Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think this might be the winning argument. There may not be any meaningful reason for telemetry to outweigh the bad actors and damage they've done.

For me, i'd love to enable telemetry for some of my more liked, FOSS apps - but even with those my question immediately arises "What are you sending?".

Without someway to monitor, are they sending filenames? Are they sending file contents? How much is it? etcetc

To satisfy my questions i need some sort of router-enabled monitoring of all telemetry specific traffic. So i can individually approve types of info... and that seems difficult. But the days of blanket allowances from me are long gone due to the bad actors.



Excellent point. As a user, here are my requirements if you want me to opt into your data collection scheme:

1. All exfiltration of data must be under my direct control, each time it happens. You can collect all the data you want in the background, but any time it is transmitted to the company, I must give consent and issue a command to do it (or click a button).

2. All data that is exfiltrated must be described in detail before it is exfiltrated. "Diagnostic data" isn't good enough. List everything. Stack trace? Crash report? Memory dump? Personal info (list them all out)? Location information? Images (what are they, screenshots? from my camera?) Time stamps from each collection. If it's nebulous "feature usage data" then list each activity that is being logged (localized in my language). Lay them all out for me or I'm not going to press that Submit button.

3. I need to be able to verify that #2 is accurate, so save that dump to disk somewhere I can analyze later.

4. The identifiers used to submit this data should be disclosed. Is a unique user id required to upload? Do you link subsequent uploads to the same unique id? Is that id in any way associated with me as an account or as a person in your backend? I want you to disclose all of this.

5. For how long do you retain the data I sent? How is this enforced? Is there a way for me to delete the data? How can I ensure that the data gets deleted when I request it to be deleted?

6. Do you monetize the data in any way, and if so, am I entitled to compensation for it?

I don't know of many (if any) data collection schemes that meet this bar, yet.


I'm fairly sure Android crash reporting is all manually done, and even zips it up for you to inspect.

But some of these are impossible, e.g. how do you localize a stack trace?


If you install an app via Google Play, crash reporting & some telemetry are silent and enabled by default. This is in addition to any crash reporting built into the app.

https://support.google.com/accounts/answer/6078260




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: