Muse Group Continues Tone Deaf Handling of Audacity
hackaday.com
hackaday.com
Edit: To clarify, "tracking" means that you're following a particular user around. "Some user pressed the Audacity record button at 13:04:42 Sunday" is not tracking data (although with sufficiently granular data you could do fingerprinting (which is tracking), the countermeasures for which should be obvious) - "User #1934602 pressed the Audacity record button at 13:04:42 Sunday" is tracking, even if it's anonymized.
There are different levels of privacy that people care about (e.g. some people are ok with anonymized tracking, while others don't want tracking at all). Conflating them is an underhanded tactic used by people to emotionally manipulate others. Furthermore, "non-tracking statistics" is a category of things that few people care about, versus "anonymous tracking", so conflating these two is particularly egregious.
Non-personalized telemetry and crash reports would have been fine to me, but none of their discussions have convinced me that it’s where they would stop (or even really, where they’d start).
I’ve since moved to a paid option, and feel good about the move so far.
Good point - reminds me of a principle I recently heard someone espouse, "Disregard whatever promises a corporation/individual in power makes, and only pay attention to their legal constraints."
Just because you have the legal right to be an asshole doesn't mean you are an asshole. And conversely, the law can be broken, and clever loopholes can be exploited. There may be consequences, but it doesn't you will get repaid personally.
For me, privacy policies are just indicative. I try to approach the problem considering incentives, risks and benefits. What are the consequences for breaking the promise, for me, and for the company. For the company, imagine yourself as a shareholder, you want to maximize your profit, you know that by breaking your promise customers will be unhappy, will they go to the competition? is your image a valuable asset? is the short term profit worth it? For you, what is leaked? How will it affect your productivity and security? Can you easily switch to a competitor? At what point too much is too much?
If I only cared about legal constraints, I would get into every scam. I mean, advance fee fraud is illegal, so that Nigerian prince cannot take my money, right?
If they're explicitly carving out the legal rights to be an asshole, I think it's fair to assume, regardless of what they say, they are going to quickly become a giant asshole.
In essence, companies are incentivized to be "assholes" when it furthers their valuation. Unfortunately, being an "asshole" is very often a lucrative move as long as it's done carefully.
I don't believe everyone who works at a large corporation (example being Amazon) is evil and immoral. However, collective action taken by the company on large scales has shown in many cases to have "asshole" effects. Also, fuck Jeff Bezos.
Especially the quote from one of the authors of audacity which states "telemetry collection is optional and configurable at any time"
Wether it's opt-in or opt-out is a smaller issue IMO. Like the article on Ars also states, even Firefox telemetry is opt-out, and you don't often see people raging about FF not being privacy sensitive enough....
[1]https://arstechnica.com/gadgets/2021/07/no-open-source-audac...
Sure, what they're doing right now appears not to be nefarious. But they're putting language into their user agreements that opens the door for them to be nefarious in the future with no warning or recourse.
There are actually a bunch of HN threads about just that.
Further, the subject of the article is the CLA, and the entire telemetry part is just to recap recent events.
People hate the telemetry the most, I think, but it's just one example of a pile of bad ideas baked into their privacy policy.
Look at the VLC/Apple issue. This is an insurance policy against something similar in future.
CLA is not to be able to create a paid version of Audacity, that is fundamentally against our core beliefs. Creators should have free access to software; the money is in content.
In addition, the CLA allows for the ability to share code between the MuseScore and Audacity projects, greatly accelerating development. MuseScore has had a CLA in place from the beginning so it is only possible to share code between projects if similar CLA is in place.
The next version of MuseScore will introduce a completely redesigned/rebuilt UX, VST3 support, realtime effects, a redesigned mixer, expanded MIDI support, and a proper sequencer is soon to follow.
All of these features have been popular requests of Audacity users and will greatly (and quickly) extend the capabilities of Audacity.
Not applying a CLA actually limits the potential of the project (availability on popular devices and using code from MuseScore) more than applying the CLA.
You hereby grant to Company , a perpetual, non-exclusive, worldwide, fully paid-up, royalty free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute your Contribution and such derivative works.
Someday "MUSECY SM LTD, an affiliate of MuseScore and Ultimate Guitar" could be acquired or come under the control of an entity that does not share the "core beliefs" the CLA was drafted under. I wouldn't be comfortable relying on beliefs in lieu of a legal document spelling out exactly what contributed can be used for. The language in the CLA is what matters, not beliefs.
I haven't contributed to Audacity so it's not a practical matter for me. I wouldn't contribute to a project with a CLA that grants such a broad license. I'm a minority, to be sure, but there are probably others who feel the same way.
I've been burned, in business relationships, by verbally-articulated intentions that weren't codified in contracts and weren't honored. The whole "I thought you said..." and "I meant..." game has made me very wary of accepting terms that aren't articulated as part of a legal agreement. If something is important enough to agree upon it's important enough to put in writing.
Audacity is transitioning from an entirely voluntary development team to a team of many engineers, designers, testers, project managers, and a product manager all working full-time on the project.
While we welcome and encourage community contributors to the project we anticipate that most of the contributions will be from the dedicated team.
MuseScore underwent a similar transition to where more than 85% of commits are now from the dedicated team, while the number and frequency of commits has also significantly increased.
We expect Audacity to be similar.
This comes down to the actual definition of community.
Our priority is the contributor community and the user community as a WHOLE.
Of those complaining on Github and online, not a single one of them have contributed a single line of code to the project. Not even one.
Their complaints and concerns are also not very representative of the actual user community (1.2% of users are running Linux, while the overwhelming majority of complaints were from Linux users).
So, in addition to the contributor community and the user community as a whole, I do not see any other community.
There is this nebulous broader FOSS community that is often referred to. A group demanding to impose their version of idealogical purity on the project, yet not contributing a line of code.
But if they are not contributors and not representative of the actual user community... why should the project be forced to cater to the demands of 1.2% of the user base at the cost of convenience to the other 98.8% of users?
How absolutely insane would it be for any other software project to be beholden to 1.2% of their actual users?
Don't get me wrong, we are extremely committed to FOSS, and our motivations are actually quite ideological - we believe every creator deserves equal/free access to professional quality software.
The difference is our ideology is not the same as this very vocal minority that is primarily anti-corporate and whose demands limit capabilities for the overwhelming majority of users.
I run OSX/Tenacity, not a Linux user looking for idealogical purity - just a long-time user that sees a lot of red flags on the wall with your acquisitions. Your comments in the musescore-downloader project after the legal threat were simultaneously the first red flag I was made aware of and the first time I had heard of the "Muse Group".
For a director of strategy, your strategy and how you deal with the users and fans of the software/good will you've purchased seems less than ideal to this outside observer. Good will was generated by a long-term interaction between the community and the open-source project and you've managed to squander it and apparently continue to do so.
I only know of two - the contributor community and the actual user community.
Regardless, this has cemented my transition to Tenacity and I'll be recommending to everyone in my circle to move on from Audacity. I hope one day you'll see how you and your company are poisoning the well, but I don't hold out a ton of hope that your company isn't suffering from a seriously rotten culture and inability to admit mistakes.
Anyways, in the unlikely event that anyone is actually reading this thread, marcan's comment [1] and the legal thread [2] was my first intro to the terrible way that Muse handles acquisitions and I haven't seen anything that suggests the company is handling things any better.
[1] https://news.ycombinator.com/item?id=27005385 [2] https://archive.is/w8O3L
They completely screwed the launch of their "telemetry" collection, so bad that no mount of "reasonableness" is even being considered by many in the community.
Seems like a lot of effort for this. What is their ultimate end game? I’m not sure that this is worth all the money they have invested is it?
It's in the article. They are having the contributors sign CLAs, which would allow them to do this.
The ones who don't sign the CLA, they will re-write that code themselves to get around it.
This is not just writing stuff from scratch like all of us have done at one time or another with our own code.
Audacity was/is/always will be GPL.
I still have a 2.2.x version that I use for day to day recording, flakey, unstable but works if I fiddle enough with it.
commit 2a37cd19a022fd6bc63d1c0a403840eb300dfd1c Author: Cookie Engineer <cookiengineer@protonmail.com> Date: Sun Jul 4 10:22:57 2021 +0200
:shit: Remove Breakpad Crash Reports
commit 5728dd542fac39c0673dbb1c9d716838a25d69bd
Author: Cookie Engineer <cookiengineer@protonmail.com>
Date: Sun Jul 4 10:20:24 2021 +0200 :shit: Remove Update Check
commit bbf352d36d725335962718f91fc3591a1037f39b
Author: Cookie Engineer <cookiengineer@protonmail.com>
Date: Sun Jul 4 10:19:04 2021 +0200 :shit: Remove Sentry ReportingGitHub thread with links to some 4chan posts: https://github.com/tenacityteam/tenacity/issues/99
So I would not take what cookie says as fact at face value.
( FWIW, Audacity is a million miles better than it was 10 years ago (aka it's more stable) )
Reaper's non-destructive editing is bloody priceless when compared to Audacity's.
Plugins for reaper are... less well integrated into the application as a whole. Audacity makes for a great ACX mastering tool because of the open source, purpose made, plugins they have available.
Reaper's ability to add SFX chains to tracks without modifying the track directly is pretty incredible. You can both live preview SFX changes, and change settings without having to undo between changes.
I miss spectrograph editing when in Reaper. Word is there's an external plugin, but... see point 2.
More seriously, I propose a general disintermediated solution to the general problem of bug verification via automatic reports:
1) All crash reports are opt-in.
Reports are created locally after a crash or other event. They are added to a log folder. Users are given tools to examine the report data.
Then either:
A user can choose to upload any reports they want. A user can have already chosen to upload all reports automatically.
Either way, transmissions include nothing but the reports logged for review by users. A condition that can be verified by examination of the programs source.
The transparency of what is sent, and requirement of consent, both strongly incentivize reports constructed to be anonymous and limited in terms of any possible nefarious use.
2) The transmission goes to a third party bug identification agent of the users choosing. Users can make their choice based on a public list of such agents and their sites with their public reports.
3) The bug identification party is a third party, separate from the developer group, that works to identify and characterize the bug in the source code.
Bug characterization reports are then created that include a list hash values for each of the crash reports that contributed to the report.
The bug identification report is then made available publicly so users can be aware of it and developers can use it to identify and implement solutions.
The public disclosure of the bug characterization incentivizes a report that reveals little or nothing that could be interpreted as privacy violations.
An exception is made if the bug reveals serious security concerns, in which case the bug identification report can be made to developers earlier than public release, with assurances in writing that developers have a certain amount of time to act before the bug identification is made public.
Instead of immediately making the bug identification public, only its hash is made public so users can be aware of an anonymous bug fix in progress.
Developers in that window of time have the opportunity to fix the bug, determine that a bug fix is not practical or important enough, or they will continue working on the bug, etc., but must be transparent about either within the time frame or be seen to have violated trust.
At the end of the window, the bug report agent will publish the bug report, and the developers actions (fix, decision not to fix, decision to take more time, etc).
Note that the bug report agent can operate unimpeded without any cooperation from developers if there is none. But developers certainly have some incentive to take the bug reports seriously.