Count me on Team Crash Report, for sure. Anyone who's worked on any kind of project like this knows how valuable live user telemetry is. These features make software better for all of us. If you really don't like them don't use them and carefully audit the opt-out mechanism to make sure it works. Don't throw poop on the walls.
Software should not collect information in the first place if it may get necessary for law enforcement, litigation and authorities to demand it. If the information is interesting for a third-party then the collection filter is not fine grained.
Live user telemetry does not have to mean Personal Data. If I know that 80% of users who download version 1.2.3 got a crash within 5 minutes, which living person can I identify with it? If I however get download logs of IP addresses, browser identity tags, file names, windows profile names, user directory names (and so on), then that cash report is providing unnecessary personal data.
If I have access to the crash reports, can I do business intelligence gathering? Can I discover information which gives stock market insights? If the answer is yes, then you are collecting too much information.
The only reason to not publish all crash reports openly on the web for anyone to download should be undiscovered security vulnerabilities. The data itself should be inert.
For some reason free (gratis) software attracts the most entitled users ever. If I were in charge of Audacity I'd be inclined to charge a $1 "distribution fee" just to weed these users out.
I think rather it is rather an example of an external company (Muse group) not understanding the community behind the piece of software they have taken over.
They could do the data collection themselves and chose not to store personal identifiable information, in which case they can remove the legal boilerplate since it won't be needed. This suggestion naturally already exist in the GitHub issue.
Leaving the data collection on all the time, makes data-collection part of the terms of use of the software. Which makes data-collection part of the business model. Which makes the software spyware. It is always watching you.
If I followed you around all day, you’d label me a stalker, If I didn’t approach you, didn’t proactively threaten you, didn’t tell anyone else what I knew about you, you could still legally bring sone level of force against me. How is constant telemetry any different?
This - audacity - is supposed to be a bloody offline desktop app.
No connection to ANY online service, including telemetry.
That is what I meant.
Unless you do not collect said information in the first place.
Try to live in a society where everyone, including your closest family members, might collect such information.
Compromising a telemetry server is a one-off operation, would work at scale and is much less risky as the targets have no way to detect it.
Also, since you can fork it, as has been previously mentioned, there seems to be no purpose in objecting to this type of FOSS acquisition. Worst case, the project ends as it was before the acquisition, with no corporate support or funding whatsoever, at which point it seems it won't make any difference whether there was a complaint or not.
Do you have any examples for OSS? Because i do not believe that to be true.
> When do we share your information with others? ...When the law requires it. We follow the law whenever we receive requests about you from a government or related to a lawsuit.