Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #10341 > unrolled thread

Inquiry regarding Debian's Main Archive

Started bynpdflr <npdflr@zoho.com>
First post2019-02-25 10:20 +0100
Last post2019-02-25 12:10 +0100
Articles 5 — 3 participants

Back to article view | Back to linux.debian.project


Contents

  Inquiry regarding Debian's Main Archive npdflr <npdflr@zoho.com> - 2019-02-25 10:20 +0100
    Re: Inquiry regarding Debian's Main Archive Joerg Jaspert <joerg@debian.org> - 2019-02-25 11:20 +0100
      Re: Further inquiry regarding data privacy Joerg Jaspert <joerg@debian.org> - 2019-02-27 22:10 +0100
        Re: Further inquiry regarding data privacy (for packages installed  in Debian) npdflr <npdflr@zoho.com> - 2019-05-21 16:20 +0200
    Re: Inquiry regarding Debian's Main Archive Yao Wei <mwei@debian.org> - 2019-02-25 12:10 +0100

#10341 — Inquiry regarding Debian's Main Archive

Fromnpdflr <npdflr@zoho.com>
Date2019-02-25 10:20 +0100
SubjectInquiry regarding Debian's Main Archive
Message-ID<xvkAx-77-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi,

I have gone through the link: (Exploring Cryptographic Software in Debian's Main Archive)  https://www.debian.org/legal/cryptoinmain



I would like to clarify what I have understood: one is not allowed to use Debian's main archive for commercial use (as it contains community source) if one is downloading Debian from a US server.



In my case: I have downloaded a Debian iso cd file (debian-9.8.0-amd64-xfce-CD-1.iso) from a Singapore server and I want to use Debian on my laptop which will be used for commercial purpose, am I allowed to do so?. (Please note I am just using Debian not distributing/selling any of the Debian iso file or packages.)



Thank you.

[toc] | [next] | [standalone]


#10342

FromJoerg Jaspert <joerg@debian.org>
Date2019-02-25 11:20 +0100
Message-ID<xvlwB-Gz-5@gated-at.bofh.it>
In reply to#10341
On 15324 March 1977, npdflr@zoho.com wrote:

> I have gone through the link: (Exploring Cryptographic Software in
> Debian's Main Archive)  https://www.debian.org/legal/cryptoinmain

> I would like to clarify what I have understood: one is not allowed to
> use Debian's main archive for commercial use (as it contains community
> source) if one is downloading Debian from a US server.

I don't think thats the right takeaway from that.

> In my case: I have downloaded a Debian iso cd file
> (debian-9.8.0-amd64-xfce-CD-1.iso) from a Singapore server and I want
> to use Debian on my laptop which will be used for commercial purpose,
> am I allowed to do so?. (Please note I am just using Debian not
> distributing/selling any of the Debian iso file or packages.)

You are fine to do so.

As long as you just "use the laptop with Debian on it" for doing your
business, there is no constraint at all attached. Have fun.

If your business happens to be one of selling Debian, a modified version
of it, or just parts from the software you find in Debian, then further
terms may apply, which you can find in the copyright files coming with
the software. Still, its usually not forbidden to use for commercial
use, but requires to fulfill certain points (like providing source,
patches, ... - depending on the exact involved licenses).

-- 
bye, Joerg

[toc] | [prev] | [next] | [standalone]


#10347 — Re: Further inquiry regarding data privacy

FromJoerg Jaspert <joerg@debian.org>
Date2019-02-27 22:10 +0100
SubjectRe: Further inquiry regarding data privacy
Message-ID<xweCK-3E1-1@gated-at.bofh.it>
In reply to#10342
On 15326 March 1977, npdflr@zoho.com wrote:

> I am posting an excerpt from the 'Data privacy' page
> (https://www.debian.org/legal/privacy):

> Service related logging

> In addition to the explicitly listed services above the Debian
> infrastructure logs details about system accesses for the purposes of
> ensuring service availability and reliability, and to enable debugging
> and diagnosis of issues when they arise. This logging includes details
> of mails sent/received through Debian infrastructure, web page access
> requests sent to Debian infrastructure, and login information for
> Debian systems (such as SSH logins to project machines). None of this
> information is used for any purposes other than operational
> requirements and it is only stored for 15 days in the case of web
> server logs, 10 days in the case of mail log and 4 weeks in the case
> of authentication/ssh logs.

> a) Does 'system' and 'Debian systems' in the above excerpt mean an
> installation of Debian OS?

No. It means a system installed and run by Debian admins providing a
service. Like the machine handling this list, or a machine handling a
webserver for www.debian.org.

> b) I am assuming that 'Debian infrastructure' means the 'Debian
> Security Infrastructure'
> (https://www.debian.org/doc/manuals/securing-debian-howto/ch7) which
> is used to handle security in the stable distribution. Please correct
> me, if wrong. 

No, it means the whole infrastructure. We have many machines.

> c) Details regarding non-personally identifiable data: Does Debian
> (Debian.org) collect any kind of 'telemetry' or 'monitoring data'
> other than required for operational requirements? I am asking this as
> from a company's or business point of view: one is concerned about
> intellectual property, company data etc.

As written, no we do not.

> d) (This is related to the above point) Does the statement in the
> above excerpt "This logging includes details.....    login information
> for Debian systems" mean that Debian stores username and passwords of
> users? In my case: A local login not a network based login.

Not in the sense you read into it, no. We do not, in any way, collect
users data of systems installed with Debian[1]. The above is for machines
running "inside" the debian.org domain and affects Debian Developers,
not any user who just happens to install Debian.


[1] There is one tool named popcon. That does actually send data our
way. That is opt-in and you can find more information at
https://popcon.debian.org/

-- 
bye, Joerg

[toc] | [prev] | [next] | [standalone]


#10481 — Re: Further inquiry regarding data privacy (for packages installed in Debian)

Fromnpdflr <npdflr@zoho.com>
Date2019-05-21 16:20 +0200
SubjectRe: Further inquiry regarding data privacy (for packages installed in Debian)
Message-ID<y0dMu-741-1@gated-at.bofh.it>
In reply to#10347

[Multipart message — attachments visible in raw view] — view raw

Hi,

Would you recommend me or debian users to go through privacy policy for the default packages/softwares installed in Debian images/iso files.



An example would be the firefox-esr that has data collection policy: https://wiki.mozilla.org/Firefox/Data_Collection

The default is off for Web activity data and Highly Sensitive data so it should not be a problem.



But for other default packages should I go through their privacy policies?

 
Note: As for the packages installed manually by the user (not default packages), it would be the user's responsibity to make sure that they don't send any sensitive data.



Also, what ways can one check the privacy policy of the packages installed (by default or manually installed)?

- One way  would be to open Synaptic Package Manager (for the packages installed from the repositories listed in sources.list), check for homepage (if there) for every package installed and then read the privacy policy on that homepage.

- For the packages downloaded from elsewhere, I think the user would have to check the source/homepage etc for its privacy policy.


Thank you.





---- On Wed, 27 Feb 2019 13:02:28 -0800 Joerg Jaspert <joerg@debian.org> wrote ----



On 15326 March 1977, mailto:npdflr@zoho.com wrote: 
 
> I am posting an excerpt from the 'Data privacy' page 
> (https://www.debian.org/legal/privacy): 
 
> Service related logging 
 
> In addition to the explicitly listed services above the Debian 
> infrastructure logs details about system accesses for the purposes of 
> ensuring service availability and reliability, and to enable debugging 
> and diagnosis of issues when they arise. This logging includes details 
> of mails sent/received through Debian infrastructure, web page access 
> requests sent to Debian infrastructure, and login information for 
> Debian systems (such as SSH logins to project machines). None of this 
> information is used for any purposes other than operational 
> requirements and it is only stored for 15 days in the case of web 
> server logs, 10 days in the case of mail log and 4 weeks in the case 
> of authentication/ssh logs. 
 
> a) Does 'system' and 'Debian systems' in the above excerpt mean an 
> installation of Debian OS? 
 
No. It means a system installed and run by Debian admins providing a 
service. Like the machine handling this list, or a machine handling a 
webserver for www.debian.org. 
 
> b) I am assuming that 'Debian infrastructure' means the 'Debian 
> Security Infrastructure' 
> (https://www.debian.org/doc/manuals/securing-debian-howto/ch7) which 
> is used to handle security in the stable distribution. Please correct 
> me, if wrong.  
 
No, it means the whole infrastructure. We have many machines. 
 
> c) Details regarding non-personally identifiable data: Does Debian 
> (Debian.org) collect any kind of 'telemetry' or 'monitoring data' 
> other than required for operational requirements? I am asking this as 
> from a company's or business point of view: one is concerned about 
> intellectual property, company data etc. 
 
As written, no we do not. 
 
> d) (This is related to the above point) Does the statement in the 
> above excerpt "This logging includes details.....    login information 
> for Debian systems" mean that Debian stores username and passwords of 
> users? In my case: A local login not a network based login. 
 
Not in the sense you read into it, no. We do not, in any way, collect 
users data of systems installed with Debian[1]. The above is for machines 
running "inside" the debian.org domain and affects Debian Developers, 
not any user who just happens to install Debian. 
 
 
[1] There is one tool named popcon. That does actually send data our 
way. That is opt-in and you can find more information at 
https://popcon.debian.org/ 
 
-- 
bye, Joerg

[toc] | [prev] | [next] | [standalone]


#10343

FromYao Wei <mwei@debian.org>
Date2019-02-25 12:10 +0100
Message-ID<xvmj0-1cu-11@gated-at.bofh.it>
In reply to#10341

[Multipart message — attachments visible in raw view] — view raw

On Mon, Feb 25, 2019 at 12:58:50AM -0800, npdflr wrote:
> I have gone through the link: (Exploring Cryptographic Software in
> Debian's Main Archive)  https://www.debian.org/legal/cryptoinmain
> 
> I would like to clarify what I have understood: one is not allowed to
> use Debian's main archive for commercial use (as it contains community
> source) if one is downloading Debian from a US server.
> 
> In my case: I have downloaded a Debian iso cd file
> (debian-9.8.0-amd64-xfce-CD-1.iso) from a Singapore server and I want
> to use Debian on my laptop which will be used for commercial purpose,
> am I allowed to do so?. (Please note I am just using Debian not
> distributing/selling any of the Debian iso file or packages.)

Hi,

(IANAL; THIS IS NOT A LEGAL ADVICE.)

The article you are referencing was to deal with the US law of exporting
cryptographic code.  The export control is less strict now, and we don't
have separated ISOs for US and non-US anymore since Debian 3.1 (sarge),
which was released in 2005.

  https://wiki.debian.org/non-US

Yao Wei

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.project


csiph-web