Apologetic Audacity rewrites privacy policy after 'significant lapse in communication'
- Reference: 1627061411
- News link: https://www.theregister.co.uk/2021/07/23/audactiy_apology/
- Source link:
An updated privacy policy accompanied the apology, in which the team insisted it had just been misunderstood, and that a look at the source would have shown its intentions.
"We are deeply sorry for the significant lapse in communication caused by the original privacy policy document," it said. The fact that it didn't regret the actual document itself seemed to alarm a good many users.
[3]
The update removes phrasing that "discourages children under 13 years old from using Audacity." The wording has also been updated to emphasise that no additional data is being collected for law enforcement purposes and that no personally identifiable information is being stored.
[4]
[5]
We'd wondered if the age restriction was perhaps related to consent for data collection and, indeed, the company said: "After extensive further consultation with our lawyers, we have determined that this provision is unnecessary given the actual mechanics of data transmission and storage. The provision had been included out of an abundance of caution, but in the end turned out not to be required."
It sounds like somebody got a bit too handsy with the copy and paste buttons, popped in some boilerplate text and sent it out into the wild world of GitHub without first considering the implications. Coming so soon after the [6]telemetry fiasco , one would have hoped that Audacity's new owner, Muse Group, might have paused before poking an already angry open-source bear.
[7]Open-source dev and critic of Beijing claims Audacity owner Muse threatened him with deportation to China in row over copyright
[8]Audacity fork maintainer quits after alleged harassment by 4chan losers who took issue with 'Tenacity' name
[9]Audacity users stick the knife – and fork – in to strip audio editor of unwanted features
[10]Not for children: Audacity fans drop the f-bomb after privacy agreement changes
Alas, it seems not. The company said: "We are now taking steps to improve our processes for releasing any information related to Audacity in the future to ensure that users are appropriately informed."
It has taken a while for the change to occur, and at least one user [11]observed it was "too little, too late," although the majority opinion on the update appears to be positive. New boss Martin Keary (aka Tantacrul) [12]apologised for the tardiness and laid the blame on the time-consuming process of getting legal teams involved.
[13]
"What we want more than anything else," he said, "is for people to see clearly what we are doing."
Which, we suspect, might be the problem in the eyes of many of Audacity's users. ®
Get our [14]Tech Resources
[1] https://github.com/audacity/audacity/discussions/1353
[2] https://www.theregister.com/2021/07/05/audacity/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPs7-TmrCAp64oWaTBYd7gAAAAs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPs7-TmrCAp64oWaTBYd7gAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPs7-TmrCAp64oWaTBYd7gAAAAs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/05/14/audacity_telemetry/
[7] https://www.theregister.com/2021/07/20/muse_group_deportation_threat/
[8] https://www.theregister.com/2021/07/07/tenacity_maintainer_quits_4chan_harassment/
[9] https://www.theregister.com/2021/07/06/audacity_fork/
[10] https://www.theregister.com/2021/07/05/audacity/
[11] https://github.com/audacity/audacity/discussions/1353#discussioncomment-1037636
[12] https://github.com/audacity/audacity/discussions/1353#discussioncomment-1037659
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPs7-TmrCAp64oWaTBYd7gAAAAs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
I think it was the other way around. That guy was in China and @worksintheory was threatening to have him extradited to the US. All because @worksintheory set up a webservice that delivered copyrighted content without a subscription verification - the API itself is supposed to act as the key. This went on for two years, and @worksintheory still never bothered to change the website to require a subscription key.
In theory and in practice, a recipe for failure.
Nope, he is in Canada and Muse Group insinuated that his right to stay there was at risk.
The new normal
" t sounds like somebody got a bit too handsy with the copy and paste buttons, popped in some boilerplate text and sent it out into the wild world "
Over half of the privacy "policies" we examined on our research project were just like this - boiler plate text that failed to comply with the law. Unfortunately this is not something the regulators seem particularly interested in - they concentrate on "data breaches" and unlawful mass marketing. The fundamental purpose of data protection legislation (at least in wider Europe) - to protect the human rights of data subjects - has apparently been entirely forgotten.
However in the case of Audacity the whole issue seems to have been a case of foot and mouth disease rather than any attempt to actually infringe personal privacy.
In general though, the big problem is consulting corporate lawyers when creating a privacy "policy". The function of the corporate lawyer is to protect the company. The purpose of data protection law is to protect the data subject. There's a bit of a conflict of interest there.
Re: The new normal
"In general though, the big problem is consulting corporate lawyers when creating a privacy "policy". The function of the corporate lawyer is to protect the company. The purpose of data protection law is to protect the data subject. There's a bit of a conflict of interest there."
I'm sure that's just an oversight that will be remedied promptly. Yep.
Re: The new normal
"The function of the corporate lawyer is to protect the company. The purpose of data protection law is to protect the data subject. There's a bit of a conflict of interest there."
You've hit the nail on the head. While the purpose of the law is to protect human rights, the mechanism by which it intends to do so is to make compliance less expensive than non-compliance. Indeed, that is the essential mechanism behind all effective law and has been since at least the time of Hammurabi. If the company believes there's a conflict between its interests and compliance with the law, either the penalty for noncompliance is too small or the risk of being punished too low. When the law is working properly, there is no conflict: lawyers for the company will rightly advise management that their interests lie in complying with the law.
The only remaining question is whether the 4% of turnover maximum penalty needs to be far higher or the machinery of law enforcement more vigourous. The history of piracy in the 16th and 17th centuries is instructive: when the risk of being caught was low, piracy abounded. When the risk of being caught rose, the irrational were hanged in chains and the rational, seeing their former competitors in that state, quickly opted for compliance. Penalising a corporation a mere 4% of turnover is a far cry from hanging a man in chains, but the Royal Navy was also far more effective at catching pirates than the ICO and its peers are at enforcing GDPR. Managers and corporate lawyers must be made to feel relentless pressure: that there is no escape from the law. But the penalty must also be much stiffer. They need to consider adding individual liability for these crimes, including prison time. If that's not enough, I'm quite sure that encountering one's gibbeted peer swinging over the Thames would encourage the necessary sort of reflection.
Re: The new normal
It should be a criminal offense to churn out policies etc. that don’t comply with law. Especially when it comes to a click-trough agreement between an individual and a company. Even if no one is hurt, automatic public prosecution nonetheless. Otherwise this abusive behaviour will not end.
Re: The new normal
I think you risk giving them the benefit of too much doubt. This is what the 3rd piece of assholery in quick succession from a Muse owned company.
Fool me once. Shame on you. Fool me twice -shame on me.
any new project forks?
new forks might put pause into Muse to stop messing around.....
Re: any new project forks?
I think the current plan is to spam their telemetry service with nonsense. Seems only fair - they want to collect it, we provide it.
the mechanics of data transmission and storage
I.e. they have no plans to remove the phone home features that everyone objects to.
The thing is...
Once you've lost trust, it takes a long time to restore it.
Veiled threats to Chinese dissidents doesn't exactly help, even if they were ham-fisted mistakes. There are better ways to get compliance, and in that other case Muse were considerably at fault for providing unsecured access to copyright material.
Let's take the following at face value...
'The wording has also been updated to emphasise that no additional data is being collected for law enforcement purposes and that no personally identifiable information is being stored.'
1. '...no additional data is being collected for law enforcement purposes...' - so data is being stored (where: locally/uploaded?) and this pre-existing data collection is/maybe being used for law enforcement purposes.
2. '...no personally identifiable information is being stored.' - so, as above, information is being stored (where, and for what purpose, etc.?); and is not 'personally identifiable', i.e. Trust us on this.
Now call me paranoid, but what is bumpf like this actually worth, given the realities of corporate and personal behaviour we are exposed to on a daily basis?
Maybe Muse have made a straight up and monumental PR cock up of things, maybe they are just not very practised at being dishonest, maybe... - who knows?
What we do know is that once upon a time, in a more innocent age, 'Audacity' was just audio editing software that went about it's business on a local machine in a pretty usable kind of way, i.e. it wasn't crap. And that was about all there was, and needed, to be said.
Re: Let's take the following at face value...
"Now call me paranoid, but what is bumpf like this actually worth, given the realities of corporate and personal behaviour we are exposed to on a daily basis?"
There's also the fact that Muse is in Russia, which will happily thumb its nose at any attempt to enforce European law against its resident corporations. In other words, no matter what they claim, you can't rely on it because there's no real incentive to comply with their own policy. If a European court were to find against Muse and then make noise about enforcing penalties against Russian assets in the EU, Putin will threaten to turn off your gas and your politicians will put in a quiet word to the judge; that will be the end of it. Therefore if you use software from Russia, they can take whatever they want and do whatever they want with it. If you don't like that, don't use it. The back and forth over words on a page is mere theatre.
Non-apology apology
Textbook example.
"We are sorry that you didn't understand what we are up to, stupid."
Can this sink any lower?
Per their other recent headlines, let's hope that whoever made this mistake isn't a Chinese dissident that can be threatened with deportation back to China. One Mafia-esque threat a week is more than enough.