Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. as the person who pushed for the alpine core team (now TSC) to adopt a policy of rejecting telemetry features in alpine-packaged software, i have opinions on flathub 🙃

as the person who pushed for the alpine core team (now TSC) to adopt a policy of rejecting telemetry features in alpine-packaged software, i have opinions on flathub 🙃

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
6 Indlæg 1 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • ariadne@social.treehouse.systemsA This user is from outside of this forum
    ariadne@social.treehouse.systemsA This user is from outside of this forum
    ariadne@social.treehouse.systems
    wrote sidst redigeret af
    #1

    as the person who pushed for the alpine core team (now TSC) to adopt a policy of rejecting telemetry features in alpine-packaged software, i have opinions on flathub 🙃

    mostly i am concerned that pushing users to use vendor-provided builds distributed on flathub may be exposing users to harmful software misfeatures like telemetry in ways that they would not if those same users installed packages from a distribution which patches out these misfeatures as a matter of policy

    i wish that flathub would explicitly ban telemetry and check for telemetry features during their review processes. i would be more likely to recommend flatpak in more cases if they did.

    ariadne@social.treehouse.systemsA 1 Reply Last reply
    0
    • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

      as the person who pushed for the alpine core team (now TSC) to adopt a policy of rejecting telemetry features in alpine-packaged software, i have opinions on flathub 🙃

      mostly i am concerned that pushing users to use vendor-provided builds distributed on flathub may be exposing users to harmful software misfeatures like telemetry in ways that they would not if those same users installed packages from a distribution which patches out these misfeatures as a matter of policy

      i wish that flathub would explicitly ban telemetry and check for telemetry features during their review processes. i would be more likely to recommend flatpak in more cases if they did.

      ariadne@social.treehouse.systemsA This user is from outside of this forum
      ariadne@social.treehouse.systemsA This user is from outside of this forum
      ariadne@social.treehouse.systems
      wrote sidst redigeret af
      #2

      my philosophy here effectively boils down to a simple position: your computer should not be a rat.

      ariadne@social.treehouse.systemsA 1 Reply Last reply
      0
      • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

        my philosophy here effectively boils down to a simple position: your computer should not be a rat.

        ariadne@social.treehouse.systemsA This user is from outside of this forum
        ariadne@social.treehouse.systemsA This user is from outside of this forum
        ariadne@social.treehouse.systems
        wrote sidst redigeret af
        #3

        to be clear: this policy only applies to software that has default-on telemetry. if it asks the end user if they consent to telemetry sharing, we don’t particularly care about that (as long as it is respecting user consent anyway, otherwise it’s a release-critical bug…)

        ariadne@social.treehouse.systemsA 1 Reply Last reply
        0
        • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

          to be clear: this policy only applies to software that has default-on telemetry. if it asks the end user if they consent to telemetry sharing, we don’t particularly care about that (as long as it is respecting user consent anyway, otherwise it’s a release-critical bug…)

          ariadne@social.treehouse.systemsA This user is from outside of this forum
          ariadne@social.treehouse.systemsA This user is from outside of this forum
          ariadne@social.treehouse.systems
          wrote sidst redigeret af
          #4

          my point here is that distributions sometimes do curation that upstream does not want, because the distribution is acting in the interests of its user base, while flathub is more about allowing upstreams to distribute their own builds.

          do distributions need to curate all software? of course not.

          but i would trust the alpine build of firefox to respect my privacy moreso than the flathub one, because i know that we patch firefox to be compliant with our telemetry policy, and i know flathub does not have any such policy.

          ariadne@social.treehouse.systemsA 1 Reply Last reply
          0
          • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

            my point here is that distributions sometimes do curation that upstream does not want, because the distribution is acting in the interests of its user base, while flathub is more about allowing upstreams to distribute their own builds.

            do distributions need to curate all software? of course not.

            but i would trust the alpine build of firefox to respect my privacy moreso than the flathub one, because i know that we patch firefox to be compliant with our telemetry policy, and i know flathub does not have any such policy.

            ariadne@social.treehouse.systemsA This user is from outside of this forum
            ariadne@social.treehouse.systemsA This user is from outside of this forum
            ariadne@social.treehouse.systems
            wrote sidst redigeret af
            #5

            but why should a distribution care about telemetry?

            distributions are advocates for user concerns, including and especially user privacy. or, at least in the idealized world, they would be using their role as curator in this way.

            why do we, as curators, care about browser telemetry? well, the world is backsliding into fascism, and if your browser shares with its telemetry service that you searched for “misoprostol”, then your door might get kicked in.

            as curators we have a responsibility to reduce harm potential.

            ariadne@social.treehouse.systemsA 1 Reply Last reply
            0
            • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

              but why should a distribution care about telemetry?

              distributions are advocates for user concerns, including and especially user privacy. or, at least in the idealized world, they would be using their role as curator in this way.

              why do we, as curators, care about browser telemetry? well, the world is backsliding into fascism, and if your browser shares with its telemetry service that you searched for “misoprostol”, then your door might get kicked in.

              as curators we have a responsibility to reduce harm potential.

              ariadne@social.treehouse.systemsA This user is from outside of this forum
              ariadne@social.treehouse.systemsA This user is from outside of this forum
              ariadne@social.treehouse.systems
              wrote sidst redigeret af
              #6

              in the world we have built, data can be easily weaponized. that is enough reason to care about defanging telemetry functionality in software.

              for example, for the average windows 11 user searching for “misoprostol” on a new copilot-enabled computer we have the following leaks:

              * microsoft edge telemetry noting that you searched for “misoprostol”
              * microsoft bing telemetry also noting this when you searched for it using edge (since bing is the default)
              * microsoft windows copilot taking a screenshot of you searching for misoprostol

              and of course digital forensic tools misinterpret the data they find too, and that can become very problematic: https://www.digital-detective.net/digital-evidence-discrepancies-casey-anthony-trial/

              so in this hypothetical situation, the trump kangaroo court arrests you after a miscarriage… you’re just screwed.

              1 Reply Last reply
              1
              0
              • abekonge@venner.networkA abekonge@venner.network shared this topic
              Svar
              • Svar som emne
              Login for at svare
              • Ældste til nyeste
              • Nyeste til ældste
              • Most Votes


              • Log ind

              • Har du ikke en konto? Tilmeld

              • Login or register to search.
              Powered by NodeBB Contributors
              Graciously hosted by data.coop
              • First post
                Last post
              0
              • Hjem
              • Seneste
              • Etiketter
              • Populære
              • Verden
              • Bruger
              • Grupper