4 ms·
That is why ethical distributions do not check for updates without user's permission.
by codedokode 2y ago
That is why ethical distributions do not check for updates without user's permission.
- sodality2 2y agoDo you ever plan on updating? Also, if the telemetry was automatically sent whenever you requested an update, would it be acceptable? By painting telemetry as bad _because_ of the inherent tracking available due to the TCP/IP connections being made in the background, that does nothing to say the above is bad, since you've already agreed to implicitly worse tracking (since third parties now have that data) in an affirmative manner by requesting an update. I would agree that this implementation (and opt-out telemetry in general) is bad, but let's not pretend that it's bad because it makes connections to servers over the internet.
- Lammy 2y agoWho's pretending? I build and host my own package updates, host my own NTP, etc. None of my machines do anything that leaves my network unless I'm the one actively doing it. It's not that hard.
- sodality2 2y agoSo all your software that does the updating of your packages are bad, because they make network requests? opt-out telemetry is bad because it disrespects user consent by assuming they have it. Not because it uses the network.
- codedokode 2y agoI can run a package manager command for update manually when I need it. Or I can enable periodic update checks. Computer should do what I order, so sending telemetry without my permission is not ok. In Linux you (or package manager) typically don't send requests for an update; you download a package list, see which packages are updated and download and install them. The request should not include any identifiers like installation id or software version. You can also download from a mirror in a selected country or even self-hosted mirror (which is useful for some companies). This is what distinguishes open software from commercial software: you can choose a provider for network-based services or become a provider yourself. > By painting telemetry as bad Bad is doing things with user's computer or data without explicit permission/request to do it.
- vanviegen 2y agoIt is now considered ethical not to notify users that there are important security updates?
- ryandrake 2y agoImportant for who? I should be the one to decide what is important enough to install, not the developer. If I want to know whether patches are available for my software, I will poll their websites at an interval that makes sense for me.
- vanviegen 2y agoAnd you're welcome to do just that. But do you really believe that should be the default behavior, expecting people to remember checking for updates regularly?
- ryandrake 2y agoThe default behavior should be to not do anything that the user does not command, but if that’s too extreme for 2024, then at the very least, the software developer should obtain the user’s consent before doing anything on its own.
- sodality2 2y agoTo be fair, I've never had a Linux system that auto-updated, and even for the ones that do have that feature built-in, it's never enabled by default. But I'm sure most linux distros make network connections during startup that you didn't "command".
- codedokode 2y agoYes it is not ethical to check for updates if the user didn't agree for that.