Homebrew's analytics have moved to the EU and away from Google
docs.brew.sh
docs.brew.sh
> We gather less data than before and have destroyed all Google Analytics data:
> https://docs.brew.sh/Analytics
just noticed this morning, running some updates
$ brew analytics
InfluxDB analytics are disabled.
Google Analytics were destroyed.Removing that one will turn on the InfluxDB analytics.
(More generally, if you're going to be a paranoiac about these things: the US intelligence community loves it when things are provided by non-US entities. No warrants are required!)
The title is that analytics moved to EU. Which might be true technically but still goes to US company
I'd recommend not reading into others' editorializations. Homebrew doesn't control them.
From the guidelines:
> If the title includes the name of the site, please take it out, because the site name will be displayed after the link.
> If the title contains a gratuitous number or number + adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids."
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
> If you submit a video or pdf, please warn us by appending [video] or [pdf] to the title.
Which is to say the chosen title of the thread was editorialized by the submitter to emphasize what they wanted to emphasize rather than the original title that the Homebrew Project used.
Personally I think it's a cool thing.
- I like knowing the tech stack used.
- I like knowing where my data lives
- And on InfluxDB: It's well documented, & it was easy to get a PoC running.
HOMEBREW_NO_GOOGLE_ANALYTICS 1
HOMEBREW_NO_ANALYTICS 1
If you run the `brew analytics state` command like this it shows: InfluxDB analytics are disabled.
Google Analytics were destroyed.
Then you do `brew update`: brew update
Warning: HOMEBREW_NO_GOOGLE_ANALYTICS is now a no-op so can be unset.
All Homebrew Google Analytics code and data was destroyed.
==> Homebrew's analytics have entirely moved to our InfluxDB instance in the EU.
We gather less data than before and have destroyed all Google Analytics data:
https://docs.brew.sh/Analytics
Please reconsider re-enabling analytics to help our volunteer maintainers with:
brew analytics on
Installing from the API is now the default behaviour!
You can save space and time by running:
brew untap homebrew/core
brew untap homebrew/cask
You'll still want to keep the HOMEBREW_NO_ANALYTICS 1
Otherwise the InfluxDB one turns on.The data that is collected could still be identifiable via device fingerprinting.
1. Homebrew is entirely maintained by open source contributors. Keeping thousands of packages up to date is a significant task even before considering maintaining the packaging core itself, and analytics serve as both a warning system and hard data for package importance, instability, etc.
2. Homebrew is somewhat unique among package managers because of its relationship with the host OS: it has no say over how macOS behaves, and needs to adapt quickly to changes made unilaterally by Apple. Analytics help detect that kind of top-down breakage.
FD: Current member of Homebrew, former maintainer.
Although, admittedly, I use Nix-Darwin to manage my Homebrew apps.
Thanks for your contributions to Homebrew :)
Why?
Homebrew is provided free of charge and run entirely by volunteers in their spare time. As a result, we do not have the resources to do detailed user studies of Homebrew users to decide on how best to design future features and prioritise current work. Anonymous analytics allow us to prioritise fixes and features based on how, where and when people use Homebrew. For example:
- If a formula is widely used and is failing often it will enable us to prioritise fixing that formula over others.
- Collecting the OS version allows us to decide which versions of macOS to prioritise for support and identify build failures that occur only on single versions.The only improvement I personally want for Homebrew is for library packages to never include version numbers in the dynamic library file names.
you're trivializing a very big and complicated issue. why not both?
what is worse - anonymous usage statistics or needing to sign up with an email address to get notified of surveys and whatnot. one is passive, one is active.
it's also about more than just feature improvements... brew runs on a ton of different platforms/environments (https://formulae.brew.sh/analytics/os-version/30d/) and having this data helps prioritize the efforts of open source developers.
without analytics data you are flying blind.
Analytics are an essential burden-reducing component of the Homebrew maintenance workflow; the maintainers would not have time to make improvements like the one you're requesting if they spent their time on the things that analytics do for them.
Homebrew is an open source project solving a fairly complex problem with volunteer maintainers. Analytics are constant and measurable signal on all sorts of things and can be used both proactively and reactively to deal with an array of concerns from user experience issues to bad rollouts.
https://arstechnica.com/tech-policy/2023/07/big-tech-can-tra...
Almost sounds like the annoying popups are in spite and not out of need
Besides the obvious "less data, fewer problems" angle there's also the bureaucracy angle - last time I worked on gdpr compliance I got stuck in the middle of a fight with security (who wants to store all the data for ever), the legal team specifically in charge of figuring out what's in scope for GDPR, and another more generic legal team (this one was the worst - they had no idea what the system does and ignored any attempts at explaining it, plus they kept pushing for unrelated often contradictory retention changes)
Logs like that fall under 6.1.b-f, basically "making sure malicious actor can't fuck with site" overrides needing to get permission to process that. Again, if they are used ONLY for that and are stored securely.
Same reason why security footage (which also falls under GDPR) doesn't need consent, only information visible onto property entrance informing who is processing that info.
And if you want to gather data it's also not too hard, just ask for it and tell user exactly what you're going to do with it.
It's when you want to cajole user into agreeing for gathering way more data than they would consent to if someone explained the extent to them plainly, and to send it to a bunch of 3rd parties too, that's where the difficulty starts and you have to use the blackest of black of techniques to cheat user while still being technically compliant to law.
For example, does your company have employees? Congrats, their HR files (and anything else with their name on it) are covered under GDPR. But you can’t just get consent to handle their data here, since they’re employees and there’s a power mismatch. Instead, you need to rely on the “legitimate interest” clause, which requires specific legal documentation on impact analysis that must be kept up-to-date.
Or another example: if your error logs contain IP addresses, that’s PII and subject to all the complexities of GDPR handling. Even in the absence of logging, I’m not sure a plain web server with all logging off isn't subject to GDPR given how broad the legislation is - after all, it has to process PII (IP address) to send responses, and GDPR covers any system that “uses” PII.
To be perfectly clear, I’m not saying this is bad, but I am saying it’s complicated and not just as simple as “just don’t gather data” or “just get consent”. It’s not easy, you probably need a lawyer’s help.
For example, you don't need consent to store server logs with IP addresses if all they're used is for security and auditing. You don't need consent to archive receipts and invoices if you need to do that for tax purposes, even though those are full of PII. You don't always have to let people opt out of that, either!
That's called legitimate interest, and did you know you have it?
If the person might be a child then the rules have been complex and obtuse since forever. You might need a DPO for regulatory compliance, much in the same way you might need an accountant.
You can’t just claim legitimate interest, you need specific, up-to-date legal documentation in the form of an impact assessment.
> You might need a DPO for regulatory compliance, much in the same way you might need an accountant.
Exactly! All I’m saying is (much like accounting) GDPR compliance is not easy or simple or something you can spend fifteen minutes on and be done. GDPR compliance is complicated. I’m not saying it’s bad, but I am saying that (contrary to some of the comments here) you can’t just say “Oh, I have consent or legitimate interest so GDPR is solved”.
You totally can, until someone challenges you and proves you don't; otherwise, common sense applies. A storage unit might have a legitimate interest in keeping license plate numbers but an ad company probably doesn't.
As with most things in law, there is no black-and-white. Just use your brain. If you feel like you can stand up to a judge and defend it with a straight face and no mental gymnastics, you're probably golden.
source: implemented GDPR in 2018 at a multi-national company and worked with attorneys around Europe.
A handful of businesses with their hands in multiple pots may have more trouble.
It's basic human shit. If I lend you a book and you lend it to one of your friends, I'd expect you to let me know; _before_ I ask you for it back. This is basic human decency, (I think?). This law was enforcing basic human decency that companies seem to have forgotten along the way.
It quite obviously says that. That is literally the whole purpose of the law.
> This law was enforcing basic human decency
The law has nothing to do with human decency or book lending
Basically, you need to sit down and figure out: 1. What data are you storing, 2. What are you doing with it and who you are giving it to, 3. Is it personally identifiable information, 4. Why are you storing it and do you really have to.
Yes, the GDPR's intent is to force businesses to think about that. For a lot of businesses the answers to those questions are actually quite simple.
Logs containing IP addresses is exempted from GDPR for anything related to security. Processing the logs for purposes other than security require the complexity of GDPR handling. It is the purpose that define the complexity, not the logs.
PII is defined so broadly, but so is also its exceptions. Employers has to first know a bunch tax law and employment regulations related to employing people, and those do require specific legal documentation on impact analysis that must be kept up-to-date. People who do not do this can not employ people, or risk breaking the law (especially tax law).
They aren't exempted, they fall under legitimate interest.
(49) The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned.
This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping 'denial of service' attacks and damage to computer and electronic communication systems.
You’d be comfortable with services publicly sharing IP/geoip details of its private users?
Homebrew is a complex system that can break in lots of ways, and it’s being developed on an entirely open source basis, with no company behind it.
Having some visibility into the operation of a running system is table stakes. You’re asking the developers donating their time to this very useful project to tie a hand behind their back because you are paranoid.
More often than not, if people like you got their way OSS software just wouldn’t be built, or would be taken over by a for profit entity that has much less benign ideas about spyware.
This is literally a story about the homebrew project listening to the community and migrating to privacy-preserving self-hosted analytics. People like you will never be happy, so they should be entirely ignored.
It's not like Google can't get all the data it wants from the people using Chrome.
All GA really does is ensure the non-Chrome users get captured by Google.
And -- more importantly -- give you insight into what Google sees on your site.
So if you turn off GA... sure you sort of hinder Google... in that Google gets maybe 10% less usage data from your users (at most 10%).
But you take away your ability to see what they see about you.
Google is still 90%+ of search traffic. So moving away from GA just feels like putting your head in the sand.
So I don't know, I mean I get that you don't want to be tracked, and have your data shared, but that's not what moving away from GA solves.
I don't know what moving away from GA solves.
3 days later, EU signs off on data transfer.
There's something to be said for not wasting time on changes that don't matter in the end. All these people getting worked up for nothing.
https://arstechnica.com/tech-policy/2023/07/big-tech-can-tra...
If Google isn't in compliance, Google will get there... or appeal the ruling, or find some other way so that every user of GA doesn't have to migrate off it.
So I find it cringe because I see it as the tech equivalent of those people who rave about 5G making their COVID vaccines magnetic. It's just GA... use it, don't use it. But jumping to comply with a poorly written law, and saying like, "See this law that is poorly written deserves our respect!" Meh. It'll all get overturned. It's a poorly written law.
Plus there are plenty of places to go to "get your GA into compliance" without uninstalling GA.
* How to Make Your Google Analytics 4 [GA4] Implementation GDPR Compliant? - Reflective Data | https://reflectivedata.com/how-to-make-your-google-analytics...
GA was found to not comply with GDPR, so unless you want EU ban you have to leave GA
https://usercentrics.com/knowledge-hub/google-analytics-and-...
A Swedish company just got a huge fine: https://techcrunch.com/2023/07/03/google-analytics-sweden-gd...
Here's an article that linked from the one you sent. Even the EU Parliament is in violation of GDPR. =P
* European parliament found to have broken EU rules on data transfers and cookie consents | TechCrunch | https://techcrunch.com/2022/01/10/edps-decision-european-par...
I wear a tinfoil hat as much as the next guy, and I have studied up on GDPR rules at work, and all I can say is they are designed to basically give any country the ability to say, "We don't like you, Americans. You are bad and we don't like you."
Like it or not, we're all connected. You can look at websites in France, or Germany, or America.
Having different rules for the data makes sense at the company-level, or server-level. "Here are the rules for Norwegian companies..."
But it just doesn't make a lot of sense for French laws to apply to US-servers. Where does that end? If Alabama passes a law saying "You have to have just English on your website..." but Canada says, "You have to have your website in French and English..." who wins? What do the developers use as the source of truth for their requirements?
And if we have to have one version of the website for each and every state and country... isn't that problematic... I mean you get that's problematic, right?
I think these courts ruling against Google are small courts, I think it'll get overturned. I think it likely has more to do with finding different ways to punish Google / Apple / other tech companies for not paying more taxes inside of those countries.
EU nations set up a lot of taxes, then get upset when global companies don't choose to build offices there. All of the regulation around data just feels like another "what can we do to be petty in response for them not paying us more taxes?"
Exactly like the USB-C adapter thing.
Anyway, just my 2 cents.
Google is skeezy, I get it... but fragmenting the web into a different set of rules for viewers in every nation... that's not the answer. It really can't be the answer.
I agree, but that boat has sailed, and now Homebrew is dealing with it.
For myself, Google never seemed to pick up which websites I visit. At least ads never followed me around. Probably because of my surfing habits: I open websites in a new browser instance and then close the instance. So no cookies stick around. Because I have set Firefox to delete cookies when closed. They could have tracked me via fingerprinting, but I have not noticed that happening.
Others surely have other browsing habbits. Keep cookies around forever, and Google knows most of the websites they visit. So when they google for a new fridge, they see fridge ads everywhere for a week.
But is that really a problem? What are the real world negative consequences?
Tech companies now seem to geo-fence their new products and keep European users out right from the start.
Which makes us even less productive by having less and less tools available.
Is it worth it?
Or are we just shooting ourselfes in the knee, having to crawl instead of walk, and turn into a 3rd world continent?
Also, pop-ups are a bit annoying, but most of the time websites work OK if you refuse to save cookies. So, like, I'm 1 click away from stopping those political actors to have info on me - a W for me
Add CCP to that list and you might see some eyebrow raising in Congress.
You name the 10 most important tech products of the year so far.
And then we go through them and see if they are available in Europe.
the burden of proof lies on the one who makes a claim
Now you made a claim. Time to proof it.When asked for proof, you've run away.
Do name them, please. And then revisit that list and ask yourself: how many of them exist because of two things:
- unlimited investor money with no expectation of profitability
- blatant disregard of data privacy, user privacy, and/or other laws.
Great example is OpenAI. They said they welcomed regulation. The moment EU proposed level-headed sensible regulation [1] that among other things required documentation on how foundational models are trained and where they get their data, Altman screamed that they would pull out of EU.
[1] https://softwarecrisis.dev/letters/the-truth-about-the-eu-ac...
which is a bit weird because if shops does none of the business with EU they don't even need it...
Threads isn't blocked either. It's Facebook's own conscious decision because they haven't yet found a way to circumvent privacy laws.
I said Instagram.Threads, to separate between threads.net and threads.com.
> because they haven't yet found a way to circumvent privacy laws
So the fence is working.
Ah, didn't catch that :)
> So the fence is working.
Indeed.
Sorry for misunderstanding!
Then overall, privacy is a much larger problem. For one, with generative AIs coming, it is very scary to realize that those big corps know almost everything about almost everybody (maybe not you, if you don't use cookies, don't have a smartphone, etc), and are technically able to train generative AIs with that data.
The second problem is that because the business model is surveillance capitalism, then big corps don't optimize for making a product that users are willing to pay for, but instead they optimize for gathering more and more data about their users so that they can make profit with it. Typically social networks play against their users in order to sell them.
Loss [or lack] of privacy. I'm assuming you clear your cookies - why?
1. Morally, are we encouraging tech to go in a more human direction? Definitely.
2. Operationally, is gdpr working well? I have gotten many companies to delete my data and stop spamming me by referring to gdpr, so on that front I see a big win. Cookie banners are not essential or required by gdpr but an industry choice to bully users to accept something. So on that front, I feel gdpr falls short as it still allows companies to go this route.
3. Economy wise, have we lost anything? Are data brokers an essential service for a functional society and economy? I don't think anyone or anything except spy services and as tech lose out from gdpr.
4. Communication wise, people rarely see the benefits and only the fallout from gdpr (cookie banners) and the lobby push against it (business newspaper articles on the horror of compliance as their company needs vast amounts of data on non- customers). The benefits are much more hidden.
You go through more effort, time and work in just this one step every day than "all this work the GDPR causes"
"I fixed problem for myself but I'd like for it to not be a problem at all for other people that are poorer or less technical than me" is perfectly reasonable stance to take.
GDPR is only a problem if your main business is selling people's data. As it should be.
I should re-read things before I reply :)
This thing drops a supercookie on your device that persists forever, and they close every issue raised discussing the privacy implications of same.
Anyone who runs the analytics service can see the approximate travel history over time of every Homebrew user (by geolocating the source IP).
It's not a for-profit project. There is no legitimate purpose for tracking installs.
From the very top of the linked page:
> Homebrew is provided free of charge and run entirely by volunteers in their spare time.
> As a result, we do not have the resources to do detailed user studies of Homebrew users to decide on how best to design future features and prioritise current work.
> Anonymous analytics allow us to prioritise fixes and features based on how, where and when people use Homebrew
It then goes on to list some examples. Opt in renders this useless.
Yes, many tools give you an option to opt out nowadays, but then again do you want to learn how to do that dance every single time? It’s almost like we need some kind of… DNT, but for the console.
And even that misses the point: with the German concept of Datensparsamkeit, there shouldn’t be any data collected at all, unless it is absolutely necessary to conduct your business. Popularity contest in Debian comes to mind when talking about informed consent.
The point is not InfluxDB or GA. That just sounds like good guy with a gun/analytics vs. bad guy with a gun/analytics logic. The point is: the combined genius of the computing world, and all we could come up with even after the 100th iteration is “Analytics go brrr”.
In practice, I'd expect the behaviour of the modal complainer to be: 1. to complain about any broken/removed functionality 2. refuse to fix it themselves (or fund the fixing) 3. refuse to opt-in to tracking so as to give impartial of usage.
So I think the trade-off of default analytics where the volunteer contributors make a best-effort to keep things working for as many people as possible is beneficial to most users. (And for those who disagree, they can opt out).
Opt in is renders the data statistically useless in the same way.
This data is required to allow Homebrew to continue to operate and make decisions.
They go out of their way to inform you before sending any data. First sentence of the article:
>You will be notified the first time you run brew update or install Homebrew. Analytics are not enabled until after this notice is shown, to ensure that you can opt out without ever sending analytics data.
Imagine if you posted a "entry is consent to physical interaction" notice on the door to your building.
Consent does not work that way.
So, while you’re right that the EU and the US both have flaws in this area, this move is still an improvement.
That's so vague it can apply to anything in any country... Wanna add specific examples?
Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC
Digital Services Act
>Digital Services Act
-20 is better than -30 but still far below 0. That's why I said "EU either."