This could have been handled much better with some sort of opt-in prompt like the debian installer does for its popcon usage tracker.
I agree with you. I'd much rather have this be out in the open - like, ever 5th time I run 'brew' or something, it asks me for permission to send analytics, and the options are "YES-once, YES-Always, NO-NEVER", and if I say NO, NEVER, it never asks me again.
If spying on me can be automated, so can not spying on me.
Its, of course, always your choice if you're willing to trade it for something.
Do you think money or privacy violations must be part of the equation to make good software?
That is like the old argument against free/open software that I heard from a lot of people, back in the 90's. I thought we were past that.
So yes. Running their own server would be much preferable.
> The Google Analytics anonymous IP setting is enabled i.e. 1 (https://developers.google.com/analytics/devguides/collection...)
I'm not sure if they use it to improve their ad products, but I wouldn't be surprised if the answer is no.
Secondly, do you have a source for that? I find that a very dubious claim, from a business perspective.
https://www.google.com/intl/en/policies/privacy/
"When you visit a website that uses our advertising products (like AdSense), social products (like the +1 button) or analytics tools (Google Analytics), your web browser automatically sends certain information to Google... When you visit websites or use apps that use Google technologies, we may use the information we receive from those websites and apps..."
https://www.google.com/policies/privacy/partners/
It should be noted this does not directly contradict what GP claims.
"""
Google Analytics protects the confidentiality of Google Analytics data in several ways:
Google Analytics data may not be shared without customer consent, except under certain limited circumstances, such as when required by law.
Security-dedicated engineering teams at Google guard against external threats to data. Internal access to data (e.g., by employees) is regulated and subject to the Employee Access Controls and Procedures.
"""
For their definition of "confidential", which they can change at any time.
> certain limited circumstances
If they only intended the "required by law" example, they wouldn't use such a broad - and completely undefined - set of circumstances.
> guard against external threats
Google may have good security practices now, but an continually growing collection of highly-revealing tracking data is a very tempting target for many businesses, governments, etc. If Google (or anybody else) wants to claim that they are protecting your data, they should indemnify the subjects of their spying against any damages those caused by those "external threats".
I despise GA as much as the next guy, but you'd have to be pretty crazy to expect any business to provide such a guarantee. Google isn't your insurance company.
Businesses are acting like there is no risk in holding personal information. When people complain, they respond with claims that the data is safe. When businesses act like they are secured and that we should trust them, we should be asking them to stand behind those claims. I agree, this is crazy, but businesses really want to make strong claims but not be bound by those claims. An honest business that actually believed in their own promises shouldn't have problem putting those promises into a formal guarantee.
Yet you do seem to expect that guarantee:
> An honest business that actually believed in their own promises shouldn't have problem putting those promises into a formal guarantee.
You can't use such guarantees to vet businesses because no sane company would meet your requirements!
This may be a dumb example, but if I get someone (I don't know very well) a glass of water from the kitchen, I won't take a little sip from it on the way. Yes, they might not care, and it's super unlikely that I would infect them with anything. But it's still not my call, and you only need to see someone not get something so basic once to lose a lot of trust in them, certainly if they actually start arguing about it. It's more than optional courtesy, it's a respect for boundaries and personal choices.
And it doesn't matter at all how much they are doing otherwise for you, that is orthogonal. By that I mean: nobody asked anyone to make something for free, we're just asking people to not unwittingly have them feed GA if they don't want to. If there are too many things to fix and too few developers, fix fewer things. It's just homebrew, not cancercure. If enough users disagree with that, let them all opt-in and/or volunteer their own time, problem solved either way.
But nobody actually cares that much, only enough to complain. At length.
Do you want to share data with google to imrpove our products?
Do you want to pool your data for benchmarking purposes?
Both are unchecked by default. But here you go, I will search for "google analytics data sharing" for you.
If you're too busy to do this "right" why bother? Are you hoping making more shortcuts will increase adoption?
Current employer doesn't much care about these things, but last employer did. Having shared this thread with their IT folks, they've decided to cut people off from homebrew while they figure it out.
I guess costing yourself users is one way to free up some time.
How does that sound?
For example: "Linux has issues" "It's free. Nobody's forcing you to use it."
or
"FreeBSD has issues.." "It's Free. Nobody's forcing you to use it."
or
"I had a hard time installing Gentoo because of bad documentation. Somebody should fix that. No, seriously, metaland." "It's Free. Nobody's forcing you to use it."
I'm all for "beggars can't be choosers", but when there's nothing else to choose, of course people are going to complain.
"Malware" is an umbrella term used to refer to a variety of forms of hostile or intrusive software, including computer viruses, worms, trojan horses, ransomware, spyware, adware, scareware, and other malicious programs. It can take the form of executable code, scripts, active content, and other software.
Tracking people's online activity through a large percentage of the internet, without their consent or even knowledge qualifies as malicious to me.
If it's not malware, it's certainly really similar to it.
Malware
-------
- Any software that actively attempts to do any of the following:
- Do harm to the system, applications or data
- Deliberately weakens system security
- By changing system or user security settings
- Contains or installs backdoors
- Downloads updates as executables
- Use executables to wrap otherwise readable data
- Expects higher or more privileges than is needed by it's function.
- Circumvent the wishes or intention of the user
- Makes it self the default application for file-types that already have an application assigned to them
- Inserts itself into other applications against the users expectation (eg. as a plugin)
- Uses the privileges of other applications to circumvent system policy
- Hide its activity from inspection
- Anti-debugging, and other rootkit like behaviour
- Use "dark patterns" to trick the user into performing or agreeing to some action
- Installs toolbars, etc.
- Compromise the privacy of the user
- Phones home, access data irrelevant to it's function
- Resists removalIf software compromises my privacy, I feel that I have been betrayed and lost something that I can not take back.
If you don't get to automatically participate in a "anonymous" usage survey, have you lost something you can not undo?
That in my opinion, is why software should always err on the side of privacy.
...anyway, complaining about getting downvoted is a surefire way to keep getting downvoted :P
Requiring the user to set an environment variable to opt out is smarmy.
A Homebrew analytics user ID e.g. 1BAB65CC-FE7F-4D8C-AB45-B7DB5A6BA9CB. This
is generated by uuidgen and stored in ~/.homebrew_analytics_user_uuid. This
does not allow us to track individual users but does enable us to accurately
measure user counts vs. event counts
https://github.com/Homebrew/brew/blob/master/share/doc/homeb...Of course, you have to trust homebrew, but hell, you're already running their software, so it's a little late.