Obviously if you opt out (or rather, didn’t opt in) you shouldn’t be sending telemetry. But the line between a necessary network call and an optional one is often blurry.
Obviously if you opt out (or rather, didn’t opt in) you shouldn’t be sending telemetry. But the line between a necessary network call and an optional one is often blurry.
> But the line between a necessary network call and an optional one is often blurry.
What would be an example of a necessary network call that an ideal OS (i.e., one that cannot be easily compromised and does not require updates around the clock to correct programming mistakes) has to perform on its own?
If a company is interested in how users use their applications and desperately need our data for it, they may be interested in funding dedicated studies and appropriately compensating users that send their data, if it is so valuable for the company.
Syncing the clock with NTP?
So every app, instead of querrying the OS, shall make a network call, to get the time from an NTP server ?
So the claim that telemetry is used to improve products is simply a lie IMO.
The fact that telemetry is sent at all for no apparent reason and deliberately without clear consent is an ironic example of this. The fact that it's been happening more and more over the past decades as the OS'es evolved is another confirmation of it.
Still think it shouldn't be there by default - it reduces privacy and is a lame excuse not to do (paid) user studies.
Would it count as a paid user study if enabling telemetry for Windows knocked $10 off of the price of your computer?
I can’t decide if that’s a neat idea or dystopic. Which, historically, probably means it’s dystopic and that plenty of people are already doing it.
I think “traditional” paid user studies often suffer from the same sampling problems that make political polls and behavioral paid medical studies less useful (you’re not surveying the average voter; you’re surveying the average voter who likes to answer polls). But maybe the “$10 off” idea would capture a broad enough demographic as to be more useful.
You get sensitive data out of system settings, such as for instance health data: Does the user have a vision or hearing impairment, use assistive technologies etc.?
You need a good volume of data and you aren’t going to want to pay for it for one simple reason: you can get it for free and only a tiny group of users are going to be upset enough by this.
Not sure what the reference to “ideal OS” is about. I thought this was about windows in particular.
Necessary network calls would be related to updates, licensing etc. But the thing is: they would be going “home” to the exact same servers as telemetry AND they would easily contain the same payload.
it is called testing. _Testing_. But of course, testing sucks and it's expensive.
Those are not questions for which pre-release testing can provide answers.
I’m not weighing in on opt-in vs opt-out, or on anonymization. Just saying that testing doesn’t cover this niche.
(Separately, I think you’re largely wrong about testing as well: crash dump collection is about finding issues that pre-release testing wouldn’t find at any price. For things like OSes especially, the permutation space of hardware * software * user behavior is too large. While I’m sure a few companies use crash reporting as a crutch to support anemic QA programs, I do not think that many do.)
You mean you implement something even if nobody asked for it ? Wow.
The project really has some spare budget.
You will never know without actually asking enough users (which is a large sample). And there is a simple way of ”asking” this.
You can’t say how your users use your software through testing. Not by surveys/panels/interviews either.
But yes: alternatives are also morr expensive (which means it’s expensive for the end user). Users pay one way or another.
DHCP
I grew up sans DHCP with static IP assignments per device .. and still practice that on modern home networks and production networks.
The only DHCP calls here are made by foreign devices wanting an assigned address, which gets them on a narrow range on a side net.
Luckily static IP addresses can be set up by the majority of teenagers that just want to play Doom, etc.
At least that was the case decades ago .. is this now "deep knowledge" that necessitates that OS's have to use DHCP with no other option ?
Perhaps we have different understandings of the words "necessary" and "sufficient", etc.
...unless they're done asynchronously
Years ago when spyware was not the norm, there would be outrage if anyone caught some software sending as much as a single packet of data that was not legitimately initiated by the needs of the user/owner. We need to return to that mindset.
If it’s hard to disable, contains any PII or sensitive info (urls, file names) then it’s not OK.
It's all about privacy; and by privacy, I don't mean the "privacy" that often gets thrown around by Big Tech to mean "only we can see what you do". What I do on my computer is none of their business.
You can’t send the telemetry over http without revealing an ip, but obviously that ip can’t be stored as part of the telemetry data. That’s PII and not anonymous at all.
Important: if I collect anonymous telemetry you better trust me that it’s anonymous when I say it is. Because if you don’t trust me on that then you can’t run the software at all (if it’s a piece of software that relies on web requests in some form at least). Otherwise why would you even trust that my opt in is respected? You have to trust software vendors of software that makes http requests. It’s as simple as that. You can use open source or try to inspect packets. Or firewall the software. But if it does (for example) one update check on startup which is common, then it’s almost impossible to tell whether it contains telemetry data. Because even the bare minimum request “this is FooApp 2.9.1 are there any updates” contains important usage stats: it’s +1 for the use counter and +1 for the v2.9 use counter!
I made mistake thinking it was user's software.
You didn’t answer the question: should it be somehow banned?
Because it's not their fucking computer!
Nothing about this is necessary.
Nothing here is "blurry".
If a piece of software says “this will do X if you run it” and then it does X then I don’t see the complaint (yes I realize lots of software uses dark patterns or doesn’t say what it does, especially windows, but _in principle_ I don’t think anonymous telemetry with good clear opt out/in is evil).
I don’t think anyone thinks it’s ok when it’s not done right (not anonymous, dark patterns for opt in/out, etc).
So it’s not a very interesting discussion to have since there is no one arguing for it.
Instead my argument is: when done right, anonymous telemetry isn’t “evil”. To be fair I don’t know if many argue it is either. There are a few absolutists that think not even opt-in telemetry is acceptable and that developers should do more expensive studies to find how their software is used. It’s really only those I disagree with.
Just from the top of my head: Telemetry means extra code, hence extra bugs and maintenance overhead. It costs you in extra ram/cpu/storage/network. The networking means NSA and friends have a beacon declaring a windows computer exists, and they probably can derive other facts from the message statistics. After Snowden, we should assume they have a backdoor and get the unencrypted data if they want.
All this assumes Microsoft has only the good of you as end user in mind, are not hackable, and can't be coerced by governements. All of this now and in the future.
'Done right' is not a good yardstick. There are tradeoffs needed, Microsoft decides which ones, and they decided the user has almost no voice in these tradeoffs, and doesn't even get to see te choices made. These tradeoffs are the interesting discussion.