ones to target you personally I don't think that's what's happening at all, and certainly aren't meaning to imply it. What I think is happening is that data is being collected without consent. What makes it worse is that some of that data is clearly being collected for marketing purposes.
- kklisura 3y agoThe more these things are happening and the more I read about it, the more I understand and agree with Richard Stallman.
- troyvit 3y agoRight? The world is getting so weird that RS is starting to seem normal.
- hvis 3y agoYou won't get this on Linux, though. Unless they manage to bake his shit into GPU microcode somehow.
- iamsanteri 3y agoApple was right in moving on from these guys.
- junon 3y agoIntel is never going to save itself at this rate...
- wesapien 3y agoHopefully these destination IP addresses or domains or hosts are bing added to some lists so it can be filtered. Does anyone have these new Intel telemetry destination info.?
- jhoelzel 3y ago*IP addresses AND domains please
- dmvdoug 3y agoI was most intrigued by the “collect, use, and combine” language. Specifically, I didn’t see anything limiting them to combining only information they collect. So, what’s stopping them from purchasing additional data from data brokers to combine with what they collect in order to develop an even more in-depth profile of you? Nothing in the language quoted.
- xuhu 3y agoHow do you turn it off after the drivers are installed ?
- type0 3y ago> Those include the types of websites you visit, which Intel says are dumped into 30 categories and logged without URLs or information that identifies you, including how long and how often you visit certain types of sites. Will Intel Arc GPUs be optimized for VR porn?
- lakomen 3y agoNvidia has been doing it for years. I'm not surprised Intel is also doing it. I don't like it.