I agree with the criticism that they should draw a clearer line between the cost and the benefit but there's nothing to be gained by softening the language used to describe the cost.
I agree with the criticism that they should draw a clearer line between the cost and the benefit but there's nothing to be gained by softening the language used to describe the cost.
I use Firefox and have search suggestions disabled there so I am somewhat sympathetic to their point.
That said, calling server-side autocomplete on a field you explicitly are typing in strikes me as about as sensible and forthright as calling an Amazon text field that takes my credit card number a card skimmer.
I think the description of autocomplete as a keylogger is a good fit from the security perspective.
Exactly, and waters down the impact of the termminology. If "card skimmer" is anything that can read a credit card, than the term is meaningless for security.
If "keylogger" is anything connected to the web that responds to a keypress...
GNU is risking turning into the boy who cried wolf here.
As with a lot of the FSF's messaging, I think the substance of the message may be correct, but the way they convey it just isn't effective.
If this is for a general audience(!), no-one was ever convinced by the 48th item in a list who wasn't already convinced by the 47th. You don't persuade people just by being right, and certainly not by banging on about the very many subtly-different ways in which you're right. Pick few strong examples and prosecute those decisively.
If this is a resource for campaigners, set out the audience and intent before you start. Preface it with something like “Here are various ways that certain aspects of Google's software can be seen as indistinguishable from malware. They may be useful counterarguments if someone suggests Google's software is trustworthy.”
There's no warning that a text field autocompletes, and no reason to assume all users are tech savvy enough to realize that google has to see every character typed to send back recommendations.
Autocompleting doesn't change that.
The Amazon text field would have to send your credit card number for a credit check without telling you to compare.
It can also be turned off extremely easy, not exactly what we know as "malware" if it allows you to turn off its "malicious" activities.
On Windows asking for a handler for all key presses will often trigger the antivirus, while asking for a single application often will not.
And if you say bandwidth you're fired. It's privacy the FSF is grumbling about. And for that it's been rhetoric and theoretical suffering, but no actual real-world damage. And not for lack of adoption.
Put that cost in your pipe and smoke it.
At the end of the day, serverside autocomplete is useful, and coal is cheap!
If you're not logged in, as I'm sure FSF people are, then this is a much bigger deal, but it doesn't apply to the vast majority of people.
All that said, the keylogger would take a good deal of interpretation to get a complete or even partial history, since autocomplete choices would likely be chosen anyways, not fully typed out URL's. If they send that history anyways on any time you press enter, the autocomplete feature again doesn't matter because they have it with our with.
Also, your aggregate value argument is quite apt: It's valuable to know what percentage of a city speaks English, but the fact that you personally do or don't is of no real value at all, specifically because it's "your" individual data, not despite the fact. And insisting that you've been hypothetically robbed of your entitled half penny for disclosing your language preference to the McDonalds cashier is precisely as sensible as complaining about the value of your half-typed URLs.
Type "p" in the address bar at work?
Don't visit sites on work computers you don't want others to know about!
You've never accidentally typed a password in a URL bar? You've never accidentally focussed the browser window when typing something you don't want Google or anyone else to know?