2. VSCodium is just a FLOSS VSCode binary. You could build it yourself from the available VSCode source. However, the VSCode binary is not FLOSS so you cannot be sure what it is running.
It's not like VS code is the next PRISM-- I'm sure MS has better ways to spy on users ;). The real pull is whether you prefer FLOSS by default.
That's equally true of the VSCodium binary. It's not a reproducible build, I have no way of knowing from which source code the binary was generated.
Of course I could build from source, but VSCodium is just VSCode built from source with a build flag set. So in this regard it's not contributing anything notable (and doesn't claim so either).
* https://reproducible-builds.org
* https://en.wikipedia.org/wiki/Reproducible_builds
Sorry, but I don't think I am qualified to explain clearly
Seems to just bring another problem by trying to solve one.
https://github.com/VSCodium/vscodium/blob/master/DOCS.md#dis...
If you dislike outdated software, try switching to a Testing or Unstable version of your operating system, or choosing a distro that packages less conservatively (Arch or Fedora, for instance).
In short: Once you've worked with a large enough number of nighmarish Linux installations, you treat them as adversarial systems and wish you could install software just by clicking through a few screens.
The difference is whether you have to click through one of those wizard things to get the program you want.
I don’t quite understand your point. Do you think that it’s hypocrtical to use and benefit from OSS work and investment? It seems important to respect the creator’s intent and if software is released under an OSS license it’s not dissonant or hypocritical or bad to reuse, or even make money under many licenses. It’s a feature, not a bug.
In the 90s there used to be these companies that sold “internet in a box” in waldenbooks and other stores in the US. It was about $70 but it was all just OSS stuff- trumpet winsock, Eudora, mosaic, etc. I thought it was really crazy because it’s all available for free. One day I was in line behind an old guy who was buying it and he was so happy because it was conveniently packaging everything together and he had no idea how to bootstrap all these tools onto his PC. OSS is designed to allow this.
If you have trust issues with Microsoft, you shouldn't be using software authored by them, as software can have backdoors and security issues hiding in plain sight (heart bleed bug, for instance).
Atom has/had the exact same kind of telemetry, but hasn't attracted this type of hysteria, because GitHub wasn't Microsoft. This is all plain and simple dogma.
So why is it problematic now for other people to build on top of what Microsoft added?
There's absolutely zero problems with people using OSS as intended. But for me personally, as I stated in the original parent comment, value obtained by persisting with Microsoft's VSCode, despite telemetry, is worth continuing to use it, as against an entity's fork whose USP is furthering unfounded FUD.
So they have created a fork of the project.
I would not trust an installer from a third party without knowing what was really changed, that's scary as hell if you ask me. Just look at the bootstrap 4 backdoor that was introduced but luckily was caught.
Telemetry lets you shed all the baggage of supporting the minority.
Less severely, there's an awful lot of long tail business productivity served by obscure software features that is very difficult to satisfy with modern hyper-engagement-optimized tools.
Software products may be developed for a mass audience or they may be developed for a narrow niche.
In either case, making the product accessible to people with disabilities is something developers should try to do.
And in every case, having data on user behaviour, software performance, bugs, crashes, etc, will enable the developer to do a better job of catering to their users' needs.
Have I missed something about how these objectives must be mutually exclusive?
No need to be sorry, it is pretty obvious that it is my opinion, since I made no attempt to support the statement, that is all it could be. That said, it would have been more polite to ask me why I believe what I wrote rather than being dismissive.
> "less effectively" ... "greater expense"
I feel that in order for me to provide satisfactory support of my claim to you, we'll have to first agree upon a strict definition of these terms. You're right to call them out in quotes as my use of them was intended to be qualitative and informal. How about more "effective" development being development that is more focused on serving the needs of its users & the goals of its developers, and "expense" include direct monetary cost, manpower, and any other resources whose use incurs an opportunity cost?
> There is NO telemetry in Linux (the kernel) and many other great software.
1. As I mentioned above, my comment was informal. It was not intended to make a strong claim about all software, without exception.
2. Unless a majority of pre-internet software was developed as effectively and cheaply as Linux and the other software you were thinking of, it is possible that my claim is still correct in the general case.
3. Software used primarily by those who actively contribute to it (such as Linux during its early development) has a very different communication dynamic from other software.
4. Linux is not representative of software developed pre-internet, considering the project was first announced by Linus in the comp.os.minix newsgroup in 1992[1]
* To be clear, any additional claims I have made above are _also_ my opinion.
Telemetry not being disabled I have disabled telemetry as described in the FAQ. I have set the following properties in the settings: [..] Now despite of this, when I log my network traffic (with Wireshark) I can see that Visual Studio Code periodically contacts vortex.data.microsoft.com.
For the record,
Even with: [..] I still see connection attempts by Visual Studio Code to marketplace.visualstudio.com and vortex.data.microsoft.com at startup.
Response is: I'm pretty sure we [VS Code Core] are doing the right thing here and we would love any pointers (all code is OSS).
Which almost sounds like a complete deflection of the issue. The ticket was locked.
https://github.com/Microsoft/vscode/issues/16131#issuecommen...
Though there's no explanation for why VS Code continues to ping vortex.d.m.c even after updating is disabled. Hmmm.
I suppose it's not clear why vortex.data.microsoft.com is still on the list of servers being contacted at this point, but it seems quite plausible that this is coming from an extension.
The VSCodium docs (linked in an above comment) mentions baked-in telemetry. Presumable this refers to the binaries rather than the source code, but then the issue is two-fold, being telemetry in the source and telemetry Microsoft may insert into the binaries. So following some FAQ to disable telemetry will not address the latter if you're not building from source.
This is the main problem as I see it and MS hasn't been transparent in question on what can actually be added to the binaries which bring us to the necessity of fork such as VSCodium.