Live data from Hacker News

Brew commands send data to Google Analytics

tobiastom.name

221–230 of 342 posts

Re: Brew commands send data to Google Analytics

#221

Earlier quoted context omitted.

> The EU approach to privacy (eroded by lobyying and lack of control over US companies) is that citizens have a right over their information. They can ask what personal information a company has on them, ask that it be corrected or deleted. This has resulted in companies that are more careful with data. More like, this has resulted in things like nonsensical "Cookie warnings" that only waste the user's time.

It has resulted in a lot of good things. Cookie consent is most certainly not one of them.

IMO, the intent was good... but yeah, the implementation is a grand demonstration of what you get when legislators don't understand the technology they're regulating. It would be far better if they'd required browsers, not websites, to show the notifications - much like they already do when a site wants to access your webcam/mic/location/etc[0]. That would mean much less implementation work (once per browser instead of per site), no way for underhanded sites to use cookies without the user being notified or despite the user declining them, consistent UI across all sites...

Such a thing could provide significantly more useful information, too - I envisage a notification with "This site wants to use a cookie on your computer" at the top, "allow/deny, now/always" buttons and a "What are cookies?" link at the bottom, and a user-friendly breakdown of this particular case in between, things like:

• "only visible to this site" vs "visible to ad.doubleclick.net" etc - maybe including, say, the Organization Name from the cookie domain's SSL cert, at least in the case of cookies set to "Secure" (maybe only if the cert's EV)

• "until you close your browser" vs "for a week" etc - perhaps with a way for the user to force session-only if desired

• possibly some kind of warning about snooping risk if the cookie's not marked secure, or not HTTP-only & 3rd-party scripts are on the page, etc

• for the case of 3rd-party cookies, it'd be possible to list which other sites have used the same cookie in the past

And so forth. The most importantant point being that you could actually trust this information - your browser has no motivation to lie to you about it, but any random site might.

[0] eg, https://i.imgur.com/NcxWz8zh.jpg

Re: Brew commands send data to Google Analytics

#222

Earlier quoted context omitted.

I can totally see the benefits of telemetry. But it would be way less phishy if it were opt-in, or at least opt-out with a very visible information message.

The problem with this is, do you want every program you ever use, to start prompting you with a series of questions about various opt-in / opt-out questions? I get annoyed enough that gnu parallel keeps asking me about citing it, and that's one program. Bash would like to record analyitics. y/n/more information > y > ls *.c ls would like to record information about how you use it. y/n/more information. > y file1.c fi…

No, I want every program I ever use not to leak data about me all over the internet.

I'm amazed we're even having this discussion

Re: Brew commands send data to Google Analytics

#223
post #129

Earlier quoted context omitted.

> Looking at the website one of homebrew's developers (or at least the website developers) is based over here in Europe. He might be a nice target if you want to raise a stink and litigate. Homebrew lead maintainer here. We're chronically understaffed and underfunded. We have analytics so we can make Homebrew better by figuring out how to prioritise security, maintenance and bug fixes on packages based on how much th…

Mike, I'm just saying that you're putting yourself on risky ground, not that I want to do something personally. In fact I'd even consider keeping GA enabled IF BEING NOTIFIED. The current notification is the problem, as it is close to invisble. Hiding output in a long log message is a dark pattern, I think it did not happen out of spite (you just used your normal shell output mechanism to show that). However: Such a…

[deleted]

Re: Brew commands send data to Google Analytics

#224
post #17

Earlier quoted context omitted.

Please make it opt in. If you truly believe people closely read the prompts for having their data harvested, a default to "No" should not impact you at all. If you don't believe they read the prompts closely, you're an asshole for stealing data by default.

Is it "stealing data" to record that certain options in my program are never used, or used frequently, or whenever a user clicks on options A,B and C in sequence the app crashes? My problem is that I believe that 90% of the users of my app won't care one way or the other if I record these stats. If I default opt-out these people, then I lose all that useful data and in the process, I believe, make my app worse for ev…

>My problem is that I believe that 90% of the users of my app won't care one way or the other if I record these stats. If I default opt-out these people, then I lose all that useful data and in the process, I believe, make my app worse for everyone.

If those people wouldn't volunteer to opt-in, it's just as likely that the reason they are not opting-out is because they missed the notification that someone is collecting data about them.

It's a UX anti-pattern to default behavior to something the users may not want. If you're worried they'll accept whatever default there is, just explicitly ask them if they want to relay usage stats and you'll be surprised how much of the 90% you claim don't care will start caring.

Look at the comments on this thread, there are multiple accounts of people surprised by this. The very fact that this article is on the front page is proof that Brew tricked users.

>Especially when the data is anonymised and doesn't contain any private/identifying information.

You've either made massive breakthroughs in the field of information security or this is a bogus statement. If the user's computer even connects to an analytics service, they've already got an IP address, frequency of connections from that IP, etc and all of the correlation that comes with enabled by their other data sets. Just because it's anonymized by the time it comes out of Google in Brew usage reports doesn't mean it hasn't given Google additional information to profile people.

Re: Brew commands send data to Google Analytics

#225
post #38

As I didn't update brew for a long time I did not have the analytics version. So I upgraded to see what happens. In fact it did NOT prompt me when enabling analytics, but it did display a notice (hidden in several hundred lines of output during brew upgrade): ------------------- + 5a9e19f...7f13b37 master -> origin/master (forced update) * [new tag] 0.1 -> 0.1 HEAD is now at 7f13b37 Merge pull request #1562 from wood…

> Looking at the website one of homebrew's developers (or at least the website developers) is based over here in Europe. He might be a nice target if you want to raise a stink and litigate. Homebrew lead maintainer here. We're chronically understaffed and underfunded. We have analytics so we can make Homebrew better by figuring out how to prioritise security, maintenance and bug fixes on packages based on how much th…

There is some kind of dispute about privacy, with commercial companies wanting to collect as much data as possible and some people opposing to it. Is not your project picking the wrong side here? This can be used as an argument later: "see, even popular open source projects do this".

I think that giving up on user's privacy is not an acceptable solution. If you don't have enough time to fix all the bugs and nobody is willing to help then nothing can be done.

What I expect from open source software is that an application should not collect and send home any data by default (I understand that it is not written in the license but still expect this). Breaking this expectation makes me and maybe not only me a little disappointed.

Re: Brew commands send data to Google Analytics

#226
post #33

Earlier quoted context omitted.

> Data is being sent to Google everytime you do almost anything in almost all websites using the save technology No, it's not. µblock, µmatrix + clean links.

Is there a point in running both ublock and umatrix? Also, what do you mean by "clean links"? Striped of "utm..." parts?

Clean Links is a plugin that strips the utm-like trackers, affiliate codes, outbound redirects, window.open, and some other relays from links.

Re: Brew commands send data to Google Analytics

#227
post #143
post #75

Earlier quoted context omitted.

>Data is being sent to Google everytime you do almost anything in almost all websites, using the same technology. So what? This still doesn't mean we should just shut up and take it for desktop software. What anyone does on its OS shouldn't leave the LAN - same critique stands for recent MS endeavour with Windows 10.

I definitely don't mean that we should shut up and take it. But before we complain about an open source project that maaaaany devs use happily, let's complain about those other cases first, yea?

let's complain about those other cases first, yea?

Search HN for "Windows 10" and you'll get plenty of complaints.

Re: Brew commands send data to Google Analytics

#228

Earlier quoted context omitted.

Opt-in can be implemented other way without questions. For example, user could set an environment variable or type a command.

Then we hit the problem that if we don't push that request at users, probably a tiny fraction will turn it on. Worse, that fraction will be the statistically unusual people who bother reading and finding such options, meaning we can't derive any statistically useful results about the user base from them!

Maybe you should ask them better. For example you could ask for help on the home page of your project or in the beginning of a tutorial. Or maybe they do not want to paticipate. Is it right to ignore this and turn analytics on by default?

Re: Brew commands send data to Google Analytics

#230
post #184

Earlier quoted context omitted.

How about try not to assume malice out of people's free software from the very first thing they did that you don't agree with? Its open source. Why not open an issue, contribute a patch to make the process opt-in, start a discussion, start a fork? Oh, of course, why would we do that when we can attack the maintainers, call their software a spyware, and threaten to sue instead? While we're at it, let's use words like…

> Why not open an issue The maintainer already stated it's not a bug, plus the nature of the message implies opt-out was a design choice. > of course, why would we do Why start a fork before "attacking" the maintainer? Are you suggesting we need to audit every code base we use? As reasonable as checking every box of morning cereal for glass shards. The software is spyware. Words like "spyware" and "stealing" are corr…

> The software is spyware. Words like "spyware" and "stealing" are correct, I don't care how it paints the maintainer to describe the situation accurately, they created that situation.

No, that is not "correct". The aren't even tracking their user, they are tracking the use of their software. Your use of the words are manipulative and dishonest.

> by "calling out this kind of behaviour" you attacking critics with poor arguments? That's not support, its fan-boyism.

None of the things I called out are "critics". Legal threats because they live in a place that makes them a "good target"? Calling the software a "spyware" because they collect usage data? That is not critic. That is bullying.

If the people doing those things think the I'm a fanboy for calling them out, since clearly logic matters little to them anyway.

Post reply on HN