Urgent.News

What's breaking now, across thousands of outlets.

Tech

Telemetry that asks first

Usage telemetry is genuinely useful. Knowing which commands people actually run, where the errors cluster, whether anyone ever touched the feature you spent a fortnight on... that's the stuff that makes you a better maintainer. Wanting it is completely legitimate. The trouble is that the usual way of getting it, on by default and quietly hoovering up everything, is a small betrayal of the people…

Telemetry can be a valuable tool for developers, providing insights into how their software is used. Knowing which commands are frequently run, where errors commonly occur, and whether users engage with certain features can help improve the software and maintainers' effectiveness. However, the way telemetry is typically implemented raises concerns about user privacy and trust.

By default, many tools silently collect a vast amount of data, including command arguments, file paths, and IP addresses, without explicit user consent. This can be seen as a betrayal of the users who installed the tool to accomplish specific tasks.

In contrast, go-tool-base takes a different approach to telemetry. By default, telemetry is disabled, and users must actively enable it through clear and visible options. The framework ensures that no personally identifiable information is collected, even from opted-in users. Instead of recording data like command arguments or file contents, it focuses on thin events such as which command was run and how long it took. This approach minimizes the amount of data collected while still providing useful insights.

Additionally, go-tool-base allows developers to choose where the telemetry data is sent, up to and including not sending it at all. This flexibility enables the tool author to decide on the most appropriate backend, whether it's a noop backend that sends data nowhere or a custom backend that suits their needs. The framework provides the necessary plumbing without interfering with the developer's choice of destination.

Perhaps most importantly, go-tool-base includes a mechanism for users to withdraw their consent and delete any collected data. This one-way door ensures that consent is not a one-time action but can be easily revoked, reinforcing the trust between developers and tool users. By adhering to these principles, go-tool-base demonstrates that telemetry can be a valuable tool without compromising user privacy and trust.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Compliance Evidence for SMS OTP Login Polling Status When Provider Webhooks Are Missing

Short answer: for a B2B marketplace using SMS OTP login, choose a provider boundary that emits the verification evidence your reviewers need.

  • SMS OTP login requires polling for status when provider webhooks are missing
  • Hosted verification service minimizes operational surface and policy control
  • Separate rails track challenge state and message status for accurate authorization

Nobody Reads Your Notifications. That Is an Architecture Problem.

In early 2024 an operations director at a manufacturing customer told me something I repeated to my own team for months afterward. She said it politely, which somehow made it worse.

  • Notifications are slow, causing 27-hour manual wait time
  • Notifications lack identity and governance, making them unmanageable
  • Treating notifications as governed entities improves communication

More from Wednesday 7 October →