Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. ⚠️ Github CLI now has telemetry spyware built in:

⚠️ Github CLI now has telemetry spyware built in:

Scheduled Pinned Locked Moved Uncategorized
privacyfossgithubcybersecuritysurveillance
35 Posts 20 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

    ⚠️ Github CLI now has telemetry spyware built in:

    Link Preview Image
    Telemetry

    Take GitHub to the command line

    favicon

    GitHub CLI (cli.github.com)

    They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

    Run `gh config set telemetry disabled` to disable it.

    #privacy #foss #github #cybersecurity #surveillance

    nuclearplayer@fosstodon.orgN This user is from outside of this forum
    nuclearplayer@fosstodon.orgN This user is from outside of this forum
    nuclearplayer@fosstodon.org
    wrote last edited by
    #3

    To disable:

    export GH_TELEMETRY=false

    export DO_NOT_TRACK=true

    gh config set telemetry disabled

    Each of these work individually too.

    stevenodb@mastodon.socialS jumile@mas.toJ 2 Replies Last reply
    0
    • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

      ⚠️ Github CLI now has telemetry spyware built in:

      Link Preview Image
      Telemetry

      Take GitHub to the command line

      favicon

      GitHub CLI (cli.github.com)

      They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

      Run `gh config set telemetry disabled` to disable it.

      #privacy #foss #github #cybersecurity #surveillance

      rocky1138@dosgame.clubR This user is from outside of this forum
      rocky1138@dosgame.clubR This user is from outside of this forum
      rocky1138@dosgame.club
      wrote last edited by
      #4

      @nuclearplayer don't use GitHub CLI

      1 Reply Last reply
      0
      • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

        ⚠️ Github CLI now has telemetry spyware built in:

        Link Preview Image
        Telemetry

        Take GitHub to the command line

        favicon

        GitHub CLI (cli.github.com)

        They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

        Run `gh config set telemetry disabled` to disable it.

        #privacy #foss #github #cybersecurity #surveillance

        sl007@digitalcourage.socialS This user is from outside of this forum
        sl007@digitalcourage.socialS This user is from outside of this forum
        sl007@digitalcourage.social
        wrote last edited by
        #5

        @nuclearplayer

        I asked @EUCommission multiple times how this can be legal ...
        I forgot their level of corruption so it is understandable that nobody answers there.

        1 Reply Last reply
        0
        • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

          ⚠️ Github CLI now has telemetry spyware built in:

          Link Preview Image
          Telemetry

          Take GitHub to the command line

          favicon

          GitHub CLI (cli.github.com)

          They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

          Run `gh config set telemetry disabled` to disable it.

          #privacy #foss #github #cybersecurity #surveillance

          i@toot.pouyan.netI This user is from outside of this forum
          i@toot.pouyan.netI This user is from outside of this forum
          i@toot.pouyan.net
          wrote last edited by
          #6

          @nuclearplayer@fosstodon.org I think the correct command is apt autoremove --purge gh.

          1 Reply Last reply
          0
          • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

            ⚠️ Github CLI now has telemetry spyware built in:

            Link Preview Image
            Telemetry

            Take GitHub to the command line

            favicon

            GitHub CLI (cli.github.com)

            They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

            Run `gh config set telemetry disabled` to disable it.

            #privacy #foss #github #cybersecurity #surveillance

            nieldk@infosec.exchangeN This user is from outside of this forum
            nieldk@infosec.exchangeN This user is from outside of this forum
            nieldk@infosec.exchange
            wrote last edited by
            #7

            @nuclearplayer lol

            $ gh config set telemetry disabled
            ! warning: 'telemetry' is not a known configuration key

            1 Reply Last reply
            0
            • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

              ⚠️ Github CLI now has telemetry spyware built in:

              Link Preview Image
              Telemetry

              Take GitHub to the command line

              favicon

              GitHub CLI (cli.github.com)

              They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

              Run `gh config set telemetry disabled` to disable it.

              #privacy #foss #github #cybersecurity #surveillance

              rootwyrm@weird.autosR This user is from outside of this forum
              rootwyrm@weird.autosR This user is from outside of this forum
              rootwyrm@weird.autos
              wrote last edited by
              #8

              @nuclearplayer my favorite part is how it has a hard-coded "oh god we'll get in so much trouble" killswitch if it detects a GHES token.

              1 Reply Last reply
              0
              • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                ⚠️ Github CLI now has telemetry spyware built in:

                Link Preview Image
                Telemetry

                Take GitHub to the command line

                favicon

                GitHub CLI (cli.github.com)

                They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

                Run `gh config set telemetry disabled` to disable it.

                #privacy #foss #github #cybersecurity #surveillance

                kkarhan@jorts.horseK This user is from outside of this forum
                kkarhan@jorts.horseK This user is from outside of this forum
                kkarhan@jorts.horse
                wrote last edited by
                #9

                @nuclearplayer or don't use their weird #CLI tool and instead go with their regular #API & #git that any decent #IDE can use…

                1 Reply Last reply
                0
                • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                  ⚠️ Github CLI now has telemetry spyware built in:

                  Link Preview Image
                  Telemetry

                  Take GitHub to the command line

                  favicon

                  GitHub CLI (cli.github.com)

                  They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

                  Run `gh config set telemetry disabled` to disable it.

                  #privacy #foss #github #cybersecurity #surveillance

                  danni_storm@hachyderm.ioD This user is from outside of this forum
                  danni_storm@hachyderm.ioD This user is from outside of this forum
                  danni_storm@hachyderm.io
                  wrote last edited by
                  #10

                  @nuclearplayer I've always been confused why people use gh instead of vanilla git.

                  iain@hachyderm.ioI 1 Reply Last reply
                  0
                  • danni_storm@hachyderm.ioD danni_storm@hachyderm.io

                    @nuclearplayer I've always been confused why people use gh instead of vanilla git.

                    iain@hachyderm.ioI This user is from outside of this forum
                    iain@hachyderm.ioI This user is from outside of this forum
                    iain@hachyderm.io
                    wrote last edited by
                    #11

                    @danni_storm the feature set is quite different https://cli.github.com/manual/gh

                    danni_storm@hachyderm.ioD 1 Reply Last reply
                    0
                    • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                      ⚠️ Github CLI now has telemetry spyware built in:

                      Link Preview Image
                      Telemetry

                      Take GitHub to the command line

                      favicon

                      GitHub CLI (cli.github.com)

                      They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

                      Run `gh config set telemetry disabled` to disable it.

                      #privacy #foss #github #cybersecurity #surveillance

                      tyil@fedi.tyil.nlT This user is from outside of this forum
                      tyil@fedi.tyil.nlT This user is from outside of this forum
                      tyil@fedi.tyil.nl
                      wrote last edited by
                      #12
                      @nuclearplayer@fosstodon.org
                      Run gh config set telemetry disabled to disable it.
                      Better yet, stop using Github!
                      1 Reply Last reply
                      0
                      • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                        ⚠️ Github CLI now has telemetry spyware built in:

                        Link Preview Image
                        Telemetry

                        Take GitHub to the command line

                        favicon

                        GitHub CLI (cli.github.com)

                        They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

                        Run `gh config set telemetry disabled` to disable it.

                        #privacy #foss #github #cybersecurity #surveillance

                        ringods@hachyderm.ioR This user is from outside of this forum
                        ringods@hachyderm.ioR This user is from outside of this forum
                        ringods@hachyderm.io
                        wrote last edited by
                        #13

                        @nuclearplayer Let's all switch to @andrewnez 's Forge CLI

                        Link Preview Image
                        Forge

                        A unified CLI for GitHub, GitLab, Gitea, Forgejo, and Bitbucket.

                        favicon

                        Andrew Nesbitt (nesbitt.io)

                        1 Reply Last reply
                        0
                        • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                          ⚠️ Github CLI now has telemetry spyware built in:

                          Link Preview Image
                          Telemetry

                          Take GitHub to the command line

                          favicon

                          GitHub CLI (cli.github.com)

                          They're shifting the burden onto users by requiring YOU to opt out, instead of making it opt in.

                          Run `gh config set telemetry disabled` to disable it.

                          #privacy #foss #github #cybersecurity #surveillance

                          justin@toot.ioJ This user is from outside of this forum
                          justin@toot.ioJ This user is from outside of this forum
                          justin@toot.io
                          wrote last edited by
                          #14

                          @nuclearplayer better to just #GiveUpGitHub

                          1 Reply Last reply
                          0
                          • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                            Link Preview Image
                            Enable telemetry without env var by williammartin · Pull Request #13254 · cli/cli

                            GitHub’s official command line tool. Contribute to cli/cli development by creating an account on GitHub.

                            favicon

                            GitHub (github.com)

                            The PR that enables the spyware without much deliberation.

                            darrel_miller@mastodon.socialD This user is from outside of this forum
                            darrel_miller@mastodon.socialD This user is from outside of this forum
                            darrel_miller@mastodon.social
                            wrote last edited by
                            #15

                            @nuclearplayer I'm going to put on my lead lined suit here and ask a question because I genuinely want to learn. This issue comes up time and time again. The GitHub CLI telemetry provides product owners with information about how their product is used. You can see what it captures here https://cli.github.com/telemetry It is pseudonymous data. There is no user identifying data there. So yes the telemetry is spying on what the app is doing, but not on which user is doing it.

                            darrel_miller@mastodon.socialD nuclearplayer@fosstodon.orgN dalias@hachyderm.ioD aeris@firefish.imirhil.frA 4 Replies Last reply
                            0
                            • darrel_miller@mastodon.socialD darrel_miller@mastodon.social

                              @nuclearplayer I'm going to put on my lead lined suit here and ask a question because I genuinely want to learn. This issue comes up time and time again. The GitHub CLI telemetry provides product owners with information about how their product is used. You can see what it captures here https://cli.github.com/telemetry It is pseudonymous data. There is no user identifying data there. So yes the telemetry is spying on what the app is doing, but not on which user is doing it.

                              darrel_miller@mastodon.socialD This user is from outside of this forum
                              darrel_miller@mastodon.socialD This user is from outside of this forum
                              darrel_miller@mastodon.social
                              wrote last edited by
                              #16

                              @nuclearplayer When you call an API or make a git request to some remote repo, there are going to be logs of that activity on that remote site. We acknowledge that site owners need some visibility into what is happening on their service. However, when it comes to code that is downloaded and executed on a local machine there seems to be an expectation that the code owners no longer have any rights to see how that code is executing. Help me understand why the rules are different.

                              darrel_miller@mastodon.socialD w@11n.orgW 2 Replies Last reply
                              0
                              • darrel_miller@mastodon.socialD darrel_miller@mastodon.social

                                @nuclearplayer When you call an API or make a git request to some remote repo, there are going to be logs of that activity on that remote site. We acknowledge that site owners need some visibility into what is happening on their service. However, when it comes to code that is downloaded and executed on a local machine there seems to be an expectation that the code owners no longer have any rights to see how that code is executing. Help me understand why the rules are different.

                                darrel_miller@mastodon.socialD This user is from outside of this forum
                                darrel_miller@mastodon.socialD This user is from outside of this forum
                                darrel_miller@mastodon.social
                                wrote last edited by
                                #17

                                @nuclearplayer I would think the important thing is what data is being collected, not the the fact that any data is being collected. If that remote site is collecting end user identifiable information, that should be as big a problem as if a local tool is doing it. What is good about a "source-open" collecting the telemetry is that you can see and verify what is being collected. You can't with a remote service.

                                darrel_miller@mastodon.socialD 1 Reply Last reply
                                0
                                • darrel_miller@mastodon.socialD darrel_miller@mastodon.social

                                  @nuclearplayer I would think the important thing is what data is being collected, not the the fact that any data is being collected. If that remote site is collecting end user identifiable information, that should be as big a problem as if a local tool is doing it. What is good about a "source-open" collecting the telemetry is that you can see and verify what is being collected. You can't with a remote service.

                                  darrel_miller@mastodon.socialD This user is from outside of this forum
                                  darrel_miller@mastodon.socialD This user is from outside of this forum
                                  darrel_miller@mastodon.social
                                  wrote last edited by
                                  #18

                                  @nuclearplayer And as a Microsoft employee, my experience has been that we are extremely careful about not logging any information that directly identifies users and any customer created content. It isn't lip service to privacy. I've seen projects delayed while we scrub logs because a developer accidentally logged the name of some artifact that they should not have.

                                  josepvives@mastodont.catJ 1 Reply Last reply
                                  0
                                  • iain@hachyderm.ioI iain@hachyderm.io

                                    @danni_storm the feature set is quite different https://cli.github.com/manual/gh

                                    danni_storm@hachyderm.ioD This user is from outside of this forum
                                    danni_storm@hachyderm.ioD This user is from outside of this forum
                                    danni_storm@hachyderm.io
                                    wrote last edited by
                                    #19

                                    @iain Ah thanks for clearing that up for me. That makes more sense.

                                    1 Reply Last reply
                                    0
                                    • darrel_miller@mastodon.socialD darrel_miller@mastodon.social

                                      @nuclearplayer I'm going to put on my lead lined suit here and ask a question because I genuinely want to learn. This issue comes up time and time again. The GitHub CLI telemetry provides product owners with information about how their product is used. You can see what it captures here https://cli.github.com/telemetry It is pseudonymous data. There is no user identifying data there. So yes the telemetry is spying on what the app is doing, but not on which user is doing it.

                                      nuclearplayer@fosstodon.orgN This user is from outside of this forum
                                      nuclearplayer@fosstodon.orgN This user is from outside of this forum
                                      nuclearplayer@fosstodon.org
                                      wrote last edited by
                                      #20

                                      @darrel_miller How about they ask for permission first? Why is that concept so hard to grasp for Microsoft?

                                      1 Reply Last reply
                                      0
                                      • nuclearplayer@fosstodon.orgN nuclearplayer@fosstodon.org

                                        To disable:

                                        export GH_TELEMETRY=false

                                        export DO_NOT_TRACK=true

                                        gh config set telemetry disabled

                                        Each of these work individually too.

                                        stevenodb@mastodon.socialS This user is from outside of this forum
                                        stevenodb@mastodon.socialS This user is from outside of this forum
                                        stevenodb@mastodon.social
                                        wrote last edited by
                                        #21

                                        @nuclearplayer the original post was deleted?

                                        1 Reply Last reply
                                        0
                                        • darrel_miller@mastodon.socialD darrel_miller@mastodon.social

                                          @nuclearplayer I'm going to put on my lead lined suit here and ask a question because I genuinely want to learn. This issue comes up time and time again. The GitHub CLI telemetry provides product owners with information about how their product is used. You can see what it captures here https://cli.github.com/telemetry It is pseudonymous data. There is no user identifying data there. So yes the telemetry is spying on what the app is doing, but not on which user is doing it.

                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.io
                                          wrote last edited by
                                          #22

                                          @darrel_miller @nuclearplayer This term "product owners" says everything we need to know about how GitHub is wrong on this.

                                          GitHub is NOT the "product owner" of my computer or anything running on it. I am.

                                          They are the "product owner" of the service running on their website, but this still does not entitle them to collect personal information without consent, regardless of whether it is "pseudonymous"/"anonymous". This is a basic principle of data protection anyone familiat with relevant law and ethics should be aware of.

                                          darrel_miller@mastodon.socialD 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups