Live data from Hacker News

Fedora, UUIDs, and user tracking

lwn.net

71–80 of 87 posts

Re: Fedora, UUIDs, and user tracking

#71
post #70
post #66

Earlier quoted context omitted.

IMHO, there were serious consequences. 5 years ago I would not have consider using fedora on my desktop because ubuntu was trustworthy and I was considering fedora as useless fragmentation. Now, I see redhat as a knight on my side to improve linux adoption (I hope that IBM will not ruin this) and I see fedora as stable and up to date than ubuntu.

Can I ask what was / is it about Debian that made you discount it, and embrace RH / Fedora instead?

Not the OP, but I made a similar transition. I got fed up with using APT to manage packages while Yum/DNF seem much more complete and elegant. I seem to get far fewer package conflicts with Yum, and the error messages when something does go wrong are more digestible, though this may be just due to my use case/package selection. I also dislike the use of the dash shell by default. To me, it just further muddies the water between compatibility of sh, bash, and dash. I'd rather just have bash and be done with it.

Fedora's packages are also more up to date while being as or more stable than Ubuntu. Debian is still probably king of stability, but when compared to CentOS, I prefer CentOS' default package selection and configuration (postfix vs exim, sudo installed by default, ssh installed and enabled by default) , especially since they embrace systemd while Debian seems to use it grudgingly while also keeping around old methods of configuration that don't quite fit with systemd (network configuration being the big one here, don't even get me started on Ubuntu's adoption of friggin' Netplan)

Re: Fedora, UUIDs, and user tracking

#72
post #70
post #66

Earlier quoted context omitted.

IMHO, there were serious consequences. 5 years ago I would not have consider using fedora on my desktop because ubuntu was trustworthy and I was considering fedora as useless fragmentation. Now, I see redhat as a knight on my side to improve linux adoption (I hope that IBM will not ruin this) and I see fedora as stable and up to date than ubuntu.

Can I ask what was / is it about Debian that made you discount it, and embrace RH / Fedora instead?

Your question pre-supposes that the GP evaluated Debian and decided against it. While this may be true, he/she never said that.

In my case tho, I found Debian to be moving at a glacial pace. Fedora OTOH is always fresh and current. There's nothing wrong with Debian, and sure some people don't mind running Sid. Fedora is my favorite flavor of ice cream tho.

Re: Fedora, UUIDs, and user tracking

#73

Earlier quoted context omitted.

(disclaimer: I work at Red Hat, not on any OS/distro) This is a nitpick, but Red Hat did not get bought by IBM. What happened was IBM announcing the intention to buy Red Hat. It's maybe a subtle, but possibly important distinction. Red Hat is still its own independent entity until the deal goes through (which means IIRC passing the board's approval, SEC and likely other stuff). This is expected to happen in late 2019…

Thanks for clarifying for me, I had that mixed up

No worries! Pretty much everyone I talked to who was aware of the deal (online and off) thought the same.

These things are pretty complex.

Re: Fedora, UUIDs, and user tracking

#74

Earlier quoted context omitted.

I can understand the slippery slope threat in a proprietary system, but Fedora is a open system. Should data collection at some point go beyond whatever it is the devs announce, someone is going to pick it up and everyone is going to drop the distro like a hot potato. So I'm not sure this is a big issue.

The lack of serious consequences to Canonical regarding their spyware-like, opt-out search integrations in Ubuntu with Amazon way back when (and then doubling down with legal threats against fixubuntu.com) gives me doubt as to this being the case. That goes double given Fedora's position as what boils down to RHEL upstream. Too much corporate support for any backlash to make a dent, even if it could get critical mass…

As one other commentator has pointed out, there actually has been serious consequence to Canonical, as least as far as Ubuntu as a desktop end-user distro is concerned. Many other community distributions have risen in popularity specifically around this issue of corporate involvement.

But more importantly, I don't think there is anything wrong in principle with Ubuntu collecting user data if they openly communicate it to their users. I do not agree with this Stallman-esque usage of the term spyware, if the exchange of data is voluntary and the consequence of informed decision.

If customers disagree with Ubuntu on data collection they can switch to a different distribution, but as long as the information is out there, this is not an issue, spyware or a slippery slope.

Re: Fedora, UUIDs, and user tracking

#75
post #52
post #35

Earlier quoted context omitted.

> You speak of "tracking" as if it's all the same thing. True, and that's bad of me. I'm speaking in shorthand. > Every sale you make at a store is tracked But the store does not track me if I don't use a card. Returns are handled through the receipt that they give me during the transaction. That's a kind of tracking, but tracking the transaction itself, not me. > Every time you visit a doctor, they add the info rega…

> But the store does not track me if I don't use a card. Returns are handled through the receipt that they give me during the transaction. That's a kind of tracking, but tracking the transaction itself, not me. That's exactly analogous to what's happening here. The data being tracked isn't you, it's generic information about how many Fedora installs of what type there are. The countermeasures in place mean it cannot…

> That's exactly analogous to what's happening here. The data being tracked isn't you

If we're talking about using a unique identifier, then I disagree. This isn't analogous to getting a store receipt at all. With a store receipt, there is nothing that connects me to the transaction described in the receipt except that I am in physical possession of the receipt.

> If you visit the same doctor, even without a log of prior visits, he or she might remember you.

Indeed, but that's in no way similar to what we're talking about.

> I feel it's akin to looking at the ills that automobiles have brought about with pollution, and taking a stance against vehicles. When someone comes by to show you a bicycle, you say no-thanks

I think this analogy also misses the mark. If tracking is like a car, then the UUID tracking we're talking about is like a compact car. Not at all like a bicycle (Poettering's suggestion, which I'm OK with, is more like that).

> You're equating tracking, as being discussed here, with identity tracking, which is not really on the table as an option at all.

I view this as effectively identity tracking. Much like the "advertising IDs" that Android uses.

> And I would classify it as an overreaction to that problem.

Perhaps it is, but if so, it's because as a user it's impossible to determine which tracking is OK and which isn't, therefore it's wise to avoid it all.

> but does that mean we should attack real solutions which do not exhibit that problem just because it shares some easily identifiable similarities, such as a name?

Of course not, but I'm not sure that this is an example of that. Also, it's important that a company prove (I'm not sure how that would be done, admittedly) that their representations of the tracking system are accurate, and that future business decisions couldn't change that.

> That's what we already have, by nature of using IP transport.

It's not, really. For instance, I run about a dozen Linux machines at home. Each of those machines does not go to the distro's repository for updates -- I have an update server that caches them and the other machines get their updates from that. So, if you're looking at the repository's logs, it looks like only one machine is getting updates. And, if I wanted to be even safer, my update server could get the updates using a VPN and thus completely disconnecting my IP address from the IP address the repository is seeing.

Besides, as I said before, just because there's one data leak doesn't mean it's OK to introduce another one.

> All they are proposing is to get a finer grained view (but still not perfect) of how many systems there are and what version they are.

Yes, I understand.

> I can't reconcile your hard line in one instance and apparent blasé attitude in the other.

That might be because you're assuming I have a blasé attitude in an area where I don't.

Re: Fedora, UUIDs, and user tracking

#76
post #48
post #19

Earlier quoted context omitted.

You're right in general, of course. But here's the reason for my hardline stance on that: history shows that trusting promises or assertions made about things like unique identifiers is unwise, and so I have to take a strong defensive stance. > you can design a unique identifier system that does not allow tracking You can (sortof), but we run against that trust issue again. If I'm giving a unique identifier to someon…

> A company's "need" to collect metrics is their problem, not mine. And your need to run an OS on your computer is your problem, not theirs. What do you do if everyone on the sell side of the market uses telemetry? Just stop using computers?

> What do you do if everyone on the sell side of the market uses telemetry? Just stop using computers?

Well, that's not going to happen. I doubt Slackware would go down that road, for example.

But lets say that what you assert happens -- all that means is that I won't use distros. It doesn't mean that I won't use computers.

It's entirely possible to install Linux without using a distro or prebuilt binaries at all. It's also possible to keep using an older version of the operating system.

But, being essentially lazy, what I'd most likely do is an extension of what I do with with most applications these days: firewall off the servers that the OS is trying to communicate with.

Re: Fedora, UUIDs, and user tracking

#77

Earlier quoted context omitted.

The lack of serious consequences to Canonical regarding their spyware-like, opt-out search integrations in Ubuntu with Amazon way back when (and then doubling down with legal threats against fixubuntu.com) gives me doubt as to this being the case. That goes double given Fedora's position as what boils down to RHEL upstream. Too much corporate support for any backlash to make a dent, even if it could get critical mass…

As one other commentator has pointed out, there actually has been serious consequence to Canonical, as least as far as Ubuntu as a desktop end-user distro is concerned. Many other community distributions have risen in popularity specifically around this issue of corporate involvement. But more importantly, I don't think there is anything wrong in principle with Ubuntu collecting user data if they openly communicate i…

> I don't think there is anything wrong in principle with Ubuntu collecting user data if they openly communicate it to their users.

As long as it's opt-in, I agree.

> I do not agree with this Stallman-esque usage of the term spyware, if the exchange of data is voluntary

Being truly voluntary is key. If that's the case, then I agree with this. However, if data is being collected about me or the hardware/software that I'm using without my affirmative consent, that completely qualifies as "spying".

Re: Fedora, UUIDs, and user tracking

#78
post #70

Earlier quoted context omitted.

Can I ask what was / is it about Debian that made you discount it, and embrace RH / Fedora instead?

Not the OP, but I made a similar transition. I got fed up with using APT to manage packages while Yum/DNF seem much more complete and elegant. I seem to get far fewer package conflicts with Yum, and the error messages when something does go wrong are more digestible, though this may be just due to my use case/package selection. I also dislike the use of the dash shell by default. To me, it just further muddies the wa…

> especially since they embrace systemd

I will never forgive Red Hat for SystemD, and even more than that, I will never forgive Debian for adopting it. But that's off-topic.

Re: Fedora, UUIDs, and user tracking

#79
post #70

Earlier quoted context omitted.

Can I ask what was / is it about Debian that made you discount it, and embrace RH / Fedora instead?

Your question pre-supposes that the GP evaluated Debian and decided against it. While this may be true, he/she never said that. In my case tho, I found Debian to be moving at a glacial pace. Fedora OTOH is always fresh and current. There's nothing wrong with Debian, and sure some people don't mind running Sid. Fedora is my favorite flavor of ice cream tho.

> I found Debian to be moving at a glacial pace.

I view this as a feature, not a bug!

Re: Fedora, UUIDs, and user tracking

#80
post #34
post #17

I'm not sure what they want to count. It definitely isn't users, as they ignore multiple users per system. It seems to be something like "currently active and online machines". But then you should not ignore machines that will not be updated. Maybe they mean "machines that follow the weekly update schedule this week"? That seems to be what Poeterring's approach counts.

Disclaimer: I work for Red Hat on Fedora. Take that for what you will As far as I know, the desire is to get better numbers on how much the parts of Fedora are being used. There is always more work to do than there are folks to do all of it; having better numbers on how much different bits are being used helps us make better decisions on what to focus on. Granted, I'm not Matt but I've heard him talk about similar th…

But Fedora should remain wary of an over-reliance on telemetry. It's very, very easy to draw the wrong conclusions about things, leading to decisions that reduce the quality of the product.

As an example, there are very likely to be packages that aren't often needed, but are absolutely critical when they are.

Post reply on HN