Manjaro is experimenting with **opt-out telemetry
discuss.privacyguides.net
discuss.privacyguides.net
Apple, who is known for being pro-privacy, makes your Mac "phone home to obtain a special boot signature, known in Apple jargon as a 'ticket'" just so it can boot after an update.[0] It's also known that macOS has checked app signatures online for over 2 years [1] in the past, not sure if it still does.
I'm happily using a MacBook nevertheless and I bet a lot of people browsing HN also do. Free software should be better than that, but we (their users) should also make their developers' lives easier. You can't expect high-quality software from mostly-volunteering engineers if they are fighting fires, and data-driven decisions if there is no data to begin with.
[0] https://mjtsai.com/blog/2022/06/16/apple-reneged-on-ocsp-pri...
[1] https://eclecticlight.co/2020/11/25/macos-has-checked-app-si...
It is still much less data, and does not allow them to identify you AFAIK. Even if they go with opt-in (not yet decided - it seems to be being debated and thy are asking for feedback) it is still far better than proprietary OSes.
Like any at all?
There's this deep sense of entitlement coming from software devs and vendors, that's completely unjustified. Comparisons on the amount and type of data collected is missing the point. It doesn't matter whether Manjaro is sending more or less telemetry than MacOS - neither of them should be doing it in the first place.
They have no actual right to that data, no matter how much having it makes the devs' jobs easier. What they should do is ask for it, honestly and convincingly, like asking users for a favor, because it's exactly what it is (and it's not like anyone is considering compensating user for the service).
I frequently wonder what breed of human sincerely disagrees. I sometimes think the realm of software encourages through detachment (remoteness, distance from the users) a sense of liberty for the id. If this shit was attempted physically, in person, there'd be a lot of missing teeth.
Data collection can be harmful, but it's also extremely useful to know how people are using products and infrastructure. There's a balance, and if you're on the "zero data collection" side, I think you need to justify making the devs' lives harder by explaining what harms will come from the proposed collection.
I disagree. I don't need to show actual harm to reasonably object to being spied on. At least Manjaro isn't talking about making this mandatory, but opt-out is is still a very poor look that would make me avoid using it as long as there are other options that are more respectful.
Please explain what specifically Manjaro is proposing to do that you classify as being "spied on." Don't handwave this away, actually answer the question.
What I'm complaining about is the evasion of having to get informed consent to collect personal data. Opt-out is a way to try to cover your ass while at the same time being able to avoid asking for consent.
The argument for it is always the same: if we make it opt-in, then not enough people will opt in. Which is another way of saying "if people won't give us permission to collect data about them, then we need to stop asking permission."
It's not really a compromise. It's devs declaring that they deserve access to this data regardless of what users want, and trying to make it less objectionable. It remains the case that this is a back door method of extracting data from users that they don't really want to give.
If users didn't mind giving it, then enough would say "yes" to the opt-in screen that it wouldn't matter. But they don't, so these devs are trying to impose the very thing users don't want as forcefully as they can get away with.
This is all about disempowering users.
Precisely!
That is, the specific information does not matter; the fact that someone wants to keep it hidden (which is their stated preference), and someone else wants to collect it through clandestine means (which is how we could interpret a sneaky opt-out mechanism) is enough to define it as being spied on.
2. It very much matters what the specific information is. I too wouldn't want my Linux distro scanning my GMail inbox through their distro-bundled browser, of course. But how many times I started Kitty is something I don't quite enjoy being shared but I also wouldn't be outraged if it was.
Nuance matters, just doing an extremist takes does not help anyone.
Yes it is, until I choose to share it. That is the point of consent - I decide what I want to share, not you.
As said in another comment of mine posted just minutes ago -- practice shows that anonymous telemetry is the only viable way of getting some usage data. Almost nobody fills out surveys.
Do most software need those stats? I'd say they don't, but I worked on pieces of software that absolutely needed to know which parts are most used and which are almost not used because the extra features cluttered the UI and confused people, leading to less buys / subs.
There are endless examples of data flowing where one wouldn't expect. Doesn't IP6 wrap the MAC address into the IP? This alone is pretty significant. It goes on and on, but I don't see this as an excuse to go full-nudist in a fit of futility with all data.
And another thing I frequently wonder: who benefits? I honestly don't see things functionally improving in a way that I can't live without as a result of all this telemetry. I don't see that many people clamoring for the kinds of improvements this telemetry is supposed to enable. I know technology does improve, but I just can't remember where things were so bad I needed to mass-email my dossier to the world. Generally, I just made a forum post or bug report.
I've done so, no less than 15 times in the last ~9 years. We always took special care to never include anything personally identifiable; it was a hard requirement and was enforced in code reviews and because of that we ended up hashing user IDs because we still wanted to do flame graphs and various distribution statistics of API endpoint usage and user IDs were one of the axii (two others were hours of day and days of week), but we didn't care who the user was.
Seriously, a little less extremism helps. I am a programmer, likely just like you. We are trying to get some data to improve our software. In several of my previous gigs even the CTOs barely cared about the telemetry graphs and aggregation dashboards and only looked at them at the middle of the quarter to make sure we're not spending too much on Grafana so the executives won't bite their heads off. And the CEO / marketing? Forget it, they don't care.
Of course there are some very predatory companies out there, no doubt. But I think we would be very hard-pressed to put the team of an open Linux distribution among them.
Sure, but that's not really the point. First, in every company I've worked at that has dealt with PII, their definition of "PII" excludes quite a lot of data that should count.
But even if all PII is properly excluded and everything is actually anonymized, that still doesn't address the point. The point is all about consent. Consent seems like it should be table stakes, no?
I agreed for most of my career but not anymore. Truth is, everywhere I worked, the voluntary user surveys had extremely low engagement rate -- which was frustrating for the dev team who wanted to make sure their users like the product. Sometimes that means deprecating / removing parts of the software.
I get your idea and I don't generally disagree. It's just that practice has shown that collecting anonymous telemetry is the only really viable way of getting information of what's being used, how much, does it perform well (I used telemetry stats to optimize a hot code path on a number of occasions) both in terms of hardware efficiency and business terms, and others.
It's one of those things that I solved for myself by trusting or not trusting each piece of software individually. That's why I am currently slowly migrating back to Linux (from macOS); Apple overdid the telemetry to downright complete spying and sometimes censorship so I am no longer okay with them.
So if people don't want to volunteer their data and time, you engage in dark behaviors to get the data out of them regardless?
Don't look for boogeymen on HN, they are not on this forum. ;)
I'll again agree opt-out by default is not the most privacy-friendly approach but voluntary user surveys had almost non-existent user base. So some companies took a more aggressive approach. Those I don't like. But a Linux distro? Dunno, seems like an overreaction in this particular case.
Again, we come back around to "if users don't want to willingly give us this data, then we're just going to take it." That's what I think is ethically objectionable. Sure, the data is useful -- but if people don't want to give it, that usefulness does not justify taking it anyway.
Opt-out is better than not being able to even do that much, but in my view, it's still unethical. And, practically, it means that I have to treat all software as suspicious and can't really be comfortable with any of it.
I'm used to that with smartphones and Windows, and deal with that by avoiding installing any software if unless I absolutely have to. I'm just trying to avoid having to take the same stance with OSS. But perhaps that's a lost cause and trust in any software at all is not supportable.
While it may be commonly accepted by most, I don't want my personal computer crawling with telemetry. I despise the idea.
The harm is, in my opinion, partly in creep, where just a little more, here and there, leads to a festering, unchecked data brothel. And regarding 'harm' as a necessary parameter for maintaining privacy, dignity, etc; it would cause absolutely no harm to me if I was watched every time I used the bathroom, provided responsible handling of the acquired video. But I don't want this and would object to any effort otherwise. I don't think harm is the only factor.
People who genuinely care to fine-tune their software to work better for their users. What monsters.
I personally don't think it's such a monster move to send some anonymous usage data, especially if you present a box with a choice once the program starts for the first time. (Granted that's not what Manjaro is doing here.)
I'd rather people become overly (even unreasonably) sensitive to it than keep going with the flow. It's too easy to start with innocent bits, then more and more until real-time surveillance style Windows Recall shittery.
That was my point, yes. And I'll agree it's a slippery slope.
0. Only link I could quickly find: https://www.reddit.com/r/linux/comments/nbio7c/audacity_resp...
> Like any at all?
No, don't sidestep the question, actually answer it. What data are they collecting and how is it harmful? The devs feel this information is useful to make their software better. If you think you are harmed by this, please explain how.
This is why some users opt for a system that enforce Opt-In or even Opt-Never by default. The sheer peace of mind is worth a lot.
And it's not even such a strange stance. Consider eg Enterprise or National security. Why shouldn't a regular user have such security by default?
So? Crime being profitable doesn't make it legal.
> No, don't sidestep the question, actually answer it. What data are they collecting and how is it harmful? The devs feel this information is useful to make their software better. If you think you are harmed by this, please explain how.
So if I enter your house you will also enter a discussion of what I stole and if you really needed it before you are allowed to kick me out even though I never had permission to enter your house in the first place?
I disagree. Breaking into a home and stealing stuff is obviously harmful. I don't think you have demonstrated the harm of "taking your data".
It's theirs, not yours. Fundamentally, it's not about harm - it's about you getting stuff you have no (moral, cultural, and in many places legal) right to.
As for harm: there is possibility of it, a lot of software does collect data for it to be used against users' interests, and I have no reason to believe yours isn't one of them.
'Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith. '
The TL;DR is that data about a system does not reflect the underlying system perfectly, and thus is a distortion of the real system. Decisions based on this distorted data can be equally distorted, sometimes dangerously so.
For software telemetry for instance, telemetry only gives the "what", not "how"
eg. feature X is not used.
Possible explanations:
- Not useful to users -> Probably should be removed.
- Not discoverable -> Probably should be kept and made more discoverable.
- Difficult to use -> Probably should be kept and made easier to use.
Most times (I'm looking at you here Mozilla and every commercial software provider ever) people take the shortcut of assuming the first explanation and removing it prematurely.
OR
- "Users interact with feature Z a lot" -> "Z is very hard to use and requires lots of fiddling"
- You've forgotten the denominator
Features A and B may be equally important, but B may be applicable only in specific circumstances. If you'd compare A and B on the metric of "how often it's used", you may see B being used much, much less than A, but that's not reflective of the feature, but of the job being done.
- But how is collecting data harmful?
The problem isn't any single data point. It's that historically, seemingly innocent data collection has repeatedly enabled serious harm when contexts change. (And yes, I'm aware of Godwin's Law[1], and/but the historical examples are directly relevant here.)
- Surely one more app collecting data isn't the end of the world?
No, but it's death by a thousand cuts. We're at a point where young tech professionals are already resigned to total surveillance. Each new data collection might seem minor, but they're all contributing to a flood of personal data leaking from our devices. We need to start turning off the taps, not adding new ones.
Asking the users what they like and why is much more useful.
I expect my computer to do what I order to do and not to do shady things behind my back. Imagine if you were a business owner and your new hire would sell your commercial secrets to competitors. Would you like it?
As for improving software, users should contribute voluntarily, not mandatory otherwise it looks like a form of non-monetary tax.
That's an incredibly low bar. I think that good software should aim much, much higher than that.
Apple has a few advantages that make this the case: a) they have really good marketing and b) they will always be compared against Google, Meta and Microsoft, which make their money from selling your data (either directly or through targeted advertising); whereas Apple makes their money from selling overpriced hardware.
But Apple is not pro-privacy, it is just less anti-privacy than other companies. And there are still people like me which would never use their products on principle.
I think it's a bit cliché; where do you draw the line? Should free software also display a copy of their license at first start and ask their users to click "I agree"?
When you start using a piece of software (free or not), there is a set of terms and conditions that you agree to (explicitly as is often the case with proprietary software or implicitly as with free software), which may include opt-out telemetry. As long as this is communicated, I don't see any problem with it.
To give credit where its due, I agree that Manjaro users may have never accepted opt-out telemetry when they first started using the OS and now this is being rolled out after the fact. Still, for a general-purpose OS that makes no privacy claims (e.g. Tails), I don't see how collecting their screen resolution etc makes a big difference. An average webpage today collects more than that in a single page view.
ToC may include anything whatsoever, it doesn't mean it's binding (in B2C setting). Opt-out telemetry, in particular, is against reasonable expectations, and in much of the world isn't even legal in the first place.
Correct, which is why I have severely curtailed my use of the web. The situation is horrible.
Writing "our software is allowed to do whatever we want" somewhere deep in your terms of service doesn't actually give you the right to distribute malware.
> Still, for a general-purpose OS that makes no privacy claims (e.g. Tails)
Operating systems did not have to make privacy claims because this was assumed implicitly. It is a relatively recent fad to make everything online connected.
> I don't see how collecting their screen resolution etc makes a big difference. An average webpage today collects more than that in a single page view.
The specific data collected is irrelevant. I don't want my computer making any unneccessary connections to third parties.
No, because people don't have to agree with free licenses for using free software.
(And yes, free software installers that make the user agree with them are bad.)
Earlier you could in practice trust Apple etc with your data since it was inpractical to spy on you if you were 'insignificant'.
Machine learning changed that and now even mpre with the new LLMs, it is way cheaper to profile a random user.
Not really sure how to snap apple customers out of their dream, but i think people just like playing pretend, and like it even more when they pay a lot of money to do so.
You're using weasel language. Are they known for it, or do they exhibit it?
>I'm happily using a MacBook nevertheless and I bet a lot of people browsing HN also do.
Yeah, of course I am too. Because when I voice certain displeasure with mass market products people tie too much of their ego to, well that makes me a cold cynical asshole subject to social rebuffing.
In office after office of software professionals, I am the weirdo for caring about product features. So at the next office, I just stopped having those opinions.
That said, it's a funny choice for Manjaro to go for opt-out telemetry. As a simplified Arch it seems to be popular among privacy conscious users. (But I don't know the project goals, maybe that's just coincidental)
If one is very interested in security and privacy however, using VMs for isolation of different apps or services is important, so having an OS that helps that is useful. Bare arch _can_ do this, but requires quite a lot of script development.
Qubes seems to be the answer many grab for, though much is still written in C, which comes with all of the vulnerabilities mentioned constantly. So, something like https://diosix.org/ (a Rust-based hypervisor for Risc-V) is a great option to make a start towards decently secure system. Of course if your threat model includes state actors or something, you're SOL (change your perspective or what you're doing) since they always have an easy backdoor into any hardware, but sometimes things like diosix can protect against the constant script kiddies and other individual hackers.
No. The standard is extremely simple, and for-profit companies deviate from it because there is no regulation guarding privacy sufficiently. No opt-out telemetry, ever. Opt-in telemetry is fine.
As a statistician, I get it. You want unbiased samples which an opt-out option helps to get to versus opt-in. But privacy has been violated too many times for people to be okay with opt-out telemetry.
The bar appears higher for FOSS because you can see the telemetry code directly. Just because for-profit companies are failing the bar doesn't mean FOSS should too.
You could also argue that opt-in telemetry still collects too much information, or programs might lie about not sending data in the first place.
Opt-in telemetry may well collect too much information _for a customer to be comfortable to use the feature_. However, it's an _option_ to an user instead of a _default_ for the user. Hence the categorical difference.
Some FOSS make opt-out inclusion a required feature. Forking a complex project isn't a reasonable approach in many situations.
I know that telemetry should be opt in, but no players will ever turn it on. And that leads to a conundrum- do I incentivize turning it on? Make it opt out? Gate some features (like heat maps on a play session or skill visualizations) behind it?
Would it be useful to have the ability to see exactly what was sent? Like, I could show a telemetry json or yaml blob in the options screen to show what events I collect. Would it be useful to have fine grained telemetry controls, like, the ability to toggle any arbitrary telemetry event from being fired?
It's a tough spot to be in, as a dev, to want insight into how people interact with your system, while also wanting to give people a chance to decline.
Maybe an opt-in analytics type feature, a dashboard of sorts to see how one plays. I would be curious to see how often I use items, abilities etc. in games
I know this is an unreasonable amount of work and most non-devs would not react differently or have a higher conversion rate.. but that's the type of reports I have given to various open source projects, because explaining it in detail and then sending different stuff I do not agree with is a kind of maliciousness I don't usually expect, except from content marketers and growth hackers.
Still, can you do without?
> It's a tough spot to be in, as a dev, to want insight into how people interact with your system, while also wanting to give people a chance to decline.
It is, but the underlying issue is trust, or rather, lack of it. Vendors feel so entitled to this data, that even when they obey what's actually rule of the land over here in EU, they don't even try to level with the user and give them a reason to opt-in - they'd rather show a beg screen with information-free boilerplate text, and then act annoyed that pesky regulators and lazy users deny them the data they're entitled to. Thing is, they're not entitled to it. Never were.
"We collect data to improve our product and your experience" is zero-information-carrying bullshit that hardly anyone believes in. In fact, the first sentence of your comment is strictly superior - so much, that I'd consider opting in based on that alone:
"it's useful for me to have stats about how frequently abilities are used, what items players use, etc. to tune game systems"
Now I have at least some idea what you're collecting and why, and how it benefits me and other players. And, more importantly, you came forward with it.
> Would it be useful to have the ability to see exactly what was sent?
Very much yes. Not for everyone, most players probably won't care. But some will, and I imagine reviewers will too. Being open about what you're collecting would go a long way towards establishing trust with the players, and if more people would do that, it could even change the overall perception users have.
Two adjustments I could think of that would make it better (besides explaining clearly, etc):
Ask me when you're not actively obstructing me from getting to what I want. Like asking on first boot I've gotten no value from the software yet that I might feel I need to pay back, and I'm actively trying to get _in_ to the game and your pop-up is in my way. The easiest and safest way to get rid of it is "do not allow". Try asking _after_ I finish a game/round/whatever.
And that would also give you the opportunity to do something like collect real analytics information to show to the user. Like "Hey I hope you're enjoying the game it's useful for me to have stats about how people use abilities and items to tune and balance the game systems. Would you be willing to contribute to the game's further development by sending information like that below which was collected from your last round?" And then skip the JSON/etc unless your audience is programmers, just show them a table.
Finishing some play time having had fun and getting a pop-up that explains what, why, and gives me a chance to make an informed decision on whether to send something innocuous like "(offset-timestamp, event-type, item-id/ability-id)"... I'd actually probably allow it.
A way to package it would be to show end of game stats compared to global averages. Histograms of mana/health/bullets vs the world standard. Maybe a personal historical trendline vs past performance. On that screen, give an option to share metrics with the community. Users can immediately see what the aggregated data can provide and might feel more likely to consent.
To be most user forward, keep a local non-obfuscated log of what is shared. This also makes it possible for dedicated users to potentially mine their performance.
Or wait do I have to launch the game and see if it prompts me?
https://trac.wildfiregames.com/browser/ps/trunk/binaries/dat... https://feedback.wildfiregames.com/
It doesn't show you the exact data being submitted, but IMO that should be mandatory. ISTR some Mozilla stuff does, maybe the crash reporting.
That's helpful (as long as the user can opt not to send it after review), but to be honest, I never really trust that all of the data that is going to be sent is being disclosed. Our industry hasn't exactly behaved in a way that encourages trust.
This is true for big companies and absolutely false for everybody else. There is a worrying lack of nuance in your comments.
If you don't want to provide telemetry information to the devs of the software you are using, that's your right -- do it, prevent it.
I simply don't think that "opt-out by default" is such a heinous crime. Some devs really do land in situations where they are lost on which features are worth improving or winding down (or even removing). A lot of teams have limited dev time / energy budgets so it pays off for them to know where to pay attention IMO.
I object to it because it's a cover-your-ass approach to avoiding getting consent.
As a dev, I fully understand the value of this data. But that's irrelevant to the point, to be honest. That a thing provides value to devs is not an argument that the thing is justifiable.
I am simply leaning a bit more to the dev point of view is all.
That it should be fiercely discussed whether you need telemetry to improve your product is also true but again, in some cases (in my practice) it was unavoidable. I'd agree that the question whether there should be telemetry at all is one that should be posed much more often that it is right now.
It's often startups that just do whatever because the only thing they care about is showing value to investors and avoid getting canned next month.
Then add a: "If anything about that should ever change, you you will be notified and asked again within this game".
Then consider addin an option where technically interested users can actually see that data in full.
If you collect reasonable data and explain clearly why people help you the dev when they share it with you, more people might be inclined to do so.
If you make a wishy washy marketing speech that says nothing will just click no.
TL;DR: Be honest, precise and make a promise that people can check you on and explain why they help you with this.
If you just ask the user yes or no and they massively decide no, who are you to turn it on by default and make them dig around to turn it off? Yes a lot of them won't go to that trouble or simply don't know it's there. But you know they're not ok with it when given the option.
Telemetry should always be opt in.
Anyway, I gave Devuan another try a few months ago, and haven’t looked back. It let me put off my inevitable (?) switch to a BSD by at least another year.
I also recommend trying Alpine. It gets most used in other contexts but it does make a nice desktop OS. And it's a half-step towards the BSDs IMHO.
That said, all of the big 3 (Open/Free/Net) are pretty great and if your hardware is supported you'd probably have a good time if you don't mind doing a bit of legwork in terms of having to set things up starting from a terminal. Of course if Alpine is your reference point then you'll be fine.
I use it on my desktop as daily driver. It's really capable and well documented.
Systemd does have bugs (e.g. the resolver, wow), but these are their responsibility and not something to be fixed by Arch.
I'm now using systemd, Wayland, Pipewire and all that in my NixOS installation and can't understand the hate. People should maybe just let go...
A simple version of the same is runit. Side by side, you can see the complexity differs by orders of magnitude.
I switched to Manjaro from Arch in 2017 because I don't have time to debug / fix broken updates, and the same Manjaro install has been completely stable since then.
Is there another distro which can do this (and I also don't want to have full reinstalls / upgrades every few years like Ubuntu/Mint)
Arguably I collect some "telemetry" with some products I work on. It's some very basic "anyone even really use this feature" stats that I would find difficult to narrow down to a user / and some "woah did this crash" type information.
But that's nothing like some software...
Telemetry must be opt-in only.
It is one less reason to change from Windows to Manjaro...
People that can't get such a simple thing as no "opt-out" spyware in the distro right can't be trusted.
But now the subscription is canceled, and I have to look for migration options (there will be pain). Maybe Debian is the safest? I don't have much time these days to maintain or install Arch, or even have time to keep an eye on telemetry gathering practices of my OS.
Install "popularity-contest" if you want to turn it on.
May be premature to start switching systems. Hopefully they won't proceed with opt-out. I can understand telemetry being tempting/useful, but the fact they made the poll signals deference to community feedback.
I've been using Arch for the past decade and other than the turbulence when switching over to systemd, I don't do anything other than `pacman -Syu` and can only recall exactly one time where the system broke and it was because mkinitpcio failed to run after updating a kernel and was fixed by chrooting into my system and rerunning it.
I often had more issues with Debian or other distros because of having to fight the system to install packages that were built within the past year.
But you make me think... I should give Arch one more try before giving up!
MDD - Opt-in vs Opt-out
- Testers needed: Manjaro Data Donor https://forum.manjaro.org/t/testers-needed-manjaro-data-dono...
Makes me a little sad, I'm super comfortable with my current Manjaro Cinnamon setup. This ain't a big enough issue to migrate, at least not yet... but I'll definitely keep an eye out for more shenanigans and jump distro if it ever becomes too much.
It’s taken me a while to tweak the environment to my liking, and right now my priorities are elsewhere; I don’t want to have to distro hop and do all of this yet again.
https://news.ycombinator.com/item?id=42043539 ("Manjaro Linux prepares to enable telemetry by default (manjaro.org)")
That's not a problem, that's the correct behaviour. Privacy should be the default setting.
What is probably a reason for not collecting anything that you'll use for statistical analysis. Bug reports is an example of something that don't need statistics, things like those can still be useful.
1 - Doesn't even matter if opt-in or opt-out, or even if it's "optional" due to firewalls or a site somewhere explaining how to hack your software.
It blows my mind how far the debate has shifted that people think ubiquitous telemetry is even slightly reasonable just because the devs need representative sample of metrics. They really don't.
They will be just fine without any metrics at all.
I keep asking what the privacy issue is in anonymous usage statistics, but there are never any answers. Remember: The "anonymous" in "anonymous usage statistics" means there can't be a privacy issue. Then it's not anonymous any more! You could think of it as for example, sending only the program version in, and the only stored data is how many sessions are run of each version, every month. So you could know "is it reasonable to deprecate version 1.0 and only support 2.0?". What exactly is it that you think is an invasion of privacy here? The fact that it makes http requests?
> They will be just fine without any metrics at all.
Most who added telemetry has a time from before metrics and a time after. And I imagine very few would want to go back. It's driving blind. You can't simply "ask your users". They don't know whether they use Ctrl+C or use Copy on the context menu. And if you ask them, you find that they think they did one thing when in reality they didn't. Knowing what they actually do instead of what they think they do or say they do is invaluable. And luckily at least in enterprise, users are pretty happy to supply this, but it's definitely based on a trust that already needs to exist between seller and customer.
Anonymous telemetry is be a non-issue for privacy.
This is going to depend very much on how you describe it.
> The middle ground is having a clear question where the telemetry option and the no-telemetry option is clearly shown and the telemetry is preselected. So you have to do a choice but the "I don't care" next > next > next choice is going to be to opt-in.
That's not a middle ground at all but very biased towards data collection. The middle ground is to play it safe and not collect any data where you are not sure you have informed consent, which includes users who do not understand the question or do not care to read it.
The better option would be to not add the data collection at all.
> Whether this is acceptable also depends on the nature of the program and the users. It's much easier to get acceptance for this if it's a piece of software that will make 100 requests to 10 different servers during normal operation (where all of those servers will likely know program version and even more client info anyway), but now makes 101 requests to 11 servers when you enabled the telemetry. A program that used no network requests at all without telemetry should probably be strictly opt-in since its such a major change in behavior.
It sould be strictly opt in for ALL software. Otherwise you are writing malware.
It did say on startup that it collects anonymous usage stats. It’s not “quietly enabled and opt-out has to be searched for”. It says front and center what is going on. You are free to exit at that point and not run it at all. Or just choose the no telemetry option. It’s basically more benign than 99% of web apps.
It’s not a sneaky secret feature that does something behind your back. It’s not transmitting any information it wouldn’t transmit anyway. No information is stored that can identify a user either by fingerprinting or directly by some identifier.
Manjaro are experimenting with telemetry, are debating whether it should be opt-in or opt-out, and are running a use poll on their forums about it: https://forum.manjaro.org/t/mdd-opt-in-vs-opt-out/170462
Doesn't seem that sensitive?
By painting telemetry as bad _because_ of the inherent tracking available due to the TCP/IP connections being made in the background, that does nothing to say the above is bad, since you've already agreed to implicitly worse tracking (since third parties now have that data) in an affirmative manner by requesting an update.
I would agree that this implementation (and opt-out telemetry in general) is bad, but let's not pretend that it's bad because it makes connections to servers over the internet.
opt-out telemetry is bad because it disrespects user consent by assuming they have it. Not because it uses the network.
In Linux you (or package manager) typically don't send requests for an update; you download a package list, see which packages are updated and download and install them. The request should not include any identifiers like installation id or software version. You can also download from a mirror in a selected country or even self-hosted mirror (which is useful for some companies).
This is what distinguishes open software from commercial software: you can choose a provider for network-based services or become a provider yourself.
> By painting telemetry as bad
Bad is doing things with user's computer or data without explicit permission/request to do it.
When users ask you to copy MS Windows, they mean the user interface and how things just work out of the box, they aren't asking for spyware and Microsoft's dark patterns.
You could always, you know... talk to your users.
Your telemetry will just be used to confirm your own biases, or even worse, your bosses' biases.
This is from the guidance of the UK's data commissioner, the ICO:
"You must ask people to actively opt in. Don’t use pre-ticked boxes, opt-out
boxes or other default settings. Wherever possible, give separate
(‘granular’) options to consent to different purposes and different types of
processing."
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...