Live data from Hacker News

Microsoft: Require user consent before sending any telemetry

github.com

41–50 of 129 posts

Re: Microsoft: Require user consent before sending any telemetry

#41

Earlier quoted context omitted.

Which law? Instead of shit talking, they can report it, file lawsuit.

G.D.P.R., it says so in the thread. And Europe is not a litigious environment, we start with complaints first.

There is a suggestion that some data sent is in violation with the GDPR. There is no specifics about what it would be that is in violation however. I think 90% of sites with cookie banners are blatantly violating the GDPR - but whether I'm correct in that assessment is anyones guess. It would depend on court processes that hasn't happened yet. It's based on my understanding and interpretation of the regulation, nothing else. I guess it's the same with the complaint here. If there is a question of a violation then it's probably due to microsoft and the commenter having different interpretations about specific data such as hashed mac addresses (Which certainly isn't clear cut).

Re: Microsoft: Require user consent before sending any telemetry

#42

I'm not qualified to weigh in on the merits of the request, but asking a corporation to change something and then throwing in a bunch of legalese about compliance and GDPR seems like an excellent way to guarantee that the poor reviewer of the requests is not going to deal with it, let alone quickly. At best, they raise it to their internal legal contact. The inhouse lawyer rapidly advises them to not respond in any w…

This language in the bug makes it easier to build a legal case against them.

Re: Microsoft: Require user consent before sending any telemetry

#43

To be fair if someone comments to me with things like: > Please give an answer within the next week until the 16th of June. I wouldn't respond to them either out of spite

I suspect they are dating it to trigger some terms of the GDPR, eg., reasonable response lengths when notified of infraction

That opens another question: which means of communication would count for that? Does commenting on a GitHub issue really count? Wouldn't you have some sort of contact details specifically for that in a license agreement or similar?

Re: Microsoft: Require user consent before sending any telemetry

#44

To be fair if someone comments to me with things like: > Please give an answer within the next week until the 16th of June. I wouldn't respond to them either out of spite

I suspect they are dating it to trigger some terms of the GDPR, eg., reasonable response lengths when notified of infraction

GDPR terms allow them to ask for any data about them personally. And Microsoft can say no if for example all the telemetry data is anonymous and aggregated. These attempts at sounding like a lawyer with demands to answer make the issue commenters sound like they are 14 years old and any engagement with that issue will never end unless it's locked.

Re: Microsoft: Require user consent before sending any telemetry

#45

To be fair if someone comments to me with things like: > Please give an answer within the next week until the 16th of June. I wouldn't respond to them either out of spite

I've written to companies in the UK before with similar deadlines, it can be statutory - I am giving you notice that this communication starts the clock on the 30 day period I am required to allow you to give me a satisfactory resolution before I will escalate this case to the relevant authority.

Last time I had to use that sort of language was with a deranged ISP who had failed to deliver an internet connection, then decided to chase a debt for unpaid bills for this non-existent connection two years later.

Re: Microsoft: Require user consent before sending any telemetry

#46
post #23

A user should be able to configure a program (or all programs) such that outgoing communication is not possible, logged or both. It really shouldn't be up to the program to decide what it wants to send as it could easily scan the entire hard drive on the users behalf.

Have you tried running a firewall with explicit prompts? Everything connects home now. It's infuriating.

The majority of FOSS programs don't connect anywhere - although there has been an increase, for sure.

Last year we had an argument this regarding LibreOffice, where an option to collect some telemetry was suggested as a nagging-opt-in. Opponents argued against this because some fraction of our users will press Accept just to get through the installation, or without understanding what they're accepting; plus we just didn't want this kind of mechanism in a respectable piece of software. For now the idea seems to be dead in the water.

Re: Microsoft: Require user consent before sending any telemetry

#47
post #45

To be fair if someone comments to me with things like: > Please give an answer within the next week until the 16th of June. I wouldn't respond to them either out of spite

I've written to companies in the UK before with similar deadlines, it can be statutory - I am giving you notice that this communication starts the clock on the 30 day period I am required to allow you to give me a satisfactory resolution before I will escalate this case to the relevant authority. Last time I had to use that sort of language was with a deranged ISP who had failed to deliver an internet connection, the…

Virgin Media by any chance? I had them do that to me when I clawed back the money through my bank that they took for an install they never delivered.

Re: Microsoft: Require user consent before sending any telemetry

#48

Earlier quoted context omitted.

Which law? Instead of shit talking, they can report it, file lawsuit.

G.D.P.R., it says so in the thread. And Europe is not a litigious environment, we start with complaints first.

You got no idea bud...

Re: Microsoft: Require user consent before sending any telemetry

#49
post #42

I'm not qualified to weigh in on the merits of the request, but asking a corporation to change something and then throwing in a bunch of legalese about compliance and GDPR seems like an excellent way to guarantee that the poor reviewer of the requests is not going to deal with it, let alone quickly. At best, they raise it to their internal legal contact. The inhouse lawyer rapidly advises them to not respond in any w…

This language in the bug makes it easier to build a legal case against them.

It's very easy: Complaints should be directed to whoever is listed in the Personal Data Protection Policy issued by (in this case) Microsoft. The privacy notice (Which nicely seems to be the same one across microsoft products!) clearly says how to complain, as it should https://privacy.microsoft.com/en-us/privacystatement

And that method is not a github comment.

The commenter might have followed the correct route to complain too, but could then at least have said that "I have contacted microsoft at [..] as outlined in the Personal Data Protection Policy and expect a response within [..]"

Re: Microsoft: Require user consent before sending any telemetry

#50
post #33

Earlier quoted context omitted.

in the Google fonts CDN the court ruled that: it's irrelevant if the website or Google had the opportunity to link the IP address to the user. the mere possibility of this is enough to consider it as protected PII.

Question is whether Google Fonts CDN/server was storing the IP address or not. Linking to a user is secondary. If a server does not log or store raw IPs in the first place, where's the fault?

My man you are arguing with an established case verdict. https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/ The wording that is irrelevant what Google does with the IP (just the theoretical possibility of misuse is enough) is in the case verdict.
Post reply on HN