Live data from Hacker News

Microsoft: Require user consent before sending any telemetry

github.com

121–129 of 129 posts

Re: Microsoft: Require user consent before sending any telemetry

#121
post #102

Earlier quoted context omitted.

> There is no such thing as truly anonymous. in order to send any data you need to connect to a server. at that moment you are in violatation of GDPR because you are exposing the users's IP which is protected by GDPR. This is misinformed. There is nothing in the GDPR that relates to "exposing" or "transmitting" anything (other than transmitting further from a processor to a third party). GDPR relates to how data is s…

I last studied the gdpr years ago but that most definitely appears false, provide your sources. The GDPR deals with "processing" and this is the definition of processing: " ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration,…

I could be mistaken but I think whether the http request makes anything ‘available by transmission’ is down to the definition of who is the data controller and which data processors exist. So in the case of telemetry where no PII changes hands, and no PII is stored, then I can’t see how it applies. That is, assuming that the Telemetry backend here belongs to the same entity that made the app. Such as if a microsoft product phones home to its own backend.

Apps that make http requests to other endpoints belonging to third parties are much murkier.

As far as consent is concerned: Whether consent is required for making a http request containing an IP in the header based on legitimate interest is also murky. Consent is only one way of permitting the processing. Whether Telemetry is legitimate interest I don’t think is established. But it’s important to remember that not only “absolutely essential” functionality that is a legitimate interest. That is: something isn’t automatically not legitimate because it could be removed and still deliver the functionality to the user. Online ads are contested (because profit can be a legitimate interest). The same for telemetry. It’s certainly of interest to the developer to get the data. I have not seen any rulings yet on that but Microsoft has made a pretty decent legal analysis when they conclude that they will never need consent here.

A web server owner can even store data for some time since preventing denial of service attacks could mean they need to store IPs for a short while before deleting. As that’s a legitimate interest, this would not require user consent from visitors.

Re: Microsoft: Require user consent before sending any telemetry

#122

Earlier quoted context omitted.

There is a suggestion that some data sent is in violation with the GDPR. There is no specifics about what it would be that is in violation however. I think 90% of sites with cookie banners are blatantly violating the GDPR - but whether I'm correct in that assessment is anyones guess. It would depend on court processes that hasn't happened yet. It's based on my understanding and interpretation of the regulation, nothi…

Yup, there are lots of violations: https://noyb.eu/en And I do think Microsoft has good lawyers and believe they reviewed any activity prior to receiving consent quite carefully.

Are there any concluded legal processes that are concerning

1) the form of consent banners

2) consent vs legitimate interest for ip transmission as part of http request headers

3) whether ads are a legitimate interest for web sites?

Those seem to me to be the 3 “big questions” of the GDPR. The regulation and most legal processes however seem to focus more on large scale data storage cases, failure to answer user requests etc. And those are important from a privacy standpoint but from a technical standpoint to software developers the 3 above seem much more interesting, yet mostly ignored by courts? I get a feeling they don’t want to touch it because they are a can of worms

Re: Microsoft: Require user consent before sending any telemetry

#123
post #104

Earlier quoted context omitted.

Microsoft’s own telemetry solutions (AppInsights/LogAnalytics) seem perfectly capable of handing async/buffering/backoff etc. I agree there should be a single place, at least in Windows to control Microsoft telemetry on a per app basis. It should be very easy to accomplish. On other platforms less so. In a desktop product I do for work we had the dilemma of opt in/out and showing the query clearly and hiding it in se…

A pre-enabled checkbox is invalid for obtaining gdpr consent

We are assuming here (incorrectly or not) that since no PII is transmitted or stored, the GDPR doesn’t come into play, and the consent is just asking for permission and not “gdpr consent”

Of course it’s impossible to actually transmit anything anywhere without including the source IP in the http header - a fact we are ignoring completely. But that’s similar to the topic of this discussion: Microsoft does exactly this under the same assumption, that non-PII data can be sent (even via http) without gdpr coming into play. Otherwise they couldn’t have it enabled by default. If there is a ruling that says otherwise then everyone will need to change.

It could also be that first party servers (Microsoft app talking to Microsoft servers) is acceptable and then everyone would route telemetry to their own servers.

Re: Microsoft: Require user consent before sending any telemetry

#124
post #87

Earlier quoted context omitted.

As was said elsewhere, since telemetry itself is not a functionality, ip address is personal information and requires consent.

Read the replies elsewhere. GDPR doesn’t care about whether a http request containing an IP is necessary or not. The GDPR is not in any way regulating how or why any PII is “transmitted” out of your system.

…at least not if the transmission is within the supervision of the same controller as we are discussing here.

Re: Microsoft: Require user consent before sending any telemetry

#125

Earlier quoted context omitted.

Yup, there are lots of violations: https://noyb.eu/en And I do think Microsoft has good lawyers and believe they reviewed any activity prior to receiving consent quite carefully.

Are there any concluded legal processes that are concerning 1) the form of consent banners 2) consent vs legitimate interest for ip transmission as part of http request headers 3) whether ads are a legitimate interest for web sites? Those seem to me to be the 3 “big questions” of the GDPR. The regulation and most legal processes however seem to focus more on large scale data storage cases, failure to answer user requ…

1) YES https://noyb.eu/en/where-did-all-reject-buttons-come

2) Consent vs legitimate interest is not for data but for data processing purposes. A company, say Paypal, may have a legitimate interest to process (and, therefore, collect) your IP address in fraud detection systems. If you don't give consent, fraud prevention dept cannot share your IP address with the marketing dept (and would have to erase it once it's no longer used by the fraud detection system). Which is why you get pestered with more consent requests than needed. Consent also has to be freely given: https://edpb.europa.eu/news/national-news/2019/facial-recogn... + https://noyb.eu/en/pay-or-okay-tech-news-site-heisede-illega...

3) Ads are not personal data (data that came from you and/or data related to you, not necessarily PII). GDPR is only about careful handling of all personal data. It does not prevent a company from showing you ads. But GDPR does prevent tracking to show targeted ads: https://noyb.eu/en/norway-temporary-ban-behavioral-ads-faceb...

Re: Microsoft: Require user consent before sending any telemetry

#126
post #104

Earlier quoted context omitted.

A pre-enabled checkbox is invalid for obtaining gdpr consent

We are assuming here (incorrectly or not) that since no PII is transmitted or stored, the GDPR doesn’t come into play, and the consent is just asking for permission and not “gdpr consent” Of course it’s impossible to actually transmit anything anywhere without including the source IP in the http header - a fact we are ignoring completely. But that’s similar to the topic of this discussion: Microsoft does exactly this…

I haven't checked how they handle it for VS Code, but you probably agreed to some term before using it, and they're probably relying on legitimate interest

My gdpr is quite rusty anyhow

Re: Microsoft: Require user consent before sending any telemetry

#127
post #96
post #95

Earlier quoted context omitted.

Yeah, however there have been other cases where the outrage was ignored, like on how the modules story went.

Modules isn't any worse than NuGet for privacy. Neither are good, but it's hard to say the outrage was "ignored" - people bring it up constantly.

> people bring it up constantly.

Of course. Because the Go team ignored everyone and implemented it anyway.

Re: Microsoft: Require user consent before sending any telemetry

#128
post #102

Earlier quoted context omitted.

I last studied the gdpr years ago but that most definitely appears false, provide your sources. The GDPR deals with "processing" and this is the definition of processing: " ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration,…

I could be mistaken but I think whether the http request makes anything ‘available by transmission’ is down to the definition of who is the data controller and which data processors exist. So in the case of telemetry where no PII changes hands, and no PII is stored, then I can’t see how it applies. That is, assuming that the Telemetry backend here belongs to the same entity that made the app. Such as if a microsoft p…

So first of all you said "There is nothing in the GDPR that relates to "exposing" or "transmitting" anything (other than transmitting further from a processor to a third party). GDPR relates to how data is stored or processed." .

That was false, since the definition of processing explicitly includes transmitting.

VS Code requires accepting the all-encompassing Microsoft privacy statement, and I couldn't find quickly what legal reasons they use for telemetry.

"Legitimate reasons" can practically indeed mean almost anything, and the only limits to it are those placed by subsequent guidances or interpretations of the central or local privacy authorities. It's what largely makes the gdpr a joke. It's very likely that Microsoft relies on it, whether that's acceptable or not.

You seem to consider a local software as part of the software's copyright holder infrastructure, and that appears ludicrous, transmission of usage data from a local application to an other company's server is most definitely transmission.

If VS Studio's telemetry is legal or not I don't know and I'm not interested in delving into it right now, if I had to use it I'd block it and probably wouldn't use it if it became impossible.

Re: Microsoft: Require user consent before sending any telemetry

#129

No answer is forthcoming from the VS Code team, because they know you won't like the answer. Microsoft trawls their[1] endpoints mercilessly for every bit of telemetry that they possibly can, and they go out of their way to prevent customers from disabling this. Windows 10 or 11 with Office requires something like 200+ individual forms of Microsoft telemetry to be disabled! Notably: - They keep changing the name of t…

We need a "just say no" campaign that boycotts companies employing these slimy behaviours.

I've been boycotting Microsoft for around 25 years now... But I've noticed most people, even in the tech world, don't mind supporting companies with slimy behavior.
Post reply on HN