Live data from Hacker News

Audacity 3.0 called spyware over data collection changes by new owner

appleinsider.com

61–70 of 75 posts

Re: Audacity 3.0 called spyware over data collection changes by new owner

#61

Earlier quoted context omitted.

> people complain about Firefox as well Not nearly as vehemently as with Audacity.

If Firefox had told people they would collect data for law enforcement there would be more noise there as well. There are good and legitimate reasons for collecting user data, but many of us think it should be voluntarily, minimal and at least not shared with anyone for anything but its original purpose. In fact we had a very interesting court case in Høgsterett (kind of Supreme Court) here last week where it was fin…

Yes it certainly seems as though Mozilla (or at least their executives) have been bought and sold by Google.

At this stage they seem to be toeing the line for plausible deniability of Google's monopoly, while being thoroughly defanged from doing anything to reduce the actual monopoly.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#62
post #38

Earlier quoted context omitted.

Why would anyone acquire it except to turn it into malware? I can't recall a project that wasn't built for commercial success from the start being bought for any other reason. I guess sourceforge stopping malware bundling could count.

I don’t doubt that’s what’s happening but I’m curious if/how it can be a good business decision

Business profit doesn't have to be a global value. If Audacity is purchased at value X and pillaged in such a way that you can get a third party to pay you value Y for what you did to/with it, and Y > X, that's profitable depending on how much effort/expense you had to go to during that process.

Doesn't have anything to do with even Audacity's users, much less the sustainability of the Audacity ecosystem. If there exists somebody somewhere who would pay more to see Audacity scuttled than it'd cost to buy, that becomes a potential profit motive to a facilitating third party if they know of that dynamic out there to be exploited.

This is of course subject to whether it's allowed to just wreck stuff for your benefit, and how. In cases of simple property, it's generally not: you can't just burn down a rival store to benefit yourself because that's against the rules.

I don't think such limitations currently apply to businesses past a certain level of abstraction, and what's happening to Audacity is not in the least meant as 'just burn it down', even if that's what happens: it's meant as 'get more control over this property', for whatever reason. That may or may not be a wise business decision, but in terms of being able to extract profit, it's a good business decision if in any way, for any reason, it works to get them more money than they paid for the property.

I think it's a very bad decision in the larger sense of things in the world, ability to trust in the things we know about, ability to function within larger systems of known properties and build order out of chaos for the sake of real progress. But that wasn't the question.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#63

Earlier quoted context omitted.

If Firefox had told people they would collect data for law enforcement there would be more noise there as well. There are good and legitimate reasons for collecting user data, but many of us think it should be voluntarily, minimal and at least not shared with anyone for anything but its original purpose. In fact we had a very interesting court case in Høgsterett (kind of Supreme Court) here last week where it was fin…

Yes it certainly seems as though Mozilla (or at least their executives) have been bought and sold by Google. At this stage they seem to be toeing the line for plausible deniability of Google's monopoly, while being thoroughly defanged from doing anything to reduce the actual monopoly.

Just for thr record: I'm not saying anyone should drop Firefox for a Chromium browser - that would be even worse.

I am saying I want

- authorities to look into these dealings

- someone to create a (paid?) unborked version of modern Firefox

- or a "vetted" safe version of Pale Moon or something

- Google to be split into number of chunks

Re: Audacity 3.0 called spyware over data collection changes by new owner

#64
post #6
post #3

Anyone can call it whatever they like. It doesn't make it true. Is Firefox spyware?

I think the argument is that things like Firefox need to share some data with third parties to function correctly. The remote web server needs to know what page you want, your login details etc. That's not to say there's other things that Firefox does that isn't privacy focused, but it's accepted that Firefox has to share some data at some point to function. Audacity, however, doesn't. It's a standalone application.…

Firefox is tracking users pretty aggressively by default, though. Telemetry on by default, experiments on by default, opening a "you've updated Firefox" page with trackers unless you've gone into about:config, the list goes on.

Firefox tries better to anonymize the data collected and is a more reliable company than whoever really owns Audacity these days, but as a Firefox user, I'm pretty annoyed with the amount of settings I need to change to my Firefox installs to keep my data out of the hands of Mozilla of all people, who claim to value my privacy so much.

I can only assume those Mozilla pages telling me I've pressed the update button collect my full IP address for at least logging purposes, as every website does by default. This stuff doesn't need to be on the web, they could easily launch a local HTML file with the same contents.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#65
post #58
post #42

Earlier quoted context omitted.

One possible reason would be to "group" reports: if 95% (or even 100%) of a certain error come from a single computer then there's either a very obscure bug or something wrong with that computer. If all reports come from different computers then it's a much more serious issue. IP addresses aren't really super-reliable for this (corporate networks, ISP NAT), but many people still are under the misapprehension that the…

It seems more natural for the app to create a UUID for the purpose, then stash it in a prefs file for later use?

That's how I would do it as well, but that doesn't mean that Audacity's developers do.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#66
post #8

Earlier quoted context omitted.

Browser extensions with 10k users are routinely acquired as a "spying platform".

So information from as few as 10k or 100k users have any value? What is it that is gathered and sold, and in what form?

Doesn't matter. All that matters is if someone can be made to think it matters, enough to pay for access to whatever information it is.

I feel like HN folks often look for underlying meaning, a structure or purpose through which transactions like this can contribute to greater progress in line with the promise of capitalism. But that's only true when channeled by the constraints of rule systems, which aren't a given.

In the absence of other meaning, it doesn't matter what the 10k user information is. That userbase can still be cannibalized if there's somebody who can be fooled into thinking that act is useful/profitable. Rules saying 'this sort of destructive community-pillaging will cost you more than you gain' aren't necessarily there.

In the absence of them, you don't need to prove harming the 10k community will be profitable over the long or even short term: you only have to find somebody with money who can be persuaded they'll benefit, even if that's not true. If they think that, then you definitely can benefit from selling out the community. You can know it's a doomed exploit, but if you get paid, you're out of it by the time the truth comes out.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#67
post #18

Is it like, Audacity is widely used by whistleblowers, so by tracking down its users, authorities could prevent human rights violation from being uncovered? What else are these features useful in context of “law enforcement”?

There's a chance that it's just the wording for CYA situations. They will cooperate with LE either way, so maybe the lawyers decided to put it clearly in the t&c-s. This really applies to almost every company, since barely anyone will fight LE in your name. It's just rarely spelled out clearly in public.

I will nevertheless move to a fork, but that makes a ton more sense than the conspiracy explanation. Maybe just the word choices are different from typical Western ones as the corporate is in Russia.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#68
post #15

Earlier quoted context omitted.

1) that's whataboutism 2) people complain about Firefox as well and many are avoiding Firefox as a result, blocking Firefox's connection to Mozilla with various tools, etc.

Yeah, I agree. Mozilla toes the line, and there are many instances where they got push back for straying too far. But wouldn't you agree that HN would go apeshit if Mozilla tried to introduce a "law-enforcement" clause like Audacity did?

[deleted]

Re: Audacity 3.0 called spyware over data collection changes by new owner

#69

Earlier quoted context omitted.

Yes it certainly seems as though Mozilla (or at least their executives) have been bought and sold by Google. At this stage they seem to be toeing the line for plausible deniability of Google's monopoly, while being thoroughly defanged from doing anything to reduce the actual monopoly.

Just for thr record: I'm not saying anyone should drop Firefox for a Chromium browser - that would be even worse. I am saying I want - authorities to look into these dealings - someone to create a (paid?) unborked version of modern Firefox - or a "vetted" safe version of Pale Moon or something - Google to be split into number of chunks

Google needed to be split up decades ago.

Re: Audacity 3.0 called spyware over data collection changes by new owner

#70
post #67

Earlier quoted context omitted.

There's a chance that it's just the wording for CYA situations. They will cooperate with LE either way, so maybe the lawyers decided to put it clearly in the t&c-s. This really applies to almost every company, since barely anyone will fight LE in your name. It's just rarely spelled out clearly in public.

I will nevertheless move to a fork, but that makes a ton more sense than the conspiracy explanation. Maybe just the word choices are different from typical Western ones as the corporate is in Russia.

For comparison here's google's privacy policy which uses very similar wording in the list: https://policies.google.com/privacy?hl=en-US

> Receive your account information in order to satisfy applicable law, regulation, legal process, or enforceable governmental request

Audacity:

> data necessary for law enforcement, litigation, and authorities' requests (if any)

Post reply on HN