Example - Mozilla is going to remove support for TLS 1.0 and 1.1 [1]. A good change, we can all agree. But what if half their user base was relying on this feature? Can they still remove it? Should they commission a user survey asking everyday users about TLS? Fortunately, they have telemetry that tells them that only 1.2% of all connections are made with these versions of TLS. Cool, this change can go ahead.
If you were in charge at Mozilla and you don't want to collect opt-out telemetry, please tell me how you would have made the TLS decision.
Literally what are you scared of that telemetry will send? If you're so concerned about it, why don't you just opt out?
[1] - https://blog.mozilla.org/security/2018/10/15/removing-old-ve...
This is dangerously close to a “nothing to hide” argument. The issue with telemetry is that it’s difficult to do it right, and often it ends up just siphoning data that ends up being abused or mishandled. Having this be opt-in raises questions of consent.
If you think there is something that it might upload that you might not like, please let us know. Here's the extension - https://github.com/Microsoft/vscode-extension-telemetry. You can check for usages here - https://github.com/Microsoft/vscode
There is plenty of personal information that I never want shared with anyone, like my location history, who I speak to and so on. But what shortcuts I use, what features I use in an application, after it's been anonymized? I have "nothing to hide" there.
[1] - https://news.ycombinator.com/item?id=19427773
[2] - https://news.ycombinator.com/item?id=19109815 (this one is great, because it's a task raised on dotnet cli, but posted on the thread about VS Code release notes)
Also, if you're so worried about being de-anonymized, then opt-out?
They disclose vulnerabilities to US government agencies first and stil to this day have no transparency about what information they share with governments.
Wow do you actually believe that? Have we forgotten about NSA KEY already?
Perhaps you’re assuming too much. I’d class this forum more as a “tech enthusiast and startup” forum. A lot of software developers, a lot of hardware developers, and a lot of conscious users of both.
I do agree with what you’re saying though. When I was doing open source things, I sometimes joked about how much easier it would be with some telemetry.
One time, me and someone else spent a day of testing and not doing anything, while in the back of my mind I just wished I could look at a database to see the results from users. Then we all could’ve just made things better.
Software engineers, not cops and marketing specialists.
Seriously, I know that might sometimes make our work harder, but the answer to many of those questions is "we don't, it's none of our business." Except for crashes, making them opt-in is trivial.
If anything telemetry gives developers an excuse to use users as QA.
if it's a crash on the client, you should apologise to the user and ask if it's ok to send the crash dump to the supplier and give them an option to review the content and add additional information if they see fit.
CHOICE is not a forbidden word in 2019.
In the age of Web apps how is that any different?
Wasn't the problem with Microsoft telemetry that it is not so much opt-out as many users would wish?
Microsoft: Umm- looks like nobody used jumplists in start menu. Lets remove in windows 8+
Everybody: Windows is getting worse for power users.
I myself use Arch as my default OS with dmenu and rofi to help me.
Do you have a source for that?
What data are they collecting maliciously? For example, what program(s) with telemetry are using it to exfiltrate my financial information or passwords?
No thanks. That's disrespectful towards the customer and quite illogical. Why?
1. We deal with a lot of personal information and we do not want risk vectors associated with telemetry under GDPR. If you don't have full control over your data then you put your customer data at risk. This is indicated by Microsoft already getting into trouble over Office telemetry leaking customer data.
2. Opt-out is not a logical option because of the fragility of positive configuration. All things should fail safe. Microsoft already broke the opt out for dotnet core on Debian once.
3. It creates a hell of a lot of network traffic to tens of different hosts which makes it difficult to quantify what is telemetry and what isn't.
4. It costs us money to admin. Literally a pile of cash goes into compliance every year and this makes it harder and more expensive trying to plug all the holes in a giant swiss cheese. We'd rather have a cheddar and just make the holes we need in it.
5. If you're not an enterprise customer you can't opt out. This is just WRONG.
With respect to Mozilla and ending support for TLS v1.0 and 1.1, you do what we are doing with TLS deprecation which is communicate with your users, something Microsoft seem to have forgotten about in their drive to marginalise user opinion and move to a subscription model.
The problem is software management has got lazy and stupid and figures that every problem can be solved if you collect enough data about your clients and that total isn't true. What you end up with is a lot of data and a poor signal to noise ratio.
Edit: downvoters - explain yourselves! I explained my perspective!
I mean, I can't think of a different interpretation of this line…