Live data from Hacker News

Fedora, UUIDs, and user tracking

lwn.net

21–30 of 87 posts

Re: Fedora, UUIDs, and user tracking

#21
post #12
post #7

Any distro that phones home with a unique identifier is a distro I won't touch with a ten foot pole. I don't care what they claim they will or won't use that identifier for.

Maxims that act on the symptom rather than the problem rarely help in the end, as the problem just evolves to support its needs through other means. For example, sending a unique identifier is not the problem. Tracking people through a unique identifier is. So, depending on your goals, you can design a unique identifier system that does not allow tracking (or at least makes the tracking period so small as to be unuse…

There are reasons to draw a line in the sand, to say that even attempting to do some things is contrary to a strong norm that we will defend even if you promise that you're not using it for anything malicious, something which is hard to police.

Taking a strong stand against tracking and, therefore, in favor of privacy is perfectly reasonable for people who use Linux in part due to our hatred of the deep tracking closed-source OSes do.

Re: Fedora, UUIDs, and user tracking

#22
post #4

This post describes a bad way to track users, but the real utility of this post is in the email that describes a way to count Fedora users without tracking them: https://lwn.net/ml/fedora-devel/20190108152239.GA24118@garde...

That actually sounds more reasonable, although it does run tiny risk of being trivial to mess with if a malicious client wanted to skew numbers. But I don't think it's possible to defend against that without being horribly invasive, privacy perspective. I must say, it feels odd to support a Poettering proposal, but this actually does look like a good solution.

> although it does run tiny risk of being trivial to mess with if a malicious client wanted to skew numbers.

I don't doubt it will happen if this becomes well-known. Activism takes many forms.

Re: Fedora, UUIDs, and user tracking

#23
post #20
post #19

Earlier quoted context omitted.

You're right in general, of course. But here's the reason for my hardline stance on that: history shows that trusting promises or assertions made about things like unique identifiers is unwise, and so I have to take a strong defensive stance. > you can design a unique identifier system that does not allow tracking You can (sortof), but we run against that trust issue again. If I'm giving a unique identifier to someon…

> A company's "need" to collect metrics is their problem, not mine. When it's couched in how to deliver software updated, it becomes your problem as well. That's a transaction, and they want to charge more for it now. You can decide it's too costly, as you indicate here, but it's not like they're giving nothing in return. I think it's important to note the goals of those involved. In this case, it's the people that p…

> When it's couched in how to deliver software updated, it becomes your problem as well.

I honestly don't see how. If/when I'm ready to take an update, I can come get it myself. If they want to charge me (or charge me more) for it, then they can do so at that time. No tracking needed except for that associated with payment.

> Adding an additional system that allows better tracking of the useful information without increasing the personally identifying features of IP based tracking (which still exists) is laudable, in my eyes.

Not as laudable as not engaging in tracking in the first place. However, I don't see how this doesn't increase personally identifying features. On the contrary, it's adding one: a unique identifier.

Re: Fedora, UUIDs, and user tracking

#24
post #21
post #12

Earlier quoted context omitted.

Maxims that act on the symptom rather than the problem rarely help in the end, as the problem just evolves to support its needs through other means. For example, sending a unique identifier is not the problem. Tracking people through a unique identifier is. So, depending on your goals, you can design a unique identifier system that does not allow tracking (or at least makes the tracking period so small as to be unuse…

There are reasons to draw a line in the sand, to say that even attempting to do some things is contrary to a strong norm that we will defend even if you promise that you're not using it for anything malicious, something which is hard to police. Taking a strong stand against tracking and, therefore, in favor of privacy is perfectly reasonable for people who use Linux in part due to our hatred of the deep tracking clos…

The problem with drawing lines in the sand is that you trip up all the players that make an effort to act responsibly as well, thus reducing the incentive to act responsibly.

You're basically reducing market effectiveness by ignoring the details of available information and grouping unalike things together. The market will likely respond by reducing access to or the clarity of that information *e.g. they'll track you, but hide it even if it's innocuous and the vast majority would have no problem in what info is given up because apparently the people can't be bothered to make a decision on anything but the coarsest of details).

Re: Fedora, UUIDs, and user tracking

#25
post #13

>unique user ID (UUID) for each installed system that would be sent with DNF mirror-list requests. It explicitly calls out privacy concerns: "We don't want to track; just count." If Fedora server is compromised they can serve different packages to different users.

With control over the mirror list you can prevent certain users from getting updates which is a security problem but without being able to sign packages the danger is limited.

Re: Fedora, UUIDs, and user tracking

#26
post #23
post #20

Earlier quoted context omitted.

> A company's "need" to collect metrics is their problem, not mine. When it's couched in how to deliver software updated, it becomes your problem as well. That's a transaction, and they want to charge more for it now. You can decide it's too costly, as you indicate here, but it's not like they're giving nothing in return. I think it's important to note the goals of those involved. In this case, it's the people that p…

> When it's couched in how to deliver software updated, it becomes your problem as well. I honestly don't see how. If/when I'm ready to take an update, I can come get it myself. If they want to charge me (or charge me more) for it, then they can do so at that time. No tracking needed except for that associated with payment. > Adding an additional system that allows better tracking of the useful information without in…

> If they want to charge me (or charge me more) for it, then they can do so at that time. No tracking needed except for that associated with payment.

That's what's proposed? An identifier sent along with the request to see the current list of updates available?

> I don't see how this doesn't increase personally identifying features. On the contrary, it's adding one: a unique identifier.

An identifier that changes every week or so. At that point it is useless for identifying an individual, but can still be used statistically to determine how many systems are running what versions of Fedora, even behind NAT gateways. The only difference from before is now instead of "there's one IP with more than average check-ins, or check-ins from two or more different configurations", it's "there's one IP with X number of unique identifiers that randomize weekly seen over the last 28 days, so we can approximate X/4 different systems behind that IP".

Re: Fedora, UUIDs, and user tracking

#27
post #24
post #21

Earlier quoted context omitted.

There are reasons to draw a line in the sand, to say that even attempting to do some things is contrary to a strong norm that we will defend even if you promise that you're not using it for anything malicious, something which is hard to police. Taking a strong stand against tracking and, therefore, in favor of privacy is perfectly reasonable for people who use Linux in part due to our hatred of the deep tracking clos…

The problem with drawing lines in the sand is that you trip up all the players that make an effort to act responsibly as well, thus reducing the incentive to act responsibly. You're basically reducing market effectiveness by ignoring the details of available information and grouping unalike things together. The market will likely respond by reducing access to or the clarity of that information *e.g. they'll track you…

If you are opposed to tracking, then a company being aboveboard about it doesn't resolve the issue anyway.

Re: Fedora, UUIDs, and user tracking

#29
post #26
post #23

Earlier quoted context omitted.

> When it's couched in how to deliver software updated, it becomes your problem as well. I honestly don't see how. If/when I'm ready to take an update, I can come get it myself. If they want to charge me (or charge me more) for it, then they can do so at that time. No tracking needed except for that associated with payment. > Adding an additional system that allows better tracking of the useful information without in…

> If they want to charge me (or charge me more) for it, then they can do so at that time. No tracking needed except for that associated with payment. That's what's proposed? An identifier sent along with the request to see the current list of updates available? > I don't see how this doesn't increase personally identifying features. On the contrary, it's adding one: a unique identifier. An identifier that changes eve…

> The only difference from before is [...]

Yes, I understand, but your explanation isn't reassuring to me. It's confirming that I actually do understand the mechanism and its ramifications.

Red Hat can do whatever it likes (although my take on it is that they're not likely to do this unique identifier thing). I'm not saying otherwise -- that's their right, after all.

All I am saying is that software that does this sort of thing is unacceptable to me and I will avoid it to the best of my ability. As is my right.

Re: Fedora, UUIDs, and user tracking

#30
post #27
post #24

Earlier quoted context omitted.

The problem with drawing lines in the sand is that you trip up all the players that make an effort to act responsibly as well, thus reducing the incentive to act responsibly. You're basically reducing market effectiveness by ignoring the details of available information and grouping unalike things together. The market will likely respond by reducing access to or the clarity of that information *e.g. they'll track you…

If you are opposed to tracking, then a company being aboveboard about it doesn't resolve the issue anyway.

You speak of "tracking" as if it's all the same thing. Every sale you make at a store is tracked, and for good reason to both the customer and the store (how else do you allow returns). Every time you visit a doctor, they add the info regarding your visit to a log. That's tracking. Tracking itself is not bad.

Tracking individuals and personal information about them while they are trying to remain anonymous or have no expectation anything peraonal has been revealed is bad.

Attacking anything with the word tracking in it because it's been conflate with this even though it shares little or no resemblance and can't be used later for this purpose it it's current form is just FUD and an indicator or how broken human communication fundamentally is.

Post reply on HN