Audacity 3.0 called spyware over data collection changes by new owner
appleinsider.com
appleinsider.com
Anyone knows if there is more known about this new owner, their history and or financial backers?
When this news initially broke, I remember there was a lot of mystery (with some few red flags) surrounding this new owner. I got an uncomfortable feeling that this could even be a front or proxy for a commercial entity that sees Audacity as competition. Not sure how much was payed, but this could be a relatively cheap way of knocking out an open source alternative. On the other hand, abusing an existing install base for any kind of intelligence harvesting also is a popular business model these days (actually criminal in many countries, but sadly hardly ever enforced as such).
Either way, after reading several pages of back and forth on this issue a while ago, I'm convinced that these new owners either don't quite get what they bought (or what it means) or that they do but simply can't really care (and therefore can't be trusted).
Until there's a fork, I'm not toughing this with a ten feet pole.
They are a known entity (owners of the well-known Ultimate Guitar site), and their previous purchases make it clear what their likely motivation is with Audacity: to make money in a somewhat standard way among startups these days.
They are likely adding trackers so that they can sell ads within audacity and improve their ad targeting on their actual sites. They will likely add premium features to Audacity and sell some kind of subscription service. I wouldn't be surprised to see the same kind of dark patterns/false urgency that you see in the Ultimate Guitar app.
I think that people should be legitimately concerned, but their behavior is no worse than 90% of the startups discussed on HN (not to say that's a good thing, but just to give perspective)
It sure sounds plausible, as much as I dislike it. It's one thing to see startups involved in questionable business practices with their own/new products. Quite another seeing existing useful software be destroyed by it. Looks like all that talk about the GPL being too restrictive doesn't mean that much in practice, if stunts like these can still be pulled.
Is this the future of FOSS? So dystopian.
[1] https://www.audacityteam.org/about/desktop-privacy-notice/
What else are these features useful in context of “law enforcement”?
This really applies to almost every company, since barely anyone will fight LE in your name. It's just rarely spelled out clearly in public.
> Receive your account information in order to satisfy applicable law, regulation, legal process, or enforceable governmental request
Audacity:
> data necessary for law enforcement, litigation, and authorities' requests (if any)
IP addresses aren't really super-reliable for this (corporate networks, ISP NAT), but many people still are under the misapprehension that they are, and it's probably reliable enough for this purpose.
I don't know if that's the reason; but it could be.
It's not people suddenly objecting a standard practice - it's another episode of the ongoing fight against attempts to normalize this practice.
That has nothing to do with crash reporting, and there is no sane reason for a desktop, offline audio editor to collect such data.
The problem arrives when people start actually reading these vague and wide conditions. It's a bit like when you tell your son or daughter to take some money to go to the movies, and when you find out they have taken 500$ they say "don't worry, I won't use it all, but at least I'll be sure to have enough".
If they would have explicitly stated what they were logging, and for what purpose, I think reactions would have been much less.
Personally, I would have asked for permission upon crashing, with a button to show what is being sent.
> "data necessary for law enforcement, litigation, and authorities' requests (if any),"
This is very different from "crash reporting".
I feel like HN folks often look for underlying meaning, a structure or purpose through which transactions like this can contribute to greater progress in line with the promise of capitalism. But that's only true when channeled by the constraints of rule systems, which aren't a given.
In the absence of other meaning, it doesn't matter what the 10k user information is. That userbase can still be cannibalized if there's somebody who can be fooled into thinking that act is useful/profitable. Rules saying 'this sort of destructive community-pillaging will cost you more than you gain' aren't necessarily there.
In the absence of them, you don't need to prove harming the 10k community will be profitable over the long or even short term: you only have to find somebody with money who can be persuaded they'll benefit, even if that's not true. If they think that, then you definitely can benefit from selling out the community. You can know it's a doomed exploit, but if you get paid, you're out of it by the time the truth comes out.
https://github.com/greatsuspender/thegreatsuspender/issues/1...
At least from my anecdata, a lot of people who want to do some basic sound editing without buying an audio editor (those are often quite expensive) at least try using Audacity at some point.
Doesn't have anything to do with even Audacity's users, much less the sustainability of the Audacity ecosystem. If there exists somebody somewhere who would pay more to see Audacity scuttled than it'd cost to buy, that becomes a potential profit motive to a facilitating third party if they know of that dynamic out there to be exploited.
This is of course subject to whether it's allowed to just wreck stuff for your benefit, and how. In cases of simple property, it's generally not: you can't just burn down a rival store to benefit yourself because that's against the rules.
I don't think such limitations currently apply to businesses past a certain level of abstraction, and what's happening to Audacity is not in the least meant as 'just burn it down', even if that's what happens: it's meant as 'get more control over this property', for whatever reason. That may or may not be a wise business decision, but in terms of being able to extract profit, it's a good business decision if in any way, for any reason, it works to get them more money than they paid for the property.
I think it's a very bad decision in the larger sense of things in the world, ability to trust in the things we know about, ability to function within larger systems of known properties and build order out of chaos for the sake of real progress. But that wasn't the question.
What you need is a fork which is sustainable, trustworthy and manages to pulls users towards itself.
On the last point: just a few weeks back I ran into somebody still using OpenOffice instead of LibreOffice. Audacity is referenced from many magazines and targets non-geeks to a large part.
Audacity, however, doesn't. It's a standalone application. It works on local files. It has worked perfectly fine like this for decades. And now a new owner has come in and changed that within weeks. That's not okay.
The same complaints are being made about other software doing similar. For example, Microsoft's attempt to make all Windows accounts online. We've had 30+ years of Windows without online accounts. Why should that change? and most importantly, why must it be forced upon unsuspecting users?
I do agree with you, though, that anybody can call it anything they want, and that doesn't make it true. But it's also fair to be suspicious of unnecessary changes that, on their own may seem innocuous, but together lead to something far worse.
And yet, Firefox does this: https://support.mozilla.org/en-US/kb/telemetry-clientid
Not nearly as vehemently as with Audacity.
There are good and legitimate reasons for collecting user data, but many of us think it should be voluntarily, minimal and at least not shared with anyone for anything but its original purpose.
In fact we had a very interesting court case in Høgsterett (kind of Supreme Court) here last week where it was finally decided that the police could not aquire biological samples from the university of Oslo to help in a missing person investigation as the person in question had not agreed to it, so obviously some very influential judges in one civilized country do agree.
-----
That said, between the I Robot extension, mandatory data collection and the gutting of the extension system Mozilla seems to be on a multi year marathon effort to play all their cards into Googles hands.
Firefox is still my main browser though but to a large degree because the alternatives aren't quite there for me as a power user.
At this stage they seem to be toeing the line for plausible deniability of Google's monopoly, while being thoroughly defanged from doing anything to reduce the actual monopoly.
I am saying I want
- authorities to look into these dealings
- someone to create a (paid?) unborked version of modern Firefox
- or a "vetted" safe version of Pale Moon or something
- Google to be split into number of chunks
Erm... Firefox has told people that they would hand data to law enforcement. They have to! Everyone has to!
https://www.mozilla.org/en-US/privacy/
> When do we share your information with others?
> When the law requires it. We follow the law whenever we receive requests about you from a government or related to a lawsuit.
So what? The counter argument is that people are being hypocritical with their criticism towards Audacity here.
Why are you okay with some applications collecting telemetry, but not with others?
But wouldn't you agree that HN would go apeshit if Mozilla tried to introduce a "law-enforcement" clause like Audacity did?
It's the psychology of "well, it's already sharing some data. what's the harm in a little more?" There will always be people that want minimal data sharing, and I'm one of them, but the vocal minority are exactly that - the minority. The majority of users don't actually care, which is why the data harvesting industry is as big as it is - plenty of data out there to harvest.
They don't care until it directly affects them personally somehow, and then suddenly they instantly forget that it happened because they allowed it to happen, and they make a huge noise about it as if it's the first time they heard about it.
Firefox tries better to anonymize the data collected and is a more reliable company than whoever really owns Audacity these days, but as a Firefox user, I'm pretty annoyed with the amount of settings I need to change to my Firefox installs to keep my data out of the hands of Mozilla of all people, who claim to value my privacy so much.
I can only assume those Mozilla pages telling me I've pressed the update button collect my full IP address for at least logging purposes, as every website does by default. This stuff doesn't need to be on the web, they could easily launch a local HTML file with the same contents.