Intel's CIP wants to collect the “categories of websites you visit”
intel.com
intel.com
Telemetry is now an attack vector for privacy in general because no one can be trusted with the data.
If people are using more streaming services, that means Intel should focus more on their Integrated Graphics platforms. If people are downloading significantly more data than ever before, they should probably make sure their networking drivers receive more support.
Knowing how people use their PC's, even by category, can help Intel manage its driver development.
Knowing how people use your products helps allocate new development features. This problem isn't unique to intel.
They might find that a market segment doesn't do a lot of playing 3D games, but does spend a lot of time watching Youtube on battery, and so make the decision to drop integrated GPU shader cores and dedicate more die area to video decoding, to make energy efficiency better when watching video.
> I'd hope this could be measured without collecting a ton of personal data.
Intel's claim is that they don't: "we would like your permission to collect [...] The categories of websites you visit, but not the URL itself" also the privacy safeguarding statement at the top of the page.
The whole purpose of CIP is to gather data on actual users' computing needs. For many computer users, the web is most of their computing experience -- it seems appropriate therefore to include usage of the web in the program.
Much like any customer experience study, privacy is an issue. Intel do at least claim to be mitigating the impact to privacy.
And intel want it for free
> what data is collected and how is it used?
> The categories of websites you visit, but not the URL itself
> If I participate in the program, is there any personal information in the data collected?
> Will not include the URL (web address) for specific sites visited
edit: also the knee-jerk reaction most people are going to have to this, is concern about certain categories of websites.
From a technical perspective, how does this work? I can only think of two ways:
(1) Intel downloads a big "map" file containing a huge list of pre-defined domains and categories. This means either the categories are pretty slim or you have a GB's big file
(2) Each URL is sent to Intel (aka "collected"). Maybe they don't "store" it ("We promise") but as soon as it leaves your system you have no control on this
There is probably some flaw with this method... curious if others think there's a "safe enough" way to do something like this...
And besides, FPGAs are used for web scale applications, many of them applicable to small computers.
Like the Computing Improvement Program, hosted on an obscure web page and systray menu?
> Q: How do I participate in the Intel® Computing Improvement Program?
> A: When you download and install the Intel® Computing Improvement Program, click Accept on the invitation to join.
The legitimate way to acquire this information would be to purchase it from partners who have a legitimate reason to collect it. If you want to know how popular 4K streaming is, for instance, Netflix, Twitch (etc) can provide that information.
My uninformed guess is that the information would be far less costly and of far better quality than using some large-scale spyware deployment instead. Unless there's something more that can make it worth Intel's while.
But realistically it's just for advertising.
I recall that being a big challenge when I worked on browsers - it’s very difficult to see what users actually encounter beyond “top X website” lists, which are of questionable value.
Just because they process the data doesn't mean they need to record it. I feel like a good analogy here is the ISP is your secretary. Sure they must have access to your documents to do their job, but if they're reading through your stuff for "gossip" or snapping photos of your documents, that'd still be an invasion of privacy.
(And even as we trust Cloudflare of 2019 doesn't do it, who's to say Cloudflare of 2021 will still live by this code? Can you guarantee that? I often find myself wishing for an established way for a company to make legally enforceable vows about its behavior. Maybe there is something like this already?)
I do not think most webmasters or web surfers know this.
see "Among other things, that resulted in us cooperating around monitoring potential hate sites on our network and notifying law enforcement when there was content" - and more, via: https://blog.cloudflare.com/terminating-service-for-8chan/
> Intel keeps the data for a maximum of seven years. Intel takes reasonable steps to reduce the risk that any data kept for over three years can be traced to a particular computer.
Tied to user for 3 years. From a law enforcement perspective I’m more interested in the ‘other devices in your computing environment’. They state they are generating a random UID tied to your system, so I assume if I know the UID from the suspect computer then a warrant could be issued to Intel for this information.
If there is any "risk that any data ... can be traced to a particular computer" on day 1 that the stuff is stored, then that risk never goes away.
I was surprised that I could unfold these questions at all with Javascript disabled. Usually, I am stuck with this kind of pages.
Please webmasters, use <details> for your FAQs if you want foldable questions.
[1] https://developer.mozilla.org/en-US/docs/Web/HTML/Element/de...
edit: and I guess a JS shim can be used if it really matters.
In no small part due to Microsoft's decision to make IE11's rendering engine the only browser that could support: Java Applets, Flash, ActiveX, that almost all major companies and large governments use. If they had incorporated those into Edge and hidden them behind ten layers of security warnings, we wouldn't be in this mess.
Try to service large corporations and governments. Our IE11 user share is over 70% for the product (but under 30% for the marketing/public pages). This won't change until every last Java Applet/Flash/ActiveX control dies, and that isn't happening fast -- companies literally in 2019 still sell products using the tech' (Oracle!).
I was excluding this from the "most cases", but thanks for the wake up call anyway. Outch.
Yes this is too bad. Great feature.
It's not a choice I have, so fuck it: I'll make it viewable without JS, and usable with JS.
I understand your feeling, and by making it usable without JavaScript you are already going a long way, but using those tags also makes your pages accessible.
Making your pages beautiful with animations is only extra. Things already work out of the box in any case without <details> without effort, only better if it is supported.
HTML is mostly designed to gracefully degrade, detection is not always necessary.
How would you like things to be handled? Handling retro compatibility is hard and I find HTML does a good job at it.
Bosses are particularly impressed with the speed.
I've built a website like that, for someone drawing comics. Fully works in simple HTML, looks better with CSS, and faster and slightly more enjoyable with JS. The JS avoids jumps and flashes (especially annoying since the website has a black background) when opening a page by only reloading relevant parts so the browser does not need to fully redraw the website, with great care to handle history correctly and consistently with what would happen with JS disabled.
Don’t animate it, let the user agent use the appropriate animation.
</jk>
EDIT: Well, it's supposed to be opt-in, but apparently Intel has been sneaking it on user computers without their approval, which suggests that the checkbox used to install it from the driver assistant might be checked by default... so not opt-in.
> Intel uses information about your computer's performance to make product improvements that may benefit you in the future.
I'm sure you'll feel better knowing this. /s
While they state only "The categories of websites you visit, but not the URL itself" is transferred. I'm wondering how you do this? The most privacy friendly method would be to have an offline mapping with e.g. the 10000 most visited sites and their categories.
I think they're using this data to help guide how they should compete with AMD and ARM.
They also say they're saving the RAM used and software applications you use... To me that's about figuring out what's more important to end users; incredibly powerful (multi-core) machines or incredibly efficient (fastest single threaded speed per watt) ones.
Right now Intel is getting hammered on both fronts with ARM chips dangerously fast for single threaded applications (A13) and AMD totally slaughtering their desktop/server market... They have no modem business, and if I was Intel, I'd be pretty fucking scared right now. The weight of the rest of the industry might be large enough now to truly make 'em irrelevant.
As a result, they need to be very, very careful about where they invest resources as the future could be very dim for them...
P.S. I do think: sure they could sell it, but is that data really going to make up for the dip in their actual business? Nah.
To me this is like people projecting doom and gloom for Apple after Microsoft makes better products for 2 years, but maybe I'm missing something.
If either Microsoft or Apple had continued to only have one meaningful product they'd both be shells of who they are now.
"Y'all keep innovating, we'll be right here when you run out of monetization ideas."
I informally interviewed with Intel's process engineering in the early 2010s and was amazed to grok that they truly viewed Moore's law as a target. The job looked extremely stressful, as a new miracle was required roughly every eighteen months, and every piece of the process had to work, or the whole line would fail. Intel's (and modern chip-building in general) fabrication work is truly astounding.
Intel's real competition is Nature, and Nature gets exponentially more difficult.
But now there are tangible reasons to move away from x86. The industry spent the last decade doing the heavy lifting to make their software cross platform, which has allowed companies to not only easily move from x86, but to also create completely custom hardware. Intel's customers are also their competition.
I will be seriously impressed if Intel manages a pivot, because, as far as I can tell, they don't have a secondary business to fall back on.
It's a persistent extreme exaggeration, that's all it is. It's a projection of what some people want to have happen (death to Intel, rise of AMD; if AMD dominates, it'll then be death to AMD), rather than a reflection of what reality actually looks like. Aka wishing it were so.
What does reality actually look like? Intel's profits keep climbing and climbing.
2018 was the best year Intel has ever had in its entire history. $70.8 billion in sales, $23 billion in operating income. Operating income skyrocketed 58% in just two years. The extraordinary level of profitability they're sitting at has only been reached by a select few companies in all of corporate history.
Intel generated more operating income just last quarter than AMD has net in its entire 50 year history combined.
But surely sales must have declined then, given the scaremongering, even if profitability remained high? Nope. 2018 was a great year for sales growth for Intel, fastest growth they've seen in a decade.
They went from $55b in 2015 to $59b to $62b to $70b in sales, after many years of near-stagnation.
Surely Intel is seeing really bad erosion then in its most recent quarterly results? No - $6.5 billion in operating income last quarter. More than AMD's sales for the last four quarters combined. And one of the best quarterly profit figures Intel has ever generated.
Revenue, which is really about what has already happened, is a lagging indicator of bad news.
I have no horse in this race, but I think it is instructive to point out that after the iPhone launched in 2007, BlackBerry maker RIM would go on to attain impressive revenue numbers in its history starting in 2009 ($11,065m) and 2010 ($14,953m) before peaking in 2011 ($19,907m). It has been on a downward trajectory ever since.
> How do I participate in the Intel® Computing Improvement Program?
>When you download and install the Intel® Computing Improvement Program, click Accept on the invitation to join.
> What if I don't choose to participate?
> System performance information is not collected or sent to Intel. As a result, performance information from your computer cannot be used to improve future products.
Usual disclaimers: I don't work for Intel, never have, no plans to, no direct financial interest in them, etc.
If it stays that way
These days you need to really understand your threat model when it comes to using the internet and who might be able to record every keystroke and website you visit.
We used to call them "keyloggers" but now GBoard and Windows 10 have "clipboard sync" features.
I think there's going to be some genuine business in having scripts make random web searches, copy/paste random things with the cloud sync feature enabled etc to trick algorithms and what data can be harvested from what they collect.
If you poison the data they have on you then what use is it collecting it? Maybe I just am a raging furry, and adore Adolf Hitler and buy Nazi related materials.
There, now you don't need to collect any data.
The characteristics (memory access, numeric operations, etc) are complex and simply saying “make all of it fast” isn’t helpful - presumably intel is trying to make their chips faster at everything in general, but if they find that there are a few particular bottlenecks maybe they could allocate more resources/surface area to those particular instructions, etc
Not saying this is a remotely sane way to do the study, just that's probably the rationale
If that's not enough, they could also require all their contractors to opt their households in.
Instructions unclear, got speculative execution attacks. Slapped a fix, now everything runs slow.
Not at all! https://tinywall.pados.hu/features.php (it's free)
- Create a program that allows developers and other companies to upload their code to be stored and executed by Intel to test and store performance improvements and regressions
- For those who don’t trust Intel with their code, allow them to register their site as part of a testing program. Intel can then rank the importance of these sites internally by popularity or whatever kind of metrics they want.
If developers and companies care, they’ll participate and work with Intel directly. If they don’t, they won’t. Stop pushing this crap onto users’ machines, building profiles, storing data, and invading everyone’s privacy.
We really need an anti-telemetry law in the US.
If it is free
I won't do that, but if someone agrees I don't see any ethical issue with it.
Is there anything I'm missing?
You're probably thinking metrics because that's how the program is presented: as a way to help ensure Intel products and drivers are performing well.
But what does browsing data have to do with that?
E.g. I notice the privacy policy covering this data specifically allows them to use the data they collect for advertising and allows them to let their partners use it for advertising as well.
Is that what you were expecting from the Intel CIP?
I wouldn't want them to be able to read my CPU SN though and connect it to any browsing data. But there sure are people that wouldn't mind.
If I compare this behavior to MS and their telemetry crap, this is a gigantic improvement. Not saying that collecting usage information should even be further normalized.
But clearly they should reword it to be more explicit.
s/categories of websites you visit/
- Each month, whether you have or have not visited some streaming video website on this list (click to see list) (i.e. a single "yes" or "no" for the whole list) - Each month, whether you have or have not visited some shopping website from on this list (click to see list) - ... /
Don't you understand?
Does Pentel need to know the categories of ransom notes that I write?
Ford CEO Jim Hackett: “We already know and have data on our customers. By the way, we protect this securely; they trust us. We know what people make. How do we know that? It’s because they borrow money from us. And when you ask somebody what they make, we know where they work, you know. We know if they’re married. We know how long they’ve lived in their house because these are all on the credit applications. We’ve never ever been challenged on how we use that. And that’s the leverage we got here with the data.”
TLDR: "They trust me, Dumb fucks"
> If I participate in the program, is there any personal information in the data collected?
..then they proceed to tell you what they don't collect. You can read between the lines that yes, they do collect PII.
I wish other companies had a real opt-in process.
It's an offer to purely voluntarily provide telemetry on non-personal data, no strings attached.
Or buy a report from one of the hundreds of companies doing this kind of user tracking.
There’s no great reason why they would need to begin collecting data on each of their users.
They wouldn't have access to the frequency of visits, an important factor.
> There’s no great reason why they would need to begin collecting data on each of their users.
I've given you one above.
Also, it's not "each of their users", it's those voluntarily agreeing to submit this information (as opposed to "you need to install X to unlock feature Y", and installing an executable.
The same way having a few sparklers in your closet safe enough, having a few websites of your users is safe. But when you have a huge cache of personal data from large numbers of users, it becomes attractive to foreign governments, foreign gangs, feature creep from questionable law enforcement practices under a corporate surveillance state, unethical domestic lawyers, script kiddies, and so on. It's like having a whole fireworks store in your closet... It just keeps getting harder and harder to store safely the more information you collect!
And you're not totally wrong- at least they're doing the right thing and making this opt-in. However, this collection appears to be one done by a bunch of GPU nerds, which raises warnings that it won't be protected as well as, say, google doc data.