Live data from Hacker News

Console Do Not Track – Proposal for a standard environment variable

consoledonottrack.com

321–330 of 352 posts

Re: Console Do Not Track – Proposal for a standard environment variable

#321
post #316
post #267

Earlier quoted context omitted.

"Behaving ethically wouldn't work for us, so we decided to behave unethically" is not a legitimate viewpoint.

Who is the ethics arbiter in that quote? "Submitting anonymous usage data in order to build a better product" sure sounds legitimate to me.

1) it's stealing of data if it's nonconsensual

2) it's not anonymous

Re: Console Do Not Track – Proposal for a standard environment variable

#322

I'm not sure "do not track" would even be the right terminology here. We want to prevent apps from calling home or calling some telemetry or error reporting endpoint, sure. But is that "tracking" in the same sense as we're being tracked from website to website? I'm not aware of any malicious use of that data yet so we might not want to throw them in the same group as google and other advertisers and user data aggrega…

If a tool collects days on what command line arguments I use and how frequently (some people in the comments argued it's a useful thing), there is hardly a better word for it than tracking.

Re: Console Do Not Track – Proposal for a standard environment variable

#323
post #79
post #33

Earlier quoted context omitted.

The approach I use is Little Snitch. It's how I discovered most of these telemetry misfeatures in the first place.

How do you trust Little Snitch?

You can use Lulu it’s an open source alternative to little snitch. https://objective-see.com/products/lulu.html

Re: Console Do Not Track – Proposal for a standard environment variable

#324

Sure. But I have a question: why ? Why should we opt out of the telemetry? To me, this idea seems to not just be admitting defeat, it's ensuring defeat right from the start. Telemetry should always be opt-in. Yes, that means vendors will get much less data. It's on them to deal with it. On a related note, I wonder how long it takes until one of the vendors of popular CLI tools or desktop apps get fined for GDPR viola…

"If you want me to test your app(lication), pay me." - so-called "power user" What many of today's software authors want/expect is free testing. "To me, this seems to not just be admitting defeat, it's ensuring defeat right from the start." While I do not use any of the example programs the mentioned, it seems like these environmental variables would be appropriate if the user wants to toggle between tracking and no…

> What many of today's software authors want/expect is free testing.

Many of apps and tools are open-source and free. While I assume everyone wants to provide best experience, it's hard for me to justify being angry for bugs and problems in tools that I got for free, not bought them.

Secondly, the industry realized that going fast, releasing often, measuring results, and improving over time is a winning strategy. No matter how often we as users will complain that "they changed something again", we still want to get things fast. Deploying new version once per year is not something we would really like in most cases.

And fast development cycle inevitable comes with bugs, but they can be fixed quickly, not in the next year. Because even if you spend 2 months on testing your app, it will still contain bugs that will surface after the first real user touches the app.

Re: Console Do Not Track – Proposal for a standard environment variable

#325
post #256
post #245

Earlier quoted context omitted.

> It was strange to see it get labeled as a marketing attempt during my attempts to gain some traction, considering I'm not selling a damn thing. Clicking on your HN profile, I see “I am available for hire”. It was clear to me that’s what the maintainers were referring to: you marketing yourself, which you’d have been able to do with greater effectiveness as the originator of a feature adopted by popular open-source…

> which you’d be able to do with greater effectiveness as the originator of a feature adopted by popular open-source projects I'm not sure that's true at all.

Regardless, could you fathom that someone might think that to be true? If so, there you go.

Re: Console Do Not Track – Proposal for a standard environment variable

#326

This is a losing proposition that will only lend credence to the inherently violent opt-out approach to data collection. Instead how about a do-not-hire-or-collaborate-with registry of the individual contributors participating in projects that employ those tactics and see how they like trying to opt out of it.

> inherently violent

Sorry, data collection cannot actually be "violent", by definition. Please stop trying to abuse the English language and actually start making reasonable arguments.

> Instead how about a do-not-hire-or-collaborate-with registry of the individual contributors participating in projects that employ those tactics and see how they like trying to opt out of it.

Mob justice - the tool of hypocrites everywhere, to be used against their enemies and then denounced when it's not convenient for them.

Re: Console Do Not Track – Proposal for a standard environment variable

#327

Earlier quoted context omitted.

> even something as inane as "automatically report crashes to the developers so we can fix them quicker" or "tell us how many users are on each version so we can estimate the blast radius of some backward-incompatible change" would be categorized as tracking. Devil is in the details. Unless you are very careful, even a basic crash report may leak PII (commonly, through careless logging). > Here's the problem: people…

The standard of "care and effort" in software engineering today begins with observability. An error-handling branch without a counter on it will not get through code review. That an incident was detected through user reporting and not telemetry/alerting is a deeply embarrassing and career-limiting admission in a postmortem. That logs were insufficiently detailed to reproduce them problem will be a serious and high-pr…

The standard of care and effort in human interactions begins with consent.

Re: Console Do Not Track – Proposal for a standard environment variable

#328

On linux you can use network namespaces to deprive the program of access to the network (shouldn't be necessary, but this is the world we live in.) $ sudo ip netns add jail # create a new net namespace with no access $ sudo ip netns exec jail /bin/bash # launch a root shell in the new namespace # su - your-normal-username # become non-root $ ping google.com # see if network is accessible? ping: unknown host google.co…

I really hope that someday someone builds some proper UX around network namespaces for desktop Linux. It would not be all that difficult to implement something akin to Qubes if you made NetworkManager namespace aware and integrated with dbus-launch to start the applications in the desired namespace.

Re: Console Do Not Track – Proposal for a standard environment variable

#329
post #200

Earlier quoted context omitted.

Lots of people in the Free Software community think that programs should exist only to help the user, and should just do exactly what the user tells them to do and nothing else. I am one of those people. Showing ads, making network requests that aren't necessary to carry out the expected functionality, etc. all fall under violations of that principle. Some violations are worse than others, but I treat them the same w…

> making network requests that aren't necessary to carry out the expected functionality I think regularly updating the package formulae for homebrew is actually necessary to carry out the functionality most users expect from homebrew.

Homebrew doesn't show ads either. They weren't just talking about Homebrew.

Re: Console Do Not Track – Proposal for a standard environment variable

#330

Earlier quoted context omitted.

The standard of "care and effort" in software engineering today begins with observability. An error-handling branch without a counter on it will not get through code review. That an incident was detected through user reporting and not telemetry/alerting is a deeply embarrassing and career-limiting admission in a postmortem. That logs were insufficiently detailed to reproduce them problem will be a serious and high-pr…

The standard of care and effort in human interactions begins with consent.

You consent to a scope of work. If you want line item control over exactly how the work gets done, what tools the workman gets to bring, what creature comforts he is and isn’t allowed on the jobsite, that’s something you can negotiate.

Like if you’re Amish or under some weird historic preservation regime or working near a delicate billion-dollar scientific instrument. Perhaps you really need carpentry done with hand tools. You can find a contractor who wants to do that. You don’t hire a normal firm and then get mad that they failed to seek consent before plugging in their table saw.

Post reply on HN