The spyware epidemic is real, and FLOSS is not immune.
The spyware epidemic is real, and FLOSS is not immune.
Caddy v1 also came with telemetry, but it was trivial to rebuild it with the telemetry switched off. The best you can do with closed software like Windows is to apply a hack and hope it's not undone after an update.
FLOSS or not, most software is still products, with a name and an owner. The openness could, in principle, enable a "network of slightly different forks" model of software evolution, but it didn't. There's universally a single canonical repo, with the "real" owners, and occasionally some niche forks. A fork takes over only when it can win the marketing game against the repo it forked from. So, each time an owner of the canonical repo decides to include telemetry in their project, their users who aren't software developers are screwed.
Downloads and execs unexamined code released by the devs, potentially backdooring your whole machine solarwinds-style.
It also divulges to MSFT (GitHub admins) all the IPs of Bitwarden users (even ones using a selfhosted API).
This is how the solarwinds hack happened.
> By default, Mozilla collects limited data from Firefox to help us understand how people are using the browser, such as information about the number of open tabs and windows or number of webpages visited. This does not include data that can reveal sensitive information about users’ activity online, such as search queries or the websites users visit.
I think you are defining the term spyware too broadly.