“I saw that you spun up an Ubuntu image in Azure”
twitter.com
twitter.com
The Canonical quote is the most illuminating :-
"As per the Azure T&Cs, Microsoft shares with Canonical, the publisher of Ubuntu, the contact details of developers launching Ubuntu instances on Azure. These contact details are held in Canonical’s CRM in accordance with privacy rules.
"On February 10th, a new Canonical Sales Representative contacted one of these developers via LinkedIn, with a poor choice of word. In light of this incident, Canonical will be reviewing its sales training and policies."
Thinking about it though, a lot of it is a question of surprise and unknowns. I would find this message to be a lot better - "We see that you've taken advantage of the Ubuntu image that Canonical provide in the Azure Marketplace. I am available to you for (etc.)".
No. That's not better at all.
The mere fact that Canonical has specific information to reach me when I am not a direct customer of Canonical is a complete violation of my privacy.
Ubuntu is a free product. Canonical should not be able to find out if I (specifically me or my organization) allocates or runs 1 or 10000 instances of Ubuntu.
So MS sharing "their" customer details with the image provider seems more generous than evil. Provided there's a "Do not share" config option somewhere.
Ubuntu is gratis, so Canonical can't have coerced Microsoft into doing so; it is quite probable that one approached the other to make a deal, and that Canonical is paying a certain fee for this information.
I don't expect an OS based on an OS based on an OS based on a half-finished OS based on free software principles to have shady data-dealing attached, yet hidden from the people whose data is being dealt.
I mean, it's kind of ridiculous to think that you could do anything in a cloud environment system and not have your actions tracked. Hell, with automated load balancing and load-based billing, that's literally what you're signing up for.
Privacy protection is not an obligation, but transparency and openness is. Yes, you're not contractually required to not make a separate computer system that's proprietary and closed and disempowering, but that's so pedantic as to be malicious.
We're talking about a curated, supported, official image here, right?
If folks want to use a "MyUbuntuImage" they or someone else packaged and uploaded, more power to them.
But by pulling a Canonical image, you have a relationship with Canonical. Expecting that relationship not to exist "because open source" seems to be misunderstanding who does what work.
As to whether this should be opt-in, done, etc. is another matter entirely. But the fact that it exists at all doesn't feel particular shocking.
It's not like we're talking about everyone who pulls a RedHat image's info being sent to Canonical!
If I download packages and Ubuntu, and assemble my own image, or use one assembled by another org, probably not.
I think the disconnect is that for me, image packaging and updating is work, and that work has an author, and the author is deserving of certain rights others are not.
If Azure is auto-pulling Ubuntu images, building containers, and publishing themselves, then that's a different story.
I agree with the message behind this and obviously Canonical and Microsoft are both being extremely gross.
But Ubuntu as a binary image (or source code) is a very different product than a VM with Ubuntu pre-installed and pre-configured, which is what you paid for (and is why you got ensnared by their horrible anti-user license).
How? Why? If it's different in any meaningful way from just clicking "next" on the installer then it's no longer Ubuntu, and certainly not Canonical Ubuntu, that's pre-installed. It's become, at best, Microsoft-Ubuntu-Because-Microsoft-Added-Telemetry-For-Azure. Or it's Canoncical-Ubuntu-Configured-By-Microsoft-With-Azure-CLI-Preinstalled.
It's not "Ubuntu" any more.
When I'm paying for an official Azure version of Ubuntu on Azure, I darn well expect there will be a closer support relationship than the free desktop version.
Okay, but maybe other people don't want that if it entails their information being shared with a company they haven't initiated a business relationship with?
> haven't initiated a business relationship
????
To say that you have no business relationship with Canonical while paying Canonical to use Canonical software with official Canonical technical support is absurd to the highest degree.
You deciding to resurrect the comment because you happened to see it before I deleted it is really not OK. It's the exact kind of toxic hostile, creepy interaction I was trying to avoid from you by deleting the comment!
I thought your comment was interesting and merited a reply for others to see and discuss. But I see you disagree so I've removed the content of my reply.
Feel free to flag any comments you find particularly toxic or hostile. You can do that by clicking on the timestamp of the comment and clicking the `flag` link.
Or even better, let me know (like you have done so here). I can't improve myself if I don't know there's a problem.
Posting something and deleting it after it has been seen is basically gaslighting. Imagine the kinds of harassment people could get away with if they said rude things to coworkers on chat, then edited the messages to appear benign after the coworker responded to their hostility.
That is why people quote the text of comments to which they want to reply.
Furthermore is strenuous disagreement now toxic and hostile?
Wouldn't it be more trivial to say I do not wish to engage and leave it at that? Ironically calling someone toxic hostile and creepy is... pretty toxic.
I think someone has the right to change their mind about something they've said. That's why I edited my comment to remove it.
> Furthermore is strenuous disagreement now toxic and hostile?
I don't think so. But I know that I sometimes get passionate about my opinions. I welcome someone's input to keep me friendly.
> Wouldn't it be more trivial to say I do not wish to engage and leave it at that? Ironically calling someone toxic hostile and creepy is... pretty toxic.
I would like to think better than that. I think it was good of @ojnabieoot to let me know that they thought I'd wronged them.
Some people can feel very anxious or awkward to conversation for very good reasons. They can state opinions and then choose to retract their opinions for any reason -- even if the opinion is held but they choose to remove themselves from the conversation. I think that's a good thing to discuss but this isn't the venue to.
Ditto the Ubuntu images on Docker Hub.
This is a big misstep for Microsoft, from my point of view. I think it's less a reflection on Canonical, because once they have the information, it's ultimately going to be used. Microsoft just should not have agreed to the arrangement at all.
To quote the old native american (?) fable: You knew what I was when you picked me up.
I don't think that most of the people have a problem with that. The problem is being sucked-in to something without ever agreeing into.
In the era of privacy sensitivity (which I think is healthy), being watched in a place and prodded from a different channel is disturbing.
I don't mind people trying to reach me with the hope of sales based on information I've provided to them, but this is too far.
Also it removes two veils from both companies at once:
1. It seems Microsoft still has sneaky tactics, but they're more invisible.
2. Canonical is somewhat more aggressive and greedy than it seems, and Ubuntu desktop is just a freemium product, or another capturing device for further vendor lock-in.In this case, the license is the GPL, none of which has anything to say about privacy. Maybe this is a failure of the Free Software Foundation's to not include privacy protection in the GPL. Though even if they were to create a GPLv4, the Linux Kernel is still only licensed under v2, so distro implementors have no obligation to use a more restrictive license.
AKA, "the cat is already out of the bag".
In the OP's case, they additionally are are customer of Microsoft's, who explicitly stated they share this kind of information with their vendors.
Debian Free software guideline does not allow discriminate against using debian for evil.
Citation needed. RMS, the FSF and many other orgs made public statements around privacy many times.
Now, I can't exhaustively prove a negative, but I think I can easily demonstrate that the FSF has never meaningfully expressed an opinion on privacy. Go to https://www.gnu.org/philosophy/philosophy.html, open every single page it links to in the body of the text, and search for the word "privacy". It does not show up in the body text of any of those documents. It shows up once in a footnote that mentions a change that Samsung made had that "caused privacy concerns".
The closest they get to even mentioning the concept of privacy is when they talk about the right to modify software and use those modifications "privately", which clearly does not mean anything about user privacy.
If privacy were so big of a concern for the FSF, you'd think they'd talk about it in their official documentation on their philosophy, or put something about it in the ONE tool they have to have power over anyone: the GPL.
The anti-patent-trolling, anti-tivoization and copyleft provisions are there to protect developers and users.
Additional clauses around privacy and security would be very nice.
Unfortunately, corporate-sponsored FUD made a lot of people wary of the GPL - which is ironic, given its protective features.
There is a certain level of reasoning where one might say that, if the software were truly libre, you could "just" fork it and rip out the parts you don't like. But because you clearly can't "just" do that, then the software must not be free.
Yes. The software is not Libre.
But it's not clear to me that this is the case because the system is hosted on Azure or the distro is Ubuntu. Your rights within a marketplace go only so far as you can throw your alternatives. Software, especially operating systems, are just too complex to expect the concept of Free Software to be sufficient to protect user privacy.
Another interesting question: aren't you a direct customer of Canonical here? When you buy stuff off of any marketplace or though a reseller, it seems to me you are a customer for multiple companies. Examples: buying an iPhone from AT&T, buying a laptop from Amazon, buying a Subaru through a dealer.
When you get it a certain way through Azure you both enter a contractual agreement with each other, and that does make you a customer.
That (enterprise support) is a very important side business. Whether they got cash from other OSes or just set it up the same to fight an eventual Anti-Trust Case is anyone's guess.
edit: The data doesn't just magically show up in Canonical's CRM. They spent time and effort establish an integration with Microsoft and then building processes on top of that data.
It’s like if you tell a friend that there's a key to your back door under the mat but to keep it a secret and instead of keeping the secret they tell a mutual friend about it and that mutual friend robs you since they know where the key is.
You shouldn’t trust the friend that told the your mutual friend where the key was and you shouldn’t trust the mutual friend who robbed you.
The friend who told your mutual friend may have done so for what they thought were useful reasons, like letting the mutual friend know so they could fix something for you while you’re out, but they still violated your trust non matter what their intent was.
In the business world, having data marked "customer support only" is pretty common. There are quite a few laws acknowledging the difference. Importantly, the data is supposed to be kept separate and it sounds like Canonical screwed up here.
Neither one is an innocent party.
Companies now leak alot of metadata about what they are doing. If a teeny company like Canonical is mining stuff like this, consider what Microsoft knows about how you use their products, and I'm sure your EA negotiation as a big company is at some level driven by what they know.
Canonical is the one who violates trust here. Because they are using this information for marketing purposes, which they are not allowed to do under the information sharing agreement that they have with Microsoft.
So yes, we could argue whether Microsoft should be providing the installation information in the first place. It should at the very least be opt-out (on by default with the ability to not share), and preferably it should actually be opt-in (off by default, check a box to allow). So there is a violation of trust going on here, but this isn't any different than every other major tech company is guilty of right now (not that it makes it right).
But Canonical is the one that took the information and used it in a way that was never agreed to by either the person sharing the information (Microsoft) or by the user via the ToS (the ToS says that it is strictly for tech support, not for marketing). Canonical is the one that really overreached here.
An unstated assumption of using any "free" product is that it's not actually free. Canonical screwed up, to be sure, but I do think many of us just expect getting harassed by salespeople to be the cost of using a "free" product.
Microsoft, on the other hand, charges me by the hour for using Azure. They've taken their pound of flesh, so my business expectation is that I'm going to be left the hell alone for anything other than billing matters. Them sharing the data in the first place, for something I've paid money for, FEELS like the bigger violation to me.
For a linux distro, my expectations are that it's "free" but support will cost you money. My expectation is not that it's "free" and the OS will spy on you and report back to HQ so sales can make more sales.
If I don't give personal information on installation my expectation is the product is not harvesting or forwarding that information (For example, I expect that with Facebook, I don't expect that with GIMP).
Both are certainly wrong IMO. MS for giving personal info to a 3rd party and Canonical for bundling spyware with their OS. Both are super icky.
And you're selling the information in order to get tech support from Canonical, otherwise you can get it without selling your info (but won't really receive tech support).
As an aside, "pound of flesh" doesn't mean "payment", it means "something that is one's legal right but is an unreasonable demand (esp in the phrase to have one's pound of flesh)", both in Shakespeare and in current usage.
Unless you feel Microsoft's price is unreasonable and you have no other option, "pound of flesh" isn't the right expression.
Something like "they've taken their cut" is more accurate.
Too late to edit, though.
I wonder what have the consequences been for that guy.
I don't think the (non-)apology even gave that much, just that the training/policies will be "reviewed", which is even weaker:
>>In light of this incident, Canonical will be reviewing its sales training and policies.
Pretty ironic considering the meaning of the word "ubuntu".
- Azure is the second largest cloud provider worldwide
- Ubuntu is probably the most common Linux distro installed in the cloud
- We never heard about another episode like this before
Now if Canonical was allowing / encouraging this kind of behavior from their sales rep, I think we should have seen it happen in the wild before (like, a thousand times?) already; since it only happened once, I'm inclined to believe them. Also see [1]
Now let me think: I'm not OK with Canonical accessing my contact information because I spin up a VM, but I'm also not OK with Microsoft sharing my contact information with Canonical. What's wrong with "let me call them if and when I need?" But I'm European so maybe a little too privacy focused.
[1] BTW: let's say 99% Ubuntu VMs are spun to host some boring Wordpress site, nuvelle cuisine blog or leather shoe shop. What's the chance of an Ubuntu sales representative to ever make a sale this way? I guess it must be pretty slim, so he'd have to contact hundreds of potential customers to turn a few sales - something that would quickly get reported if it was a corporate business habit. This reinforces my first impression.
You know what they say, the definition of "gaffe" is when someone tells the truth.
But where they specifically went wrong? Well one of them was absolutely the way the "point of contact" reached out. If my professional email was shared with you as part of a professional agreement, adding it to a mailing list to sell me on the paid version of what I used for free makes sense. Sending some of those specific details to my personal account, which by the way you aren't sure is actually me, is way over the line. The salesperson personally screwed up big time there for sure.
The other thing is the granularity of the data, and that's also over the line. I read that agreement and think sure - they'll know our company has used their company. But specific actions taken by specific developers? There are users that avoid certain providers like the plague because in some way they're competitive, and even if they trust them not to directly compromise security measures, interfere and steal data - they still don't want a competitive company having insight into their costs, development, traffic, etc. This kills the trust you may have in Microsoft from that standpoint.
I mean, is it even possible to buy an Oracle license without Oracle knowing who you are?
In Canonical's statement they never regretted using the information to contact the user. The part they regretted was TELLING the user that they are monitoring the installs and linking those installs to personal contact details.
Canonical promised to improve training to avoid those "poor choice of words", NOT to stop the practice. Basically they will train their staff to make it feel more serendipitous when they just so happen to reach out about selling an enterprise license moments after you install the VM on Azure. Canonical doesn't regret this sales practice and plans to keep using it. That's the scary part in this story.
>A look at the terms for the Azure Marketplace throws up this sentence: "If you purchase or use a Marketplace Offering, we may share with the Publisher of such Offering your contact information and details about the transaction and your usage."
So the publisher of something on their Marketplace gets some information.
This doesn't seem 'that' weird (well the linked in contact does) as it seems semi related to ... say apps and app stores and etc.
Edit: I'm not justifying the policy, but I am noting that on a marketplace with third parties, this seems pretty standard / something you should always consider when you install something from a third party.
The idea that a AWS or Aszure market place with third parties involved is different than say my example, an App store with third parties seems like a good way to think about it.
I'm not justifying the policy, but I am noting the context isn't that different and how we should think about it.
For warranty purposes of course
> You buy soap from Walmart. They send your name and address to Johnson & Johnson.
In case they need to recall the soap
> You buy a sandwich at your local deli. They send your name and address to Boar’s Head. Cool?
So you can get some cool Boar's Head swag!
Just kidding of course. We need much better data privacy protection.
I can’t even imagine what that might be. But technical support for my sandwich making needs would be fun. Kind of how Butterball (I think it’s them) has a help line on Thanksgiving for cooking turkeys. They made the news a few years ago by hiring men to work the phones because they learned that men cook more frequently now but feel uncomfortable asking women for advice. I had a good chuckle at that.
A mounted boar's head to mount on the wall that makes grunting sounds when it's sammich time. But being HN, it'll also have cameras for eyes (3d) and microphones in the ears so that it knows when it is time to re-order more product. Maybe it'll link with Alexa/Siri/GHome with an articulated mouth so that it makes it look like it is Alexa. If you place it where it can see the contents of your fridge and/or pantry, it will be able to automatically order food for you.
The lack of imagination these days... /s
I mean, you do anything for long enough, you get good at it. Especially if you're soliciting feedback from even more people who are doing it.
I think somewhere out there there's a story of a Brita customer support rep tracking down a filtration engineer to get a technical answer to how long one could filter and drink urine for.
Since most appliance manufacturers require you registering your product with them for warranty service, yes, please take care of that for me (many appliance stores do). Now _should_ Maytag require that registration? If it makes for a quicker and smoother warranty service process then I'm okay with it - better than needing to dig up a receipt in three years, only to find that the thermal printing has faded.
Manufacturers legally have to honor their warranty regardless of you giving them your information. They don’t exactly say you won’t be covered by warranty if you don’t “register”, because they legally can’t.
In my most recent case I received such a packet 6 days after the date they said they activated the service. I called the same day and told the agent I wanted to cancel my trial subscription, citing specifically that I did not want the service and refused the terms of the agreement. The retention script (which is the same no matter which agent you talk with) is, "well you can keep the trial going and it will just expire", and repeat it several times. You have to be persistent and use the language "cancel my subscription", or you will get nowhere.
To be clear, I do not think any of my efforts will get my contact info out of their databases. Auto purchases are recorded publicly (at least in my state).
My comment above was about the extent to which Sirius, as a company, puts up hurdles to protect their nuisance practices, including shrouding them with legal claims that they will defend at the highest levels of jurisprudence. They lost their case in 2014 and updated the language in their agreement, presumably to address the weakness of their previous agreement, since it still claims to bind the customer without any action on their part.
In any case, I do not want to derail this thread any further.
If you bought one, your information was shared with the entity ("Radiotjänst") in charge of collecting the mandatory TV fee (funding public service radio and TV programming).
The fee is now collected as tax instead, so that's no longer the case.
Again, think of the grocery store example: you go in, there is a Boar's Head counter where they sell sandwiches. You grab a sandwich and head to the checkout line. You pay the grocery store worker who is wearing a grocery store shirt and get a grocery store receipt that says you just bought a $5 sandwich and used your grocery store loyalty card. Do you expect that Boar's Head will get the details of your loyalty card, which sandwich you bought, what else you bought, etc. even if the back of the receipt says in fine print that the grocery store may share that information with someone?
If Boar's Head had their own clerk and their own cash register you'd be doing business with them. But then it would be clear cut, right? The fact that the grocery store is processing the payments and presenting it as essentially they are reselling Boar's Head products would imply that Boar's Head is not involved in your individual transaction.
If this is a service you are buying from Boar's Head but they simply use the grocery store's cash registers, accounting, inventory, etc. then I would argue it's on the grocery store and Boar's Head to make it crystal clear who you are doing business with, or else you run into situations like this. And if a situation like the one that started this whole debacle happens, their response should be "We are sorry. We never made it crystal clear why we get this information. You see, we are partners with the grocery store and when you buy our delicious sandwiches from your local Piggly Wiggly you are actually doing business with us. We know it's in the grocery store's TOS, but we think it should be clear that you are actually our customer as well when you transact business with them for our goods. This is to provide benefits X, Y, and Z. If you don't want to do business with both Piggly Wiggly and us, here are some alternatives to get our delicious sandwiches elsewhere and some recipes to make your own. In addition, this incident happened because our sales staff was not properly trained on how we should use our customer data. We are going to review our privacy policies and publish an update in six weeks or sooner with what we will be doing going forward. If you have any concerns, please contact me directly. XOXO CEO of Boar's Head."
It's OK for the grocery store to see my data for because I explicitly consented for them to do that when I gave them my name and address when I filled out the loyalty form. Same way that I need to give some info to Azure to create an account, right? They aren't an anonymous service. But it's an active opt-in situation. You give them your info. They don't just take it.
There was much concern, but this isn't THAT different than any other marketplace. Gotta treat it that way.
We should praise Apple for not giving our identifying info to app developers.
> I belive you spun up the VM based on an image from the Azure Marketplace, specifically one from Ubuntu. That is not a microsoft image, you accepted an offer from Ubuntu and now they contact you to follow up. That's my understanding of the situation. Hopefully someone can clarify
> Where exactly it is visible any ToS?! As soon as I clicked on "add new VM", the first option suggested was Ubuntu 18.04. I didn't dig into the Azure Marketplace. I just picked the first option available since I quickly need a linux-based test VM.
I mean, I'm not as familiar with the AWS marketplace, but I use the GCP marketplace, and when I choose an offering from that marketplace it's very clear I'm just buying a prepackaged solution from another vendor, and I'd expect that other vendor gets my info. IMO this is very different from choosing the OS for your VM from a dropdown.
If I'm buying a SaaS or DBaaS from a vendor over a marketplace, or launching a metrics collector where phoning those metrics home is a core value prop, I'd be fine to be told that sharing information with the end operator, not just the marketplace, is necessary to fulfill the transaction. And there should be contracts in place to ensure my data's not used for unrelated purposes. If the operator breaches those contracts, the operator is liable.
But in what possible way is "using a pre-packaged Linux distribution" a transaction where sharing information with the packager is "necessary?"
I have no doubt that Microsoft's lawyers have covered their posteriors here. But the spirit of these regulations would be that users don't have the expectation that they're opting into Canonical getting their info just because they use a bog-standard Ubuntu distro. Users didn't knowingly consent to this.
(EDIT: not a lawyer, not legal advice)
https://twitter.com/LucaBongiorni/status/1359737285118410752
If we accept that the Ubuntu image is a marketing device then this screen is using dark patterns.
This is the last part of the Microsoft statement:
"Our terms with our publishers allow them to provide customers with implementation and technical support for their products but restricts them from using contact details for marketing purposes"
Canonical then tells us that this person was a Sales Representative, and it is clear from the content that this is a message aimed towards selling. Canonical has broken Microsoft's terms. That said, I can't see where that legal restriction is (e.g. can't see anything like that in https://azure.microsoft.com/en-us/support/legal/marketplace-...).
The part I find the most enlightening (ie: disturbing) is that Canonical's only regret is that the sales rep used "a poor choice of word" and they will train their salespeople better.
I assume the "poor choice of word" was when the salesman said, "I saw that you spun up an Ubuntu instance". Was Canonical's biggest regret that the salesmen INFORMED the user that they are monitoring installs and linking them to contact information?
Canonical never said "oh the salesperson wasn't supposed to market to you with this information", instead they basically said, the salesman wasn't supposed to TELL YOU that we are monitoring what you install and linking it to personal contact details.
Exactly. The old "I'm sorry I got caught" and not "I'm sorry I did it."
The word "better" does not imply a commitment towards customers and/or investors. *The word "do" should not be seen as referring to the taking of any specific course of action which may or may not yield tangible change. *The word "can" does not signify a concrete ability and is not forward-looking. *The word "We" should not be interpreted as Canonical Ltd. nor any of its subsidiaries or affiliated entities.
>It Depends on what the meaning of the word is is
There's a big difference between "is" and "was". Which is what he should have said. There were no semantic games in that particular statement, in stark contrast to some of the other things he said.
The sales rep was probably expected to reach out claiming some other reason, making it look like the standard LinkedIn spam, but in reality much more targeted.
I don't really understand why everyone is up in arms here. In this case, Microsoft is basically a reseller. They told Canonical that they sold one of their product to a customer and Canonical reached out on LinkedIn, a professional social network. It all seems fair game to me. This is not some creepy internet tracking using dubious way to segment people. This is basic direct marketing in a B2B context.
It's all pretty tame.
Well maybe it is ok from that perspective. However my personal reaction as a customer to such sales approach would simple be something in line of GFY to that salesperson.
It is actually completely unacceptable on what is advertised as a secure platform to engage in targeted marketing AT ALL. If any information about what my company is doing on your platform is shared to other companies, then you are not secure by any definition of the word that I'm aware of. It is not for you to judge what information is valuable or damaging for us.
Security and data sharing have nothing in common. It is perfectly acceptable to share customers list when you are resellers if you clearly state you will do so in the contract. It doesn't become true because you write it in all cap and say it is not for me to judge. If you so value your company information, maybe you should start reading what you sign.
Once again, we are not talking about an unreadable EULA for personal software. Azure is a platform geared towards professional. Nothing creepy is happening here. That's Canonical reaching out and giving a potential customer a point of contact if they ever need support. This has nothing to do with broad data collection and spying and is perfectly reasonable. I don't understand why some commenters here find the idea of talking with an actual human being so traumatic.
> If you so value your company information, maybe you should start reading what you sign.
Is exactly what people are up in arms about. Even reading the EULA, you may not expect Microsoft to permit data sharing in this way. And if this is entirely unacceptable for you, then it's time to leave Microsoft.
Or you can make noise about it online like this, and cause Microsoft to realise this sharing will lose them customers. I doubt the data is worth the churn, and Microsoft will likely change the policy rather than lose the customers.
Canonical never said "oh the salesperson shouldn't have had this information".
There's only one way they could have used it.
It's probably part of the contract between MS and Canonical.
"Customer privacy and trust is our top priority at Microsoft. We do not sell any information to third-party companies and only share customer information with Azure Marketplace publishers when customers deploy their product, as outlined in our Terms and Conditions. Our terms with our publishers allow them to provide customers with implementation and technical support for their products but restricts them from using contact details for marketing purposes."
My interpretation is:
Every time you buy or use something from the Marketplace, MS will give your contact details to the Marketplace publisher. That publisher is then restricted in what they can do with the information. They may not use it for Marketing, they may use it to provide technical support.
And if the answer to that last question is no, what can Canonical do with the data that's actually valuable to them? If I were given access to a database of sales leads that I was explicitly disallowed from contacting, I would actively avoid even accessing the data to avoid any accusation or perception that I violated those terms, just in case I independently got in touch with those same leads through a different channel.
Interesting that this is not so.
Microsoft being lily-white (/s) would ensure they had GDPR-like positive consent from customers that they could pass on those customers info to specific third parties...
The idea that companies keep some sort of information wall between their support and marketing departments is pretty ridiculous. MS have to be fully aware of this, surely.
So, the story is Canonical taking part in the same crap as the more overtly crap companies, and just this one agent not being clever enough to keep their leads under wraps.
GDPR obliges companies to provide information on all this parties PII has been passed to. Given cookie lists (or UBlock blocked files) are hundreds of companies long I'm surprised we're not getting reports of who is buying up all this info.
The data on who was doing what would be useful for providing implementation and technical support to people who has already contracted with Canonical for those services, both for providing the service and, depending on price structure, possibly for billing.
So then why should everyone else who doesn't have any contact with Canonical have their data forwarded to them too? This should be opt-in rather then opt-out, let alone always happening with no way to opt out
“The first rule of the the surveillance economy is don’t talk about the surveillance.”
Of course they have the raw data, but it's possible the people who sent that tweet just have access to a database that contains only anonymized data.
I don't understand - what's the difference between marketing and sales? Sales is trying to sell you something? But that's also marketing?
I haven't trusted Canonical since I noticed their pattern of creating competing alternatives to new Linux standards instead of helping them (Mir & Wayland, Snap & Flatpack, Unity & Gnome 3). It'd be one thing if they were bringing better ideas and long-term support to their alternatives, but they just seem to be half-baked copies. I appreciate all they've done for the Linux ecosystem, but I'll stick with my Debian.
Snap came BEFORE flatpak. Flatpak was the "new competing standard" in that situation.
And Gnome shell, quite frankly, sucked. IMO it still sucks, but back then it sucked WAY worse.
At the end of the day the scorecard reads:
- Mir: failed
- Unity: failed
- Snap: mostly failing
Meanwhile RedHat takes over stuff that doesn't work, makes it work a bit better, and pushes it on the whole ecosystem as "the" solution. And they win, and win, and win.
As much as I hate Snap and remove it from my Kubuntu systems, I don't see where it is failing. I frankly see a lot more non-linux-focused vendors support to snap than flatpak. Could you expand on that point?
It’s not a question of which one will succeed between snap and flatpak, it’s whether the ecosystem really needs either one of those.
Unity didn't fail: ongoing development on it was cancelled because there was no way to successfully monetize it. It was, and remains, one of the most successful desktops out there.
If your definition of community is "people who develop desktop environments for open source software" then you're already limiting the size of your community to a few dozen or so individuals, and we had a few dozen contributors to Unity so I'm not convinced of the strength of this argument.
If your definition of community is "people who don't use Unity" then of course "everybody knows" that's trivially true. Some people also know it's a tautology.
unity failed because they abadoned it, but it was way better than wayland+gnome. the problem was that it was based on gnome2 and had mir under its belt, so it would've been really really hard to somehow upgrade it
What exactly is it that you think Wayland couldn't do and why was it necessary to invent an incompatible application interface to achieve that?
> Snap came BEFORE flatpak. Flatpak was the "new competing standard" in that situation.
And AppImage came before snap.
From the mir technical architect (found on askubuntu): https://samohtv.wordpress.com/2013/03/04/mir-an-outpost-envi...
> And AppImage came before snap.
Exactly right! And if the ONLY goal was compatibility, we all should be using appimage over snap. But snap was and is trying to promise more in terms of end-user security and transactional updates from the vendor. So there is a legitimate reason to make something new.
In general, I personally prefer the way Debian works (Debian the Project - not the Distro). It has a board of elected developers governing the project. I would prefer that over somewhat opaque functioning inside a company (Canonical).
To cite as an example, here's how they decided on the question of init systems [1].
I even tried to install Debian while I'm still not really used to Linux, but the graphics card immediately crapped itself on boot, so it will have to wait...
Nvidia was the least terrible solution about 10 years ago (I have PTSD from installing binary blobs and editing Xorg.conf to make it work.) While others have improved tremendously and you don't have to do anything to get full 2D and 3D acceleration (just boot the system), the Nvidia experience™ hasn't changed much since then.
Some of them nice projects in their own right, but it's hard the shake the feeling of NIH syndrome.
I'm starting to learn too much about apt to try and prevent things from reinstalling themselves.
What was the poor choice of word?
I get that the whole concept is poor. But what word or words?
(did something that you didn't expect me to see)
1. Agent had enough details at hand to confirm that the LinkedIn profile was indeed that of the customer.
2. Access to LinkedIn profile itself (e.g. profile URL).
If 2. how did MS make that association? AFAIK there's no mechanism for the user to connect LinkedIn profile to Azure or vice versa.
P.S. I know MS owns LinkedIn.
That's also why I use Sublime Text instead of VS Code and run a private Gitlab instance instead of developing on Github (barring open-source work, which I do in the open anyway), as I'm pretty sure MSFT will find an excuse to mine my telemetry data for their own benefit eventually.
It's actually legal to send unsolicited spam to business emails sadly.
A few months ago I spent like a week or two playing with Azure Sentinel -- I'm a contractor for a company that develops some security solutions, and I was trying to see if and how the feature I was working on could be integrated with a SIEM. Sentinel, of course, was one of 'em.
So I do my thing, then a few weeks pass, then out of the blue, one afternoon, my phone rings...
...and there's a Microsoft representative at the other end, asking me what I thought about Sentinel, if I encountered any difficulties with it, what my plans are and so on. She seemed to be working off a full report of my usage, too, as the questions were pretty specific.
Thing is, my total usage of Microsoft Azure Sentinel was on the order of, what, 16-20 hours? spread across several months. I don't think I've issued 50 request in total, and I would've issued less than 5 if Log Analytics didn't take like forever to show my data on the free tier (not that I'm complaining, the price is unbeatable :P). I was on the free tier the whole time, it seemed like such a gimmick that I didn't even bother going through the company I was doing all this for.
Either the Azure team is desperate for customers or they have more salespeople than Oracle has lawyers if they ended up calling a small fish like me.
I don't agree with any of it, it's a violation of trust and burying it in small print doesn't change that. But having people reach out on their personal networks takes the cake.
The negative impact of this goes on his shoulders where the positive responses from this get passed off to someone else who is outside the blast radius.
Stuff like this is the norm when sales is viewed as an extension of marketing ("we need more leads") and not as a function that helps companies coordinate the evaluation and purchase of software ("we need to find out if this is the right fit for them") and the ones who pay the highest price are at the lowest levels when it's executives who are giving the orders.
Well, in this case, people are mad at Azure/MS and Canonical for betraying developer trust, not the individual salesperson. He's just a pawn in the game. It's not like this guy went rogue; this is his job.
The system is setup in a creepy way to enable this type of upselling, which makes people uncomfortable. Whether or not Azure or Canonical change policies, we shall see.
It's still his linkedin profile plastered all over twitter right now though more than Azure's EULA/T&C's.
And indeed the Azure T&C's are definitely referenced a in the Twitter discussion with the OP. Such as:
My reading of this statement is that they are scapegoating the guy.
I really hope he comes out of this unscathed.
The actual quote acknowledges that the company's training and policies are at fault. I'd also expect a scapegoat to be publicly fired or disciplined, did they say that elsewhere?
This was their official statement regarding this matter. They provided this to The Register to defend their actions when this story got written up: https://www.theregister.com/2021/02/11/microsoft_azure_ubunt...
Edit: Yes so just to be clear, according to their official statement they are scapegoating the salesman. They call him a "new Canonical Sales Rep" to imply he isn't experienced and made a mistake. The only responsibility that Canonical took is that they will "review its sales training".
Canonical said that they need to review their policies. To me, this implies that what he did was not against policy.
This is pretty disgusting that someone didn't think to cover his name or image while complaining about what is essentially privacy and having a central beef with two companies. That said, while it's disgusting to me, it can easily be shrugged off as "thoughtless" by others because privacy is not a mainstream concept.
I log on there and it's all spam-ish content. And really all I want to know is what people I worked with are doing now / how they're doing....
It's a sickening mess of PR giddiness but unfortunately it's needed to get a job nowadays.
I hate it so much though, never post anything and I only accept people I actually know.
The employee was referred to as a salesperson. Any difference from marketing is pedantic.
As I said no court would ever agree that “I’m your point of contact” is marketing.
1: https://www.goodreads.com/book/show/192408.Normal_Accidents
We don't know that
It could also have been that this person, just in the company and wanting to make a sale has used leads he wasn't supposed to act on.
I can definitely see an inexperienced person doing that kind of mistake. Not blaming the guy, he was just trying to do his job and meet his targets.
But I've seen a lot of "stupid" things done by new people at a company with various degrees of "making the customer or other departments annoyed" (in sales and in technical positions)
I demoed it with 5 companies to a member of the sales team, and he politely asked me to remove the script from the company laptop, and seemed to be annoyed at my script kiddie antics. He said it was nearly impossible to build a lead out of that kind of information, and that any shop that would try and use that kind of poisoned fruit would quickly tarnish their reputation.
I think one of the caveats to that is good sales folks probably would do exactly as you describe. But there's always good sales folks who are making sales, and then the desperate ones who have nothing but time on their hands to try other things simply because they have time on their hands or are desperate.
There are always starving dogs out there.
https://twitter.com/LucaBongiorni/status/1359885001844744195
Some devs have complete disconnect from reality.
(ofc he screams #censorship)
Also if you believe privacy is a right, you should ask that person before sharing this digital content he created that has hid identity in it, otherwise you should hide it.
For a paper letter it’s obviously different, once you received it it’s obviously yours.
Fair-use affirmative defence (under US law), fair dealing (UK),or equivalents elsewhere, may apply. Infringement claims, if any, would rest on thin grounds. Under the specific circumstances here, privacy claims likewise.
There is no copyright protection in the fact of communication. Nor in the details of who did so.
Generally I'd argue for a legitimate public interest in sharing the communication in cases such as this.
Only at the most primitive level of morality. Over that basic layer, I'd still consider how the publication of the message may affect the other person.
For example: Do you think it's morally OK to publish nudes that your partner sends you? I don't think it should be illegal, but only a massive asshole would publish their (ex) partner's nudes.
If you send me unsolicited commercial messages, I'm gonna feel no compunction about publicizing that you're a spammer.
In fact, by publishing his name you're giving the company an opportunity to throw him under the bus. It redirects culpability. Microsoft and Canonical should be the only focus.
Regardless, it seems abundantly clear that this is his _job_, and he is not at fault for following the directions of his corporate overlords. No one's saying to go trash his house, and all the information he posted (name, photo) is publicly attached to his linkedin profile that is accessible to any authenticated LinkedIn user.
Think it through for a second; if he had, instead of posting the name and avatar of the user in the screenshot, at-tagged the sales rep's Twitter account; would he have gotten banned? I think not. That's totally normal behavior on Twitter; it happens a billion times every day. And its exactly the same thing.
Twitter has, in the past, left Trump's account up for far, far worse offenses. They need to get their act together. The word I'm hearing around Wall Street is that Twitter's moderation strategy is one of the bigger reasons why the company is so undervalued, and investors are becoming concerned that there's too much Emotion, not enough Process, in their decision making, well, process. Its a critical thing to get right in a social media platform; too little and you get Parler or russian election interference, too much and it becomes unusable. Twitter is getting it wrong; very very wrong.
Azure is a big fish. If they managed to get that, they definitely got smaller ones.
I would recommend using debian buster. People lose their minds over systemd and it's ridiculous. Debian has been the best experience of any distro that I've used, and I've tried most of them. For my router I use openbsd.
The rest will run as well or better. FreeBSD is a more cohesive unit and by some claims is more performant than Linux.
tl;dr: no it won't be a seamless move because the only seamless move would be from Ubuntu to Ubuntu. But if you are willing to explore tech that isn't the current in-vogue stack you will find some really cool stuff in BSD-land. And their rc.conf is a pleasure to work with compared to to the million config files you need to use on Ubuntu/systemd.
Additionally, orchestrating is simplified with docker-compose vs managing many jails. I used to manage freebsd jails via cli in FreeNAS, but orchestration with docker-compose is much easier and trackable in git. Transferring between machines is as easy as setting up docker, git cloning, and setting secrets. [0] Podman solves some issue docker has, but using stuff like S6 [1] in containers helps a ton. Perhaps most importantly, docker images are reproducible (for the most part) while jails only have templates, so it's up to you to manage reproducibility.
Don't get me wrong- OpenBSD and FreeBSD are amazing distros. OpenBSD has the best user experience in my opinion, which is why I use it for my router. But they suck for modern gaming and stuff like docker.
"custom-compiled nginx version downloaded off some guy's FTP"
This is a strawman argument. But, sometimes one might want custom compilation without installing a host of build tools on the host system. Or one might want to have a reproducible build not tied to the host system. Compilation may be expensive (like with ffmpeg) or the host may be underpowered like a Raspberry Pi. Etc.
[0]: https://github.com/andrewzah/lilac-docker/tree/main/services
As far as do you need Docker in the first place? Well maybe. One of my favorite orchestration and deployment systems I built was based on packaging everything as .deb files and running our own apt repo. Since all workstations ran Ubuntu and all servers ran Ubuntu getting our system up and running was as easy as adding our custom repo and running `apt-get install our-custom-project`. apt is great for resolving dependencies and this way we don't end up with a mess of files all over the place. Plus this way we got all the benefits of not having to update every container when a libssl update was required. Just run `apt-get update && apt-get (dist-)upgrade` and suddenly you are fully up to date and restarted.
Orchestration on this system was accomplished by using puppet to set up the custom repo, install the packages, install all the current config files for the system services as well as our own, and starting all the services in order. Reproducible to the point where when one of our servers (we had a few pieces of beefy physical hardware) blew up, we simply set up a new one, ran the puppet manifests and were back to full capacity within like an hour. Mind you this was back in 2010-2012 and tooling has only gotten better since.
This type of thing also allows you to nicely package any custom versions of software you want as well. Want a custom build of nginx? Go run the script that builds it and makes a .deb out of it, then upload to your repo. You aren't relying on some guy with a blog post to keep his server up. You aren't even affected by GitHub going down if you don't host your apt repo there. Or use it out of a PPA someone else maintains. But there is zero need to wget/make/make install with this setup. You aren't doing reproducible builds because it's a build once, run everywhere system. And it makes you very directly consider what your dependencies are. Do you really need that unmaintained library written in an esoteric language that requires a SPARC to compile? Docker allows you to hide bad dependencies behind the idea that they are inside a container so the harm they can cause is limited and the headache is localized. But that just treats symptoms, not the problem.
Admittedly our company is small (~5 fulltime devs), but we have: mac osx catalina, debian buster, debian bullseye, and ubuntu bionic beaver. So precompiling .debs won't work here. Docker gives us all a common ground, minus some wonky mac docker issues with DNS.
Also, this assumes that one is using a server in the first place. We run our own kubernetes cluster that we automatically provision and deploy pods to, so there is no server to upload files to.
"You aren't relying on some guy with a blog post to keep his server up. <...> And it makes you very directly consider what your dependencies are. Do you really need that unmaintained library written in an esoteric language that requires a SPARC to compile? Docker allows you to hide bad dependencies behind the idea that they are inside a container so the harm they can cause is limited and the headache is localized."
Again, this is a strawman. You can butcher things with docker, or without docker. The same can happen with i.e. Ansible & Terraform (which we also use). I can, and do, analyze our images to see what we can reduce to. Most of our images are either on Scratch or Alpine Linux, thanks to multi-stage builds.
Since each build is localized to a container, we can independently update images and not have to worry about dependency mismatches, or random directories being modified, etc.
My opinion will be biased because I've written at least ~120 docker images in the last two months and spend a good bit of time tweaking and optimizing them.
That does make it more difficult. Docker does sound like the common ground then.
> Again, this is a strawman. You can butcher things with docker, or without docker. The same can happen with i.e. Ansible & Terraform (which we also use). I can, and do, analyze our images to see what we can reduce to. Most of our images are either on Scratch or Alpine Linux, thanks to multi-stage builds.
It's a related argument. My point is that Docker allows you to take shortcuts too easily compared to other methods. And when you are faced with figuring out how to make your software work with widgetlib 1.0.4 provided by the system instead of widgetlib 1.0.5 which is what you originally built it for, you have a choice of packaging 1.0.5 yourself and potentially doing that improperly (make && make install inside a Docker container, paying no attention to dependencies or upgrades), or properly (by creating a standard reproducible build you can track). Docker allows you to take the shortcut easily. It's a powerful tool and it does allow you to create good images, but I have also seen some terrible ones (just like I've seen bad examples of .deb packages, but a lot fewer of them).
Regardless, it's about how you work and how you structure things. I am coming around to Docker as a workflow, but I doubt I'll be creating 120 microservices to run one project anytime soon. Too many things to keep track of and update.
* They show you ads on login
* They periodically phone home with: Ubuntu version, kernel version, architecture, CPU model, curl/wget version, cloud (if applicable; aws/openstack/...). This is part of the delivery system of the ads mentioned above. See /etc/update-motd.d/50-motd-news for the actual script.
Ubuntu's however, is a free OS, so any cloud hosting can use it without major repercussions even without any support contract with Canonical. Any cloud provider that doesn't like this agreement, doesn't have to make it.
I've at least done this on AWS and have never seen anything from Canonical.
The one time we tried to set up SendGrid "from the marketplace", it failed horribly.
Because why not, it's allowed by T&C
What's interesting is whatif any enforcement action comes of this. It's not like MSFT can restrict Ubuntu image use on Azure; Linux is literally the majority of their usage. Can they sue?
Upon trying to install the incredibly common package I was given some error about it not existing and some nonsense about using snaps. I don't care about learning how to use snaps, I just want to get something done. I quickly installed Debian instead and got back to doing the work I needed to do. It really soured my opinion of Ubuntu - a distro I first used back when they were still mailing out CDs.
This furthers my negative opinion of Canonical and solidifies my position that I'll never use Ubuntu again. Debian it is for me if I need Linux.
Like you, I don’t care about “snaps” (though in my ignorance I’m willing to accept I may be missing out on something useful...)
Even when you go to their Download page for Server, the first option is not a download link but some blurb about “Multipass” which I’m pretty sure is not what the majority of people are looking for when they click a menu option called “Download” for a server OS.
But this LinkedIn crap is just awful and surprises me coming from Canonical.
However, I've never packaged anything for snap, so not sure how it is to use.
You get three options to run Ubuntu server.
The first option is to run Ubuntu server in a VM, and most users will want to run Ubuntu server in a VM. Multipass is a tool that helps you run Ubuntu server in a VM. Multipass is just a front-end for KVM when you use a Linux distribution. If you use Windows, it is a front-end for Hyper-V, etc.
The second option is to perform a manual installation, which means that you get the ISO and do your thing.
Between the two, most people would want to install Ubuntu Server in a VM rather than on baremetal. I think it makes sense to put that first. If a person is a power-user, then can read on and select Option 2.
I see that there is a perceived negativity on anything Ubuntu that if something is different, it is perceived as something bad is happening.
I don’t agree that Multipass is the obvious default way that most people will want do this, given that Multipass is clearly aimed at local workstations for dev/testing and not actually servers.
I’m working on the assumption that “Ubuntu Server” is designed primarily for servers, and Multipass, by its own description page is categorically not designed for servers. It’s for a secondary use-case of running a test environment locally on a dev machine.
My point was that it seems strange to push a secondary use-case as the first option on the download page.
I’m not saying this is absolutely terrible, but it was just an example of some seemingly unnecessary friction being introduced.
From the Multipass info page: [0] > “Ubuntu VMs on demand for any workstation”
Last week my son installed ubuntu on his cheap tablet pc. it worked flawlessly : wifi, sound, track pad and even touch screen. on screen keyboard worked. even the wacom tablet worked out of the box. when he was on windows he had to install a driver for it to work!
so I guess I'm not mad at ubuntu anymore. it's just not for me. or any linux geek. it's for windows users.
You can learn to use the windows controls on the left. I got used to using them and it takes a few days to feel at home. When sadly Ubuntu switched back to GNOME Shell and reverted this change, it felt really unnatural to have those windows controls on the wrong side. Still, you get used to it after a few days.
Honestly as a half-half Windows user the stupid window controls on the wrong side is a big enough turn-off for me that I won't even consider Ubuntu. I think it's for Mac users.
How does that cause user lock-in?
There is a usability package 'command-not-found', which is a handler for the shell and runs when the command you tried to run, was not found.
You mentioned though that you tried to install a package, the package was not found and got a suggestion to use snaps or something. There is no such thing as far as I know.
There are two packages, 'chromium-browser' and 'lxd'. In Ubuntu 20.04, both these packages are now only available as snap packages. If you try to install them with `apt install`, you get a notification that they are now only available as snap packages, and the installer transparently installs the snap package for you. This has been discussed a lot before implementing, and also here. The gist is that when you `sudo apt install chromium-browser`, you want the installation to work, not get an error message to run `sudo snap install chromium` instead.
Just my 2c. I'm not well-versed in sysadmin stuff.
Actually you could be right - that script does run `python3` after apt-get'ing everything it needs. Anyway..
I didn't look into it any further because I didn't feel like investing any time into learning the 'Ubuntu way'.
I installed Debian instead and it worked perfectly without any grief. It also worked perfectly on PopOS when I used it a few days later on a different machine.
Canonical can make whatever changes they want of course, I've just become increasingly less patient when it comes to machines not acting how I have come to expect. So I'll just stick to what works. Oh man - I'm becoming one of those old dudes...
$ snap search x
$ snap list
$ snap info x
$ sudo snap install x
I've interacted with snaps to a bare minimum, and I am sure all of those are correct. I am sorry, but "some nonsense about using snaps" -> "I quickly installed Debian" -> "this furthers my negative opinion of Canonical".
Talk about Canonical getting a bad rep for pretty much everything they do...
Here is the thing from my perspective though - I have never had any trouble with apt that has made me think 'I wish to use something else'. Apt works. It does what I expect it to.
When you're just trying to get something that should be simple done the last thing you want to do is spend a bunch of time learning a new system that you didn't even ask for.
When I try to use a project that includes a quick startup script that is rendered broken by something I don't even want...well I just move on. No big deal really, I'll just use Debian and if eventually I hit a point where I want something else I'll give it a try on my own time/terms. Not in the middle of trying to do something else.
We don't use anything from conanical at work and I've never signed up for anything from them that I recall. I remember at the time thinking it was weird to get this email when I had never before used an ubuntu server in azure. I certainly never expressed any interest in "running ubuntu in a secure manner on Azure" to anyone.
I received the email on June 6, 2020, and then several follow up emails when I didn't respond.
This was the message:
> With 85% of enterprises having either a mandate, preference or exploration of open source technology I've connected with many individuals, while working from home, who have reached out to discuss how we provide proactive security for Ubuntu deployments in the cloud. I understand you have similar interests around running Ubuntu in a secure manner on Azure.
> Ubuntu Pro, our carefully optimized image for production public cloud environments, provides all-inclusive patching for over 30,000 packages (for up to 10 years), FIPS 401-2 certification and Automated security profiles including CIS and DISA STIG.
> That is just a handful of ways we keep companies safe and I was hoping to show you more. How does your schedule look this week, or the next, for a quick chat?
Edit: a comment here links to an article with more details. MS shares with Canonical. Bad on both parts I'd say, at least weird usage of the data.
Starting a VM isn't a purchase of Ubuntu. It's a rental of compute, storage, and network resources. Any other definition is, quite simply, wrong.
Then there are a great many definitions of there that are quite wrong. Many references to organising a service and so forth.
This is probably one of those instances where the dictionary needs to catch up. A dictionary documents how language is used at the time of its compilation, it does not dictate how language will/should be used for all time forward.
(is it just my terrible coordination with this slide keyboard and lack of attention to see errors as they happen, or is android's auto carrot getting less & less reliable?)
Legally, freedom of contract means the specifics of what is to be exchanged in a purchase are more or less unlimited.
Even colloquially, many purchases happen without "money" changing hands. Paying with a voucher, for example, would seem to be a form of payment that doesn’t involve actual money.
Indeed, perhaps.
> or to stop making things up.
I didn't make it up but thanks for the insinuation.
> The Oxford Dictionary
I haven't spent $90 on the Oxford Dictionary because I haven't believed it to be necessary.
> defines purchase as merely "acquiring something".
Really? Tell that to Google which claims its definition comes from "Oxford Languages" [0]. I'm sure that's not quite the Oxford English Dictionary though.
Google states:
1. acquire (something) by paying for it; buy.
2. haul in (a rope or cable) or haul up (an anchor) by means of a pulley, lever, etc.
But that's just Google and we all know Google can be manipulated. Let's take the free definition from Merriam-Webster instead [1]. 1 a : to obtain by paying money or its equivalent
Okay how about a third source? Dictionary.com [2] states: to acquire by the payment of money or its equivalent; buy.
Finally, Cambridge at the fourth source, is where a monetary transaction isn't directly part of the definition but it certainly is part of the supporting descriptions. verb: to buy something
* She purchased her first house with the money.
noun: something that you buy
* How do you wish to pay for your purchases?
So they're all free dictionaries so they're not as elite as the Oxford English Dictionary. But their definitions are fairly consistent. And, given that I think that a purchase without money is actually a barter then perhaps the Oxford English Dictionary isn't as good of a source.You might want to learn about the definition of a rent by the way. It's a bit closer to what goes on with cloud instances.
[0] https://www.google.com/search?q=define+purchase
[1] https://www.merriam-webster.com/dictionary/purchase
[2] https://www.dictionary.com/browse/purchase
[3] https://dictionary.cambridge.org/us/dictionary/english/purch...
Anyone can bypass the marketplace by creating their own machine images, it's not too difficult.
The pre-prepared image part does perpetually have value - it saves you installing from a standard ISO and Azure-ifying the result, or having your own image pre-prepared from earlier.
It is a short while since I last spun up a fresh VM in Azure so I'm can't remember if this arrangement is made clear at all, though I do remember getting an email like the one discussed at least once last year.
Or when I download the various usage-optimized ISOs from Canonical's own site?
This is exceptional, and in exceptionally poor taste.
Source: https://www.docker.com/legal/docker-privacy-policy
See Section 3. Use of Information Collected
I'd say a reasonable person would not expect to do business with Azure and have all of their information forwarded off to Canonical.
It's a scummy arrangement and execution on both sides.
I don't want some "relationship" with a company just because I buy their product.
When you buy a product you agree to whatever terms there are, you only get to write terms if you’re writing up a contract.
This thread explains it in more detail: https://twitter.com/dezren39/status/1359726235929223168
Seems pretty simple. No real story, other than the OP not paying attention.
That southpark episode, while disturbing, amusingly is spot on.
You buy a toaster, and someone from the toaster company comes to your house to try and sell you a microwave. "I see you like to warm foods, let's talk about some other ways our products can help you with that!"
Wait, now I'm not confident that doesn't/didn't happen, geez...
You've never needed warranty support before? I'm not aware of ways in which that works without them knowing who you are, or where they should mail the repaired product back to.
What's extremely unethical is contacting the person over LinkedIn. It's extremely aggressive and a huge violation of boundaries, and proves that Microsoft is sharing personal information (names of users) with Canonical.
If I buy something online from a store, I would expect a few spam emails. But it would be completely unacceptable if a sales representative showed up at my house (despite me only sharing my address for billing/shipping purposes). This is basically what happened to the Azure customer.
I have no idea what you're talking about regarding "huge violation of boundaries", because there are none on LinkedIn. I get multiple DMs a week from folks I don't know selling something.
I'm not endorsing more ad spam, but I'm really caught off guard that using a service with a real name/email and getting added to a CRM is generating this level of indignation.
Do none of you guys work in corporate? I get Linkedin/email/phone spam all the time. This isn't new. The only interesting thing here is that the trigger and the response time were so short.
Again, I'm not advocating for more of this or even saying I like it. I'm just saying "why are we all of a sudden upset about this?"
As somebody who's listed products on the AWS marketplace, when you "subscribe" to a product you give them your information as due course. This is obvious, spelled out, and known across all the marketplaces. So I'll assume the part you take issue is, is with reaching out to the individual on LinkedIn instead of through Azure. I don't understand how in a world where companies cold call you after buying your phone number, and spam you with emails after you try to unsubscribe, suddenly messaging you on LinkedIn is over the line.
It's strange, and I'm glad they're moving away from the practice, but to pretend it's this big privacy fiasco is disingenuous at best. They (Canonical) still have all your data, they're just being more subtle about it now. How is that better?
3a spells out what you're agreeing to share with the publisher of the product in the marketplace when you subscribe to it.
Additionally the listings each link to their respective privacy policy right underneath the subscribe button, plainly in view above the fold.
Finally, I've just attempted to subscribe to "Ubuntu Server" in the Azure Marketplace to see what it looks like, and it shows you a form with the information it's going to share with Ubuntu on the screen for you to modify before subscribing! So it seems like you arguing this isn't "obvious" is in bad faith, because it's obvious for any reasonable person who's actually used the marketplace.
Umm the point of linkedin is to make professional contacts and a professional network.
> But it would be completely unacceptable if a sales representative showed up at my house (despite me only sharing my address for billing/shipping purposes). This is basically what happened to the Azure customer.
This would be like the sales rep turning up at your office during office hours and leaving a card for you.
The person used a corporate account and the person was contacted via a method used to contact people about professional matters.
Ummm... no?
The issue is the poster spun up the instance in the course of his job. Microsoft and canonical would be reasonable to share that job related info.
But instead it appears that either they shared his personal info which would be unethical, or canonical takes the de-identified job info and then matches it with personal info.
In most transactions between people acting as representatives of their business, it would be very creepy for one of the businesses to then get personal info on the representative of the other business like their social media accounts or home address, especially if they do it using secret/obfuscated manners rather than explicit asking.
What would be weird is sending me a message through there before the meeting. If we are speaking using another channel (like work email accounts), stay on that channel. This is what has gone wrong in this case.
No worries with sending a connection request after our meeting “nice to meet you today and looking forward to collaborating, cheers”
As a side note it’s always funny when we are in the middle of a meeting and a notification pops up that they have looked at my profile. It’s like “hello... pay attention... I’m right here...”
If their message went: "We saw you drove to XYZ using our model Y", addressed to a private contact line of yours, then that would also lead to quite a few "wtf?" along the lines of "What data is Hertz sharing with Ford?"
This goes to show that, when dealing with big corporations, even when you're paying, you're still the product.
https://twitter.com/dezren39/status/1359726235929223168?s=20
Shortly afterwards I had a missed phone call and then a follow-up email from an Azure salesman inviting me to schedule time to discuss my interest in the platform. I declined and asked to be opted out of anything like that in future, and actually received a pretty unprofessional response to that.
So even if Ubuntu aren't allowed to do this kind of thing, MS certainly have themselves in the past.
I kinda figured it was just verifying I was a human, but I've provisioned 10~ or so other VPSes and dedicated servers with a few different providers and never got a phonecall so it was unexpected.
The next 40 years will be filled with special coders adding hooks into everything looking for new monetization channels. Be prepared for this same WTF moment every 5 minutes.
I noticed you posted a comment on Hacker News.
Be sure to reach out if there’s anything I can help with?
My personal heroku account uses my personal email address, eg. jbob@gmail.com, but my enterprise account uses my full name, eg. jonathan.bob@bigco.com.
There's a sneaky CRM tool floating around that is connecting the dots on people.
If you have money and a piece of personal info (just about any combo of name+zip, phone#, email addrs, credit card, tracking cookie, etc), these companies can quickly give you full personal details including income and housing history, mortgage status, email addresses used, employment history and full details on your employers, plus all these details on spouses and children, pretty much whatever you want. It's remarkable.
One of the things I liked most about Ubuntu is that the installation process is incredibly easy and everything "just works". Does anyone know a good alternative?
I'd love to go all in on Alpine, but using it on the desktop doesn't exactly spark joy.
"Just works" type desktop: Don't use linux. Personally, Arch is my go-to desktop and IMO if you can't deal with that, just use macOS or something. There's lots of things that don't "just work" on Linux even today. Bluetooth audio for example has a lot of problems and those will be present cross-distro.
The distros have less and less meaning nowadays, they're just what software is shipped in repos and initially. Ubuntu does a lot of custom shit so you want to stay away from them. Debian is constantly out of date but if you don't mind that it's still a solid distro. Fedora has always been pretty good as well but imo is straight up worse than Arch for sort-of-the-same philosophy.
> "Just works" type desktop: Don't use linux.
That's why I preferred Ubuntu, it felt like a good compromise between a Linux system and ease of use (or rather ease of setup).
> Just use macOS or something. There's lots of things that don't "just work" on Linux even today.
That's actually what I'm currently doing, for pretty much that exact reason.
That said, I really want to switch to Linux as my primary OS again, I guess I'll give Arch a try.
> The distros have less and less meaning nowadays.
That's a good point.
Why? Could you point me to some other straws I've missed?
> Most likely you haven't used Ubuntu for a very long time.
It's true that Ubuntu has not been my primary OS for a while, perhaps I should've been more clear.
I _am_ still using it on various laptops and servers (and have been meaning to switch back to it for daily use), which is why I'm annoyed at the prospect of having to deal with finding an alternative.
Though I switched to FreeBSD myself for my desktop.
It's indeed annoying. It's not as bad as this example because it's the same company I already deal with, which actually makes this legal in Europe. But as someone who is (admittedly) very anti-commercial it annoys me.
The strong ties between MS and Canonical are also one of the reasons I dropped Ubuntu from my private life.
Another thing that really annoys me about this is that MS removed the "block sender" option in their "New and redesigned!!" version of Outlook for Mac. In many ways the UI of the new version is much better but I strongly relied on that version. They kept the "mark as spam" but it doesn't guarantee that sender is forever blocked.
That sounds gentle in comparison. I would use the opportunity to ask for free swag or training if it was possible. :)
Welcome to the world of Microsoft products.
Love the technology, but I no longer trust the organisation
It has not gone unnoticed to me that many seem to think that, say, Canonical and Red Hat are not corporations in the traditional sense, for which the customer is prey.
Although it is fun to think about the 90s version of MS embracing linux to this degree.
https://cloudwars.co/microsoft/microsoft-wallops-amazon-in-2...
https://build5nines.com/linux-is-most-used-os-in-microsoft-a...