Ubuntu Will No Longer Track Which Packages Users Install
omgubuntu.co.uk
omgubuntu.co.uk
---
I don't know about Ubuntu, but while installing Debian the installer makes it very clear what popularity-contest does and asks the user for explicit consent.
It also makes it very clear that this setting can be changed later at any time.
The default option is "I do not wish to participate", so if someone isn't paying attention during the install process and just hits 'Enter', their privacy remains intact.
This, IMO, is the perfect way to do telemetry.
1. Is this machine primarily used as a laptop, desktop or server?
2. Is this machine owned by a business or by a person?
All sorts of popcon results are taken as being authoritative, when (I think) the overwhelming majority of responders are personal owners with laptops or desktops.
It'll quickly and destroyed, so I just keep thinking I'll pollute their stats.
Usually what happens with opt-in versus opt-out is that the people who are the heaviest users of your software, the ones who care about it, the ones who might know its details or care about privacy will turn it off and you'll just be getting analytics from people who are casual users–and it's really easy to end up interpreting this as "hey, nobody uses $OBSCURE_FEATURE, let's remove it!". Whereas if you make it opt-in, yes you will generally have smaller numbers, but the distribution might be more useful to you, and you're less likely to think that just because you have numbers on 70% of people you're going to make the right decision.
I don't think it's "irrational" to suggest that you shouldn't be collecting data from those people as they have clearly not given consent to you doing so.
Really nice distribution, btw! My favorite, so far.
Ask beforehand or it'll be denied; mandate or lie and you'll never get a single byte, ever.
I think this might be interesting for packages that are part of the default install, server side statistics would always show those even when they are not used.
I understand @notRobot's sentiment, but do not agree with it.
If the default is "no telemetry", then very little telemetry will be collected.
This is an advantage to the user, but a strong DISadvantage to the collective, because the distro manager now cannot make informed decisions as to what packages are installed where and how often.
It really is a balance of "individuals vs the collective" and I don't think that answering both needs is simple, nor is it cut-and-dried.
If it’s for caching, can they not see which packages are most frequently accessed over http and implement caching that way? Or is that against their privacy policy? I’m not very knowledgeable on this subject but would love to know more!
As a software writer, it motivates me to know that my software is used and that putting effort in maintaining it will help people. For instance, I made a small Firefox extension that requires regular updates by design. Seeing that it was installed on a hundred browsers has motivated me to maintain it. If it was just for me, I probably wouldn't have bothered so much even though this extension scratched a personal itch.
As a user, I am a bit reluctant to being tracked so a balance must be found.
Edit: the amount of downloads from the archives is not enough. Some packages are downloaded again and again by automated systems like continuous integration systems and a downloaded package can be uninstalled immediately and this would be imperfectly detected.
Also using differential privacy you can gather statistics on package use while limiting knowledge about a specific user.
(I'm agreeing with your first statement, but questioning your second one.)
The average users that you want to target don't really change those settings.
Developers can get that sweet sweet telemetry by default and those that care can just set a var in ~/.profile and be done with it.
Ahh...that thing that is mostly ignored because its based on goodwill?
> Canonical’s Michael Hudson Doyle says “…the package and backend have both been broken since 18.04 LTS without being much missed.”
Maybe someday this will be the only legal way to do telemetry.
This seems like something trivial to solve without impacting user privacy if they're downloading all the packages from you or your mirrors.
Unless the point was to see what PPAs people are using?
https://snapcraft.io/docs/snap-store-metrics
> the store assigns an anonymous identifier, the device-serial, to every new snapd client it sees. This exchange usually happens when a new installation contacts the store, and the identifier persists for the lifespan of the machine.
> Systems running snapd will periodically make a refresh request to the store, checking the for the most recent release of each installed snap. At that moment, they inform the store of their device-serial along with a list of the currently installed snaps.
PS: My other reasons: - Much more resource wasteful - Single store operated by canonical only - No simple updating a library with a vulnerability and having all apps that use that library automatically fixed. - Makes really messy virtual mountpoints everywhere.
KDE/Plasma does calculations in the launcher - which comes up immediately. Or you could open your console (I use Yakuake) and use bash/python/bc -i/whatever.
Timing with a script with a warm cache speedcrunch, kcalc, and emacsclient full-calc all take about half a second for the window to appear and are instantly usable. The quickest app I can find xterm appears in 200-250ms.
Chromium takes about 800ms. incidentally Chromium shows a big difference after dropping caches taking almost 2.5 seconds after dropping caches while others mostly lose 20%.
Firefox is the worst taking about a second warm but taking around 6 seconds after start to become usable. Some of this may be due to addons but firefox has never started quickly its only tolerable because you start it once at login.
I’m really grateful to Ubuntu for helping me get deeper into Linux in 2007, but I would never recommend them to anyone today.
Nowadays, lots of distros are just as easy(Debian, fedora, Linux mint), come with all drivers, work on basically all systems, and don't spy on you. Ubuntu isn't as easy to dual-boot windows now too. There's basically no advantage to Ubuntu now except community.
Ding Ding Ding. This is why I still recommend Ubuntu, there's a community and a wealth of knowledge out there for working with Ubuntu.
Though if you are more experienced and deal with nuanced issues you will find often the community is outdated and this is a double edged sword -- a lot of material out there is for older Ubuntu distros and is no longer relevant.
Wubi for anyone searching.
That's the best and worst reason to reccomend ubuntu. The best because it's community is large and somewhat stable. The worst because that community is under the thumb of a corporation that does not seem to understand it.
popcon-largest-unused is a useful tool whether I've uploaded their data or not.
The packages I have installed hardly seems worthy of keeping secret, the opposite in fact.
Ubuntu doesn't even run all the mirrors, so hasn't even got control of if people are collecting this data.
In other words, the headline is false because "Will No Longer" implies the opposite, which even the author acknowledges is not true.
How do people building these things become convinced this is ok?
The default option is "I do not wish to participate", so if someone isn't paying attention during the install process and just hits 'Enter', their privacy remains intact.
This, IMO, is the perfect way to do telemetry.
This is not privacy-hostile in any meaningful way.
Because they have the data proving that opt-in telemetry means no telemetry. Every time this topic comes up, HN sticks its fingers in its ears and refuses to accept this, but it's the truth. 99% of users, even for a developer-focused application like VSCode, just click through and accept the defaults. So if you want telemetry that isn't useless for any practical purposes, it has to be opt-out.
If you want, you can have a separate argument about whether having the telemetry is worth it, but if you've had that discussion and decided the answer is yes, then opt-out follows immediately from that.
If they care about their users and it's not possible to have worthwhile telemetry with opt-in, they simply can't have it.
[0]: https://insights.stackoverflow.com/survey/2019#development-e...
And this is not even something that can't be replaced : if you want to know about your users habits, ask them. I would have no problem with seeing once in a while a broadcast message after syncing packages showing me an url of a poll. But automatic data collection is never ok.
Like, instead of having a prechecked box that people would have to notice and uncheck before proceeding or a greyed out "maybe later" button, what about two different continue buttons labeled "yes, help us improve with anonymous statistics" or "no, I'd rather not contribute"? (Either way with a link available to more details in the privacy policy before deciding.)
My guess is that it would be less useful telemetry than opt-in, more useful than opt-out, and a slight obstacle to sign-ups for consumer webapps but not much of an obstacle to enterprise webapps or anything pre-downloaded.
Maybe it's still useful and smooth enough to be the right balance vs privacy?
The reasoning is simple.
The reality is complex.
Always, always think about second order effects.
Change your frame of mind from "my software" to "your computer". If your users don't explicitly opt in, you have no right to take what they do not freely offer.
Come again? Is there telemetry in the F# compiler I didn't know about? Or you mean that OOTB VSCode has telemetry, so you won't use it for your F# code, opting instead for a different text editor / IDE?
The other two main ones are Apport for crash reporting, and ubuntu-report, which sends system info if opted-in at install.