Hacker News new | past | comments | ask | show | jobs | submit login

...without consent or opt-in.



Because most other websites/services ask for consent for their analytics?


Important consideration: homebrew is neither a website nor a service. It is a local software, a package manager, and quietly enabling phone-home analytics in an update after previously not doing such has a different threshold for “informed consent”.


How exactly is Homebrew not a service? We donate hours of work each week in an honest effort to make the best package manager we can for our users. Analytics help us decide how to prioritize our work.

It’s also literally the opposite of quietly enabled [1] [2].

[1] https://github.com/Homebrew/brew/blob/e32c1515432a938093d5ef...

[2] https://docs.brew.sh/Analytics


> How exactly is Homebrew not a service?

Is youtube-dl a service because it needs to be constantly updated, at great effort, to deal with new countermeasures and the like? Still looks like software to me.

If you were running the software for me (e.g. Gmail), then maybe Homebrew would qualify as a service.

> It’s also literally the opposite of quietly enabled

I discovered it when my firewall showed me an outbound connection to Google analytics. Homebrew spews so much stuff to the console, it's not something a regular user would read unless they looked for it. That was hardly sufficient disclosure.

You guys could have prompted for consent. You didn't. You still refuse to. And you won't entertain any suggestions that you do so unless it comes from a contributor. As I said in my original comment, your collective lack of judgement and refusal to consider the opinions of users is why I don't find you guys to be trustworthy anymore. I encourage everyone to find alternatives.


> If you were running the software for me

I’m not sure on whose systems you believe packages are built and tested, and from whose systems you feel Homebrew downloads bottles.

> it's not something a regular user would read unless they looked for it. That was hardly sufficient disclosure.

That notice was colored, it was typeset in bold, it was surrounded by newlines, and it sounded an audible bell. Blaming Homebrew for the fact that you missed that message says more about you than about Homebrew.


> I’m not sure on whose systems you believe packages are built and tested, and from whose systems you feel Homebrew downloads bottles.

Is Ubuntu a service because Canonical builds and tests packages and hosts package repositories? I don't think many people would make that claim.

> That notice was colored, it was typeset in bold, it was surrounded by newlines, and it sounded an audible bell.

That's not the notice I got.

"Anonymous aggregate user behaviour analytics documentation: https://git.io/brew-analytics". No bold. No bell.

The notice you linked to was added in reaction to the outcry. The bold and bell were added at a later date.

The Homebrew maintainers continue to refuse to do the only ethical thing and PROMPT THE USER instead of making assumptions one way or another.


"Because everyone else does it" isn't a very good excuse.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: