Wacom drawing tablets track the name of every application that you open
robertheaton.com
robertheaton.com
- https://news.ycombinator.com/item?id=22247292 (this article, earlier thread)
- https://news.ycombinator.com/item?id=22803484 (comment by the author of the article)
- https://news.ycombinator.com/item?id=22512696
- https://news.ycombinator.com/item?id=27963867
One of those links was me mentioning it, and this got so under my skin it took Wacom's brand from "premium, respectable, best in class" to "untrustworthy, garbage, barrel scraping, avoid even if the alternatives function less well" in my head just instantly. Like Lenovo's "let's ship spyware with Thinkpads" did.
One hopes that companies would value their brand and reputation over some short-term profit (and yet nobody here is holding their breath). To this day I refuse to buy any Lenovo product, and as the tech guy in my family I warn everyone who asks from considering them at all.
Or maybe they don't want to live in a cave.
If my principles are "carbon neutral, no spyware, workers were not exploited", I think there are zero washing machines, cars and TVs that meet those criteria.
What are you talking about? Check out these bad boys ;) https://www.lehmans.com/category/washers_and_wash_day_access...
Do you think there’s no value in a positive action unless the person doing it also did some other, unrelated positive action? Why? I think you’re just playing gotcha.
If you mean just “less concerned”, then even then, that means the boycott still has some value, right? So what is wrong with someone just boycotting one of two “bad” companies?
Just to transpose the logic to a different situation: say if someone gives $10 to a charity fundraiser, but they actually had $20 in their wallet, does that make their $10 donation less valuable? If this is not a fair comparison, please help me understand exactly what the relevant difference is.
I mean unlikely to take the actions you're trying to push for. If you're not consistent about when to boycott a company, how can they trust you to be consistent about when to stop boycotting a company?
Heh, to think that this sub-thread began with someone (you? Can't recall) complaining about "arbitrary" boycotting... That's a mighty arbitrary number you've got there. What's to say the difference isn't actually between 80% and 99%?
How would most sellers even know whether people are boycotting them "arbitrarily" or not?!?
1) A boycott is a boycott; they only notice that people are boycotting them.
2) ALL boycotts are "arbitrary" in the sense that [almost no | few | some | many | most | almost all] people participate in them, for reasons of their own.
3) ALL boycotts are "clearly principled" in the sense that the people participating in them are doing it because of some principle that's important to them.
4) Seller A can't know -- and probably doesn't give a shit about -- whether each of the participants in the boycott is also boycotting sellers B, C, D, E, F, etc, which perhaps they ought to also boycott on the same grounds they're boycotting seller A.
5) As I already mentioned, some of the people boycotting seller A are probably also boycotting sellers B and C even though they can't be bothered to boycott D, E and F; some others boycott A, D and E although not B, C and F; some A, C, and F; etc etc. For every boycott, you'll find people who also for the same principled reasons boycott other sellers. Lots of arbitrary decisions make a random distribution; it all evens out.
And the numbers (or number-adjacent adjectives) you keep throwing around, apparently in an effort to lend your totally subjective opinion some air of scientific legitimacy, are still totally arbitrary, or to call them what they are: pulled straight out of your nether orifice. How do you KNOW that "an arbitrary boycott is less than 20% as effective as a clearly principled one"??? What data do you have to claim the question is "whether an arbitrary boycott is completely 100% ineffective or a teeny tiny smidgen effective", when it could just as well be whether it is -- to pull equally random numbers out of my own arse -- 90% effective or only 60%? Sure, that might not be "a meaningful distinction to draw", either: Both are pretty fucking bad for the seller.
So... Sorry, but to me your whole screed still feels just as arbitrary and unreasoned as you accuse those partial boycotters of being.
Well if that's all they can find out then the boycott is pointless. If a boycott is meant to change the company's behaviour then there has to be a way for them to find out what the boycott is about.
> 5) As I already mentioned, some of the people boycotting seller A are probably also boycotting sellers B and C even though they can't be bothered to boycott D, E and F; some others boycott A, D and E although not B, C and F; some A, C, and F; etc etc. For every boycott, you'll find people who also for the same principled reasons boycott other sellers. Lots of arbitrary decisions make a random distribution; it all evens out.
That's only true if everyone is making their decisions randomly though. It doesn't hold if there's a correlation in which companies people do and don't boycott, e.g. people think they're arbitrary boycotting some but not all of the companies that do X, but unconsciously they're boycotting Chinese companies but not American companies.
> And the numbers (or number-adjacent adjectives) you keep throwing around, apparently in an effort to lend your totally subjective opinion some air of scientific legitimacy, are still totally arbitrary, or to call them what they are: pulled straight out of your nether orifice. How do you KNOW that "an arbitrary boycott is less than 20% as effective as a clearly principled one"??? What data do you have to claim the question is "whether an arbitrary boycott is completely 100% ineffective or a teeny tiny smidgen effective", when it could just as well be whether it is -- to pull equally random numbers out of my own arse -- 90% effective or only 60%?
All I've been doing is clarifying what I'm saying. I'm putting numbers on it because you asked! First playpause had some strange fixation on whether I was claiming arbitrary boycotts were completely ineffective or only mostly ineffective, and then you jumped in with some strange fixation on the numbers I used to illustrate what I was saying. It's a bit much to ask for intense precision and then complain when I try to be precise.
> Well if that's all they can find out then the boycott is pointless. If a boycott is meant to change the company's behaviour then there has to be a way for them to find out what the boycott is about.
Sigh... Yes, if some people "arbitrarily" choose to boycott company A for some reason that you think is somehow "invalid" if they don't also boycott companies B, C, and D that you think it should also apply to, they will of course let the company know that "We're boycotting you because of this principled reason!" What we were discussing was (your silly hangup on) their "arbitrariness" in not also boycotting other companies, and that company A neither knows or gives a shit about.
Are you genuinely this obtuse, or just pretending because you think you'll "win" a discussion with intentional "misunderstandings"?
> > Lots of arbitrary decisions make a random distribution; it all evens out.
> That's only true if everyone is making their decisions randomly though.
No, read it again: Arbitrarily. That's enough. Because everyone's "arbitrary" is different, the sum of them all will be indistinguishable from random. (In fact, there is an old adage that if you could measure all preconditions exactly, there is no such thing as "random". Even the movements of all the molecules in a gas wouldn't be "random" if you could know the initial position and velocity of each of them exactly... But you can't; that is, in a way, what "random" is.)
> I'm putting numbers on it because you asked! First playpause had some strange fixation on whether I was claiming arbitrary boycotts were completely ineffective or only mostly ineffective, and then you jumped in with some strange fixation on the numbers I used to illustrate what I was saying. It's a bit much to ask for intense precision and then complain when I try to be precise.
No. Either you're very bad at understanding what is being asked of you, or you are just plain lying when making this quoted claim. Absolutely nobody has been asking you for "intense precision" in numerical terms. We're asking for a qualitative motivation for the particular numbers you're making up: WHY should the effectiveness of "arbitrary" boycotts be as minuscule as you claim, and not on the hugely different scale I just as arbitrarily made up?
Please stop deflecting; either provide some sensible replies or just admit that you've been bullshitting without the least speck of support from the very beginning.
But this claim will clearly be false, and so they will not be credible.
> No, read it again: Arbitrarily. That's enough. Because everyone's "arbitrary" is different, the sum of them all will be indistinguishable from random.
Call it capricious rather than arbitrary if you think that's important; the point is that people's decision to boycott company A and not company B might be not based on the issue that they claim the boycott is about, but also not random.
> Absolutely nobody has been asking you for "intense precision" in numerical terms. We're asking for a qualitative motivation for the particular numbers you're making up
The post that started this whole chain was, in full: "So, completely unconcerned, or just less concerned? Which?". That's not a request to explain my motivation, it is a request to give (IMO intense) precision.
> But this claim will clearly be false, and so they will not be credible.
This is where you're wronger than a $3,50 bill, so glaringly not-even-wrong that it baffles the mind that you can't see it yourself.
To begin with the lesser reason: "clearly". Clear how, why, and to whom? For the umpteenth time: How would the boycottee know anything about this? Maybe you have participated in more boycotts than I (not a very high bar to cross), so please tell me: Is one usually required, before being allowed to tell Nike "I'm not buying any more of your shoes as long as you keep using third-world child labour!", to declare which other companies one is boycotting and on which grounds -- and above all, which ones one isn't boycotting? How does it work, in practice; is there a form to fill out? Does each company that gets boycotted make up their own form, or is there some central registry? Or is it just hired goons that nab any picketers outside the headquarters and give them the third degree? This is anything but "clearly" false.
Mainly, of course, because it isn't fucking "false" at all. Oh sure, when I was a kid I was also very "principled". But then I grew out of my teens -- or into them? -- and realised that that isn't how the world works. I'm sorry if this comes as news to you, but there is such a thing as differences of degree, and they matter. As somebody[1] is supposed to have said: "Quantity has a quality all of its own."
That is, things can be more bad or less bad, and since nobody has the time or energy to care -- or at least, to do something about -- all of them, people pick and choose which ones they care the most about, and do something only about those. This is perfectly normal, valid, logical and correct. Everyone does it: You too. Say you don't, and we'll know you're lying.
Kids, and perhaps people on the infamous "spectrum", can't distinguish between what's important and what's much less so. This leads to the fallacy of "If you don't do something about everything, you're not allowed to be against anything!" If you're a fully-functioning adult seeing it spelled out this starkly you'll realise how fucking wrong it is. If you're very young, you will when you grow up. If you tend towards autism, this was your lesson for this week on how we neurotypicals see the world[2].
I mean, we're all against Bad Things, right? We think people who do what's obviously wrong should be punished, or at least severely reprimanded. Have you ever uttered your displeasure with some, say, rapist, drunken hit-and-run driver, drug dealer, or genocidal war criminal? Even if you didn't even write a letter to your political representative; just being one more voice contributing to the general opinion in the break room at work, you might have put the last grain on the scale that made someone else write in, right?
But that's about Really Bad People. When did you last go out waving placards -- or even just go on a bit of a tirade over a cup of coffee -- about the evils of, say, occasional littering, jaywalking, or riding a bike without a helmet?
Naah, didn't think so.
Q. E. fucking D.
> Call it capricious rather than arbitrary if you think that's important;
The only one who does seems to be you.
> That's not a request to explain my motivation, it is a request to give (IMO intense) precision.
On the contrary, it is clearly (Hah!) a request to answer a binary, black-or-white, yes-or-no question: Do boycotts, irrespective of your imputed "arbitrariness" of their motivation, still concern the boycottee? The commenter was probably going to continue in the vein of "Even if it is a bit less, who gives a shit? They're still concerned, so they'll have to do something about it." But hey, congratulations, your Sheldonning seems to successfully have deflected that. Are you satisfied with this? Even proud, perhaps?
Don't be.
___
[1]: Often attributed to Stalin, IIRC.
[2]: I gather a rather typical strategy in order to "fit in" is to learn to either understand the reasoning or, if one simply can't, to just bloody fake it. Free tip, worth every penny you're paying for it.
Sure. Boycotting company A because it does more or worse bad things than company B is perfectly reasonable and principled. But no-one's claimed that's what they were doing in this case.
> The only one who does seems to be you.
Then why are you still here, nitpicking a thread from over a week ago that didn't even involve you?
> On the contrary, it is clearly (Hah!) a request to answer a binary, black-or-white, yes-or-no question: Do boycotts, irrespective of your imputed "arbitrariness" of their motivation, still concern the boycottee?
The difference between 0% and 0.1% is exactly that kind of "binary, black-or-white, yes-or-no question", and I replied accordingly. How exactly does this support what you said a couple of posts back: "Absolutely nobody has been asking you for "intense precision" in numerical terms. We're asking for a qualitative motivation for the particular numbers you're making up"?
It's as simple as that, yes: What makes you think the difference is between 0 and 0.1 -- HOW do you know it's not a matter of 99.9 vs 88.8?
And why are you so stubbornly refusing to answer that point?
I think I know: Because you don't. You just made them up. Right?
And this claim of yours is utterly unproven, since the numbers were totally pulled out of your arse. All I've been asking for is for you to give some sensible reason for why the numbers should be your ridiculously low ones and not some much higher ones that would imply the exact opposite of your original claim. If you have no support for your numbers being so low, you have no support for your claim; if you admit that the numbers could be the much higher ones, the claim they "just illustrate" is the opposite of yours. And since you have no support for your made-up low numbers, you logically have to admit they could be much higher.
i.e, it's not just a matter of "just illustrating", it's a matter of you admitting that you have absolutely no logical support for your original claim and that for all you know the exact opposite could just as well be the case. "Just illustrate", my ass!
Frankly, this all feels so utterly bleeding obvious that it's very hard to believe that you've been arguing in good faith here. IOW: The "gotcha" is that you once again showed that you've been prevaricating, dancing around, stubbornly arguing by repeated assertion, in effect just plain (pardon my French) lying this whole time. There, "gotcha" enough for you?
So I think I'm done with this discussion.
1) Sorry to be ragging on you personally so hard about this. It's frustration out of disappointment: Many other comments by you in other threads[1] have said so much better things about your intelligence and reading comprehension that this apparent blind spot of yours, not being able to see that the numbers you brought are not some "irrelevant side issue" but actually are (just another way of putting) your whole claim, feels like more of a mountain than a mole hill.
2) Here's my original bunch of counter-arguments: https://news.ycombinator.com/item?id=29116784 .
___
[1]: For instance, there were a few on testing and deployment in the https://news.ycombinator.com/item?id=29188863 thread that I was going to upvote. Hm, maybe I didn't; gotta go check.
Bullshit. Saying "the difference between 0% and 0.1% is immaterial" says something _fundamentally different_ than "the difference between 82% and 96.5% is immaterial", so which set of numbers you chose was what you were saying.
> accuse me of all this crap because I clarified what I was saying like I was asked to.
No, you have clarified nothing. You've been harping on about the evil of numbers -- which takes quite some gall, given that you were the one who introduced them in the first place -- and said nothing about why your thesis should be true. (i.e. why the numbers should be so low; it's the same thing.)
> And now you say I'm lying about what I was saying?
Not necessarily: Either lying, or just not understanding what you actually said. Because you've been pretending -- or genuinely thinking; I don't know which is worse -- this whole time that what you originally said, and are still saying here:
> a boycott that seems arbitrary will be overwhelmingly less effective than one that seems principled
...is obvious and correct and unquestionable. Which it isn't; at least you certainly haven't shown it to be true. Sure, it's true if the difference between their effectiveness is that between 0% and 0.1% -- but those numbers are just made up from nothing out of nowhere. Plug in 90% and 99% in stead, and what you're saying is that both are effective, not ineffective.
So, your original claim that a boycott that seems arbitrary will be overwhelmingly less effective than one that seems principled -- got anything to support that? What? You've had two weeks, and brought nothing but screeching protest at having your made-up illustrative numbers questioned. I'm saying it's BS; a boycott is a boycott and just as effective regardless of how "principled" people's motivations for participating in it are.
My counterclaim: It doesn't matter if people participate in the boycott even though they then "ought to" participate in other boycotts too in order to be "principled". Or, to put it in the terms you originally did, so what if an "unprincipled" boycott is only 79,9% effective vs 92.3% for a "principled" one? And now please DON'T try to keep gibbering about those numbers per se -- they're only interesting insofar as they are the actual claim. If you're still seeing them as a separate issue -- an existing "issue" at all, actually -- you're still confused. And it's getting harder and harder to believe that such monumental confusion can be genuine.
> then by all means disagree with that.
I'm still baffled at you not getting that that is exactly what I have been doing all this time.
And you have brought absolutely zero actual arguments for your original thesis. Again: WHY should the effectiveness of a boycott be dependent on your reasoning about its "level of principledness"? (Or, to put the exact same question in your own numerical terms: WHY should the effectiveness of a boycott be only 0.32% if it's "unprincipled", and not, say, 87.8%?)
ISTR bringing some arguments against it, but it's been weeks, so I'm not sure I can remember them. AFAICR, they went something like this (apologies if I'm making up new ones; though I suspect that's more than compensated by forgetting others):
1) A boycott is a boycott; sellers suffer when people refuse to buy their stuff. It doesn't matter to the seller if those same people then also "ought to" boycott other sellers, perhaps in wildly differing industries -- that doesn't affect their bottom line.
2) The seller has no way of knowing[1] whether any one person boycotting them is also boycotting the "correct" other sellers they "ought to" boycott in order to be "principled".
3) In fact, come to think of it (this may be new, or at least expanded from earlier hints), the less "principled" any single boycotter is, the more "principled" they may look to the seller: Som "ultra-principled" boycotter -- you? :-) -- might write them a personal letter, outlining their reasons and motivations, perhaps even explicitly mentioning (or at least giving clues to) what other causes they do or don't support. Or, you know, chat with staff going in and out of the corporate HQ they're picketing. Whereas the "just jumping on the bandwagon" types (whose "unprincipled" opinions you seem to think shouldn't count) just CL1XXOR H3R3 TO 5UPP0RT!!! on some campaign page, giving no clue as to the "level of principledness" that made them do so. But: So will a bunch of the "ultra-principled" ones, because they're just not the letter-writing type, or live on the other side of the continent from corporate HQ, or whatevs. Not knowing which is which, and giving the bandwagoneers the benefit of the doubt that after CL1XXORing that page they will at least be principled enough to actually abstain from buying their stuff (even though they're not boycotting all other "equally-evil" sellers too), what can the seller do but assume the worst -- that they're all pretty much genuine?
Refute any or all of those and you're actually discussing. So far you haven't been. (Or, sorry, if you have I must have missed it.)
___
[1]: Short of hiring a poll firm to deep-interview a significant sample of boycotters about their ethical views and wider boycotting habits, I guess. Or cross-referencing all the "Likes" on the "Boycott Evil Corp X!" Facebook page with the Upvotes on the Disqus comments on the "Boycott Evil Corp Y!" Web page... Can't do that by user ID only; and a lot of them won't have the same profile pic either. Bit of a job in both cases; my guess would be pretty much nobody does either.
(Yeah, I know, "not really the same company, etc". It is, and it's the brand. Live by it, die by it.)
I I did that, I'd be in jail. It's about time we'd started treating this as what it is: data theft and stalking.
https://www.computerworld.com/article/2984889/lenovo-collect...
>The first is a principled fuck you. I don’t care whether anything materially bad will or won’t happen as a consequence of Wacom taking this data from me. I simply resent the fact that they’re doing it.
I have rarely seen the concept expressed in such a clear, direct manner.
I think when I was younger I’d assumed the sheer number of technical users out there would mean it would be hard for companies to get away with things like this but these days I realize this sort of analysis and public exposition is actually rare and the number of skilled developers investing time in this is slim
Perhaps collectively as a community we can create public bug and privacy bounties that enable and incentivise more work like this
Back in the day if user told me they have a problem accessing some Internet content I would instruct them to close all the applications and start to dump their traffic on firewall and proxy. There wouldn't be any traffic from their IP address. Then, when they started the application I would see if traffic goes through proxy or directly through firewall, and make adjustments, like putting destination domain on an exclusion list in proxy or destination ip and port on an exclusion list in firewall.
Nowadays, Windows 10 without any applications started sends hundreds of requests per minute to dozens of IPs. Something respects global proxy settings, something not. I guess Android is even worse.
Interesting idea! If it was ethical (ie still properly followed responsible disclosure processes etc) I’d donate to something like this.
EDIT: Also if supported by someone like the EFF maybe there could be a degree of legal cover for any potential issues.
But I don't mean to back the side of vendors unduly here...
I must admit I didn't put much thought into my comment on ethics but I guess what I had in mind is perhaps a scenario where the behaviour is not actually intentional, and the vendor should at least be properly informed that there may be leakage (to them) of private data as opposed to just jumping straight to blogging about it.
So rather than "responsible disclosure" perhaps just a code of conduct to ensure that such a program doesn't just attract people looking for glory and blog posts, but actually has a standardised way to report these issues to the vendor and give them an opportunity to fix and/or respond.
I don't mean to dilute the core of the idea though, it's a good one, and it definitely needs to be geared towards being in favour of the consumer rather than letting the vendor off the hook.
The only value in responsible disclosure is protection of users. If you figure out there's a way to harm a boatload of people, it's nice to do what you can to ensure it can't happen before telling everybody how. It makes sense. But there's a very good reason it comes with a not-too-distant deadline before you give up on it.
But this? We're talking about finding ways that people are being actively harmed. How does "responsible disclosure" come into play here?
The only thing it would seem to do is to protect companies and their bad decisions. That's not the point. At best they've screwed up, and at worst they're actively malicious. How do users not deserve to know that they are being harmed as soon as possible? How do potential users not deserve to know that they will be harmed by using the product, and that the company is either doing a poor job of protecting them or actively trying to exploit them?
There's no reason to try to attach any ideas of "responsible disclosure" here unless you're explicitly trying to protect the vendor.
The distinction I was trying to draw is rather than just blogging about it or unleashing a Twitter storm and jumping straight to an adversarial public crucifixion of the vendor (and by all means do that as well), there should be a standardised process of also contacting that vendor directly and engaging with them to give them an opportunity to fully understand what is being reported, reproduce the issue (in the case of it being unexpected) and fixing the problem. Some vendors won’t engage or will stick their head in the sand, but others may actually choose to address the problem. This is also in the users’ best interests.
Some issues will hit Hacker News or gain visibility in other ways, but other issues that are published may not naturally reach the eyes of someone at a vendor unless the person publishing actually takes steps to contact them. That’s the point I was trying to get across.
Not suggesting any of that is a prerequisite to publishing anything publicly in parallel.
Incentives are well aligned for a corporation to just try it.
For example, one thing that jumped to mind was we seem to be lacking any objective measures of the speed of various OS versions, so everybody is always upgrading and claiming its faster, but is it objectively faster every time? What kind of regressions might happen?
There's nobody that is spending the time figuring out this kind of information, so everyone is kind of uninformed and there's more pressure to always upgrade.
It's a funky idea, at the moment I'm suggesting more as a curiosity rather than thinking it's the right approach for something like this
My immediate criticism is you could end up with an organisation that _is_ ultimately centralized but now the major players would be hidden. Currently crypto seems to generally tend towards oligarchic growth, so I imagine you'd have a few players that control most of the shares and many people controlling negligible portions. Perhaps these issues (not to mention the energy costs) can be solved, but right now I'm curious but skeptical about these ideas
There are tons of highly skilled and wealthy folks in the HN community, who are upset about issues such as privacy in tech, poor security in public sector organizations (utilities, education), etc. With some good, informal, leadership, we could put the community's resources to good use and help solve these problems.
Folks who don't see meaning in their regular jobs could find contributing their skill or money to this and similar projects fulfilling and rewarding.
But the very fact they are so damned sneaky about it makes it look really shady. Why not openly ask the users those questions and show them what information would be sent to the vendor? (And I am pretty sure Wacom is but one of many companies behaving this way.)
I vaguely recall using some applications built-in crash report a couple of years ago, and it was a) explicitly opt-in, and b) showed me (after asking me if I wanted to see it), verbatim, the data it was going to send to the vendor, including stack trace and stuff like that, and then asked me again if I wanted to send that crash report. (Unfortunately, I do not recall what software that was, though. sad emoji)
So I know it is not only possible to handle these things differently, but some people/companies actually do that.
Why not pay money to people who spend time helping Wacom improve their products? Then lots of people would willingly help, fill in surveys, test configurations, write feedback, etc.
To show similar growth to their shareholders, they'd have to charge you more, so you're data is still paying for X
No one who buys such a peripheral would mind; they'd all like it to work better with their drawing software.
[edit: Not that this is entirely wrong, but it must be one-of-many approaches for customer feedback.]
Once the user has agreed to that valid use-case, there's not a lot the OS can do to stop the data being logged permanently.
But they really could do that in a less shitty way.
OpenBSD implemented the ASLR security mitigation as default in their operating systems first. Windows and macOS followed years later. I don’t think they did so because of OpenBSD’s market share.
https://en.m.wikipedia.org/wiki/Address_space_layout_randomi...
They could ask permission first but this sort of telemetry is a nothingburger in my opinion, as unpopular as that might be on this forum.
No, they must.
> this sort of telemetry is a nothingburger
I strongly disagree, what runs on my computer is my business and if Wacom wants to know, they can ask, and I'll tell them 'no, sorry that is not something you need to know'.
It's called consent and it's not up to Wacom to decide that I will think it is a nothing burger.
> in my opinion, as unpopular as that might be on this forum.
That's the whole point of consent: some people give it, others withhold it. You are just as entitled to your opinion as I am to mine and that is why they should ask, it's not that you get to decide for me that it's a nothing burger, just like I won't decide for you that it isn't.
Don't like it? Read the privacy policy for software you run. That, or you can write or rely on libre drivers for the tablet to run on your specific hardware setup. And deal with all the issues unsupported/maintained drivers have.
Consumers can't meaningfully consent isn't meaningful when businesses don't have an obligation to disclose what data is being collected especially when it is described as
“[including] aggregate usage data, technical session information and information about [my] hardware device.”
Far more consumers would be outraged if each application or license agreement had to: a) provide a detailed list of information collected and transmitted to the vendor b) acknowledge each time that list of data changed c) had to do this for each business they dealt with on a regular basis
Is it mentioned in the privacy policy agreement? Or are you saying that any driver I install on my machine is equal to my consenting that the driver's author can collect whatever data they want?
Something like Krita or Clip Studio Paint is more likely for drawing.
Could you write a trigger in the driver to detect this, and only ask for consent then? Probably not, since that gives you only the numerator without a denominator.
Now, if they really aren't asking at all, that is shady. But asking just once rather than on every interaction seems basically mandatory to get the data needed for product development.
Have some self respect and vote with your wallet against such companies.
That phrase has always seemed like an overly cynical take that normalizes antisocial/exploitive behavior by setting an expectation that free services should exploit the user in the first place.
I have one that I use for hobbyist purposes and when it comes time to upgrade I'd be interested in not buying another Wacom.
I'm not a professional artist though, so maybe Huions are bad for pro work. Idk, but I'm happy with my Huion.
With a Huion 1060+ the pressure response felt amazing; however that was on Windows, I never got it to work under Linux. For a hobbyist it is a really much better choice than the cheap Wacom (e.g. Bamboo line), because it is important to have a big drawing area, so that you can draw from your elbow and not from your wrist.
Also, being fully open source I don't think the Linux Wacom drivers do any of the shady stuff the Windows ones apparently do.
The Huion GT works OOtB with the Wacom drivers. For the 1060+, I tried all the out-of-tree drivers without any luck, but that was about 3 years ago.
https://digimend.github.io/drivers/digimend/tablets/
(support was added in 2018, so now it probably works after minimal work)
I’m not sure if this counts as relevant competition but I’m migrating away from my Wacom tablet to an iPad + Apple Pencil. As well as procreate, an iPad can act as an external display for a Mac - and when connected, the Apple Pencil works as a stylus in macos applications.
It’s way more expensive though - especially with the Apple Pencil. And macos only.
Companies are ever tending towards surveillance capitalism because the profit the marketplace for personal information provides them potentially far outweighs the profits of mere direct sales. Withdrawing your business from such a company will achieve very little so long as they still have some user data in the bank. Participating in surveillance capitalism provides a great competitive edge at first, but the race to the bottom makes it a necessary component of conducting business. If Wacom simply needs to sell customers' session data to stay afloat, a not-wacom that expressly refuses to do the same probably won't stay in business for long on just sales. They would need some other revenue source, in crowdfunding, venture capital, SaaS, advertisements, a corporate buyout, government or military contract, renting and franchising, anything. Save for crowdfunding, these kinds of alternate revenue sources serve to tap into the lion's share of currency consumers don't hold.
Incredibly inequal wealth distribution prevents money from functioning like a distributed democratic force.
p->q = ~pvq
So, you are a product. No matter you are paying or not.
I would love a simple utility that could not only neatly encapsulate and display the data being sent from my machine out on the network but also allow me to merely check a box to block that traffic.
A smart initial config of course would "allow list" the usual web traffic from my browser(s), mail traffic from my mail client, etc.
I don't want to mess with proxies, don't want to have to block ports using a command-line tool or by wading through my router config.
Maybe I am asking for too much.
Does Little Snitch not meet your needs there? I believe even with the challenges caused by Apple's unfortunate elimination of kernel extensions it's still powerful and effective. The GUI is solid and I've had solid success over many years with it for this sort of thing.
You make a good point that I'd not really considered. When I'm on Linux, I have a tendency to think I'm less likely to be tracked for stuff since mostly I just use the open source drivers.
I have a wacom tablet connected to my machine running Fedora and didn't install wacom drivers, it 'just worked' using whoever's amazing open source graphics tablet driver contributions.
But if I didn't know that or I had to install Wacom's sneaky drivers anyways? If I had to use Little / Open Snitch either way to use a particular piece of hardware, the thought occurs to me (this may be OT) that it I may just wander back to what I'm used to from the past: Windows.
Gravity pulls me to Windows because I'm familiar with its UX, I have lots of software I run on it, and it's less fragmented than desktop Linux.
But I am using Fedora here because it has a superior privacy stance, is not going to force me to update, is not going to violate my express preferences by willfully ignoring or un-setting my settings, and because there's less third party drivers required (provided I do the special Linux-friendly hardware dance).
I guess I'm trying to say one's personal computing choices are a constantly changing balance and your statement caused me to re-evaluate my balance there, so thank you for the thought provoking comment.
In my line of work I had used Charles (but no, that is not something I would consider was to use).
Properly understood, SELinux can provide rock-solid security. Of course, it's not a replacement of other security software, but it can prevent most of sneaky leakages such as the we had just seen in this post.
MacOS doesn't ship with SELinux, but I believe it has something similar.
A walled garden just changes the entities which can control your devices. It doesn't fix the problem of agency, trust, choice and consent.
My tablets can't have spyware, because the drivers are stock open source. The folks making the hardware aren't in control of the driver software that runs the device. I can trust the community that any attempts to do this nonsense in an open source driver will make the news. The track record against spyware in the linux kernel is spotless.
This kind of nonsense is only a problem with closed source software.
This was a well-written fun read, and I also both care about privacy a lot and have also used Google Analytics on a site too, but at the same time I’m a little bit floored how quickly his own use of GA was assumed benign while Wacom’s was assumed malicious. (Using GA is handing tracking data to Google, after all.) I don’t think the “it’s just a mouse” is a valid justification for this double standard. My browser is “just a viewer”; I’m getting tracked before I click on anything on your page. If we’re going to care about privacy deeply, I think we need to be a little more rigorous together.
This makes me wonder something as a developer - it’s not just tempting to have analytics and telemetry, it’s very, very valuable data if you care about the customer experience. And for companies that don’t do anything with this data other than improve the customer experience and fix crashes, this data is also valuable to the customers and users. So the big question here for developers is how can we collect usage data safely without compromising privacy? What data is safe to track, and what data is not safe to track? Personally I assume there are many kinds of seemingly innocuous data that could be misused. Even tracking mouse location can reveal things to an adversary. What can we do as developers to prevent customer experience from becoming adversarial? Is the only answer to not send any data? Or is there a technical way to establish and maintain trust between users and apps?
Consent and control. Do not collect anything without obtaining the user’s active, voluntary, informed consent, and give the user the control to withdraw consent later. That’s really all there is to it.
Active: you don’t hide it in the TOS. You make consent an action that the user is requested to do.
Voluntary: to the user, the software should behave identically with or without user consent for data collection. Don’t make consent a condition of using the product or features.
Informed: the user knows what he is consenting to and can understand what data is in play. No simple “check this box to help us understand stuff LOL”.
Pay money for the very very valuable data, instead of taking it and trying to hide behind legalese and finger-pointing and distraction and affront. If studying how people use your thing adds value to your company, run a usability lab where you pay people to study how they use your thing. Contact a company with a lot of users and arrange to give them discounts in exchange for data, agree up front what data will be shared and how it will be used. Offer discounts like Amazon's Kindle-with-ads is cheaper than Kindle. Make it opt-in with limited things you collect and what you do with it, and be trustworthy enough that people believe you only do that.
Microsoft PowerShell collects telemetry and it's opt-out, which is annoying for a shell/programming language. But there is a public help document about what is collected and how to opt-out[1] and the source code is on GitHub[2]. Even then I wouldn't be surprised if that was the proverbial straw which broke the camel's back. As developers keep abusing people's trust and taking liberties, something will be. It's a tragedy of the commons situation, why would you stop abusing the ~~environment~~ customer a little bit for a good reason when others are doing worse and they won't stop?
[1] https://docs.microsoft.com/en-us/powershell/module/microsoft...
[2] https://github.com/PowerShell/PowerShell/blob/master/src/Sys...
I would assume a primary internal use for this would be to test their driver against specific applications and to develop enhancements and improvements for them. The driver offers application specific mappings, so perhaps they want to know what applications are actually being used to better inform their efforts.
If the drivers are continuously updated with this information to provide an improved experience for the largest parts of their user base, then they are effectively paying back for the use of this data.
If that's as far as their use of this data goes, then what more do they directly owe you for the data?
Some companies allow you to see what they are going to sent. It still takes trust, but it goes a long way.
And the fines need to be stiff, like $10,000 per incident per user. It's gotta hurt or companies won't stop doing it.
Is this what you believe happened with Wacom in this case? How could these tracking points be converted into revenue?
Personally I think this was a good case of "Any sufficiently advanced incompetence is indistinguishable from malice", but maybe my imagination is just insufficient.
Contrary to what many, both companies and individuals, seem to think, GDPR is not about cookie pop-ups but about regulating collection, storage and use of personal data.
It seems the real problem is consent… There should be a “nutrition facts” for software that is enforced at the OS level through an aggressive permissions model and backed by a privately run app stores subject to audit by government regulators.
https://elixir.bootlin.com/linux/latest/source/drivers/hid/wacom.h
https://elixir.bootlin.com/linux/latest/source/drivers/hid/wacom_sys.c
https://elixir.bootlin.com/linux/latest/source/drivers/hid/wacom_wac.c
https://elixir.bootlin.com/linux/latest/source/drivers/hid/wacom_wac.h
If you're using a different driver it is your choice. Wacom does not advertise their support but I bought one and I just had to plug it to make it work. AFAIK, they pay developers to maintain the drivers.At the least, the title should say it is a specific driver that has such problem.
This article’s analysis took place on macOS. The drivers to which you linked are for Linux. It’s not unreasonable to assume that official closed-source drivers, especially when bundled with other software, might be more intrusive. For example, many Wacom tablets have buttons that can be remapped, but only if you install Wacom’s software.
Dismissing it as the user’s choice really isn’t fair. I’m not going to berate my mother for failing to use Linux, but that doesn’t mean she wants all her activity sent to Wacom.
The article was written about OSX. These types of spyware behaviors in drivers are very common on Windows and OSX.
For those of you who are in this same boat, there are Little Snitch config files you can download that come pre-loaded with lots of blocked hosts, so you don't have to do them on your own one-by-one, which is frustrating on a new system.
What I wish I could find is a Little Snitch list that only filters out tracking and profiling. I'm OK with seeing ads. I know the web sites have to make money. But I don't want to be tallied by some random social media company just because I visited a web site about artisanal brake clamps. Something that will allow ads.google.com, but not analytics.google.com. Or if they're the same, then dump the whole thing.
And for open-source (GPL3) macOS solution - LuLu. Switched form Little Snitch about a year ago with no issues.
Other printers and scanners from Cannon might work good as well.
I recently wanted to install a crypto currency wallet on my linux machine but I was terrified of the fact that every single software on my machine can access the whole of filesystem and can easily steal keys to the wallet. Eventually decided it's just not worth the constant worrying.
in this case it’s a kernel driver that interacts as an HID with every application. it also loads app specific macros so it needs to know WHAT app is running.
On Windows there are also a few options, Sandboxie being the best one IME. It's open source now as well, though the quality and stability have taken a hit. And there's Windows Sandbox, which has been shipping since Windows 10.
I'm glad users can still make a choice on desktop OSs. As great as app isolation is on mobile devices, there's little from that ecosystem I would want on desktop. Even though OS manufacturers are desperately trying to merge the two...
Software must install and work properly even when the user restricts its network access. When software fails to do so, the OS maker should not sign the software or allow it to market itself as "OS-compatible".
We cannot depend on good intentions. Good quality of life requires accountability for all.
There are mice that require you to create an account nowadays...
And technically, the mice do NOT require you to create an account.
I remember many years ago buying an unbranded tablet from Alibaba -- direct from an OEM -- for a fraction of the cost of a Wacom, and it didn't even need drivers to start functioning. What drivers did come with it on the CD were minimal, unsigned (very common at the time, along with the instructions to click past the warning when installing) and surprisingly even had source code. The configuration utility wasn't a bloated abomination and didn't add itself to autorun on startup.
In other words, it felt like a humble servant ready to work for you, rather than attempting to coerce you into its "experience". It probably wasn't as responsive or featureful as a Wacom, but worked decently for the cost.
Any professional digital artist (especially 3d) will tell you they use multiple pieces of software and that many benefits from having the tablet buttons assigned differently to facilitate efficiency as an artist. This is (probably) why Wacom products track the software you're using.
Finally, "Being a mostly-normal person I never usually read privacy policies." - Robert Heaton
Sure, blame Wacom for your impatience, Mr. Heaton.
I don't see that in the second to last paragraph, and the word "optional" doesn't seem to appear anywhere.
The driver being aware of which software is active makes sense and is legitimate. The driver sending that information to others is unnecessary and illegitimate (since explicit consent was not given).
But the fact that there's a legitimate customer-oriented explanation doesn't make this okay.
I mean, if I added an always-on internet connected forward-facing camera and mic to a washer and dryer, I don't think we'd accept "to help you debug issues" as a good answer.
Agreeing with the author’s conclusion: >“This isn’t the dataset that’s going to complete the embrace of full, totalitarian surveillance capitalism. Nonetheless, it’s still deeply obnoxious. A device that is essentially a mouse has no legitimate reasons to make HTTP requests of any sort.”
Also, I always disable those “experience programs,” like Nvidia’s. They just give off data collection vibes:
>“If you too have a Wacom tablet (presumably this tracking is enabled for all of their models), open up the “Wacom Desktop Center” and click around until you find a way to disable the “Wacom Experience Program”.”
Generous view -- they're attempting to find combinations of software in an attempt to correlate software and their own issues.
Possible common choices for pen technologies are {Wacom EMR, Wacom AES, Microsoft Pen Protocol(formerly N-trig), Synaptic(unnamed?), Apple Pencil}. Apple Pencil and AES/MPP are well received on lower ends as well as for non-graphic purposes(especially note taking, where EMR is near unusable), so wallet voting can happen in markets for those, but nothing had replaced Wacom EMR in professional spaces if I understand right. That's why the company gets to keep pathetic 32", 4K, non-HDR, 310 nits, 1000:1 contrast, 98% Adobe RGB display for 4 grand as their absolute flagship product. Apple Pro Display XDR has same size of 32", but is 6K XDR(HDR), with up to 1000 nits brightness, has 1mil:1 contrast, has P3 wide color support, for 5 grand.
Also I think it's worth considering how or where Wacom got this idea. As Wacom EMR pen market used to be a very stagnating space with zero competition until it had been incorporated into 1st- and 2nd-gen Surface only to be replaced by N-trig on Surface 3 onwards, I think it could be argued that it was that influx of capital that caused them realize they could "modernize" this way.
While some people take an understandable but cynical view due to the close ties between most Chinese companies and the government, that's exactly why I don't worry. Any whiff of spying would be a diplomatic hazard.
Think of the ruckus when Bloomberg accused Supermicro of installing spy chips for the Chinese government.
https://9to5mac.com/2021/02/12/super-micro-spy-chip-story/
Now imagine actual, confirmable spying. This would be the end to a huge part of Huion's business in markets it's worked hard to build a good reputation in for access to people who likely don't deal much in the kind of information a government wants to steal.
Of course Apple's "Side Car" means your iPad is a pretty good tablet.
Is there a website that keeps track of these things, that I could consult before buying stuff? If not, could someone please build it?:)
You may be able to tweak your /etc/hosts to direct traffic to a machine you control, just look out for certificate issues.
Never had such issue on Linux with Wacom tablets.
Having blob drivers is terrible in general.
Last week I set up my tablet on my new laptop. As part of installing its drivers I was asked to accept Wacom’s privacy policy.
And this is where I stopped. You're doing it wrong. Drivers belong to the kernel. You should not have to manually install it. You should pressure the vendor to correctly support their devices.I have a Wacom device, tried it in different recent distros, different computers and never needed to manually install a driver.
God I'm so sick of these holier than thou Richard Stallman level unrealistic dismissals. This take isn't brilliant - we all, at all times, know that we have the option to not ____ if we so choose. Not unlike how people say things like "well I would just choose not to work at ____". That we often choose otherwise means we can't but.
>You should pressure the vendor to correctly support their devices.
Cool like by means of a blogpost that makes it to the top of hn that details how annoying the vendor's process is?
I'm sick of those that proselytize electric cars, since not everyone has the option.
I'm sick of those that proselytize walking/biking to work, since not everyone has the option.
I'm sick of those that proselytize recycling, since not everyone has the option.
I'm sick of those that proselytize philanthropy, since not everyone has the option.
I'm the first one who thinks these small sacrifices are probably not worth it since the sacrifice is usually way too much (handicapping yourself significantly) and the benefits practically negligible (i.e. small droplet in the ocean and all that). Much better to spend your efforts on political campaigns rather than this type of small-time stuff which yes, is mostly just for the show.
But what I'm sick of is the people who not only refuse to just bow down and shut up when presented with people that do make the sacrifice, but are instead outright hostile to them.
Everything you've said in this thread could have been more clearly and helpfully condensed to "the Linux driver doesn't include this behavior, and probably never could because it's open-source and upstreamed to the kernel".
> >And this is where I stopped
>
> God I'm so sick of these holier than thou Richard Stallman level unrealistic dismissals.
I understand your position, but they correctly support their device on linux, I'm sure they can do it on other OS's. > >You should pressure the vendor to correctly support their devices.
>
> Cool like by means of a blogpost that makes it to the top of hn that details how annoying the vendor's process is?
I think this is a good step. But people not buying it and pressuring the vendor to correctly support the device is not mutually exclusive.We must consider that it is lack of knowledge and complacency from users that incentivizes vendors to act in such an abusive way.
Sorry to sound stallman-like. I just wanted to raise attention to an important point that is mostly ignored.
This community has been a bit sharper than most when it comes to the kind of side-effects that seem to be part and parcel of the tech world and if that's not to your liking it confuses me why you would join.