Earlier quoted context omitted.
>Studies do send telemetry which is not quite the same as being spyware. How is software whose sole purpose is to send my information to a third party not spyware? >The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time. JS on any webpage can't do whatever it wants, since it's restrained to the webpage itself. otoh I'm sure this "studies"…
They cannot, the studies use JS available to the browser though with internal APIs available. It is potent, but not quite as much as to allow running arbitrary executables outside the browser or usually bypass file system level protection. It can read and write files the user can access. (Which may or may not include /dev on *nix.) It can also exploit your OpenGL driver. The difference between spyware and telemetry i…
It's pretty clear what they are worried about. That's not really arguing in good faith. And "intent" has nothing to do with it--also there is no singular intent from an organisation, if it goes wrong it's just stuff that happened but nobody to point a finger at whose intent it was.
Also, anonymization measures are a joke. It just shows an "intent" to anonymize. But when it turns out that the data is in fact easily de-anonymized somewhere between the browser and the aggregation unit, or in combination with the newest "opt in" monitoring feature, again no fingers to point and your only recourse is better having been safe than sorry.