Bug#786630: josm: privacy leak: update check

Sebastiaan Couwenberg sebastic at xs4all.nl
Sat May 23 16:54:59 UTC 2015


Hi Christoph,

On 05/23/2015 06:32 PM, Christoph Anton Mitterer wrote:
> Apparently josm "calls home" each time started and checks for updates.
> 
> This is IMHO and inappropriate privacy leak.
> Keeping software up-to-date is the package management's duty within
> Debian, so there is especially no need that this is taken over partially
> by software, especially not when it means that it needlessly leaks at least
> IP address, version of my current JOSM and the times whenever I start it.

I'm tempted to downgrade the severity to wishlist, because if you don't
trust the OpenStreetMap project you shouldn't use their infrastructure.

> So this function should be either removed or made optionally (defaulting
> to being disabled).

Are you willing to provide a patch to disable the update check?

Kind Regards,

Bas

-- 
 GPG Key ID: 4096R/6750F10AE88D4AF1
Fingerprint: 8182 DE41 7056 408D 6146  50D1 6750 F10A E88D 4AF1



More information about the Pkg-grass-devel mailing list