Audacity: Clarification of Privacy Policy
github.com
github.com
Unfortunately, I don't believe the general users of audacity will ever hear about the groups actions, and will continue to use the audacity without knowledge of what has changed.
[0]: https://github.com/Xmader/musescore-downloader/issues/5
Wow, that's low. It's one thing to send dumb threats, it's another to threaten someone with involvement of a government that frequently disappears people. This is how you turn your products into the PR equivalent of radioactive waste.
Honestly, it will take some convincing to make me think this isn't nefarious at this point. At a minimum, the community is not being listened to, just placated.
It has been done for larger codebases like OpenOffice and MySql.
Time to either move to hard fork (if it happens) or find an alternative IMO, they can choose to die on this hill.
We're already tracked by so many apps (and at the OS-level for many) I think a lot of people are pushing back hard (maybe unfairly) because it's something they can control since it's FOSS.
Audacity has been around for over 20 years! It's takes some serious ego to drop in CLAs and telemetry on the community months after acquiring it.
I'd say this is a regression, and adding all that networking code makes it easier for them to push it further down the line, and adds more vectors for attacks.
At best it's bloat. Developers were able to write good software without pulling in user's data before, it says more about the devs if they think it's so necessary.
Okay say it's not spying—you now have another app on your system pinging hosts, and depending on how much you trust Muse, you have to check the changelog every time to ensure they haven't added more bloat or juiced up the telemetry.
I'd posit that spying has been normalised we don't even recognise it anymore. Opt-in isn't a get out of jail free card, since your avg user will just click whatever.
FFS, any time you connect to a website they know your IP address. A log will save it, perhaps, and they say they prune their logs after 24 hours which is reasonable.
Literally wget sends this sort of info, you can try it
wget -d example.com
unless now wget is spyware too. This whole thing is a nothingburger at best and just a pr disaster at worst.Though I agree it's a PR disaster—people are upset, I don't think folks can be reasoned with since it's partly a backlash of yet another small community being taken over by corporate mediocrity.
As for the telemetry, that's opt-in. May be the bloat and other things that are being mentioned are about that? But for the first two bullets on information that is mentioned as collected (IP addr and os info) that is mentioned in the linked github discussion, they are literally what they will get because you had to visit their site to download it or because you automatically download updates.
One of the more common ways to get audacity (via your distribution) happens to [often] not provide your/a user agent string to the audacity developers, nor do they get a copy of your ip. In the context of a distribution: the auto-update mechanism is also problematic and needs to be disabled at install time.
And all of this is
a) reinventing the wheel.
b ) breaks the assumption that the computer will only connect to the network with a human-in-the-loop.
c) completely unnecessary in the first place.
Let the distributions keep track of issues and report them upstream.
And what about Windows users?
The error reporting is by an open-source tool and is opt-in.
[1] https://old.reddit.com/r/DataHoarder/comments/oe2opu/due_to_...
Audacity needed a maintainer to help with support and development. Developer, who has a pretty active YouTube channel covering design in music software, takes interest and leads the project. Said developer adds telemetry to help make more informed decisions. People lose their collective minds.
Can someone fill me in on what this person could have done better? Honestly, it seems like pearl-clutching from a select group of users who never gave a shit in the first place and just want to whine about something they never contributed to and get to use for free.
As for how they could make it better: make it opt-in not opt-out.
This is the kind of toxic behaviour we all tolerate from commercial software, but people get mad when it leaks into open source.
Roughly.
Here is the link towards the Privacy notice on the 2nd of July. https://archive.fo/d3LBR#selection-673.0-673.129
Having children in that age range use the app would require Audacity to seek parental consent by "[making] reasonable efforts (taking into account the available technology and risks inherent in the processing) to verify that the person providing consent holds parental responsibility for the child."1
While they wrote to minors "please do not use the App", they also wrote "The App we provide is not intended for individuals below the age of 13."2 Not being a lawyer, I cannot talk about the implications of these passages.
src1: https://ico.org.uk/for-organisations/guide-to-data-protectio... src2: link in my parent comment
The school installing software that has terms not allowing those under 13 to use it, because those kids don't have the legal right to consent to the software collecting information from them, has a very real chance of becoming an issue - both for the school and whoever made the decision.
A more direct example would be in Chrome/Firefox/etc automatically checking for updates, which is the equivalent of what Audacity describes in the linked post.
It's not going to happen for all kinds of reasons, but there's a lot that could be said in favour of prohibiting _unsupervised_ Internet access to children 12 and under.
People didn't lose their collective minds.
The Muse Group acquired Audacity, then introduced:
- a CLA (which, between other things, allows them to make closed source versions of Audacity)
- telemetry
- a very controversial privacy policy
People aren't losing their minds. And please, do not spread misinformation.
But all previous commits they'd build on are GPL..
https://docs.github.com/en/github/site-policy/github-privacy...
https://www.debian.org/legal/privacy.en.html
https://fedoraproject.org/wiki/Legal:PrivacyPolicy
https://www.fsf.org/about/free-software-foundation-privacy-p...
Sure it's not "the norm" but personally I run a Poudriere[0] server and build all my own software packages. One server syncs the FreeBSD Ports collection and downloads the needed software source distfiles, but then none of my other machines/jails are allowed to install software from anywhere outside my own network. A lot of them don't get any Internet access at all.
That still has nothing to do with in-app analytics though.
It absolutely does have to do with analytics: in particular, Debian has an opt-in anayltics system called "popcon" which is mentioned in the privacy policy.
Presumably the objective is to have machines that do not connect to the network without at least a human in the loop. This used to be the default, and is still very helpful in a lot of situations. For one, it keeps the noise down when you are trying to debug network issues.
That FSF link relates to their site.
Audacity is an offline non-networked application.
I have never once used software I thought was actually good that was designed based on feedback from telemetry.
When I was a kid, computers weren't connected to the internet. The first time I had a connection it was at 33.6 kbit/s (at 25 cents per minute).
Can you imagine if I had had all these 'modern' programs on my computer that would suddenly try to talk over that tiny straw of a connection? It'd be unusable!
There are still a lot of reasons why you would like to maybe hope that a computer doesn't try to randomly talk to everyone and everything on the intertubes on a whim.
For instance: said computer might be acting as a firewall, or it's being used for SCADA, needs to comply with corporate or government security policy, or is otherwise supposed to be something-gapped.
I guess for regular consumer technology that hope has long fled. You'd think that floss software could automatically be trusted to be quiet-by-default, but I guess that time is now past as well.
Possibly software that is quiet-by-default needs to start explicitly noting that it is so; so that if you have a particular task that really needs a quiet-by-default machine, you can draw from that subset.
You are right that audacity probably doesn't need to be in the quiet-by-default category. But ...eh... somehow this feels like a retreat.
Their ability to make decisions doesn't matter. It is does not justify putting spyware into previously trusted software.
Also, nobody believes that excuse for a second. They couldn't care less about "improving" anything but their bottom line. They are merely capitalizing on the trustworthiness of an open source project in an attempt to extract maximum value out of its users.
If they wanted to improve the software, they would have hired somebody with good taste to work on it. People with good taste do not tolerate abusive spyware.
> Can someone fill me in on what this person could have done better?
They could have not collected any "metrics" in the first place. That way, this ridiculous privacy policy would never have been necessary.
I don't understand the reaction either. It's hard to talk about this stuff here because of the anti-analytics groupthink. Everyone seems to jump to the worst possible conclusion whenever it's brought up.
I can't help but wonder if the people screeching about it have ever actually put analytics in their own products. Understanding how your software is used in the real world by real users is absolutely invaluable!
Assuming integrity, I think the people complaining about it would indeed do unto others as they would have others do unto themselves. That is to say: not include telemetry.
"Just ask those people!" Is what I think every single time, when this kind of issue pops up. Ask the people what they find annoying about the product, ask them what they like. There are many questions you can ask and which yield a much more direct result than telemetry data, without upsetting a community and without coming across as sneaky and disrespectful of user privacy.
It's not uncommon for me to approve such features when I'm dealing with software I trust, and when I'm thoroughly informed of exactly what data they're collecting and why. If I see a list of reasonable data points and it's not too intrusive or overreaching (and if I can examine the data before it's sent) then I'm quite often okay with it (again, with software I already trust for other reasons).
I actually didn't think of this, I compile my own kernels and add my own text to the kernel name.
Audacity 3.0 called spyware over data collection changes by new owner - https://news.ycombinator.com/item?id=27736151 - July 2021 (70 comments)
Audacity may collect “Data necessary for law enforcement, litigation” and more - https://news.ycombinator.com/item?id=27727150 - July 2021 (254 comments)
New [July 2, 2021] Audacity Data Collection Policy - https://news.ycombinator.com/item?id=27724389 - July 2021 (34 comments)
They always claim it improves software, but all that seems to happen is it just gets dumbed down and features removed, making it worse for experienced/power users.
They may also simply think that it's just plainly required if they're going to run an online service that the app connects to by default.
That's all speculation though, hopefully they'll answer that question on the GitHub discussion.
This is gaslighting. It's not the wording people have an issue with, it's the nonconsensual spyware.
"Consensual" in that case would mean opt-in telemetry.
Imagine if your grocery store terms were that you have to pay to take them home... and also that you must consent to a grocery store employee following you home and sitting in your kitchen, watching your vegetables. They'd take note of how and where you store them, when you use them, how you prepare them, how much you eat in each sitting, what meals you eat them with, and how satisfied you seem to be with them. They'd report all of this information back to the grocery store. They'd also report anything else they see or hear and decide they might be interested in later on.
Does that really not sound extreme?
I believe this argument of "users have a freedom to either take it or leave it" has been repeatedly debunked many times over. It just isn't accurately describing reality.
As an example, UK schools are likely to have to either negotiate an alternate license or switch products.
What’s been “debunked” is that products die off because of things like adding telemetry, because plenty of people don’t consider that a dealbreaker
If you’re not concerned with the licensing on software once you’ve managed to get a copy, I guess Audacity’s behavior shouldn’t be an issue: just compel it to behave differently on your machine.
Oh I will. The thing is I shouldn't have to do this. We're all tired of these obnoxious companies forcing this sort of crap on us. Why can't they just release their stupid thing with no strings attached? If this is their "contribution" I'd rather they just did nothing.
Right there you name one of the biggest joys of FOSS for me. On my machine, I sure do love that all my tools do my bidding the way I want them to. :)
While technically legal (although the last about that might not have been said either), I think they are going to find out how their grubby ideas of right-and-wrong might not align at all with a substantial part of the user base of the product they now own.
I believe that they are already doing actual practical harm in some places, which might end up costing them dearly if it would trigger some kind of organized revolt. With their behavior so far, that can/will only end in escalation. I very much doubt that the plans of this new owner will become the financial success they may have imagined.
Sadly, Audacity as a product will no doubt suffer as a consequence. Still makes me wonder if there hasn't been some kind of financial support/injection by a commercial vendor involved, somehow. Of course it doesn't have to, but the idea just does not want to leave me alone.
It's better to consider the project dead then to argue with them
There are lots of non-FOSS but effectively-free alternatives. Ocenaudio is way better than Audacity in gobs of ways, except it's not multi-track. Reaper is pretty great but if you're hoping for commercial use with $20K+ gross/year, you need to pay $200+ USD.
In FOSS land, Zrhythm, Qtractor, LMMS...but these are DAWs so again it depends on what you were using Audacity for. You could even learn sox and maybe benefit from some command line use, like writing scripts for things you need to do all the time.
My advice: List the specific tasks you need to do, and aim to find 2-3 apps that will fill the gap. Then any extras on top of that will be gravy.
Edit: Oh and you can also use FOSS like Blender and render edited sound to mp3, or KDEnlive, or other software that's video or animation related. So if you already know those tools, or like how they work (in some ways they are pretty slick!) then they may fit better than other audio-only software.
May be the story is as I said the initial communication now, not with the privacy policy changes, no? I'm starting to feel had, there is literally no telemetry here, that's just internet hype and rumors.
EDIT: there is telemetry for bug reporting...okay that's optional so I'm still seeing no fire.
People need to keep in mind that open source software doesn't automatically develop itself just because you can fork the code. Audacity is a pretty big, complicated piece of software.
Gaudacity.
As in Ye Olde "G(ood) Audacity". Intentional misspelling of "gouda" (but sounds the same), has original name as a substring, and should come with appropriately cheesy wedge located between the headphones. Bonus points: reference to plugging one's ears with cheese.
...what? My dad humor is showing?
But in all frankness, I'm serious.
If you download and use a ready-to-run version of Ardour from ardour.org, the program will attempt to contact ardour.org at startup to determine if you should be notified about a new release of the software. If the computer where you use Ardour is connected to the internet, this process will store the computer's internet address and an identifier for its operating system.
If you report a bug to our bug tracker, we will store whatever information you provide as part of the bug report.
When Do We Privately Share Personal Data?
Never, unless required to by law.