This is also a good example of the benefit of telemetry: that they have crash numbers coming back from the field lets them tell that this really did work in practice and get a sense of how much of the problem they've solved.
This is also a good example of the benefit of telemetry: that they have crash numbers coming back from the field lets them tell that this really did work in practice and get a sense of how much of the problem they've solved.
For what it's worth, I have no issues with telemetry as long as they are opt-in and there is transparency on exactly what is collected.
It's having to opt-out (or not being to opt-out at all) and vague explanation on what and why there is telemetry that I take issues with.
Crash logs are a different beast.
And very biased towards what? People not triggering bugs?
opt-in telemetry is effectively the same as no telemetry.
if you have (or anyone has) a problem with crash statistics being tracked via telemetry then I have absolutely zero idea how to convince you that it's a good idea that this blog post doesn't already clearly state.
it's the same with OS updates; people (generally) simply will not perform system or security updates unless they are forced, because everyone thinks they are smarter than the "script kiddies" who would use an attack against them. the user thinks they would see an attack coming and avoid it. in short, they don't. viruses spread, the US Congress calls Microsoft in and asks why the systems weren't patched, and Microsoft says "the users are responsible for patching" and Congress doesn't like it.
so now we are where we are. OS updates are forced after a time, and telemetry is not only the norm, but a very good idea for applications in use by millions of people, like Firefox.
Updates were not the default. And when they became almost mandatory Microsoft started bundling "features" with security updates. That's when people started to disable this "feature".
> so now we are where we are. OS updates are forced after a time, and telemetry is not only the norm, but a very good idea for applications in use by millions of people, like Firefox.
And this doesn't change anything. Ransomware attacks are still the norm.
[1] https://www.cio.com/article/274775/it-organization-luser-peb...
My tone here is borne out of users shooting themselves in the foot and then complaining about the pain and inability to walk. At every opportunity that I have taken to give computer users the choice to do the thing that is good for them, the overwhelming majority have failed to make that choice. The people who visit this site are mostly not that kind of person, though there are plenty here who are.
We have shown Microsoft that we simply will not update our operating system or even reboot unless forced. Many, many times we have made this clear, even though patching is overwhelmingly a net positive for both MS and its users, generally speaking, users simply won't do it. They just won't. History bears this out.
Updating is a short-term inconvenience in exchange for long-term security and stability, and people do not think about those things logically. The importance of the immediate future is amplified by a large factor, and the importance of the future is attenuated by a large factor, in most people, especially when it comes to people who view their computer as a tool. Sitting in front of a computer is indicative of a user wanting to complete a task, and manual updates impede the ability to perform that task. That makes installing updates and stopping work to reboot a non-starter for those people. They just won't do it.
I don't know how else to say it. It's not a matter of tone so much as it is a matter of fact.
> My tone here is borne out of users shooting themselves in the foot
Frustration. I hear you. Sure, it's frustrating that they exercise choice (however misguided you see that) and then "complain". It's very nice if you've written code, and even nicer that you care for your customers. But, as developers, they aren't our children. I've been there and it's galling, and feels like a rejection, but to accept what is unrequited is sometimes harder than giving it.
> the choice to do the thing that is good for them,
This is the elitists' dilemma. Please don't be insulted by that word, I'm using it literally and appropriately without value judgement (I am foremost an elitist, and secondarily a peoples' champion, and it is a position that can only ride on a measure of arrogance - which must be tempered)
The fact is, it's not your computer. And that really is the long and short. One must respect that if "users" do not wish to take advantage of bug fixes more speedily available through telemetry, then it's their choice to have suboptimal, buggy programs.
In other news, our children will listen to shit music and get into drugs and relationships we disapprove of etc.
> We have shown Microsoft that we simply will not update our operating system or even reboot unless forced.
For very good reasons. Microsoft have shown themselves to be utterly untrustworthy. I really don't think that's even debatable. And it's a shitshow because I do not believe trust can ever be repaired. It leaves the reality that one of the biggest vendors on the planet is in the position of forcing users because it has squandered the reputation necessary to do good-faith business, to propagate its updates. That's tragic because they probably see no way out except doubling down on abuse, authoritarianism and beating users to their will - and ultimately that confrontation will be the end of so much we have built.
What makes this worse is that security is about more than personal choice (think vaccinations). In other words the damage that Microsoft (and other big-tech abusers) have done goes far beyond simply destroying the individual trust relations with their customers. They've corroded the social fabric of trust in computer security at a more general level - a cost that is incalculable.
> people do not think about those things logically.
You are right. And we should not assume that they should. Emotion is a powerful reasoning tool, and only a fool ignores that force of psychology. Once burned twice shy - and we as developers have been burning a lot of peoples' fingers these past 30 years.
> I don't know how else to say it. It's not a matter of tone so much as it is a matter of fact.
I see it means a lot to you. That is a good thing in itself. You care, which is x10 above the norm.
But we cannot force them to be what we wish them to be. Especially not "for their own good" which is where all tyranny begins. We cannot force people to adopt products, customs, behaviours, sing the party line, or any of that hegemonic nonsense without invoking an age of "consumer communism".
It saddens me that in 2022 we still need to address the patrician attitude. It's not the way forward. It's sad to see such a deterioration. But so long as companies like Microsoft persist a culture of smug superiority, cavalier conceit and intransigent disrespect to the dignity of their users we will have to accept "fuck you" decision making. And frankly, more power to those courageous enough to say it.
No. People do not perform system updates because a) it's a chore and b) it get's in the way or even breaks things. To do an update I need to agree to give up control over my device for some time (often undetermined) and then risk that updated code causes issues (it's not uncommon). We need to design apps and operating systems with seamless and reliable updates in mind, not force people to suffer.
That's an indication that people don't want this.
It's an indication that optional steps which do not immediately benefit the users of the software will not be taken.
The benefits to telemetry are longer-term, and because opting in is not required for the software to function, the vast majority of users simply will not do it. The thought to turn it on will likely not even enter their mind. Why would it? The software works fine.
Opt-in telemetry was tried by just about everyone that collects telemetry today. Lots of people say they will turn it on, and then never do. Telemetry is used to make better software. I'm sure there are companies that use it for [insert activity that any person might perceive as bad] and I would argue that those companies would likely not allow you to opt out.
If people understood the kinds of things that are collected, at least the things I collect in the software I write for work, I can't imagine anyone having a problem with it, but there's a lot of things that people do which make no sense to me at all, so I'm not really in a position to be authoritative.
I do know what happened in the late 1990s and the early 2000s though, and I know those things are a large part of why telemetry and forced updates are things which exist today.
I believe that absolute vast majority of telemetry is simply ignored. And I also believe it is very common that there are several individuals in most companies that couldn't care less about what is included in the telemetry.
A lot has changed since the late 90s, it really isn't good argument for telemetry nor forced updates that things were bad then. Things would have been absolutely awful in the late 90s even if you had perfect telemetry and instant updates that somehow didn't even need internet.
I don't see any real arguments for either in your posts.
Regardless of how strongly you feel about telemetry and its perceived "benefits", the choice should always rest in the hands of the individuals using the software first and foremost. Your customers should always be informed of their choice and if they feel like they are willing to participate, they can opt-in.
How would you feel if building architects decided to install a camera in your bathroom in order to analyze how you use your toilet and the shower to assist in improving future constructions?
> Lots of people say they will turn it on, and then never do.
Because most of the time, there is no benefit. The software is already made, and further development is rarely informed by telemetry data. Furthermore, customers are rarely informed exactly what data is being collected - and not given the opportunity or benefit to inspect the contents of any telemetry or crash logs that need to be sent.
> If people understood the kinds of things that are collected, at least the things I collect in the software I write for work
But they don't. And no one takes the time to educate or inform them or give them the choice to opt-in with a detailed disclosure of what is being shared, rather than having to opt-out. As people become more aware of these telemetry practices, you're going to see a wider backlash at the kind of unnecessary data that are being collected. Maybe you're not doing it - but others are.
There are other ways to test software... Especially the use-cases mostly used by users not well versed in the tech world.
I was under the impression that Firefox was written in Rust. Doesn't this eliminate crashes? Rust is a safe language after all. There should not be any crash logs with Rust.
That also said your parent equating memory safety to “no crashes” is also not correct. A process can exit early while never violating memory safety.
Rust has a `panic!()` macro which will hard-terminate the program and log a stack trace in what is functionally equivalent to a crash. It can be called in various scenarios... including out-of-memory situations (like the ones being addressed in the fine article and this thread).
This service would be guaranteed to be unidirectional, would store data publicly on non-profit-run servers and domains and fully comply with GDPR (by not storing any PII and ano/pseudonymising everything).
Developers would connect to this service over dbus and consume the uploaded data in daily batches.
Hosting and hardware fees would come from donations by distributions and other organizations distributing money to the FLOSS ecosystem.
Love the idea!
There's nothing stopping a person from creating that. You'd package it up and get it added to the Debian, Ubuntu, RedHat, etc. repos and people would be able to install and use it. That's about as close as you'll get to having it generally available for all Linux distros.
Personally I don't see the value, and think it's invasive, so I would never install it, but people who wanted it would be able to use it.
The telemetry proxy service would need packages for each distro, including scripts to work with systemd and init, and maybe a "libtelemetry" package to make using the service easier.
The way I see it working is that if the system service isn't installed, isn't running, or has remote telemetry turned off then the commands for sending telemetry will succeed but send the data to /dev/null. Otherwise the data gets anonymized and uploaded to the user's configured telemetry host.
It could almost be built on syslog, now that I think about it more, but that would be terrible.
This page from Debian Wiki may be interesting to see what all is out there: https://wiki.debian.org/PrivacyIssues
I enable it on my personal production systems and disable on everything else, both on privacy grounds (work), and not providing wrong data (disposable VMs).
This is the right approach.
Privacy should be privacy by default, and if you want users to send you crash/usage logs then you need to show them all of the dirty details, let them review it and chose whether or not to send.
https://probes.telemetry.mozilla.org/?search=crash shows automatic telemetry probes. The main bit of data in that set is FX_CONTENT_CRASH_* and you can see the back and forth from the data steward and the engineer adding the probe. https://bugzilla.mozilla.org/show_bug.cgi?id=1269961#c8
What in that report is creepy? Surely knowing the percentage of people on 32- vs 64-bit isn't problematic. Maybe add-ons? I'm genuinely curious.
Next thing you know they might try to increase engagement time like they're some sort of social network. "Unlock the new exclusive colorway by logging in 30 days in a row." seems like something that could be implemented, seeing how they're time limited already.
Usage times and intensity are of high value when trying to improve market share. People who barely use the browser are at high risk of stopping use altogether. (For example, they might use multiple browsers, but most of their activity occurs on another and if they figure out multiple profiles or something, they'll leave altogether.) You can't do an A/B test to see what improves usage intensity if you don't measure usage intensity. Also, it's far from PII. And making it opt-in would make the stats useless; people who explicitly choose to allow telemetry are going to have vastly different usage patterns than the bulk of people who do not so choose.
Extensions are very important for crash reports. Far less than they used to be; many crashes could only happen when an extension did something specific. Extensions are now sandboxed enough that this isn't nearly as common, but if a crash signature has a high correlation with a particular extension, it can easily turn a non-actionable bug into something actionable.
Extensions for general telemetry are iffier. The info is fairly high value for things like understanding how people are using the browser and what features are popular or missing. But rare extensions also provide a lot of fingerprinting info. It's important to keep those metrics away from PII, and recorded independently so they can't be correlated.
Country of origin is pretty clearly useful. Mozilla has to allocate resources across countries, including marketing resources, but I would think it's really product management where it matters most. Users gain a lot of benefit from the browser adapting to different markets. (Screenshots have a wildly different importance in countries with Asian writing systems; Europe and especially Germany take privacy much more seriously.)
> Next thing you know they might try to increase engagement time like they're some sort of social network. "Unlock the new exclusive colorway by logging in 30 days in a row." seems like something that could be implemented, seeing how they're time limited already.
Heh. I do not want to predict what our marketing people will or won't do. I have mixed feelings about quite a few things. I'm not happy about ads appearing anywhere in the interface. But I'm also not happy about being dependent on Google ad money.
How about the profiles of the people who opt-out?
Second, it's fair: if you disable telemetry, you're choosing to not be considered in any telemetry-backed decision making. If you want to still be considered, then it's up to you to make your opinions heard in some other way. (Filing bugs or https://connect.mozilla.org or discussions in places like here, though note that the latter is mostly useless. Not many Mozilla people read this forum or take what is said here very seriously. And even if they do people will be vigorously arguing both sides so it's easy to pick the side you already agree with.)
There's nothing wrong with disabling telemetry. I respect the decision, and I'd certainly rather have people using Firefox with telemetry disabled than have those people not use Firefox. But it's your browser, and even the social contract by which you're using it doesn't say you owe us telemetry data.
* telemetry is evil
* if the product is free (Firefox), you are the product
It seems Firefox executives take a large chunk of money from Google; presumably to make sure Firefox doesn't do anything too wild that would reduce Googles income.
I wonder how much of what the Tor Browser version of Firefox does, would be upstreamed to Firefox proper, if not for that deal?
(I wonder how much the Firefox team considers Tor Browser to be "the real Firefox" / "Firefox the way we intended", with Firefox itself just being "the sell-out version of Firefox"?)
Firefox is my union representative. They are better able to fight for my interests against Google than should I go it alone and use Chrome.
Its not a perfect system, but it should somewhat work.
But many of us who used it from the start think it was a much better browser before. For a long so much was sacrificed for next to no improvement.
For me it was more or less rock solid at >800 tabs and with a lot less memory and more exciting extensions than I have now.
I admit this wasn't everyones experience, but as a superuser tool it has degraded a lot over the years.
That said it is still the best browser for me: I don't think anyone else except Orion (which is Mac only) has actual tree style tabs (not to be confused with vertical, non indented tabs as seen in Opera derivatives).
The "make it hard to find" to "nobody uses it" to "let's delete it" pipeline is very real. Reminds me of the "defund it" -> "it does not work" -> "let's privatize it" pipeline in right-wing governments.
As a larger piece of the visible audience, I then hope that more attention is given me. This is especially important for open source projects. And I don't care that much about what the company is getting from me.
But listen, they collect all sorts of stuff and you should disable it unless you understand it. Ideally, privacy laws expand to the point where you need to email a signature saying you understand before you opt in to telemetry. Informed consent is required for any reasonable study.
> Telemetry is the in situ collection of measurements or other data at remote points and their automatic transmission to receiving equipment (telecommunication) for monitoring
> Wiki https://en.wikipedia.org/wiki/Telemetry disagrees
It feels like your response fails to address the point colejohnson66 is making. They are saying "some spying is done via telemetry, but not all telemetry is spyware." The automatic nature of it is orthogonal to its spy-ness or user hostility.
Basically, "automatic" here is an antonym to "manual" e.g. user emailing a bug report.
Personally, I consider the following sorts of telemetry "not spyware":
- coarse grained crash report (build version, arch, etc). this is usually a manual prompt on crash, so "semi-automatic telemetry" is how I'd define it
- anonymized metrics/spans. Basically "foo_bar() took 20ms". These are "automatic" in that the collection and transmission happen without user input, but that's orthogonal to whether the user opted in/out.
Fine-grained usage information is a lot more spyware-esque.
The benefit can be claimed only if the user consented into their private information being shared with the browser vendor in the first place. With most browser telemetry that is not the case and browser is simply not respecting users' privacy. The right to privacy, as a human right, trumps the 'right' to have the product 'improved'.
Otherwise we can find "benefit" in everything. One of the benefits of hell, for example, is that it is never cold.
But since the product is digital they just have to give it away blind? Never knowing if people even use the features or not?
So if software is a tool and my drill is monitoring the holes I make in stuff and its efficacy in doing that, that seems fine, but if the drill is sitting in my toolbox being a busybody and sending back everything it can find about me from within the toolbox, that drill is made by assholes, don't you agree?
That seems like an unfitting comparison. The problem doesn't arise in the store, but when using the product at home. The equivalent of store cctv in this comparison would rather be a server log on the Mozilla website (where people get the product). It's fine to do telemetrics there without me consenting (as long as it's only used by first party) if you ask me. But after I leave their premises it's none of their business how I use the product.
Sounds like you want it to be ok that your newly bought pack of condoms sends out a message to the factory once you open one.
Not to mention that Firefox is open source, so you (and GDPR authorities) can check yourself what exactly is being sent...
Even if that was not the case, a privacy respecting (any?) browser has no business whatsoever sending any information from my machine, including "I crashed because of OoM" or "I clicked button X" unless I consent with it doing so.
Therefore zero telemetry by default is the only acceptable standard for any browser that claims to be privacy respecting.