Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #209763 > unrolled thread
| Started by | npdflr <npdflr@zoho.com> |
|---|---|
| First post | 2019-06-08 20:10 +0200 |
| Last post | 2019-06-10 13:20 +0200 |
| Articles | 13 — 6 participants |
Back to article view | Back to linux.debian.user
Privacy policy of packages/softwares installed in Debian npdflr <npdflr@zoho.com> - 2019-06-08 20:10 +0200
Re: Privacy policy of packages/softwares installed in Debian Jean-Philippe MENGUAL <jpmengual@debian.org> - 2019-06-09 14:50 +0200
Re: Privacy policy of packages/softwares installed in Debian npdflr <npdflr@zoho.com> - 2019-06-10 09:30 +0200
Re: Privacy policy of packages/softwares installed in Debian <tomas@tuxteam.de> - 2019-06-10 10:20 +0200
Re: Privacy policy of packages/softwares installed in Debian Gene Heskett <gheskett@shentel.net> - 2019-06-10 12:50 +0200
Re: Privacy policy of packages/softwares installed in Debian <tomas@tuxteam.de> - 2019-06-10 17:20 +0200
Re: Privacy policy of packages/softwares installed in Debian Gene Heskett <gheskett@shentel.net> - 2019-06-10 18:30 +0200
Re: Privacy policy of packages/softwares installed in Debian John Hasler <jhasler@newsguy.com> - 2019-06-10 19:10 +0200
Re: Privacy policy of packages/softwares installed in Debian Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-10 19:40 +0200
Re: Privacy policy of packages/softwares installed in Debian npdflr <npdflr@zoho.com> - 2019-06-14 08:30 +0200
Re: Privacy policy of packages/softwares installed in Debian npdflr <npdflr@zoho.com> - 2019-06-23 11:10 +0200
Re: Privacy policy of packages/softwares installed in Debian Gene Heskett <gheskett@shentel.net> - 2019-06-10 19:40 +0200
Re: Privacy policy of packages/softwares installed in Debian Jean-Philippe MENGUAL <jpmengual@debian.org> - 2019-06-10 13:20 +0200
| From | npdflr <npdflr@zoho.com> |
|---|---|
| Date | 2019-06-08 20:10 +0200 |
| Subject | Privacy policy of packages/softwares installed in Debian |
| Message-ID | <y6NWV-7u0-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hello, How can one check the privacy policy for the packages/softwares (which can be free or non-free) installed in Debian? If one is downloading and installing a package from a website then he/she can check the privacy policy link on that website. Example: -- Skype (https://www.skype.com/en/get-skype/) which has privacy policy: https://privacy.microsoft.com/en-US/privacystatement -- Go programming language (https://golang.org/) which has privacy policy: https://policies.google.com/privacy?hl=en But if one is downloading a package (which may also install dependency packages) via terminal or synaptic package manager then how can one check the privacy policy of that package? Thank you.
[toc] | [next] | [standalone]
| From | Jean-Philippe MENGUAL <jpmengual@debian.org> |
|---|---|
| Date | 2019-06-09 14:50 +0200 |
| Message-ID | <y75qN-Q6-1@gated-at.bofh.it> |
| In reply to | #209763 |
[Multipart message — attachments visible in raw view] — view raw
Hi, Privacy policy makes sense for software you quote, eithr because they are closd-code, or because thy are in the cloud and users send data to servers, so it is important to know what do this data once sent. Debian provides free software and does not support non-free one even if they exist in the Debian infra. They provide tools to be installed on your computer. So when you install a program in Debian, you can check the code, but more important, you dont send data to an external source. Then I dont think Debian needs a privacy policy. Neither Debian, nor the packages themselves collect the user data. And it would be a problem to do this, from the socail contract. I think we can consider having a thought about it if some program collects data. For a non free program, this should be in its licene or on th websie of its provider. Regards Jean-Philippe MENGUAL Le 08/06/2019 à 20:02, npdflr a écrit : > Hello, > How can one check the privacy policy for the packages/softwares (which > can be free or non-free) installed in Debian? > > If one is downloading and installing a package from a website then > he/she can check the privacy policy link on that website. > Example: > -- Skype (https://www.skype.com/en/get-skype/) which has privacy > policy: https://privacy.microsoft.com/en-US/privacystatement > -- Go programming language (https://golang.org/) which has privacy > policy: https://policies.google.com/privacy?hl=en > > But if one is downloading a package (which may also install dependency > packages) via terminal or synaptic package manager then how can one > check the privacy policy of that package? > > Thank you. >
[toc] | [prev] | [next] | [standalone]
| From | npdflr <npdflr@zoho.com> |
|---|---|
| Date | 2019-06-10 09:30 +0200 |
| Message-ID | <y7mUF-2VX-1@gated-at.bofh.it> |
| In reply to | #209773 |
[Multipart message — attachments visible in raw view] — view raw
Thanks Jean for your reply.
Non-free packages should definitely be checked with their privacy policy. But what about free packages?
The license for the Go programming language is https://golang.org/LICENSE which is free but the privacy policy is invasive https://policies.google.com/privacy?hl=en
(Note: it also has a patent file with some restrictions which can make the package non-free perhaps, would give more details if required)
Free networking applications like browsers, p2p applications etc would definitely require internet but other free apps also connect with the internet automatically when starting for the first time (Eg: aseprite, libreoffice) or when checking for updates. One can know this via an application-based firewall.
Free packages are available via main repositories (through terminal apt commands or a package manager) and also via
other ways like websites, terminal commands like wget, curl etc, offline archive files
etc.
Would you say that all free packages via main repositories and via other ways (after checking their license to be DFSG-compliant) can be safely be allowed to connect to the internet?
Thanks.
---- On Sun, 09 Jun 2019 05:49:01 -0700 Jean-Philippe MENGUAL <mailto:jpmengual@debian.org> wrote ----
Hi,
Privacy policy makes sense for software you quote, eithr because
they are closd-code, or because thy are in the cloud and users send
data to servers, so it is important to know what do this data once
sent.
Debian provides free software and does not support non-free one even
if they exist in the Debian infra. They provide tools to be
installed on your computer. So when you install a program in Debian,
you can check the code, but more important, you dont send data to an
external source.
Then I dont think Debian needs a privacy policy. Neither Debian, nor
the packages themselves collect the user data. And it would be a
problem to do this, from the socail contract.
I think we can consider having a thought about it if some program
collects data. For a non free program, this should be in its licene
or on th websie of its provider.
Regards
Jean-Philippe MENGUAL
Le 08/06/2019 à 20:02, npdflr a écrit :
Hello,
How can one check the privacy policy for the
packages/softwares (which can be free or non-free) installed
in Debian?
If one is downloading and installing a package from a
website then he/she can check the privacy policy link on that
website.
Example:
-- Skype (https://www.skype.com/en/get-skype/)
which has privacy policy: https://privacy.microsoft.com/en-US/privacystatement
-- Go programming language (https://golang.org/)
which has privacy policy: https://policies.google.com/privacy?hl=en
But if one is downloading a package (which may also install
dependency packages) via terminal or synaptic package manager
then how can one check the privacy policy of that package?
Thank you.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-10 10:20 +0200 |
| Message-ID | <y7nH3-3rl-5@gated-at.bofh.it> |
| In reply to | #209786 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Jun 10, 2019 at 12:08:04AM -0700, npdflr wrote: > Thanks Jean for your reply. > > Non-free packages should definitely be checked with their privacy policy. But what about free packages? Agreed. > The license for the Go programming language is https://golang.org/LICENSE which is free but the privacy policy is invasive https://policies.google.com/privacy?hl=en This is, at least, debatable. Go deems itself independent from Google (formally it is; whether it is "de facto" is a much more difficult question). > Would you say that all free packages via main repositories and via other ways (after checking their license to be DFSG-compliant) can be safely be allowed to connect to the internet? This is a very good question, and I think there's no clear-cut answer to it. When Debian and its Social Contract [0] were conceived, the focus was more on giving end users power through free software. Nowadays free software has "won" (of sorts), but the lines of conflict have shifted to a more subtle "place". Most of the software a Facebook user is in contact with is somehow "free". Heck, FB is one important contributor to the Linux kernel. But... would you say a FB user controls his/her use of FB? Tough call. To illustrate the point you made a bit better, I've seen Google beacons embedded in the Javascript included in free packages[1]. Free but... privacy respecting? Up to debate. You can help making Debian better by trying to find such things and reporting them as bugs. I think most Debian maintainers would agree that those go against the spirit of the Social Contract [0]. Cheers [0] https://www.debian.org/social_contract [1] In one case, a web app testing package, there was even a comment in there "please, leave this in, since that's how we make money", so the inclusion was not an accident. In the other case, it was in a Debian package -- this one has disappeared since, otherwise I'd have filed a bug report. -- tomás
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-10 12:50 +0200 |
| Message-ID | <y7q2d-4H2-1@gated-at.bofh.it> |
| In reply to | #209788 |
On Monday 10 June 2019 04:11:54 am tomas@tuxteam.de wrote: > On Mon, Jun 10, 2019 at 12:08:04AM -0700, npdflr wrote: > > Thanks Jean for your reply. > > > > Non-free packages should definitely be checked with their privacy > > policy. But what about free packages? > > Agreed. > > > The license for the Go programming language is > > https://golang.org/LICENSE which is free but the privacy policy is > > invasive https://policies.google.com/privacy?hl=en > > This is, at least, debatable. Go deems itself independent from Google > (formally it is; whether it is "de facto" is a much more difficult > question). > > > Would you say that all free packages via main repositories and via > > other ways (after checking their license to be DFSG-compliant) can > > be safely be allowed to connect to the internet? > > This is a very good question, and I think there's no clear-cut > answer to it. When Debian and its Social Contract [0] were conceived, > the focus was more on giving end users power through free software. > > Nowadays free software has "won" (of sorts), but the lines of > conflict have shifted to a more subtle "place". Most of the software > a Facebook user is in contact with is somehow "free". Heck, FB is > one important contributor to the Linux kernel. But... would you say > a FB user controls his/her use of FB? Tough call. > > To illustrate the point you made a bit better, I've seen Google > beacons embedded in the Javascript included in free packages[1]. > > Free but... privacy respecting? Up to debate. I'm not a maintainer, just a user. And a instance of the above should result in the instant moving of that package into the non-free category. And put a link to a readme explaining why its contamination by such tracking code has caused its status to be changed, and moved, in the former packages location. Only by pointing it out to the potential user, will such code eventually be removed. I think debian needs to make that an upfront declaration and enforce it. Any "hardware" surveys, which seem to be more invasive than ever these days, should pop up a requester for some sort of plainly stated permission before the results are sent "home". Any form of no should result in sending that data to /dev/null. > You can help making Debian better by trying to find such things > and reporting them as bugs. I think most Debian maintainers would > agree that those go against the spirit of the Social Contract [0]. Yes, absolutely. I do not think debian could be said to have been harmed by such an action a year later. > Cheers > [0] https://www.debian.org/social_contract > > [1] In one case, a web app testing package, there was even a > comment in there "please, leave this in, since that's how > we make money", so the inclusion was not an accident. In > the other case, it was in a Debian package -- this one has > disappeared since, otherwise I'd have filed a bug report. > > -- tomás Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-10 17:20 +0200 |
| Message-ID | <y7ufw-7kv-5@gated-at.bofh.it> |
| In reply to | #209791 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Jun 10, 2019 at 06:43:17AM -0400, Gene Heskett wrote: [...] > I'm not a maintainer, just a user. > > And a instance of the above should result in the instant moving of that > package into the non-free category. And put a link to a readme > explaining why its contamination by such tracking code has caused its > status to be changed, and moved, in the former packages location. Normally a maintainer just removes such a nasty -- that's what the Debian-specific patches are for. But first you have to find it. Just imagine yourself as a maintainer of (say) 5 packages, 500k lines of code each. In your free time. Getting an update every 2 months each. Do you go with a fine comb over each and every changed line of code each time? That's why our maintainers need help. Just saying "Debian Should" is not enough help :-) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-10 18:30 +0200 |
| Message-ID | <y7vlg-7VT-3@gated-at.bofh.it> |
| In reply to | #209799 |
On Monday 10 June 2019 11:17:04 am tomas@tuxteam.de wrote: > On Mon, Jun 10, 2019 at 06:43:17AM -0400, Gene Heskett wrote: > > [...] > > > I'm not a maintainer, just a user. > > > > And a instance of the above should result in the instant moving of > > that package into the non-free category. And put a link to a readme > > explaining why its contamination by such tracking code has caused > > its status to be changed, and moved, in the former packages > > location. > > Normally a maintainer just removes such a nasty -- that's what the > Debian-specific patches are for. But first you have to find it. > > Just imagine yourself as a maintainer of (say) 5 packages, 500k lines > of code each. In your free time. Getting an update every 2 months > each. > > Do you go with a fine comb over each and every changed line of code > each time? > > That's why our maintainers need help. Just saying "Debian Should" is > not enough help :-) > All of that I'm well aware of Tomas. So yes "should" is a bit stronger sounding than I intended. But at my thinkers age, I'd like to think I have sense enough left to know my limits. So I ask. I am behind the curve of any modern language, even bash scripts I wrote 10 years ago can be a puzzle when they miss-fire until I've mentally stepped thru them several times. Its even personally embarrassing if when I find the why, and wonder WIH did I do it that way? > Cheers > -- t Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2019-06-10 19:10 +0200 |
| Message-ID | <y7vXY-8oa-7@gated-at.bofh.it> |
| In reply to | #209801 |
Gene writes: > All of that I'm well aware of Tomas. So yes "should" is a bit stronger > sounding than I intended. But at my thinkers age, I'd like to think I > have sense enough left to know my limits. So I ask. I am behind the > curve of any modern language, even bash scripts I wrote 10 years ago > can be a puzzle when they miss-fire until I've mentally stepped thru > them several times. Its even personally embarrassing if when I find > the why, and wonder WIH did I do it that way? Programming adage: Never make your code so clever that you can just barely understand it yourself because *you* will have to understand it in the future and you won't be this clever then. On the other hand "What idiot designed this? Oh. It was me." is an ordinary engineering experience. You can help the maintainers by running Unstable or Testing and filing bug reports. -- John Hasler jhasler@newsguy.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-06-10 19:40 +0200 |
| Message-ID | <y7wqZ-5U-1@gated-at.bofh.it> |
| In reply to | #209802 |
On Mon, Jun 10, 2019 at 01:33:14PM -0400, Gene Heskett wrote: > > You can help the maintainers by running Unstable or Testing and filing > > bug reports. > > Is there a URL to aid that upgrade? Or is it a start with a new drive & > iso image? I'm in favor of operational continuity, if it can be had. Most of the time, the only supported method is to install (or upgrade to) stable, and then upgrade to testing or unstable. The steps for that are typically "edit sources.list, and then run apt update, and then run apt full-upgrade", although the exact state of testing or unstable at any given moment may require additional steps. Right now, as we approach a new release, there may be an option to attempt a direct installation of buster (currently testing) using a buster install image. Doing so serves as an additional test of the buster installer, which is far more likely to have show-stopping bugs than buster itself is. https://wiki.debian.org/DebianTesting
[toc] | [prev] | [next] | [standalone]
| From | npdflr <npdflr@zoho.com> |
|---|---|
| Date | 2019-06-14 08:30 +0200 |
| Message-ID | <y8NSN-5MZ-1@gated-at.bofh.it> |
| In reply to | #209803 |
[Multipart message — attachments visible in raw view] — view raw
---- On Mon, 10 Jun 2019 04:14:59 -0700 Jean-Philippe MENGUAL <mailto:jpmengual@debian.org> wrote ---- > One thing seems sure, Debian will never have a privacy policy, I think, > but maaybe may request any package (or some packages) to include a > PRIVACY file. Should require to change the Debian maintainer and dev policy. I had inquired for privacy policy of Debian in general, before on the mailing list: mailto:debian-project@lists.debian.org. (I couldn't help but inquire as there is so much "telemetry" ... etc used by some operating systems to monitor user data) Except for the popcon tool which is opt-in, Debian doesn't collect any user data. I am posting the conversation I had, incase it seems to be relevant to the current topic for packages. #---------------------------------------------------------------------------------------------------------------------------------------------# ---- On Wed, 27 Feb 2019 13:02:28 -0800 Joerg Jaspert <mailto:joerg@debian.org> wrote ---- On 15326 March 1977, mailto:npdflr@zoho.com wrote: > I am posting an excerpt from the 'Data privacy' page > (https://www.debian.org/legal/privacy): > Service related logging > In addition to the explicitly listed services above the Debian > infrastructure logs details about system accesses for the purposes of > ensuring service availability and reliability, and to enable debugging > and diagnosis of issues when they arise. This logging includes details > of mails sent/received through Debian infrastructure, web page access > requests sent to Debian infrastructure, and login information for > Debian systems (such as SSH logins to project machines). None of this > information is used for any purposes other than operational > requirements and it is only stored for 15 days in the case of web > server logs, 10 days in the case of mail log and 4 weeks in the case > of authentication/ssh logs. > a) Does 'system' and 'Debian systems' in the above excerpt mean an > installation of Debian OS? No. It means a system installed and run by Debian admins providing a service. Like the machine handling this list, or a machine handling a webserver for http://www.debian.org. > b) I am assuming that 'Debian infrastructure' means the 'Debian > Security Infrastructure' > (https://www.debian.org/doc/manuals/securing-debian-howto/ch7) which > is used to handle security in the stable distribution. Please correct > me, if wrong. No, it means the whole infrastructure. We have many machines. > c) Details regarding non-personally identifiable data: Does Debian > (Debian.org) collect any kind of 'telemetry' or 'monitoring data' > other than required for operational requirements? I am asking this as > from a company's or business point of view: one is concerned about > intellectual property, company data etc. As written, no we do not. > d) (This is related to the above point) Does the statement in the > above excerpt "This logging includes details..... login information > for Debian systems" mean that Debian stores username and passwords of > users? In my case: A local login not a network based login. Not in the sense you read into it, no. We do not, in any way, collect users data of systems installed with Debian[1]. The above is for machines running "inside" the debian.org domain and affects Debian Developers, not any user who just happens to install Debian. [1] There is one tool named popcon. That does actually send data our way. That is opt-in and you can find more information at https://popcon.debian.org/ -- bye, Joerg #---------------------------------------------------------------------------------------------------------------------------------------------# ---- On Mon, 10 Jun 2019 01:11:54 -0700 <mailto:tomas@tuxteam.de> wrote ---- >> Would you say that all free packages via main repositories and via other ways (after checking their license to be DFSG-compliant) can be safely be allowed to connect to the internet? > This is a very good question, and I think there's no clear-cut > answer to it. When Debian and its Social Contract [0] were conceived, > the focus was more on giving end users power through free software. I'll just focus only on free packages available via 'Official Debian' main repositories. The free packages in Official Debian main repositories can be categorized as 1. Default (already installed and available for use after installing Debian via an official Debian image/iso) 2. Available for manual download and installation. I think the default packages build/represent the Debian operating system and would also represent Debian's privacy policy in general. So, there should not be any problem regarding privacy atleast for the default packages. As for the free packages available for manual download and installation via Official Debian main repositories, it should also represent Debian's privacy policy in general but I am not sure (hoping someone can clarify). One way to check for privacy policy of such packages would be to check whether the package in synaptic package manager has a homepage link to know it's website/source. Suggestion: It would be great if there is a regulation adopted to have a privacy policy for packages available via Official Debian main repositories. Again, I am talking only about Official Debian main repositories not about non-free repositories or even other main repositories which maybe out of scope of Debian. An example of such a regulation is Mozilla addon policy which states: "You must disclose how the add-on collects, uses, stores and shares user data in the privacy policy field on AMO (addons.mozilla.org)" (Link: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/AMO/Policy/Reviews#Data_Disclosure_Collection_and_Management) Thank you.
[toc] | [prev] | [next] | [standalone]
| From | npdflr <npdflr@zoho.com> |
|---|---|
| Date | 2019-06-23 11:10 +0200 |
| Message-ID | <yc6Fz-4U4-3@gated-at.bofh.it> |
| In reply to | #209878 |
Hello, Any final inputs whether there is any need for specifying privacy policy somewhere for packages from only Offical Debian main repositories? What I am looking at (and maybe even some other users too) is simply to have a secure 'core' which can be utilised further to add more packages via other repositories, websites etc. Personally, I am using core = Debian OS with Official Debian main repositories, others can use core as something different. For having a privacy file for packages from locations other than Official Debian Main repositories, I think it would be a separate task which may or may not be important as it is separate from the 'core'. [Some examples of Official Debian main repositories: deb http://deb.debian.org/debian/ stable main deb http://deb.debian.org/debian/ stable-updates main deb http://deb.debian.org/debian-security stable/updates main] Regards.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-10 19:40 +0200 |
| Message-ID | <y7wqZ-5U-3@gated-at.bofh.it> |
| In reply to | #209802 |
On Monday 10 June 2019 01:00:58 pm John Hasler wrote: > Gene writes: > > All of that I'm well aware of Tomas. So yes "should" is a bit > > stronger sounding than I intended. But at my thinkers age, I'd like > > to think I have sense enough left to know my limits. So I ask. I > > am behind the curve of any modern language, even bash scripts I > > wrote 10 years ago can be a puzzle when they miss-fire until I've > > mentally stepped thru them several times. Its even personally > > embarrassing if when I find the why, and wonder WIH did I do it that > > way? > > Programming adage: Never make your code so clever that you can just > barely understand it yourself because *you* will have to understand it > in the future and you won't be this clever then. > Chuckle. Yessir. I used to do my coding in assembler, and later in C but that C was first edition, without the advanced bit twiddling since that target cpu's didn't have a barrel shifter. My targets started out with the rca 1802 in '78. Might have included the TI-9900 but the entry price was above my pay grade, so the majority of my code output ran on a 6809 or 6309 & still does. The 6x09's with PIC were a breath of fresh air, and cleared the way for a unix-like os called os9. When the 6309 was discovered I volunteered to rewrite a portion of that os to make it run faster. But all that was 40 to 30 years ago. > On the other hand "What idiot designed this? Oh. It was me." is an > ordinary engineering experience. Head slappers, John. Feels so good when you stop :) > You can help the maintainers by running Unstable or Testing and filing > bug reports. Is there a URL to aid that upgrade? Or is it a start with a new drive & iso image? I'm in favor of operational continuity, if it can be had. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Jean-Philippe MENGUAL <jpmengual@debian.org> |
|---|---|
| Date | 2019-06-10 13:20 +0200 |
| Message-ID | <y7qvf-55Y-7@gated-at.bofh.it> |
| In reply to | #209786 |
Hi, Do you know wether FSF or OSI has some tmplate, just like licnese examples, for such thing? With a tmplate, maybe Debian might accept to ship it to the packages like thy include COPYRIGHT, or displaying a screen to mention privacy policy. One thing seems sure, Debian will never have a privacy policy, I think, but maaybe may request any package (or some packages) to include a PRIVACY file. Should require to change the Debian maintainer and dev policy. Regards Regards, Jean-Philippe MENGUAL Le 10/06/2019 à 09:08, npdflr a écrit : > Thanks Jean for your reply. > > Non-free packages should definitely be checked with their privacy > policy. But what about free packages? > > The license for the Go programming language is > https://golang.org/LICENSE which is free but the privacy policy is > invasive https://policies.google.com/privacy?hl=en > (Note: it also has a patent file with some restrictions which can make > the package non-free perhaps, would give more details if required) > > Free networking applications like browsers, p2p applications etc would > definitely require internet but other free apps also connect with the > internet automatically when starting for the first time (Eg: aseprite, > libreoffice) or when checking for updates. One can know this via an > application-based firewall. > > Free packages are available via main repositories (through terminal apt > commands or a package manager) and also via other ways like websites, > terminal commands like wget, curl etc, offline archive files etc. > > Would you say that all free packages via main repositories and via other > ways (after checking their license to be DFSG-compliant) can be safely > be allowed to connect to the internet? > > Thanks. > > > ---- On Sun, 09 Jun 2019 05:49:01 -0700 *Jean-Philippe MENGUAL > <jpmengual@debian.org <mailto:jpmengual@debian.org>>* wrote ---- > > Hi, > > Privacy policy makes sense for software you quote, eithr because > they are closd-code, or because thy are in the cloud and users send > data to servers, so it is important to know what do this data once sent. > > Debian provides free software and does not support non-free one even > if they exist in the Debian infra. They provide tools to be > installed on your computer. So when you install a program in Debian, > you can check the code, but more important, you dont send data to an > external source. > > Then I dont think Debian needs a privacy policy. Neither Debian, nor > the packages themselves collect the user data. And it would be a > problem to do this, from the socail contract. > > I think we can consider having a thought about it if some program > collects data. For a non free program, this should be in its licene > or on th websie of its provider. > > Regards > > > > > Jean-Philippe MENGUAL > > Le 08/06/2019 à 20:02, npdflr a écrit : > > > Hello, > How can one check the privacy policy for the packages/softwares > (which can be free or non-free) installed in Debian? > > If one is downloading and installing a package from a website > then he/she can check the privacy policy link on that website. > Example: > -- Skype (https://www.skype.com/en/get-skype/) which has privacy > policy: https://privacy.microsoft.com/en-US/privacystatement > -- Go programming language (https://golang.org/) which has > privacy policy: https://policies.google.com/privacy?hl=en > > But if one is downloading a package (which may also install > dependency packages) via terminal or synaptic package manager > then how can one check the privacy policy of that package? > > Thank you. > > > > >
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web