Earlier quoted context omitted.
> No, crash reporting is easily done with logs, preferably in some format you could redact any sensitive information from. This seems more like the "I will secretly phone home and not tell you about it or what I'm sending" kind of thing. It's not terribly secret, now was it? It was... you know... immediately discovered and I'm pretty sure my driver changelog AND firewall asked about it. > These are GPU drivers. It's…
I think this is a case where we need to assume guilty until proven innocent. You see, there's no way for users to know what data is being collected and sent today, or what they might change and decide to collect tomorrow. What if government wants access to this data? What if some hacker gets access to the data or their methods of collecting it (MitM)? As such, they need to prove we can trust them before we accept thi…
This is ultimately a trust relationship with your vendor. There is nothing they can do but be trustworthy.
Don't say, "open sourcing." Open sourcing code doesn't assert much of anything about the binaries you have running. sourceless propagating binary behavior is 30 year old technology.