7 ms·
Don't use Atom then? Seems pretty obvious if you care that much. I respect your privacy views and even share many/most of them (if not so strictly), and apprec
by urthen 7y ago
Don't use Atom then? Seems pretty obvious if you care that much.
I respect your privacy views and even share many/most of them (if not so strictly), and appreciate that you are probably just trying to bring this to people's attention. However, you are not the king of open source, and you cannot dictate how other authors must write their projects. It's an open source product written by a for-profit company. There's always going to be trade-offs.
- sneak 7y ago> However, you are not the king of open source, and you cannot dictate how other authors must write their projects No, but I can convince other people who don't like their computers being used a spying tools against them to put social pressure on maintainers so that they stop doing this nonsense. Atom's telemetry used to be on by default; spying silently caused them such a shitstorm that they added a consent dialog. They're almost there! Now they just have to make it functional. https://github.com/atom/atom/pull/12281 https://github.com/atom/atom/pull/12281 There are precedents. We can push back, especially against open source projects. > There's always going to be trade-offs. I don't think that's how software works. I certainly don't take that to mean that I should just accept that it's going to spy on me. I don't want that, and I don't accept that, and I will yell, loudly, at anyone who says I should accept that without a fight.
- sjwright 7y agoIt’s open source. They aren’t forcing you to use their software, and they’re certainly not forcing you to use their binaries.
- sneak 7y agoi use Little Snitch and DNS blackholing of tracking services, so these issues don't really affect me. today i decided i care more about strangers than i thought i did people brand new to our industry should be able to download a nice gui editor and not get their consent trampled and get spied on even after they click the "dont spy on me" button it's easy to laugh and be like "oh lol it's software from microsoft what did they expect, noobs" like someone else did in this thread but that's bullshit and you and i both know it the software simply shouldn't do that when you say "don't send my data away pls" i don't want everyone to have to say "oh use homebrew it's great but also add this weird line about analytics to your .bashrc before you install it oh wait you don't know what a bashrc is huh" when they talk to some teenager who just got a $15 rtlsdr and wants to install gnuradio on their mac that's not a good first-10-minutes-at-the-command-line experience. i don't think that's fair or good or optimal. i want the world to be different, and i want these maintainers to realize that they made a mistake, and revert it. i don't think they're bad people, i think they're just misguided, and they're optimizing for vanity metrics like user count, which will effectively go away entirely if i succeed and they only get telemetry from users who said "yes it's ok i don't mind". that's a lot fewer users, and they know it, which is why so many of them are refusing to engage with the ethical argument about silently using a user's own hardware to spy on them without their knowledge or consent. it shouldn't be a controversial position that our tools should not spy on us.
- BubRoss 7y ago> i use Little Snitch and DNS blackholing of tracking services Why do you need that when you can just not use things that spy on you (by your own logic)
- saagarjha 7y agoThe issue here is that there is no way of knowing what'll spy on you without using it and running these services.
- BubRoss 7y agoYes I know. This person has been saying 'no one forces you to use atom, just don't use it' as a solution to spying but also says he runs DNS tools to prevent rogue programs.
- catalogia 7y ago> " This person has been saying 'no one forces you to use atom, just don't use it'" That is a flat wrong summation of sneak's arguments in this discussion. I think you must have misread usernames, because sneak is saying quite the opposite of what you think he's saying. Note that sneak is not sjwright (the other person in this thread you've responded to and who's argument you seem to have misattributed to sneak.)
- bromuro 7y agoThanks for defending your points. I don’t understand why some here take your reports on GH personally. The fact that your reports aren’t taken seriously by the Atom team worries me. Your battle is right and presented in the right tones.
- sjwright 7y agoWhereas my point is that the developers of Atom have shown their true moral colours—and their honesty isn't sufficiently instructive to you? Unless you can get the developers to change their principles, getting them to change their source code today seems to be a rather temporary fix. Meanwhile, isn't it strange that the default behaviour (on nearly all major consumer computer platforms) that we implicitly trust all applications with near-unfettered access to the internet. And we merely hope they don't betray us.
- mirimir 7y agoBut here's the thing: They don't disclose that they'll check for updates before asking for permission. So how would a user, who hadn't seen this discussion, know that their "we'll ask" reassurance was bullshit?
- sjwright 7y agoIf you actually care about that—as opposed to complaining for the sake of it—you shouldn’t be allowing new software to establish outgoing connections without your consent anyway. So if you actually did care, you the user would know because your operating system alerted you. Nagging everyone to comply with your interpretation of “the right thing” might feel good to you, but it’s actually a very weak and porous form of security theatre.
- mirimir 7y agoOK, are there any standard Debian packages that do this? As I recall, it was a huge upset when Ubuntu app search hit Amazon by default. And when you install Debian, it asks whether you want to participate in the packages survey. And the default is "no". Edit: And just to be clear, this isn't about me. I assume that stuff will leak my IP address without warning, so I only connect via nested VPN chains. Or when I really care, that plus Tor. This is about people who trust stuff that they use.
- sjwright 7y agoA popular solution has been available for MacOS for sixteen years (Little Snitch) so if something comparable isn't already available for Linux—the operating system of the internet—that's pretty embarrassing.
- BubRoss 7y agoThis is about not lying to your users
- sjwright 7y agoIt's not a lie if they aren't logging anything. (I'm not saying that's the case, by the way. It's just an observation. We can't really know if they're lying or not—and to that extent I agree with your point.)
- marcinzm 7y ago>However, you are not the king of open source, and you cannot dictate how other authors must write their projects. And you're not the king of what people are allowed to voice their views and opinions on in public forums. Authors can do whatever they want and users can say whatever they want as a result. Doing something does not mean you are free of the consequences, including people voicing their opinions, of those actions.
- CKN23-ARIN 7y ago> However, you are not the king of open source I am, however, the king of my own computer, and this software does not respect my sovereignty.
- urthen 7y agoLike I said - if it matters to you, don't use it. I've never had a problem with people that have extremely strict views of privacy. In fact I usually think they're right. But it's incredibly impractical, and most people don't currently care, which is the real problem. Treating relatively trivial things like this as if it were some conspiracy on behalf of the surveillance state doesn't do anything to get people to listen. Get people to start dropping Facebook and Google, then we can start tackling the smaller offenses like this. Until then, treating this like you're going up against the NSA is a vanity exercise.
- catalogia 7y ago> "Like I said - if it matters to you, don't use it." Or he can do one better: Not use it and publicly criticize it.
- sjwright 7y agoThat’s not “better”, in fact it’s not really in the spirit of open source, where criticism comes in the form of patches and forks. “Doing one better” would be patching and compiling from source yourself. Better still would be maintaining an up-to-date fork for the benefit of other like-minded people.
- sneak 7y agoOk, I'll bite. Open source is a hacker thing. Hackers like open source because it avoids useless duplication of effort, which is toilsome and wasteful. Hackers don't like toil and unnecessary waste. Forks are nothing but otherwise-unnecessary waste. They become necessary through asshattery like spying on users, but they are a last resort, because everything else about a fork is antithetical to most hackers: it's boring, wasteful, duplicated work, induced solely by an unreasonable upstream. We try a lot of things before we fork, including naming and shaming.
- squeaky-clean 7y agoPlease don't make the "Don't use atom then" argument in response to someone sharing unexpected info about Atom. No one is saying that they are being forced to use Atom. They are sharing info others may not know about Atom. You're saying "Don't use Atom", but what you're implying is "Don't talk about Atom"
- taneq 7y agoHow are you meant to know about this a priori unless you've read an article about it on an obscure tech website?
- edoceo 7y agoUse strace on every process? Inspect all code that ever runs on your boxen? Those work but, I still prefer the canary-article. Much easier.
- taneq 7y agoWhat'd be really nice is transparent, built-in sandboxing of every non-system application by the OS. The desktop security model of "protect your files from other users but not from applications you run" is horribly outdated.
- rossmohax 7y agoflatpack on Linux has all ingredients to enforce such sandboxing
- matheusmoreira 7y agoOn top of all that, we also need deep packet inspection and filtering. All the data flowing into and out of the sandbox must be inspected while in the clear by filtering software under our control. If the packet is known to contain nothing but a unique identifier for tracking, it gets blocked. If it also contains useful data, the identifier is either deleted or anonymized before the packet goes through. ISPs, companies and governments can do it for surveillance, censorship and security reasons. We should be able to do it too in order to empower ourselves.