raspberrypi / rpi-imager

The home of Raspberry Pi Imager, a user-friendly tool for creating bootable media for Raspberry Pi devices.
https://www.raspberrypi.com/software
Other
1.66k stars 253 forks source link

Security & Privacy: - Telemetry: phone back home. #413

Closed qkum closed 2 years ago

qkum commented 2 years ago

Privacy & Informative focused post:

Most people don't know that "locale" means the name of your PC/Device used to flash the SD card.

Quote from the 1.7.0 update:

Telemetry: phone back home when image from repository is written:
name and URL of image written, parent category.
about the computer running Imager: OS, version, architecture,
LOCALE, Imager version, Pi revision
qkum commented 2 years ago

What Raspberry Pi HQ needs our Device/PC name for, I would like to know btw.

It would be much more intelligent to give the App a unique identifying ID that is generated at installation.

The Essence: An unique App ID created at installation would not be in any of their databases (could be hashed) and you would still be able to know if it is the same Device/PC that installed Raspberry Pi OS 10 times in 2 hours, or 10 different people/devices, etc. Detect DDOS attacks etc. (the only legit reason you could, need/ask for, such private data)

It could change the App ID when the App is re-installed, Updated, or once a month?

Would be a 1000 times better way of doing it anyway.

I hope my rambling can be used for something constructive. Have a nice day

qkum commented 2 years ago

I know we don't have "anything to hide"

But that does not mean that we should let Big Tech know & track everything we do all year, so they in the end not just know us better than ourselves. And not just that, but also can predict everything we do,- before we know it ourselves.

And that day is closer than you think.

cp2004 commented 2 years ago

(disclaimer: not a RPi person, don't know what actually goes on in the RPi imager)

Isn't locale the language/location...? Nothing to do with the device name...

Eg. my locale would be en_GB.

qkum commented 2 years ago

(disclaimer: not a RPi person, don't know what actually goes on in the RPi imager)

Isn't locale the language/location...? Nothing to do with the device name...

Eg. my locale would be en_GB.

I came back to correct myself.

I Just fell over the "Raspberry Pi Imager Statistics" page just now and saw what "locale" means in this context.

Here is where I got my assumption of it in this context meaning the Device Name. sehasehsejhse