Pretty ironic considering the meaning of the word "ubuntu".
- Azure is the second largest cloud provider worldwide
- Ubuntu is probably the most common Linux distro installed in the cloud
- We never heard about another episode like this before
Now if Canonical was allowing / encouraging this kind of behavior from their sales rep, I think we should have seen it happen in the wild before (like, a thousand times?) already; since it only happened once, I'm inclined to believe them. Also see [1]
Now let me think: I'm not OK with Canonical accessing my contact information because I spin up a VM, but I'm also not OK with Microsoft sharing my contact information with Canonical. What's wrong with "let me call them if and when I need?" But I'm European so maybe a little too privacy focused.
[1] BTW: let's say 99% Ubuntu VMs are spun to host some boring Wordpress site, nuvelle cuisine blog or leather shoe shop. What's the chance of an Ubuntu sales representative to ever make a sale this way? I guess it must be pretty slim, so he'd have to contact hundreds of potential customers to turn a few sales - something that would quickly get reported if it was a corporate business habit. This reinforces my first impression.
You know what they say, the definition of "gaffe" is when someone tells the truth.
Thinking about it though, a lot of it is a question of surprise and unknowns. I would find this message to be a lot better - "We see that you've taken advantage of the Ubuntu image that Canonical provide in the Azure Marketplace. I am available to you for (etc.)".
No. That's not better at all.
The mere fact that Canonical has specific information to reach me when I am not a direct customer of Canonical is a complete violation of my privacy.
Ubuntu is a free product. Canonical should not be able to find out if I (specifically me or my organization) allocates or runs 1 or 10000 instances of Ubuntu.
So MS sharing "their" customer details with the image provider seems more generous than evil. Provided there's a "Do not share" config option somewhere.
Ubuntu is gratis, so Canonical can't have coerced Microsoft into doing so; it is quite probable that one approached the other to make a deal, and that Canonical is paying a certain fee for this information.
I don't expect an OS based on an OS based on an OS based on a half-finished OS based on free software principles to have shady data-dealing attached, yet hidden from the people whose data is being dealt.
I mean, it's kind of ridiculous to think that you could do anything in a cloud environment system and not have your actions tracked. Hell, with automated load balancing and load-based billing, that's literally what you're signing up for.
Privacy protection is not an obligation, but transparency and openness is. Yes, you're not contractually required to not make a separate computer system that's proprietary and closed and disempowering, but that's so pedantic as to be malicious.
We're talking about a curated, supported, official image here, right?
If folks want to use a "MyUbuntuImage" they or someone else packaged and uploaded, more power to them.
But by pulling a Canonical image, you have a relationship with Canonical. Expecting that relationship not to exist "because open source" seems to be misunderstanding who does what work.
As to whether this should be opt-in, done, etc. is another matter entirely. But the fact that it exists at all doesn't feel particular shocking.
It's not like we're talking about everyone who pulls a RedHat image's info being sent to Canonical!
If I download packages and Ubuntu, and assemble my own image, or use one assembled by another org, probably not.
I think the disconnect is that for me, image packaging and updating is work, and that work has an author, and the author is deserving of certain rights others are not.
If Azure is auto-pulling Ubuntu images, building containers, and publishing themselves, then that's a different story.
I agree with the message behind this and obviously Canonical and Microsoft are both being extremely gross.
But Ubuntu as a binary image (or source code) is a very different product than a VM with Ubuntu pre-installed and pre-configured, which is what you paid for (and is why you got ensnared by their horrible anti-user license).
How? Why? If it's different in any meaningful way from just clicking "next" on the installer then it's no longer Ubuntu, and certainly not Canonical Ubuntu, that's pre-installed. It's become, at best, Microsoft-Ubuntu-Because-Microsoft-Added-Telemetry-For-Azure. Or it's Canoncical-Ubuntu-Configured-By-Microsoft-With-Azure-CLI-Preinstalled.
It's not "Ubuntu" any more.
When I'm paying for an official Azure version of Ubuntu on Azure, I darn well expect there will be a closer support relationship than the free desktop version.
Okay, but maybe other people don't want that if it entails their information being shared with a company they haven't initiated a business relationship with?
> haven't initiated a business relationship
????
To say that you have no business relationship with Canonical while paying Canonical to use Canonical software with official Canonical technical support is absurd to the highest degree.
You deciding to resurrect the comment because you happened to see it before I deleted it is really not OK. It's the exact kind of toxic hostile, creepy interaction I was trying to avoid from you by deleting the comment!
I thought your comment was interesting and merited a reply for others to see and discuss. But I see you disagree so I've removed the content of my reply.
Feel free to flag any comments you find particularly toxic or hostile. You can do that by clicking on the timestamp of the comment and clicking the `flag` link.
Or even better, let me know (like you have done so here). I can't improve myself if I don't know there's a problem.
Posting something and deleting it after it has been seen is basically gaslighting. Imagine the kinds of harassment people could get away with if they said rude things to coworkers on chat, then edited the messages to appear benign after the coworker responded to their hostility.
That is why people quote the text of comments to which they want to reply.
Furthermore is strenuous disagreement now toxic and hostile?
Wouldn't it be more trivial to say I do not wish to engage and leave it at that? Ironically calling someone toxic hostile and creepy is... pretty toxic.
I think someone has the right to change their mind about something they've said. That's why I edited my comment to remove it.
> Furthermore is strenuous disagreement now toxic and hostile?
I don't think so. But I know that I sometimes get passionate about my opinions. I welcome someone's input to keep me friendly.
> Wouldn't it be more trivial to say I do not wish to engage and leave it at that? Ironically calling someone toxic hostile and creepy is... pretty toxic.
I would like to think better than that. I think it was good of @ojnabieoot to let me know that they thought I'd wronged them.
Some people can feel very anxious or awkward to conversation for very good reasons. They can state opinions and then choose to retract their opinions for any reason -- even if the opinion is held but they choose to remove themselves from the conversation. I think that's a good thing to discuss but this isn't the venue to.
Ditto the Ubuntu images on Docker Hub.
This is a big misstep for Microsoft, from my point of view. I think it's less a reflection on Canonical, because once they have the information, it's ultimately going to be used. Microsoft just should not have agreed to the arrangement at all.
To quote the old native american (?) fable: You knew what I was when you picked me up.
I don't think that most of the people have a problem with that. The problem is being sucked-in to something without ever agreeing into.
In the era of privacy sensitivity (which I think is healthy), being watched in a place and prodded from a different channel is disturbing.
I don't mind people trying to reach me with the hope of sales based on information I've provided to them, but this is too far.
Also it removes two veils from both companies at once:
1. It seems Microsoft still has sneaky tactics, but they're more invisible.
2. Canonical is somewhat more aggressive and greedy than it seems, and Ubuntu desktop is just a freemium product, or another capturing device for further vendor lock-in.In this case, the license is the GPL, none of which has anything to say about privacy. Maybe this is a failure of the Free Software Foundation's to not include privacy protection in the GPL. Though even if they were to create a GPLv4, the Linux Kernel is still only licensed under v2, so distro implementors have no obligation to use a more restrictive license.
AKA, "the cat is already out of the bag".
In the OP's case, they additionally are are customer of Microsoft's, who explicitly stated they share this kind of information with their vendors.
Debian Free software guideline does not allow discriminate against using debian for evil.
Citation needed. RMS, the FSF and many other orgs made public statements around privacy many times.
Now, I can't exhaustively prove a negative, but I think I can easily demonstrate that the FSF has never meaningfully expressed an opinion on privacy. Go to https://www.gnu.org/philosophy/philosophy.html, open every single page it links to in the body of the text, and search for the word "privacy". It does not show up in the body text of any of those documents. It shows up once in a footnote that mentions a change that Samsung made had that "caused privacy concerns".
The closest they get to even mentioning the concept of privacy is when they talk about the right to modify software and use those modifications "privately", which clearly does not mean anything about user privacy.
If privacy were so big of a concern for the FSF, you'd think they'd talk about it in their official documentation on their philosophy, or put something about it in the ONE tool they have to have power over anyone: the GPL.
The anti-patent-trolling, anti-tivoization and copyleft provisions are there to protect developers and users.
Additional clauses around privacy and security would be very nice.
Unfortunately, corporate-sponsored FUD made a lot of people wary of the GPL - which is ironic, given its protective features.
There is a certain level of reasoning where one might say that, if the software were truly libre, you could "just" fork it and rip out the parts you don't like. But because you clearly can't "just" do that, then the software must not be free.
Yes. The software is not Libre.
But it's not clear to me that this is the case because the system is hosted on Azure or the distro is Ubuntu. Your rights within a marketplace go only so far as you can throw your alternatives. Software, especially operating systems, are just too complex to expect the concept of Free Software to be sufficient to protect user privacy.
Another interesting question: aren't you a direct customer of Canonical here? When you buy stuff off of any marketplace or though a reseller, it seems to me you are a customer for multiple companies. Examples: buying an iPhone from AT&T, buying a laptop from Amazon, buying a Subaru through a dealer.
When you get it a certain way through Azure you both enter a contractual agreement with each other, and that does make you a customer.
I don't think the (non-)apology even gave that much, just that the training/policies will be "reviewed", which is even weaker:
>>In light of this incident, Canonical will be reviewing its sales training and policies.
That (enterprise support) is a very important side business. Whether they got cash from other OSes or just set it up the same to fight an eventual Anti-Trust Case is anyone's guess.
edit: The data doesn't just magically show up in Canonical's CRM. They spent time and effort establish an integration with Microsoft and then building processes on top of that data.
It’s like if you tell a friend that there's a key to your back door under the mat but to keep it a secret and instead of keeping the secret they tell a mutual friend about it and that mutual friend robs you since they know where the key is.
You shouldn’t trust the friend that told the your mutual friend where the key was and you shouldn’t trust the mutual friend who robbed you.
The friend who told your mutual friend may have done so for what they thought were useful reasons, like letting the mutual friend know so they could fix something for you while you’re out, but they still violated your trust non matter what their intent was.
In the business world, having data marked "customer support only" is pretty common. There are quite a few laws acknowledging the difference. Importantly, the data is supposed to be kept separate and it sounds like Canonical screwed up here.
Neither one is an innocent party.
Companies now leak alot of metadata about what they are doing. If a teeny company like Canonical is mining stuff like this, consider what Microsoft knows about how you use their products, and I'm sure your EA negotiation as a big company is at some level driven by what they know.
Canonical is the one who violates trust here. Because they are using this information for marketing purposes, which they are not allowed to do under the information sharing agreement that they have with Microsoft.
So yes, we could argue whether Microsoft should be providing the installation information in the first place. It should at the very least be opt-out (on by default with the ability to not share), and preferably it should actually be opt-in (off by default, check a box to allow). So there is a violation of trust going on here, but this isn't any different than every other major tech company is guilty of right now (not that it makes it right).
But Canonical is the one that took the information and used it in a way that was never agreed to by either the person sharing the information (Microsoft) or by the user via the ToS (the ToS says that it is strictly for tech support, not for marketing). Canonical is the one that really overreached here.
An unstated assumption of using any "free" product is that it's not actually free. Canonical screwed up, to be sure, but I do think many of us just expect getting harassed by salespeople to be the cost of using a "free" product.
Microsoft, on the other hand, charges me by the hour for using Azure. They've taken their pound of flesh, so my business expectation is that I'm going to be left the hell alone for anything other than billing matters. Them sharing the data in the first place, for something I've paid money for, FEELS like the bigger violation to me.
For a linux distro, my expectations are that it's "free" but support will cost you money. My expectation is not that it's "free" and the OS will spy on you and report back to HQ so sales can make more sales.
If I don't give personal information on installation my expectation is the product is not harvesting or forwarding that information (For example, I expect that with Facebook, I don't expect that with GIMP).
Both are certainly wrong IMO. MS for giving personal info to a 3rd party and Canonical for bundling spyware with their OS. Both are super icky.
And you're selling the information in order to get tech support from Canonical, otherwise you can get it without selling your info (but won't really receive tech support).
As an aside, "pound of flesh" doesn't mean "payment", it means "something that is one's legal right but is an unreasonable demand (esp in the phrase to have one's pound of flesh)", both in Shakespeare and in current usage.
Unless you feel Microsoft's price is unreasonable and you have no other option, "pound of flesh" isn't the right expression.
Something like "they've taken their cut" is more accurate.
Too late to edit, though.
I wonder what have the consequences been for that guy.