As ztirffritz brought up initial concern w/ functionality in November, my subsequent question w/ Kerry about Privacy/Security concerns, and recent TB 2.0's release has again got me very concerned with Privacy as it pertains 2 Trixbox's required serialization, user association, & tracking with the Fonality server.
While this may not be a big deal with SOHO users, it is a very big concern of the larger companies I deal with.
From /var/www/html/user/modules/configModules.php, line 64:
[quote]This will be used to see if the Guid for this box has a userid associated with it. If not, then the box is registered but has no one to associate the box with. If this is the case, everytime a user goes to the home page of this application they will be propmted to provide personal info which will register them with the TB forum and associate there User ID from the forum with this TB and the TB's GUID.[/quote]
By Kerry in thread:
[url=http://www.trixbox.org/modules/newbb/viewtopic.php?viewmode=flat&topic_id=6343&forum=2]http://www.trixbox.org/modules/newbb/viewtopic.php?viewmode=flat&topic_id=6343&forum=2[/url]
[quote]
There are two forms of communication between an installed system and the trixbox servers.
1) When you log into the package manager, you are obviously hitting the trixbox servers. Therefor, we know what packages people are using. Nothing magic or sinister about usage logs.
2) In 2.0, there will be a spot on the trixbox user interface for dynamic content so we can inform users of updates, patches, etc. This is common in products like phpbb, joomla, etc. Again, nothing covert there.
That is it. We don't keep tabs on your system, report usage back, or antyhing else. So the only ramification of our servers being unavailable or you not being on the net, are the inability to get into the package manager and the dynamic content box would be blank.
[/quote]
I'd like to see the required Login with the Package Manager and GUID completely removed... I see no reason why Fonality can't simply use server-side hit statistics to track what packages people are using.
The dynamic content is fine, however... I would like to see it as an option (i.e. 'Check for Updates' checkbox)
While intentions may be good, logs trivial, and nothing sinister atm... it is a big concern nonetheless and opens the potential for exploit. (very similar to voting for a state lottery or tax increases in the US, once in... they're there forever and only have the potential to get worse.).
Please remove required login and GUID, much appreciated!
- J
Member Since:
2006-06-01