Another misstep for Audacity
lwn.net
lwn.net
The current state of affairs (from Muse Group's perspective) is here: https://github.com/audacity/audacity/discussions/1353 (published today)
>I have been doing 3.0.3 Release Candidate testing and all seems good:
>a) error and crash reporting are one-off opt-in each time you get such a dialog,
>b) the update checking dialog that you get on initial launch of 3.0.3 enables you to turn off update checking in Application prefs BEFORE you hit the OK button - and thus no data is sent.
Everything is now as opt-in as it can be expected to, and the privacy policy has nothing untoward in it. I'm not super happy with how long it took to get to this point, but at least the wound has been debrided.
I really don't get the wailing and gnashing of teeth against even the principle of adding update checking and error reporting features. Real, regular people will get tangible benefits from these features. Their scope is so limited and implementation (now) drawn down to such a sharp point I can't really sympathize with a hard-line counterposition that these features must be defacto evil.
Sometimes this gets mixed with observations that telemetry and auto-updates are modern-day antipatterns, encouraging bad software development practices and resulting in subpar products.
Personally, I feel that a ToS/privacy policy for Audacity would be more palatable if it explicitly limited scope of data collection to optional features of update checks and error reports.
Beyond that, there's nothing that requires them to allow for this in their TOS. There's no loose end by not including it; it's not a 't' to be crossed or an 'i' to be dotted.
I'm eager to be corrected, but I just don't see why they'd need to change the TOS at all except to replace some ownership info.
• You must acknowledge that privacy is a basic human right.¹ Maybe you were brought up in a culture where these rights don't count; well, here's your opportunity to learn and grow. Maybe you have simply forgotten your school lessons, that's not good and the blame falls squarely on your shoulders then.
• The users were promised UI improvements and an eighth zoom button, instead they got malicious software and bad treatment from the new owners.
• Look at what Muse originally planned, not what they compromised to after the public push-back.
• There is a person at Muse named Daniel Ray who is a sociopath and lacks the basic decency/internal filter in communicating with other people and utter lack of self-preservation for avoiding bad consequences for himself, such that he thinks that threatening a software developer on public Github with doxxing him into the gulag is an acceptable thing to do.
¹ Let's see how these rephrases violating some other human rights feel: "I really don't get the wailing and gnashing of teeth against even the principle of forced castration and hysterectomy." "I really don't get the wailing and gnashing of teeth against even the principle of trading and using chattel slaves."
This point is very important. Like many other open source projects, Audacity is used in a very large number of education-related projects. Having 13 as the minimum age was going to be a huge problem.
> The App we provide is not intended for individuals below the age of 13. If you are under 13 years old, please do not use the App.
They did not forbid it.
What has the law to do with offline apps on a personal computer owned by a family home when the machine is supposed to be "family machine". The next thing you know windows will forbid ages 13 and below from using their products?
Its not like there are dangers of pedos by using audacity? What about "YouTube kids"? How is that allowed when its online with automated content moderation but audacity is not for kids?
and it was shared 2 weeks ago also. Best to move along to more current developments.
Discussion on the mentioned Latest Update https://news.ycombinator.com/item?id=27927407
I'm distressed at how quickly the article brushes this off. What could The Law possibly demand of a music editors users? What am I misunderstanding here?
I think it's actually occurred in the past (many times?) which is why it's identified as an item of concern.
I understand the practicality of smaller scale inquiries, but at a certain size the rules really aught to change, no?
> I understand the practicality of smaller scale inquiries, but at a certain size the rules really aught to change, no?
shrug throw it on the pile of sorely needed legislative changes. The laws just haven't kept up with things.
In the US you may not even be given any choice in the matter. They just hand you a national security letter and you're forced to give them access to anything they want for as long as they want it while being forbidden from ever telling anyone (your customers, your shareholders, the press, etc) that it's even happening. The laws really need to be changed, but how do you petition government to give up so much power? Hell, the NSA has outright lied to congress about what they're doing so our lawmakers can't even know about the data collection going on until some brave whistleblower comes along who is willing to sacrifice everything to let us know.
Even with their "assurance" that data isn't kept for more than 24 hours, that's more than enough time for it to copied and shared with any number of parties and without independent audits we have no means to be certain the data is being cared for or removed as they claim.
Just don't collect any more info that you absolutely need and users don't have to put their faith in you that it won't be abused, you don't have to deal with the headaches and if law enforcement should ever come around asking you can just say "Sorry, we don't collect that information" and you don't have waste time dealing with those requests either.
To sell, obviously.
https://github.com/audacity/audacity/discussions/1353
They want to know when it’s safe to drop support for a particular operating system version.
Depending on how much they are truncating, it might still be easily de-anonymized.
Seems over-complicated (and it is because they could just decide to stop supporting an old OS on their own using any number of criteria), but still probably less work than collecting and securely storing IP addresses and computer details, trying to anonymize that data, controlling access to that data, making sure it's all deleted appropriately, having lawyers review court orders for the data they've collected, etc.
This is all a non-issue since the telemetry is entirely opt-in and can even be stripped out entirely with a single make flag.
On the positive side you could identify the user who created ransom_message.mp3 in the exceedingly unlikely case this scenario comes to pass. More realistically you could identify the creator of unpopular_religious_message005.mp3 or how about helping a repressive regime locate any and all creators of any of 385 banned religious or political ideas?
Once you have lost your users' trust, it is very hard to get that trust back. Especially if your "better communication" is simply to walk back (er, "clarify") some of your more outrageous statements. (Pro tip for these kind of situations: start by demanding the moon. Then, when you settle for merely owning, say, California, you look generous.)