9 ms·
Microsoft: Require user consent before sending any telemetry
- RecycledEle 3y agoWhen the owner of a device is using it, they should have the right to inspect all data on that machine in plain language and to inspect all communications to and from that machine (again in plain language.) They should have the right to stop any communications at any level they choose using plain language menus.
- butz 3y agoIt would be also great, if VSCode stopped putting random directories into $HOME, even when running in "portable" mode.
- kjellsbells 3y agoI'm not qualified to weigh in on the merits of the request, but asking a corporation to change something and then throwing in a bunch of legalese about compliance and GDPR seems like an excellent way to guarantee that the poor reviewer of the requests is not going to deal with it, let alone quickly. At best, they raise it to their internal legal contact. The inhouse lawyer rapidly advises them to not respond in any written or recorded medium. Issue goes nowhere. At worst, they realize that this is a hairball with "vaguely legal stuff" and decide to review some other issue instead for a more productive and less stressful day. Issue goes nowhere.
- aaomidi 3y agoThis language in the bug makes it easier to build a legal case against them.
- alkonaut 3y agoIt's very easy: Complaints should be directed to whoever is listed in the Personal Data Protection Policy issued by (in this case) Microsoft. The privacy notice (Which nicely seems to be the same one across microsoft products!) clearly says how to complain, as it should https://privacy.microsoft.com/en-us/privacystatement https://privacy.microsoft.com/en-us/privacystatement And that method is not a github comment. The commenter might have followed the correct route to complain too, but could then at least have said that "I have contacted microsoft at [..] as outlined in the Personal Data Protection Policy and expect a response within [..]"
- jiggawatts 3y agoNo answer is forthcoming from the VS Code team, because they know you won't like the answer. Microsoft trawls their[1] endpoints mercilessly for every bit of telemetry that they possibly can, and they go out of their way to prevent customers from disabling this. Windows 10 or 11 with Office requires something like 200+ individual forms of Microsoft telemetry to be disabled! Notably: - They keep changing the name of the environment variables[2] that disable telemetry. For unspecified "reasons". - They've been caught using "typosquatting" domains like microsft.com for telemetry, because security-conscious admins block microsoft.com wholesale. - Telemetry is implemented by each product group, which means each individual team has to learn the same lessons over and over, such as: GDPR compliance, asynchronous collection, size limiting, do not retry in a tight loop forever on network failure, etc... - Customers often experience dramatic speedups by disabling telemetry, which ought not be possible, but that's the reality. Turning off telemetry was "the" trick to making PowerShell Core fast in VS Code, because it literally sent telemetry (synchronously!) from all of: Dotnet Core, PowerShell, the Az/AAD modules, and Visual Studio Code! Opening a new tab would take seconds while this was collected, zipped, and sent. Windows Terminal does the same thing, by the way, so opening a shell can result in like half a dozen network requests to god-knows-where. [1] You thought, wait... that it's your computer!? It's Microsoft's ad-platform now. [2] Notice the plural? It's one company! Why can't there be a single globally-obeyed policy setting for this? Oh... oh... because they don't want you to have this setting. That's right... I forgot. Windows: https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization https://learn.microsoft.com/en-us/windows/privacy/configure-... PowerShell: https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_telemetry https://learn.microsoft.com/en-us/powershell/module/microsof... DotNet Core: https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry https://learn.microsoft.com/en-us/dotnet/core/tools/telemetr... Windows Terminal: https://github.com/microsoft/terminal/issues/5331 https://github.com/microsoft/terminal/issues/5331 Az module: https://learn.microsoft.com/en-us/dotnet/api/microsoft.azure.commands.common.telemetryprovider?view=az-ps-latest https://learn.microsoft.com/en-us/dotnet/api/microsoft.azure... Etc...
- tentacleuno 3y ago> They've been caught using "typosquatting" domains like microsft.com for telemetry, because security-conscious admins block microsoft.com wholesale. This seems interesting. Do you have any references for this? I would assume that the main use of such typo-squatting domains is a simple redirect, a la [0][1]. [0]: https://gogle.com https://gogle.com [1]: https://gooogle.com https://gooogle.com
- bogantech 3y agoTo be fair if someone comments to me with things like: > Please give an answer within the next week until the 16th of June. I wouldn't respond to them either out of spite
- lnxg33k1 3y agoThe issue with society or one of them, is thinking its acceptable for a corporation breaking law to feel spite, the guy was not talking to a person, was talking to a shitty corp breaking law
- blackoil 3y agoWhich law? Instead of shit talking, they can report it, file lawsuit.
- smarx007 3y agoG.D.P.R., it says so in the thread. And Europe is not a litigious environment, we start with complaints first.
- blackoil 3y agoThe complaint should come from some authority or a legal backing. The poster assumes that they are breaking GDPR and seeking explanation with some shit talk to make it sound legalese. Companies as a policy and by logic don't reply to such comments/post because the response becomes a legal document. So any expectation of answer is futile.
- lnxg33k1 3y agoMaybe you come from a place where citizens just kiss corporations and count nothing, but the complaint here for GDPR can come from everywhere, even citizen can sue https://commission.europa.eu/law/law-topic/data-protection/reform/rights-citizens/redress/what-should-i-do-if-i-think-my-personal-data-protection-rights-havent-been-respected_en https://commission.europa.eu/law/law-topic/data-protection/r...
- not_your_vase 3y agoHave you noticed that MS mostly stopped using EEE, and changed strategy to just ignore rules/laws/licenses, and wait to see what happens? We hear it frequently that "today's MS is not the same as the old MS", but I have my doubts. This particular one just the latest. But the really big one (IMHO) is the one where they simply started to ignore EFF[0], when they were asking them about the copyright status of co-pilot. If the court decides against EFF, that will have a lot of effect on the legality and enforcement of most of the OSS licenses (though I'm an armchair-lawyer, not even in the US). Fun times ahead. [0]: if I remember well, it was EFF, who mentioned that MS stopped responding to them. I have found the lawsuit, but filed by not by the EFF. Google is more useless by the day.
- oaiey 3y agoI think this is a tendency of all internationals mega corporations. Law is not homogenous around the world, and since you are consequently anyway in violation, you learn how to use that in your favor and ignore it for quite a while. And then, once its start to be annoying, you can finance an army of lawyers to delay or even change the law. For one part it is quite reasonable to work like that, on the other side it is really unethically and bad for the society as a whole.
- yjftsjthsd-h 3y ago> Have you noticed that MS mostly stopped using EEE, No, I haven't. Notice that MS now loves Linux... provided you run it on Azure or as a component of Windows (WSL). They adopted Chrome...'s rendering engine and then abused their desktop OS market share to shove the result down people's throats. They don't have the leverage they once enjoyed, but the approach didn't change, at least not in general.
- deleted 3y ago[deleted]
- pjmlp 3y agoHardly any different from FAANG so beloved by FOSS folks....
- fhub 3y agoTruly anonymous data is not subject to the GDPR. So the question is whether the data they are collecting is truly anonymous. They seem to be claiming or suggesting "Yes it is" https://code.visualstudio.com/docs/getstarted/telemetry#_gdpr-and-vs-code https://code.visualstudio.com/docs/getstarted/telemetry#_gdp....
- jeroenhd 3y agoAmong the telemetry data: > MacAddressHash - Used to identify a user of VS Code. This is hashed once on the client side and then hashed again on the pipeline side to make it impossible to identify a given user. On VS Code for the Web, a UUID is generated for this case. A hash of a hash is about as expansive as a hash and it still uniquely identifies a machine, tying telemetry events to a specific user's machine. Microsoft's own telemetry description generator calls the field "EndUserPseudonymizedInformation". Pseudonymisation is inherently not anonymisation. This bullshit is why I keep my PiHole on for my dev environment.
- alkonaut 3y agoUnless there is any PII associated with the pseudonym, there is nothing specifically in GDPR that says you can’t or shouldn’t do this so long as it’s not information that can identify a physical person. Note that being able to attribute multiple pieces of data to the same anonymous person does not necessarily identify them (and it’s important to not accidentally do so): It’s important though if you e.g have multiple products to use a _different_ pseudonymization (hash salt or whatever) otherwise you run the risk of storing data linking too much data on a user thereby de-pseudonymizing them in the worst case even though no individual app does. Having a users behavior across multiple applications could pose such a risk in extreme cases. Edit: I think it's important to separate "hashing" and "hashing". A properly hashed identifier uses a salt that is generated on the client, so that it can't be used to identify the user. basically: the first time the app runs, you generate a random salt which is only stored on the client, and NEVER sent in telemetry. Anything you would like to transmit over the wire that would risk identifying the user (E.g. a computer name, mac address) you hash with this local salt. This way no one can try to go to the database on the server side and try to match any data e.g. check if the hash abc123 matches the computername jimbob bcause hash("jimbob")= abc123. Just sending hash(MacAddress) without a local random salt would NOT be properly pseudonymous because an attacker on the server side could ask and answer the the question "Does this come from the address macaddress?".
- charcircuit 3y agoI don't get people who request for software and websites to become nagware by asking for consent.
- _xivi 3y ago> people who request for software and websites to become nagware by asking for consent What? Lol. How is this the users fault? That's just dark patterns by companies to bend users into enrolling. It doesn't have to be like this. It could be opt-in under settings, like just about anything else. It all about power play.
- charcircuit 3y ago>How is this the users fault? If a user asks for the software to nag people and then the developers make the software start nagging proper then it is the fault of the user for suggesting that behaviour be implemented. >It could be opt-in under settings, like just about anything else. Or there could be an opt out in settings like how it already works.
- weikju 3y agoDisingenous take IMO > If a user asks for the software to nag people and then the developers make the software start nagging proper then it is the fault of the user for suggesting that behaviour be implemented. People are not asking for software to nag. They're asking for the software to NOT send telemetry at all unless the user agrees to it. As it stands now, vscode sends out telemetry before the user has a chance to opt out. What people want is for software to not be hostile to the users in that way. Failing that, at least give the option before the hostile behavior begins. But really.. It's not the users' fault. It's the software maker's fault for integrating that behavior in the first place and ramming it down our throat, whether we like it or not.
- charcircuit 3y ago>People are not asking for software to nag. This issue literally is and describes what the popup should include. >hostile behavior Telemetry is not hostile. It is a standard feature for understanding how a product operations or is being used.
- osigurdson 3y agoA user should be able to configure a program (or all programs) such that outgoing communication is not possible, logged or both. It really shouldn't be up to the program to decide what it wants to send as it could easily scan the entire hard drive on the users behalf.
- mostlysimilar 3y agoLittle Snitch on macOS and simplewall on Windows. Must-have tools for anyone serious about their right to privacy.
- Sakos 3y agoHave you tried running a firewall with explicit prompts? Everything connects home now. It's infuriating.
- einpoklum 3y agoThe majority of FOSS programs don't connect anywhere - although there has been an increase, for sure. Last year we had an argument this regarding LibreOffice, where an option to collect some telemetry was suggested as a nagging-opt-in. Opponents argued against this because some fraction of our users will press Accept just to get through the installation, or without understanding what they're accepting; plus we just didn't want this kind of mechanism in a respectable piece of software. For now the idea seems to be dead in the water.
- vincnetas 3y ago"The majority of FOSS programs don't connect anywhere" is a very week position. Not sure is english has analogy for saying from other language but it translates to "trust but verify". So parents comment makes sense: Get a global firewall for outgoing connections.
- justinclift 3y agoAlso: https://github.com/microsoft/vscode/issues/161333 https://github.com/microsoft/vscode/issues/161333
- lloydatkinson 3y agoLooks like the monthly “people absolutely lose their minds over VS Code telemetry”. The same people would then be complaining if VS Code crashed constantly from bugs that they also never report in place of no telemetry.
- LightHugger 3y agoThis rediculous false dichotomy of "if not for excessive telemetry it would be crashy" is so beyond reason. If it crashes just pop up the crash reporter and prompt the user with a button to send the crash report in. Done. No ethical issues there. But no apparantly you think microsoft needs a constant faucet if your information to prevent crashes. Golly i wonder how developers managed before said faucets.
- lloydatkinson 3y ago[flagged]
- g-b-r 3y agoYou're frothing in favor of telemetry
- lloydatkinson 3y agoNot really, I'm not the one being vitriolic.
- jen20 3y ago> How would they know if performance took a hit or any number of other issues that don’t result in a crash? Testing, a QA team, and an opt-in bug reporting mechanism.
- theknocker 3y ago[dead]