Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Eudora spyware?

0 views
Skip to first unread message

Robert Link

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <nospam-962836....@enews.newsguy.com>, Michael
Wise <nos...@nospam.net> wrote:

> doing
> things like making connections to Qualcomm servers to transmit usage
> statistics w/o the users' consent or knowledge or documentation of said
> occurence in the manual

Guess I missed this thread earlier. I know anytime I'm crazy enough to
accept something like "sponsored-ware" it comes at a cost. Has anyone a
good list of just what Eudora sponsored 4.3.2 on mac is sending along to
Qualcomm?
- --
Robert Link
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOZW364HvG1x/HQ+LEQITcgCgksibl0e1wbVy4T5k9sm9VwCrbKEAnjUv
qTIn+iUvVRXDioeI22sQTAKe
=3SFg
-----END PGP SIGNATURE-----

Michael Wise

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to
In article <rlink-64EFB1.13475212082000@news>, Robert Link
<rl...@binmedia.com> wrote:


> > doing
> > things like making connections to Qualcomm servers to transmit usage
> > statistics w/o the users' consent or knowledge or documentation of said
> > occurence in the manual
>
> Guess I missed this thread earlier. I know anytime I'm crazy enough to
> accept something like "sponsored-ware" it comes at a cost.

I wouldn't be so bad, if it was just sponsored versions...but the damn
PAID versions do this.

--Mike

K.-Benoit Evans

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to
In article <120820002007434683%esm...@twcny.rr.com>, Eric Smith
<esm...@twcny.rr.com> wrote:

> In article <nospam-571837....@enews.newsguy.com>, Michael


> Wise <nos...@nospam.net> wrote:
>
> > I wouldn't be so bad, if it was just sponsored versions...but the damn
> > PAID versions do this.
>

> What exactly does the Paid version do?

In your Eudora Folder (in the System folder) you will find a file called
"UsageStats". If you open it with a text editor, you will see something
like the following:
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
This file describes how you use Eudora; we might ask you for it someday
to help us understand our users better. It will n e v e r contain any
of your email or personal information, and it will n e v e r be sent
anywhere without your permission.

0008072128 32 2 108 33389 33990 33983
0008072129 32 5 0 0 0 0 0 43 2818053 1
0008072129 32 6 13 50 0
0008072129 32 3 1 0 0
0008072130 32 2 123 33494 34110 34103
0008072132 32 6 114 34 0
0008072132 32 5 0 0 0 0 0 43 2818055 1
... etc., etc., etc. ...

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Periodically, Eudora will display a window telling you that it would
like to download your UsageStats to Qualcomm's computers. You can accept
or deny the request.

Obviously, the companies that are **paying** to run their ads in the
sponsored version want to know something about the exposure they're
getting. For the paid, no ads, version, Qualcomm would surely like to
have some real figures after all these years on how people are actually
using their software.

Some time ago, someone here posted a description of the data fields in
UsageStats. Generally speaking, Qualcomm is finding out how often the
program is opened or closed, the volumes of mail going out and coming
in, whether certain features are actually used or not, etc.

If you don't want to send your stats, you can just say NO when asked or
you can use an x-setting so that you will NEVER be asked.

<x-eudora-setting:13509>
One in this many startups ask to send audit info.

The default value is 100. I have set mine for 10000. Since my copy of
Eudora is usually on all the time and I restart it only after a crash or
software installation, I don't expect to be asked to send anything any
time soon!

--
Regards,

Benoit Evans

Michael Wise

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to
In article <SUll5.154688$8u4.1...@news1.rdc1.bc.home.com>, Avery
Raskin <ara...@mac.com> wrote:

>
> The answer is RELAX. Eudora doesn't send anything to Qualcomm without
> your tacit permission


Not so. It sends version, platform and registration info (to
jump.eudora.com) without asking....whether you are using a paid version
or not. This was discussed at length on this n.g. back in March. Even
Qualcomm people admitted as such on this very n.g.
-------------------------------------------------------------

Forum: comp.mail.eudora.mac
Thread: Paid 4.3.1 keeps dialing out for "jump.eudora.com"
Message 33 of 56
Subject: Re: Paid 4.3.1 keeps dialing out for "jump.eudora.com"
Date: 03/04/2000
Author: John Purlia <jpu...@qualcomm.com>

In article <040320001049045855%bmah...@hotmail.com>, Brad Mahone
<bmah...@hotmail.com> wrote:
> I don't ever recall my permission being requested. All I recall is my
> computer automatically attempting to connect to jump.eudora.com.

Just a reminder, folks... The connections to jump.eudora.com do NOT
contain the
UsageStats file. The only data sent to our server when performing an
update query is
version, platform and registration information -- all of which is
necessary to
determine which version(s) of Eudora are newly available to a user.

For example, in the query we'll send MacOS, 4.3 and a user's
registration
information. From that info we might be able to determine that this
particular user
is entitled to a free update to 4.3.1, 4.3.2 and 4.3.3 -- and might
also be interested
in some later version of Eudora... 6.0 or 8.0 or some such future thing.
-------------------------------------------------------------


> and it explains exactly what it wants to send
> when it asks if it can.
> It's nothing more than the typical marketing/R&D
> type survey information companies try to get out of you when you
> register a product. The only difference here is Eudora will just to it
> for you if you let it. If you say "NO", that's it.

Your confusing two separate issues:


1) The marketing data which Eudora asks you for permission to send
2) Version, platform, and registration info Data which Eudora does not
ask your permission to send and which is not documented in the manual.

The latter is what I'm yalking about. Qualcomm slipped it in quietly,
and it wasn't till people (yours truly included) concerned about their
privacy took Qualcomm to task about it repeatedly on this group that
they finally admitted it...but then tried make it out to be a feature
for our own good.

They finally told us how to disable this "feature"

---------------------------------------
<x-eudora-setting:305> When checked, Eudora will occasionally check to
see if software updates are available. Setting reversed; use "n" for ON,
"y" for OFF! To use the setting feature, open a new message window and
type: <x-eudora-setting:305>
---------------------------------------


For the back history on this topic, see:

http://www.deja.com/[ST_rn=ps]/qs.xp?ST=PS&svcclass=dnyr&firstsearch=yes&
QRY=jump.eudora.com&defaultOp=AND&DBS=1&OP=dnquery.xp&LNG=english&subject
s=&groups=comp.mail.eudora.mac&authors=&fromdate=&todate=&showsort=score&
maxhits=25

--Mike

Michael Wise

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to
In article <rlink-52B939.17314312082000@news>, Robert Link
<rl...@binmedia.com> wrote:


> > If you say "NO", that's it.

> This certainly seems fair. I gathered there was something more
> nefarious afoot.

There is.

Michael Wise

unread,
Aug 12, 2000, 3:00:00 AM8/12/00
to


> > I wouldn't be so bad, if it was just sponsored versions...but the damn
> > PAID versions do this.
>
> What exactly does the Paid version do?

http://www.deja.com/[ST_rn=ps]/qs.xp?ST=PS&svcclass=dnyr&firstsearch=yes&
QRY=jump.eudora.com&defaultOp=AND&DBS=1&OP=dnquery.xp&LNG=english&subject
s=&groups=comp.mail.eudora.mac&authors=&fromdate=&todate=&showsort=score&
maxhits=25

Eric Smith

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to

Avery Raskin

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
Forgive me for not using your private/public/whatever encryption key to
answer this, especially since this is usenet, not internal NSA. Sigh.

The answer is RELAX. Eudora doesn't send anything to Qualcomm without

your tacit permission, and it explains exactly what it wants to send

when it asks if it can. It's nothing more than the typical marketing/R&D
type survey information companies try to get out of you when you
register a product. The only difference here is Eudora will just to it

for you if you let it. If you say "NO", that's it.

In article <rlink-64EFB1.13475212082000@news>, Robert Link
<rl...@binmedia.com> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>

> In article <nospam-962836....@enews.newsguy.com>, Michael

> Wise <nos...@nospam.net> wrote:
>
> > doing
> > things like making connections to Qualcomm servers to transmit usage
> > statistics w/o the users' consent or knowledge or documentation of said
> > occurence in the manual
>
> Guess I missed this thread earlier. I know anytime I'm crazy enough to

Robert Link

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <SUll5.154688$8u4.1...@news1.rdc1.bc.home.com>, Avery
Raskin <ara...@mac.com> wrote:

> Forgive me for not using your private/public/whatever encryption key to
> answer this, especially since this is usenet, not internal NSA. Sigh.

I detect just a whiff of sarcasm, but let me say, I don't pgp-sign on
usenet so much for authentication as to make sure I don't forget my
passphrase as I have the last three times I've installed pgp.
;-)

> If you say "NO", that's it.

This certainly seems fair. I gathered there was something more

nefarious afoot. Thanks for the feedback.
- --
Robert Link

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOZXsYoHvG1x/HQ+LEQILbgCfQrS2r/l/fABjedIr/X84eUkxv2QAoJOg
Q8CcInGzYYxYyP2DvPwN2xZq
=1+w+
-----END PGP SIGNATURE-----

Sander Tekelenburg

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <rlink-64EFB1.13475212082000@news>, Robert Link
<rl...@binmedia.com> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----

Just curious. Why are you PGP-signing your messages? Your public key
seems nowhere to be found, so there's no way of varifying your sigs.

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.2

iQA/AwUBOZY02OsywKfXgqKdEQJQ3wCgrF432U1oKKjtGE4MKu8J+GiEOCoAoLp/
bnCctB1GkmnPVfs8nji4rNQO
=lOqO
-----END PGP SIGNATURE-----

--
Sander Tekelenburg, <http://www.euronet.nl/%7Etekelenb/>
Address in 'From: ' header is undeliverable. Use Rot 13 on <grxr...@rhebarg.ay>

Mac user: "Macs only have 40 viruses, tops!"
PC user: "SEE! Not even the virus writers support Macs!"

Kathy I. Morgan

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
K.-Benoit Evans <kev...@videotron.ca> wrote:

> If you don't want to send your stats, you can just say NO when asked or
> you can use an x-setting so that you will NEVER be asked.
>
> <x-eudora-setting:13509>
> One in this many startups ask to send audit info.
>
> The default value is 100. I have set mine for 10000. Since my copy of
> Eudora is usually on all the time and I restart it only after a crash or
> software installation, I don't expect to be asked to send anything any
> time soon!

Hmmmm...I wonder if maybe the default value changes after you send off a
copy? I was asked to send mine shortly after I got 4.3. I searched
through the file and found some information that I found interesting
about my computer usage (not just Eudora but also internet connections
established and similar stuff). There was nothing I saw objectionable,
so I sent it on to Eudora and expected that soon I would be asked again,
but I never was. Just now, I checked it out by clicking on the
X-Eudora-Setting, and it is showing the default number of startups as
2000.

In case you'd like to see the text of the message as it goes to Eudora,
I've posted it up again on my web pages at
<http://www.aptalaska.net/~kmorgan/stats.html>. I'll leave it up for a
week or so for anyone who wants to see exactly what it is that is sent
(or not sent, it's up to the user). The UsageStats file doesn't include
an explanation of what the various stats mean; the email message that
you review and edit before sending has an explanation at the bottom of
what all the codes mean.

--
Kathy
help for new users of newsgroups at <http://www.aptalaska.net/~kmorgan/>
Good Net Keeping Seal of Approval at <http://www.xs4all.nl/%7Ejs/gnksa/>

Robert Link

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <NOSPAM-8B3729....@newsreader.euronet.nl>, Sander
Tekelenburg <NOS...@nowhere.invalid> wrote:

> Your public key
> seems nowhere to be found

Odd; try http://phpkeys.mit.edu:11371, I sent it there immediately
before posting this note. I thought it was long since stored at
ldap://certserver.pgp.com and should have propogated from there, but
possibly I goofed when creating my key.

Mostly I sign my notes so as to keep my passphrase fresh in my mind,
it's lengthy and random and if I don't use it regularly then I'll have
wasted yet another key.


- --
Robert Link
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOZathYHvG1x/HQ+LEQKOHACgpxx3ycmkl2+8r5pK8Y0sO57ct6QAoNtU
xQ2lYcchavalBKqHxYkZ4YqU
=2NLl
-----END PGP SIGNATURE-----

K.-Benoit Evans

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <nospam-8618EC....@enews.newsguy.com>, Michael
Wise <nos...@nospam.net> wrote:

> The latter is what I'm yalking about. Qualcomm slipped it in quietly,
> and it wasn't till people (yours truly included) concerned about their
> privacy took Qualcomm to task about it repeatedly on this group that
> they finally admitted it...but then tried make it out to be a feature
> for our own good.
>
> They finally told us how to disable this "feature"
>
> ---------------------------------------
> <x-eudora-setting:305> When checked, Eudora will occasionally check to
> see if software updates are available. Setting reversed; use "n" for ON,
> "y" for OFF! To use the setting feature, open a new message window and
> type: <x-eudora-setting:305>
> ---------------------------------------

I have LOTS of software that does this, including RealPlayer, QuickTime
and Sherlock. Even NetBarrier, a firewall to detect unauthorized
computer us, has this feature. Some of them do not even give you the
choice of turning it off.

And for me, this is a feature. It is nice to know without having to
check with the software author or reading press releases that an update
is available. Most let me turn it off. And, in fact, I don't use it in
Eudora, but I do in NewBarrier.

--
Regards,

Benoit Evans

Hank Zimmerman

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <kevans-9A9714....@news.videotron.ca>, "K.-Benoit
Evans" <kev...@videotron.ca> wrote:

>And for me, this is a feature. It is nice to know without having to
>check with the software author or reading press releases that an update
>is available. Most let me turn it off. And, in fact, I don't use it in
>Eudora, but I do in NewBarrier.

I also use VerstionTracker's notification system that sends emails when
a new version of a software is available. Think about the security in
that! Some independent company has not only my name, but also my email
address and several software titles that I own and use (if I did not use
them, there would not be much use in needing up to the minute update
notification).

--
Hank Zimmerman maintains the comp.mail.eudora.mac FAQ
It can be found at <http://www.ka.net/eudora/faqs/>
The [Unofficial] Eudora Web Site can be found at <http://www.emailman.com/eudora/>
(c) 2000 Hank Zimmerman

Andrew Starr

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <kevans-9A9714....@news.videotron.ca>, K.-Benoit
Evans <kev...@videotron.ca> wrote:

> I have LOTS of software that does this, including RealPlayer, QuickTime
> and Sherlock. Even NetBarrier, a firewall to detect unauthorized
> computer us, has this feature. Some of them do not even give you the
> choice of turning it off.

Don't forget Anarchie!

Michael Wise

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <kevans-9A9714....@news.videotron.ca>, "K.-Benoit
Evans" <kev...@videotron.ca> wrote:

> > The latter is what I'm yalking about. Qualcomm slipped it in quietly,
> > and it wasn't till people (yours truly included) concerned about their
> > privacy took Qualcomm to task about it repeatedly on this group that
> > they finally admitted it...but then tried make it out to be a feature
> > for our own good.
> >
> > They finally told us how to disable this "feature"
> >
> > ---------------------------------------
> > <x-eudora-setting:305> When checked, Eudora will occasionally check to
> > see if software updates are available. Setting reversed; use "n" for
> > ON,
> > "y" for OFF! To use the setting feature, open a new message window and
> > type: <x-eudora-setting:305>
> > ---------------------------------------
>

> I have LOTS of software that does this, including RealPlayer, QuickTime
> and Sherlock. Even NetBarrier, a firewall to detect unauthorized
> computer us, has this feature. Some of them do not even give you the
> choice of turning it off.

It's not the concept of software checking the net to see if there's a
newer version which is bothersome. Rather, when software does it without
the knowledge or consent of the end-user who pays money for that
software. Qualcomm slipped it into Eudora without mentioning anything
about it in the documentation or read-me's which came with the product.
All of the sudder, those of us who got the new version of Eudora started
noticing our paid versions of Eudora making non user-controlled
connections to Qualcomm. We didn't know why it was doing it and what was
being sent...which in recent times is not the best way to keep customer
trust. For weeks, Qualcomm made it a red herring issue..by claiming that
no usage stats info is sent w/o user consent...ignoring that we werent
complaining about the marketing data transmissions, but rather the
connections to jump.eudora.com. Finally they said, that yes, even the
paid versions do this. They went on to assure us that the only info that
was being sent was platform, Eudora version, and registration info. That
may be fine for you and some others....but it is not fine for me and
many others.

Qualcomm should not have the right to use my internet connection, so
that my paid client can transfer info to them without my knowledge.
Companies like Quark do this...however, I expected much better from the
likes of Qualcomm. My client platform, client version, and
particularly...my registration info are none of their business to track
once I have paid for an registered their product. If they wish to get
that info as a "feature" for my benefit, then they can ask me for
it...and not enable it undocumented and on by default. At least they
finally told us how to turn it off.

> And for me, this is a feature. It is nice to know without having to
> check with the software author or reading press releases that an update
> is available. Most let me turn it off. And, in fact, I don't use it in

> Eudora...

Great, but Qualcomm not only did not tell people how to turn it off, but
they didn't even document that it existed in the first place. In fact,
they tried to deny it when confonted on it. They told us how to turn it
off only after scores of people cmplained about it.


--Mike

Michael Wise

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <130820001326526625%atsn...@emailman.com>, Andrew Starr
<atsn...@emailman.com> wrote:


> > I have LOTS of software that does this, including RealPlayer, QuickTime
> > and Sherlock. Even NetBarrier, a firewall to detect unauthorized
> > computer us, has this feature. Some of them do not even give you the
> > choice of turning it off.
>

> Don't forget Anarchie!

Except that Anarchie asks you if you wish to transfer this info and
enables you to say no...permanently when it asks you. Eudora neither
asks you nor tells you what its doing.


--Mike

K.-Benoit Evans

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <nospam-93A8B5....@enews.newsguy.com>, Michael
Wise <nos...@nospam.net> wrote:

> Except that Anarchie asks you if you wish to transfer this info and
> enables you to say no...permanently when it asks you. Eudora neither
> asks you nor tells you what its doing.

Do you get so worked up every time you use Netscape Navigator or
Internet Explorer to visit a Web site. Without even using a cookie, the
following information is available to the site visited and you can't do
anything about it:

1. the Internet domain name and the IP address (a number
automatically assigned to your computer by your Internet provider every
time you use the Internet) with which you access our site;
2. the type of browser and operating system used to access our site;
3. the date and time you access our site;
4. the pages you visit; and
5. if you access www.gouv.qc.ca from another site (referral site), its
address

And, if I'm not mistaken, the default setting for cookies is to accept
them all without notice. The other day, at work, someone asked about
cookies and out of about 10 people, all professional-level employees who
routinely use the Web, only 2 knew what the were and why they could be
undesirable.

--
Regards,

Benoit Evans

Hank Zimmerman

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <kevans-3BA0A3....@news.videotron.ca>, "K.-Benoit
Evans" <kev...@videotron.ca> wrote:

>And, if I'm not mistaken, the default setting for cookies is to accept
>them all without notice. The other day, at work, someone asked about
>cookies and out of about 10 people, all professional-level employees who
>routinely use the Web, only 2 knew what the were and why they could be
>undesirable.

Just for the point of clarifacation: Notice that Berniot Evans said
"*could* be undesireable" (emphasis added). In the same regard, though,
there are a lot of web site cookies out there that make life easier
without any harmful side-effects. It is for this reason that powerful
cookie-options (like what iCab uses) are desireable.

Michael Wise

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <kevans-3BA0A3....@news.videotron.ca>, "K.-Benoit
Evans" <kev...@videotron.ca> wrote:


> > Except that Anarchie asks you if you wish to transfer this info and
> > enables you to say no...permanently when it asks you. Eudora neither
> > asks you nor tells you what its doing.
>
> Do you get so worked up every time you use Netscape Navigator or
> Internet Explorer to visit a Web site. Without even using a cookie, the
> following information is available to the site visited and you can't do
> anything about it:
>
> 1. the Internet domain name and the IP address (a number
> automatically assigned to your computer by your Internet provider every
> time you use the Internet) with which you access our site;
> 2. the type of browser and operating system used to access our site;
> 3. the date and time you access our site;
> 4. the pages you visit; and
> 5. if you access www.gouv.qc.ca from another site (referral site), its
> address


No, I don't get worked up on that for the following reasons:

1) It is common knowledge that this occurs and has pretty much always
occured since the dawn of web browsers.

2) I am using my client to visit their site.
This is very much like me using my Nortel Meridian telephone to call
Nortel up. Because I am calling them, they have every right to capture
the inbound number I'm calling from (and they will if I'm dialing
1-800). If the technology existed, it wouldn't be a big deal if they
could discern the model of phone I was using as well as the firmware in
the phone.

3) The web browsing software I am using is free


Contrast that with what I'm saying about Eudora.

1) Up until 4.3, Qualcomm never did such a thing with Eudora...and there
was no reason to suspect they would.

2) I am not visting Qualcomm's site. These connections occur no matter
what I'm doing with my mail client. Just because I'm sending a mail to
John Q. Employee across the hall does not give Qualcomm make my client
connect to its server across my network, over the Internet, using my
bandwidth, to transmit data I did not give consent for them to have.
To go back to my Nortel Meridian phone analogy: what Qualcomm is doing
is akin to Nortel making my Nortel phone call them up (with out my
knowledge or consent) using my phone line to transmit data on the type
of phone I'm using, it's firmware, and when/where I registered the phone
at. They have no right to do this.

3) I paid for this software. As such, Qualcomm has no right to make my
client query it's server and keep a database on what plaform I'm using,
what OS rev I am running, and what my reg info is.


> And, if I'm not mistaken, the default setting for cookies is to accept
> them all without notice.

Yes, and it's no secret. Pretty much everybody already knows that. The
fact that such things happen is not cloaked from the user. In addition,
it's easy and intuitive to stop this from happening by just going into
your browser's settings. There is no such check box within Eudora and
Qualcomm had to be nagged to admit this behavior existed and tell us how
to stop it.


> The other day, at work, someone asked about
> cookies and out of about 10 people, all professional-level employees who
> routinely use the Web, only 2 knew what the were and why they could be
> undesirable.

What planet are these people from? I think just about anybody who is
been on the net for more than a year knows what a cookie is. They have
been widely talked about in both the consumer and trade press. Even so,
there's a big difference between pulling data about me when I visit your
site...than pulling data from me when I'm nowhere near your network.


The contrasts are quite obvious here, so I have to wonder whether or not
you just feel like arguing.


--Mike

Hank Zimmerman

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <nospam-08BEBF....@enews.newsguy.com>, Michael
Wise <nos...@nospam.net> wrote:

>3) I paid for this software. As such, Qualcomm has no right to make my
>client query it's server and keep a database on what plaform I'm using,
>what OS rev I am running, and what my reg info is.

When you register the software you pay for, don't you basically give
them the same information?

Michael Wise

unread,
Aug 13, 2000, 3:00:00 AM8/13/00
to
In article <chz1-D96D6C.2...@nntp.iglou.com>, Hank Zimmerman
<ch...@cornell.edu> wrote:


> >3) I paid for this software. As such, Qualcomm has no right to make my
> >client query it's server and keep a database on what plaform I'm using,
> >what OS rev I am running, and what my reg info is.
>
> When you register the software you pay for, don't you basically give
> them the same information?

Three things:

1) When registering software, all one should put is name (or company),
and address. That's all I ever put. Any thing else just joins the former
to be used as marketing data...either internally for mailings, and/or
sold to other companies.*

2) Nothing requires that one register in the first place. Registering
doesn't do much, but add your name to a database which can be used for
further sales efforts. The only real benefit, is that some companies
will notify you of updates (which you probably would already have founf
out about weeks earlier on versiontracker anyway) as well as an
electronic record that you bought the product should you forget your s/n
or be qualified for ug pricing. If you keep your reg card/sn handy...you
need not ever register it directly when you buy it...as you can always
provide sn and name info when/if you ever need to call for support or an
upgrade.*

3) If I buy a 100-user Eudora site license registered to "Company A."
Qualcomm has no right sureptitiously cull platform, OS versions, and
read data from those users on my network without my company's knowledge
and/or consent.


--Mike

*these statements come from experience...from a period of time where I
directed the customer service/product reg/data entry operations for a
software company (Berkeley Systems). The tactics are pretty much the
same for all software companies.

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
> The other day, at work, someone asked about cookies and out of about 10
> people, all professional-level employees who routinely use the Web, only 2
> knew what the were and why they could be undesirable.

Fire them. They're not "professionally using the web". This is called
"media incompetence".

Regards
Götz
--
http://www.knubbelmac.de/
http://www.mac-faq.de/

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
> I have LOTS of software that does this, including RealPlayer, QuickTime
> and Sherlock. Even NetBarrier, a firewall to detect unauthorized computer
> us, has this feature. Some of them do not even give you the choice of
> turning it off.

I delete software that doesn't inform me *before* it does such things.
It's easy: I can't trust the company anymore. Why should I?

If the butcher would do the same and his meat would deliver information
about my fridge contents then I would be very angry. Even if it is
"useful" and he could offer me better/cheaper/fresher meat next time I'm
shopping.

And I'm really considering deleting Eudora. It's a fine piece of
software - but I want to be asked and informed. That's my right.

BTW: In some countries software behaviour like this could be illegal.

K.-Benoit Evans

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
In article <1efcjq7.1mr0as5tt4siqN%go...@nogfradelt.de>,
go...@nogfradelt.de (Götz Hoffart) wrote:

> > The other day, at work, someone asked about cookies and out of about 10
> > people, all professional-level employees who routinely use the Web,
> > only 2
> > knew what the were and why they could be undesirable.
>
> Fire them. They're not "professionally using the web". This is called
> "media incompetence".
>
> Regards
> Götz

I don't have the authority to fire anyone and, thank God, neither do
you. Please come into the real world where only a small minority have
the level of interest and knowledge that the average member of this
newsgroup has.

A recent survey of our employees showed that only about 35% of them have
a computer at home. Generally, their experience is at work where they
were provided with a computer and sufficient training to use the
computer for their work. The employer decided to allow cookies on all
browsers and since they are, after all, his computers didn't see any
need to talk to employees about the pros and cons of automatically
accepting all cookies.

For the most part, these people are actuaries, accountants, and
socio-economic specialists. They know how to find the information they
need on the Internet and on our intranet. When there's a problem, they
call for support and generally are not interested in exactly what the
support intervention is all about.

These are not power users; they are not geeks; they are ordinary,
average middle-aged people. I expect that many of them have a VCR that
constantly flashes 12:00. They don't know much about computers beyond
the minimum needed to use them for certain tasks--just like they don't
know how fuel injection or ABS brakes work on their cars.

By the way, you are using the term "media incompetence" in a new way. As
a translator and terminologist, I notice such things. The expression
usally refers to the shortcomings of journalists, TV news departments
and others in the news media. That is the only meaning found in the 15
or so hits Alta Vista gives for the term.

I don't mean to be critical; I just want to make an analogy. Just like
people who use computers daily have limited knowledge about computers,
people who use words every day do not necessarily know all there is to
know about words.

If you wrote a paper for publication where I work and used "media
incompetence" in that way, you would not be fired. But you would get
some support from the revisors in the Communications Department. The
same goes for computer users who need help properly using their
equipment.

--
Regards,

Benoit Evans

K.-Benoit Evans

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
In article <1efcjt0.1thvzt11cammo0N%go...@nogfradelt.de>,
go...@nogfradelt.de (Götz Hoffart) wrote:

> > I have LOTS of software that does this, including RealPlayer,
> > QuickTime and Sherlock. Even NetBarrier, a firewall to detect
> > unauthorized computer us, has this feature. Some of them do not
> > even give you the choice of turning it off.
>
> I delete software that doesn't inform me *before* it does such
> things. It's easy: I can't trust the company anymore. Why should I?

It's your computer; you can delete whatever you want.

> If the butcher would do the same and his meat would deliver
> information about my fridge contents then I would be very angry. Even
> if it is "useful" and he could offer me better/cheaper/fresher meat
> next time I'm shopping.

The analogy fails. The software under discussion does NOT report the
contents of your hard drive.


> And I'm really considering deleting Eudora. It's a fine piece of
> software - but I want to be asked and informed. That's my right.

While I'm not going to delete my Eudora (or any other software) over
this issue. I do agree that openness is very important. There should be
disclosure and users should be informed in a direct, obvious way (not
through some fine print in the user license).



> BTW: In some countries software behaviour like this could be illegal.

Name three.

--
Regards,

Benoit Evans

Greg

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
On Mon, 14 Aug 2000 09:08:43 +0100, go...@nogfradelt.de (Götz Hoffart)
wrote:

>And I'm really considering deleting Eudora. It's a fine piece of
>software - but I want to be asked and informed. That's my right.

See ya!

I can barely read this NG anymore with all the bitching and
complaining going on.

Perhaps you and Mr. Wise can start your own NG (maybe
alt.whine.whine.whine.whine.and.don't.listen.to.anyone).

Out for a bit.

G

John Purlia

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
In article <nospam-E01362....@enews.newsguy.com>, Michael Wise

<nos...@nospam.net> wrote:
> In article <120820002007434683%esm...@twcny.rr.com>, Eric Smith
> <esm...@twcny.rr.com> wrote:
>
>
> > > I wouldn't be so bad, if it was just sponsored versions...but the damn
> > > PAID versions do this.
> >
> > What exactly does the Paid version do?
>
> http://www.deja.com/[ST_rn=ps]/qs.xp?ST=PS&svcclass=dnyr&firstsearch=yes&
> QRY=jump.eudora.com&defaultOp=AND&DBS=1&OP=dnquery.xp&LNG=english&subject
> s=&groups=comp.mail.eudora.mac&authors=&fromdate=&todate=&showsort=score&
> maxhits=25

Just to clarify things a bit...

The query string posted above was NOT generated by Eudora, nor was it
trasmitted by Eudora. The text above is from a news server query created
by your news reader. None of the fields (groups, subject, authors) are
generated by Eudora (I know, I wrote the code that generates our jump
actions).

While it is true that Eudora will contact our server from time to time,
that information that is transmitted is always the bare minimum
non-personal information required to perform a particular task.

For example, the update and archive queries that are transmitted in any
mode (including Paid mode -- and these are the only Paid mode queries)
transmit information required by Eudora to dynamically figure out which
versions of Eudora are available to you as an update. So, the query
includes things like:

Eudora version number
Platform (Mac, Windows or whatever)
Registration Code
etc...

I know it's a great leap of faith, but you just have to trust us when we
claim that no personal information is transmitted to our servers without
your consent. Or, as we invite people to do, take a look at the queries
yourself with a packet sniffer or other gizmo for watching HTTP requests
and we'll be happy to fill you in on any information that looks
questionable to your eyes.

-- John

...........................................................................
John Purlia : John's CD pick of the day:
Mac Programmer Guy :
QUALCOMM, Inc. : "Out Spaced"
Travel: None! : Super Furry Animals

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
First of all: f'up to poster. We're off-topic.

> I don't have the authority to fire anyone and, thank God, neither do
> you. Please come into the real world where only a small minority have
> the level of interest and knowledge that the average member of this
> newsgroup has.

I'm earning money in the real world with real customers who are shocked
that they've been [cr|h]acked. Because they didn't care about cookies,
referrers, JavaScript, Active Scripting and bad software at all. They
didn't tell anybody "hey, I don't know this, do it for me, I'll pay
you". They thought "hey, this is Internet and it is easy. Everyone can
do this".

Yes. And everyone can drive cars. Until he drives not on a small street
in nowhere but in central New York. That's why one must learn to drive
instead of being told "this is the brake, this is the steering wheel -
enjoy it!".



> For the most part, these people are actuaries, accountants, and
> socio-economic specialists. They know how to find the information they
> need on the Internet and on our intranet. When there's a problem, they
> call for support and generally are not interested in exactly what the
> support intervention is all about.

When they're socio-economic specialists I guess they have studied? Then
they learned how to handle different kinds of media. Internet contains
different kind of media. They have to learn to handle the media and know
its dangerous parts.



> By the way, you are using the term "media incompetence" in a new way. As
> a translator and terminologist, I notice such things. The expression
> usally refers to the shortcomings of journalists, TV news departments
> and others in the news media. That is the only meaning found in the 15
> or so hits Alta Vista gives for the term.

I'm not earning money by writing English texts. I'm not a native
speaker. When I entered this newsgroup I asked to excuse my bad English.

But I used the German equivalent of "media incompetence" in discussions.
And no one here at the University of Freiburg interfered.

> I don't mean to be critical; I just want to make an analogy. Just like
> people who use computers daily have limited knowledge about computers,
> people who use words every day do not necessarily know all there is to
> know about words.

Words can have several meanings. Especially English offers lots of
meanings in every-day-phrases. I can't think of a way to decide which
word is "wrong" - in a good scientific work the first chapters are about
"word declarations/definitions" :-)

> If you wrote a paper for publication where I work and used "media
> incompetence" in that way, you would not be fired.

But I don't. :-)

> But you would get some support from the revisors in the Communications
> Department. The same goes for computer users who need help properly using
> their equipment.

The Administrator can't help the users to browse web-sites. He could
turn cookies off (and lots of sites won't work) or he could offer opt-in
or opt-out lists (which always could be incomplete). Unfortunately most
of the web site designers don't care about this. They just write
horrible web pages.

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
> The software under discussion does NOT report the contents of your hard drive.

Okay - than the meat will report how it will be eaten.

> While I'm not going to delete my Eudora (or any other software) over
> this issue. I do agree that openness is very important. There should be
> disclosure and users should be informed in a direct, obvious way (not
> through some fine print in the user license).

Indeed.



> > BTW: In some countries software behaviour like this could be illegal.
>
> Name three.

I can tell you one: Germany. The Datenschutzgesetz (sorry, I don't know
a translation, perhaps "law for protecting personal data") is quite
strong here and that's good, I think. The consumer should be informed so
that he knows what happens with his data. And the feature should be
opt-in and not opt-out.

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
> I can barely read this NG anymore with all the bitching and
> complaining going on.

Two possibilities: a) we're wrong, b) you're ignorant/blinded. Or
something between a) and b).

>Perhaps you and Mr. Wise can start your own NG (maybe
>alt.whine.whine.whine.whine.and.don't.listen.to.anyone).

I don't know Mr. Wise. I can only speak for myself and the message
you're responding to was my second in this thread. Perhaps you're a bit
too sensitive.

To say "Go away" is quite easy.

John Purlia

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
In article <nospam-A4ACF9....@enews.newsguy.com>, Michael Wise

<nos...@nospam.net> wrote:
> For weeks, Qualcomm made it a red herring issue..by claiming that
> no usage stats info is sent w/o user consent...ignoring that we werent
> complaining about the marketing data transmissions, but rather the
> connections to jump.eudora.com.

This is patently untrue. We've never denied or in any other way attempted
to deceive our users about the information transmitted to our servers.
Again, no usage stats are sent without the user's explicit consent. We
have been very responsive to questions and concerns by the user community
as these issues have been raised.

> They went on to assure us that the only info that was being sent was platform,
> Eudora version, and registration info. That may be fine for you and some
> others....but it is not fine for me and many others.

"Many" is a very, very small number judging from the few complaints that
persist beyond the simple communication of what these connections actually
contain. In the vast majority of cases, clear definition of the jump
connection is readily understood and accepted. Still, we understand that
it is difficult to satisfy everyone's measure of security, and there
remain a few users for whom any connection at all is a problem.

> Great, but Qualcomm not only did not tell people how to turn it off, but
> they didn't even document that it existed in the first place. In fact,
> they tried to deny it when confonted on it. They told us how to turn it
> off only after scores of people cmplained about it.

Please cite an example of any denial. We've been very forthcoming about
how Eudora interacts with our servers. Usenet is an interesting medium,
often prone to misinterpretation and confusion. If such disconnect
occurred with the launch of Eudora 4.3, we deftly apologize, but in no
manner have we ever attempted to deceive any of our users.

Hey, we write code, it's not in our nature to deceive. :)

-- John

...........................................................................
John Purlia : John's CD pick of the day:
Mac Programmer Guy :

QUALCOMM, Inc. : "Royal"
Travel: None! : The Amazing Crowns

Götz Hoffart

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
> While it is true that Eudora will contact our server from time to time,
> that information that is transmitted is always the bare minimum
> non-personal information required to perform a particular task.
> [...]

> So, the query includes things like:
>
> Eudora version number
> Platform (Mac, Windows or whatever)
> Registration Code
> etc...
>
> I know it's a great leap of faith, but you just have to trust us when we
> claim that no personal information is transmitted to our servers without
> your consent.

I guess you're not responsible for documentation but I'll ask anyway:
Why did Qualcomm not document this in the manual? If they did it would
be not such a trouble here as it is now and you needn't have to ask us
to trust Qualcomm. Do you understand me? (damn if I had spent more time
on English in school I would probably not post into newsgroups or own a
computer at all :-)

Gerd Brodowski

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
Goetz Hoffart <go...@nogfradelt.de> wrote:

> > > BTW: In some countries software behaviour like this could be illegal.
> >
> > Name three.
>
> I can tell you one: Germany. The Datenschutzgesetz (sorry, I don't know
> a translation, perhaps "law for protecting personal data") is quite
> strong here and that's good, I think. The consumer should be informed so
> that he knows what happens with his data. And the feature should be
> opt-in and not opt-out.

As far as I know (my university time is a long time ago) another country
is Sweden. It has a much stronger law (Datenschutzgesetz) than the
german one. (Is there a guy from Sweden around here ?!)

Gerd

gr...@apple2.com.invalid

unread,
Aug 14, 2000, 3:00:00 AM8/14/00
to
In article <jpurlia-1408...@dhcp000619162153.qualcomm.com>,
John Purlia <jpu...@qualcomm.com> wrote:

> While it is true that Eudora will contact our server from time to
> time, that information that is transmitted is always the bare minimum
> non-personal information required to perform a particular task.

:
> Eudora version number
> Platform (Mac, Windows or whatever)
> Registration Code
> etc...

Excuse me, but isn't the "Registration Code" personally identifying
information, serving as an index into your registration information
database?

--
__ _____________ __
\ \_\ \__ __/ /_/ / <http://www.war-of-the-worlds.org/>
.\ __ \ | | / __ /----------------------------------------------------
^ \_\ \_\|_|/_/ /_/ Don't mail me, I'll mail you.

Darrel E. Knutson

unread,
Aug 15, 2000, 12:21:27 AM8/15/00
to
In article <1efd7sr.ymma3rzg8on4N%go...@nogfradelt.de>,
go...@nogfradelt.de (=?ISO-8859-1?Q?G=F6tz_Hoffart?=) wrote:

>I can tell you one: Germany. The Datenschutzgesetz (sorry, I don't know
>a translation, perhaps "law for protecting personal data") is quite
>strong here and that's good, I think. The consumer should be informed so
>that he knows what happens with his data. And the feature should be
>opt-in and not opt-out.

I have translated it in the past as Germany's Data Protection Law. It
really is quite restrictive, even to the point that employers are not
allowed to exchange the personal telephone numbers of employess with
anyone, including other employees.

In German Web space I have never seen a "people finder" service with
information about the addresses and location of people in this country. At
WebCrawler and Yahoo! I can easily find the exact location of my brother's
house on a map of of the USA - all I need to know is his name and the state
he lives in. I can also see a satellite photo of my mother's house at
Microsoft's Terra Server. And of course the telephone numbers, e-mail
addresses, local adresses, etc. This is simply not allowed in Germany and
it may soon apply to all of the European Union.

The EU is a larger market that the US of A, so in this respect, the EU is
setting the international standards for personal privacy while the US is
still trying to force Europeans to allow the import of hormone-treated
beef. And here we are back at meat again. :)

Darrel

--
Internet Trainer <http://darrel.knutson.com/>
Roedingsmarkt 14 <mailto:dar...@knutson.com>
20459 Hamburg, Germany GSM/D2: +49 (0)173/2088764

Darrel E. Knutson

unread,
Aug 15, 2000, 12:21:26 AM8/15/00
to
In article <jpurlia-1408...@dhcp000619162153.qualcomm.com>,
jpu...@qualcomm.com (John Purlia) wrote:

>I know it's a great leap of faith, but you just have to trust us when we
>claim that no personal information is transmitted to our servers without
>your consent.

If I were worried about Eudora doing that I would have switched to Outlook
Express long ago. :)

It would be nice to supply us with the URL of Qualcomm's privacy policy and
keep us updated of any changes.

Greg

unread,
Aug 15, 2000, 3:00:00 AM8/15/00
to
On Mon, 14 Aug 2000 20:17:48 GMT, gr...@apple2.com.invalid wrote:

>Excuse me, but isn't the "Registration Code" personally identifying
>information, serving as an index into your registration information
>database?

Yes, but they don't talk to each other. That's intended.

Michael Wise

unread,
Aug 15, 2000, 3:00:00 AM8/15/00
to


> > > What exactly does the Paid version do?
> >
> > http://www.deja.com/[ST_rn=ps]/qs.xp?ST=PS&svcclass=dnyr&firstsearch=yes
> > &
> > QRY=jump.eudora.com&defaultOp=AND&DBS=1&OP=dnquery.xp&LNG=english&subjec
> > t
> > s=&groups=comp.mail.eudora.mac&authors=&fromdate=&todate=&showsort=score
> > &
> > maxhits=25
>
> Just to clarify things a bit...
>
> The query string posted above was NOT generated by Eudora, nor was it
> trasmitted by Eudora. The text above is from a news server query created
> by your news reader. None of the fields (groups, subject, authors) are
> generated by Eudora (I know, I wrote the code that generates our jump
> actions).


I never claimed it was generated by Eudora. Post a deja search results
URL (on jump.eudora.com), so that all the people asking what it does can
go back to the discussion we hashed out in this n.g. back in March.


> While it is true that Eudora will contact our server from time to time,
> that information that is transmitted is always the bare minimum
> non-personal information required to perform a particular task.

Great, with three provisions:

1) Ask our permission first
2) Document what is being sent, to whom its being sent, and why.
3) Make it veru easy for the user to disable this "feature"

> For example, the update and archive queries that are transmitted in any
> mode (including Paid mode -- and these are the only Paid mode queries)
> transmit information required by Eudora to dynamically figure out which

> versions of Eudora are available to you as an update. So, the query
> includes things like:
>

> Eudora version number
> Platform (Mac, Windows or whatever)
> Registration Code
> etc...


Great, but as I said, unless you ask for the user's permission...all of
this is none of your business.

> I know it's a great leap of faith, but you just have to trust us when we
> claim that no personal information is transmitted to our servers without
> your consent.


That trust is hard to extend when you slipped in this "feature" with no
documentation whatsoever, made it on by default, and only told us how to
turn it off after several days of ranting. If I want Qualcomm to know my
and my users' OS, version, and reg data...I will give it to you. It is
not your perogative to take w/o asking.


--Mike

Michael Wise

unread,
Aug 15, 2000, 3:00:00 AM8/15/00
to

>
> > They went on to assure us that the only info that was being sent was
> > platform,
> > Eudora version, and registration info. That may be fine for you and
> > some
> > others....but it is not fine for me and many others.

> "Many" is a very, very small number judging from the few complaints that
> persist beyond the simple communication of what these connections
> actually
> contain.

Tha's because the vast majority of Eudora non-power users probably don't
even notice it's happening. And if they did see the quick transaction,
they probbly wouldn't think anything of it. "Hmmm, must be part of the
Eudora initialization process.


Try this experiment. Instead of a small progress window saying
"connecting to jmup.eudora.com" which quickly blows by, try this:

Make a big half-screen modal dialog with 18pt bold red letters saying:


"Your copy of Eudora is connecting to a Qualcomm server to transmit what
platform you are using, what OS version you are using, and your
registration information. Trust us, we're not getting any other data
about you like Microsoft did, like Real did, and like millions of
cookies do...just trust us....we're doing this for your own good."

See if the complaints are "few" then.


> In the vast majority of cases, clear definition of the jump
> connection is readily understood and accepted. Still, we understand that
> it is difficult to satisfy everyone's measure of security, and there
> remain a few users for whom any connection at all is a problem.


> > Great, but Qualcomm not only did not tell people how to turn it off,
> > but
> > they didn't even document that it existed in the first place. In fact,
> > they tried to deny it when confonted on it. They told us how to turn it
> > off only after scores of people cmplained about it.
>
> Please cite an example of any denial. We've been very forthcoming about
> how Eudora interacts with our servers. Usenet is an interesting medium,
> often prone to misinterpretation and confusion. If such disconnect
> occurred with the launch of Eudora 4.3, we deftly apologize, but in no
> manner have we ever attempted to deceive any of our users.

I gave the deja search URL earlier, re-read the threads yourself. I and
others asked repeatedly about this issue back in March. And each time,
we got responses from people (yourself included) that no personal data
was being sent w/o our permission. We weren't asking about that, we were
asking about jump.eudora.com. It took several days to get you to answer
that question directly...and eventually how to turn it off.


> Hey, we write code, it's not in our nature to deceive. :)


I'm not saying you personally do. Eudora is a great product...something
most of here will agree on. However, I find it hard to believe that the
jump.eudora.com was a software engineer's idea to put into a product. It
stinks of marketing big time. How can you be sure what is done with the
info?

Will you publicly state on this n.g. as a representive of Qualcomm that
the small amount of data gleaned by the jump.eudora.com connections will
never be used for anything other than determining upgrade eligibility???
Also, WTF does my reg number have to do with upgrade eligibility?

John Purlia

unread,
Aug 16, 2000, 3:00:00 AM8/16/00
to
In article <0fpjpsc2tkdvih68u...@4ax.com>, Greg
<g...@spamcop.net> wrote:

Actually, the registration code is cleverly self-validating -- there are
no database lookups required. So... nope, we don't index into a table to
determine whether or not a reg code is valid.

-- John

...........................................................................
John Purlia : John's CD pick of the day:
Mac Programmer Guy :

gr...@apple2.com.invalid

unread,
Aug 16, 2000, 3:00:00 AM8/16/00
to
In article <jpurlia-1608...@dhcp000619162153.qualcomm.com>,
John Purlia <jpu...@qualcomm.com> wrote:

>Greg <g...@spamcop.net> wrote:
>>gr...@apple2.com.invalid wrote:

>>> Excuse me, but isn't the "Registration Code" personally identifying
>>> information, serving as an index into your registration information
>>> database?

>> Yes, but they don't talk to each other. That's intended.

> Actually, the registration code is cleverly self-validating -- there are
> no database lookups required. So... nope, we don't index into a table to
> determine whether or not a reg code is valid.

But, since it is an index into a database of personal information, it is
itself a personally and uniquely identifying piece of information that
I'd rather not be sent at all. It's bad enough that my static IP
address has to be disclosed just to send the information.

Paolo G. Cordone

unread,
Aug 17, 2000, 3:00:00 AM8/17/00
to
In article <greg-3t30den...@news.binary.net>,
gr...@apple2.com.invalid wrote:

> It's bad enough that my static IP
> address has to be disclosed just to send the information.

Why is this so bad that such information is sent? Do you feel your privacy
is equally violated when you drive your car and the registration plate is
so openly displayed to the public? Mmm, I guess the police would be able to
find a correlation between number and your personal details...so we better
take that off the car right away! <grin>

Paolo

Maintainer of the Online Classical-CD Stores FAQ.
http://indigo.ie/~pamolo/faq.html

Gregory

unread,
Aug 18, 2000, 3:00:00 AM8/18/00
to
In article <B5C1FB47...@ts04-056.dublin.indigo.ie>, Paolo G.
Cordone <pam...@indigo.ie> wrote:

: In article <greg-3t30den...@news.binary.net>,


: gr...@apple2.com.invalid wrote:
:
: > It's bad enough that my static IP
: > address has to be disclosed just to send the information.

:

Tapping a phone line or wireless requires a court order for a reason.
Opt-in rather than opt-out public policy on privacy.
You can't wire-tap a fax, therefore, you can't on a data/DSL or
dial-up.

tracking.

A firewall can filter information based on domain or content from being
sent out as well as in. So I guess I could add jump.eudora to the
list.

If it looks like___ it must be.

Email needs to be protected speech like a phone, "personal effects" and
first-class mail. My name, my registration number, domain name/number,
time Eudora is open, email sent/recv'd, sent to jump?

Ads in sponsored mode are benign, but we all know that what was benign
ten or five yrs ago can be abused. VBS offers powerful, useful
features, and an open door to trojan horses. Can Workgroups be abused
- my "trusted" circle?

Just don't add scripting into Eudora.

Greg

gr...@apple2.com.invalid

unread,
Aug 20, 2000, 3:00:00 AM8/20/00
to
In article <B5C1FB47...@ts04-056.dublin.indigo.ie>,
Paolo G. Cordone <pam...@indigo.ie> wrote:
>gr...@apple2.com.invalid wrote:

>> It's bad enough that my static IP
>> address has to be disclosed just to send the information.

> Why is this so bad that such information is sent? Do you feel your

> privacy is equally violated when you drive your car and the
> registration plate is so openly displayed to the public? Mmm, I guess
> the police would be able to find a correlation between number and your
> personal details...so we better take that off the car right away!
> <grin>

More if the license plate communicated with data poles along the road
that knew I passed point A at time T0 and point B at time T1 and can
compute that I had to be going at least S miles per hour to traverse
that distance in that time. Much like what those of you with those
electronic toll tags on your cars are exposing yourselves. Funny how a
device that let's you pass through toll stations and pay without
stopping so you can save a little time also serve to monitor your speed
everywhere else so you don't save too much time.

In these same places you've got your social security number as your
driver's license number which is also encoded in a magstripe on the back
of your license which store owners love to read to make sure they can
accept your check.

And then there's the recent consideration of requiring all new cars to
have an external indicator to tell police whether the driver is wearing
his seat belt. Why not make it a law that every car has to have a
large, easily read external indicator of its speed while they're at it?

The license plate of my car doesn't create a definitive electronic
record of my whereabouts that can be retrieved at a later date for who
knows what reason.

Would you like a wallet that electronically broadcasts a signal telling
how much money you're carrying that anyone could intercept with the
right equipment just so that airport security can enforce the laws
restricting how much cash you can have on you when you fly? It sure
would improve the efficiency of the operation of your average mugger.

All that said... I allowed an electronic device to capture just how I
sign my name on a credit card receipt--not just my static signature but
also the sequence of pen strokes necessary to recreate it, including
velocity and pressure--so that I could get an additional $100 rebate on
an electronic consumer item that has the potential to reveal my personal
television viewing habits to another company every day over the
telephone. The same hour I see its manual say that my viewing data stay
on the device and not communicated to the home office I read that the
company just came to an agreement with the people behind creating
Nielsen ratings to include me and every other owner of such devices in
their statistics.

Privacy and security are practically non-existent these days for the
average citizen. The governments don't need to be Big Brother; the
private sector fills that role quite well itself. It's an information
industry that sucks up all the information we leak everywhere we go and
repeatedly tempts us to reveal more and more. Those who don't give away
this commodity find themselves disadvantaged more and more each day.

You know what the really scary part is? It's not that there is so much
information about you out there that it becomes pointless to try to
protect it. It's not that there are more and more laws being put on the
books making failure to disclose information criminal and criminalizing
methods attempting to protect it. It is that the information flows only
one way, but that no one knows where. Sure it circles, it accumulates
here and there, but can never know exactly where it will end up. It's
kept away from your eyes, somewhere you can never see, just beyond the
horizon.

Well, that's enough that. I'll close with a couple of my favorite
quotes:

"My people have a saying: `A man who trusts can never be betrayed, only
mistaken.'"
"Life expectancy must be fairly short amongst your people."
-- Mission to Destiny

"Surely now you can allow yourselves to trust me."
"`He who trusts can never be betrayed, only mistaken.' Cally once told
me that that was a saying amongst her people."
"Cally?"
"Cally was murdered. So were most of her people."
-- Rescue

Paolo G. Cordone

unread,
Aug 20, 2000, 3:00:00 AM8/20/00
to
In article <greg-7t5967n...@news.binary.net>,
gr...@apple2.com.invalid wrote:

> And then there's the recent consideration of requiring all new cars to
> have an external indicator to tell police whether the driver is wearing
> his seat belt. Why not make it a law that every car has to have a
> large, easily read external indicator of its speed while they're at it?

I actually would welcome this feature. It would not bother me at all, since
I have always perceived such mechanisms as a measure to protect me from
lunatics rather than as something to prevent me from doing a particular
action (failing to wear a seat belt or breaking the speed limit, in your
example).

> Would you like a wallet that electronically broadcasts a signal telling
> how much money you're carrying that anyone could intercept with the
> right equipment just so that airport security can enforce the laws
> restricting how much cash you can have on you when you fly? It sure
> would improve the efficiency of the operation of your average mugger.

I think you are exaggerating a bit here. Something like this would be
totally superfluous, since the exact amount of money I carry with me in my
wallet can be easily verified by an airport security officer; conversely,
it would be impractical to stop my car and ask me what speed I was doing a
few seconds earlier. That's when an electronic velocity checking device
would be useful. And anyway, to return to the wallet, even if it were to
broadcast the amount of money, I would simply not put the "extra" in the
wallet itself, but hide it somewhere else.

> Privacy and security are practically non-existent these days for the
> average citizen. The governments don't need to be Big Brother; the
> private sector fills that role quite well itself. It's an information
> industry that sucks up all the information we leak everywhere we go and
> repeatedly tempts us to reveal more and more. Those who don't give away
> this commodity find themselves disadvantaged more and more each day.

I am not sure whether your last statement is really true. In what sense do
they find themselves disadvantaged?
In general, though, I agree with your conclusion although, personally
speaking, this does not bother me too much. I have been a netizen for many
years and have seen online personal privacy change a lot and virtually fade
away...it has had no negative effect on my personal life, as I tend not to
put sensitive information in "open" places and at the end of the day have
nothing to hide. Of course, I still value my bank's strong encryption
capability when doing online transactions ;-)

Gregory

unread,
Aug 21, 2000, 3:00:00 AM8/21/00
to
In article <B5C609DC...@ts02-063.dublin.indigo.ie>, Paolo G.
Cordone <pam...@indigo.ie> wrote:

: I have been a netizen for many


: years and have seen online personal privacy change a lot and virtually fade
: away...it has had no negative effect on my personal life, as I tend not to
: put sensitive information in "open" places and at the end of the day have
: nothing to hide. Of course, I still value my bank's strong encryption
: capability when doing online transactions ;-)
:
: Paolo

Five to ten years ago I didn't need to disguise my email address.

Didn't have to fear or understand that web sites have embedded fake ftp
commands to trick a web browser into sending email address for
anonymous ftp (yes, you can, and should, uncheck this option in your
browser).

Gregory

Gregory

unread,
Aug 21, 2000, 3:00:00 AM8/21/00
to
In article <210820000924374534%greg...@mac.com>, Gregory
<greg...@mac.com> wrote:

: In article <B5C609DC...@ts02-063.dublin.indigo.ie>, Paolo G.

:
From today's NY Times (8/21/00):

Consumers' Views Split on Internet Privacy
http://www.nytimes.com/library/financial/082100pew-survey.html

: As for efforts to protect their privacy, the survey indicated that many
: Internet users were either unaware of how they were being monitored
: online or unlikely to take steps to prevent being tracked. The report
: noted that 56 percent of Internet users could not identify the primary
: online tracking tool -- a "cookie" file placed on a user's computer by
: a Web site -- and only 10 percent of the Internet users had set their
: browser software to reject cookies.
:

Now that is scary.

Hank Zimmerman

unread,
Aug 21, 2000, 3:00:00 AM8/21/00
to
In article <210820000953035508%greg...@mac.com>, Gregory
<greg...@mac.com> wrote:

>Consumers' Views Split on Internet Privacy
>http://www.nytimes.com/library/financial/082100pew-survey.html
>
>: As for efforts to protect their privacy, the survey indicated that many
>: Internet users were either unaware of how they were being monitored
>: online or unlikely to take steps to prevent being tracked. The report
>: noted that 56 percent of Internet users could not identify the primary
>: online tracking tool -- a "cookie" file placed on a user's computer by
>: a Web site -- and only 10 percent of the Internet users had set their
>: browser software to reject cookies.
>
>Now that is scary.

I find it scary that the "best" solution to "evil" cookies is to turn
them off completely. There are many web sites out there that use cookies
as they were intended (Slashdot, VersionTracker, etc.).

The solution is to use iCab (or another program) that allows you to
accept/reject cookies based on domains.

I have not set iCab to reject all cookies, does that make me in the
ignorant 90%? I would hope not, I am a persn who examines what the
cookie data actually is before accepting/rejecting. How could you do
online shopping (or any other activity like that) without cookies?

Blindly rejecting all cookies is just as ignorant as not knowing what
they are.

ObEudora:Eudora cannot access your cookies, which means that any HTML
mail that tries to relate your email address to a cookie is not going to
work.

ObEudora2: Unchecking "Automatically download HTML graphics" (in
Settings:Fonts & Displays) is a very good idea.
--
Hank Zimmerman maintains the comp.mail.eudora.mac FAQ
It can be found at <http://www.ka.net/eudora/faqs/>
The [Unofficial] Eudora Web Site can be found at <http://www.emailman.com/eudora/>
(c) 2000 Hank Zimmerman

E Right

unread,
Aug 21, 2000, 11:57:42 PM8/21/00
to
In article <nospam-A4ACF9....@enews.newsguy.com>, Michael Wise
<nos...@nospam.net> wrote:

"In article <kevans-9A9714....@news.videotron.ca>, "K.-Benoit
"Evans" <kev...@videotron.ca> wrote:
"
"> > The latter is what I'm yalking about. Qualcomm slipped it in quietly,
"> > and it wasn't till people (yours truly included) concerned about their
"> > privacy took Qualcomm to task about it repeatedly on this group that
"> > they finally admitted it...but then tried make it out to be a feature
"> > for our own good.
"> >
"> > They finally told us how to disable this "feature"
"> >
"> > ---------------------------------------
"> > <x-eudora-setting:305> When checked, Eudora will occasionally check to
"> > see if software updates are available. Setting reversed; use "n" for
"> > ON,
"> > "y" for OFF! To use the setting feature, open a new message window and
"> > type: <x-eudora-setting:305>
"> > ---------------------------------------


">
"> I have LOTS of software that does this, including RealPlayer, QuickTime
"> and Sherlock. Even NetBarrier, a firewall to detect unauthorized
"> computer us, has this feature. Some of them do not even give you the
"> choice of turning it off.
"

"It's not the concept of software checking the net to see if there's a
"newer version which is bothersome. Rather, when software does it without
"the knowledge or consent of the end-user who pays money for that
"software.

some people choose not to "register" their software products - and the
software screams - does your computer HARDWARE manufacturer make you
register it - and "their" software screams?


" Qualcomm slipped it into Eudora without mentioning anything
"about it in the documentation or read-me's which came with the product.
"All of the sudder, those of us who got the new version of Eudora started
"noticing our paid versions of Eudora making non user-controlled
"connections to Qualcomm. We didn't know why it was doing it and what was
"being sent...which in recent times is not the best way to keep customer
"trust. For weeks, Qualcomm made it a red herring issue..by claiming that

"no usage stats info is sent w/o user consent...ignoring that we werent
"complaining about the marketing data transmissions, but rather the

"connections to jump.eudora.com. Finally they said, that yes, even the
"paid versions do this. They went on to assure us that the only info that

"was being sent was platform, Eudora version, and registration info. That
"may be fine for you and some others....but it is not fine for me and
"many others.
"

"Qualcomm should not have the right to use my internet connection, so
"that my paid client can transfer info to them without my knowledge.
"Companies like Quark do this...however, I expected much better from the
"likes of Qualcomm. My client platform, client version, and
"particularly...my registration info are none of their business to track
"once I have paid for an registered their product. If they wish to get
"that info as a "feature" for my benefit, then they can ask me for
"it...and not enable it undocumented and on by default. At least they
"finally told us how to turn it off.
"
"
"
"> And for me, this is a feature. It is nice to know without having to
"> check with the software author or reading press releases that an update
"> is available. Most let me turn it off. And, in fact, I don't use it in
"> Eudora...


"
"Great, but Qualcomm not only did not tell people how to turn it off, but
"they didn't even document that it existed in the first place. In fact,
"they tried to deny it when confonted on it. They told us how to turn it
"off only after scores of people cmplained about it.
"
"

"--Mike

Michael Wise

unread,
Aug 23, 2000, 3:00:00 AM8/23/00
to
In article <1efskbo.13lkfcy19p93rkN%may00_...@engelmeier.com>,
may00_...@engelmeier.com (Thomas Engelmeier) wrote:


> > "that my paid client can transfer info to them without my knowledge.
> > "Companies like Quark do this...however, I expected much better from the
> > "likes of Qualcomm.
>

> XPress only does this if you have an extension for internet based
> information installed (the copy protection won't dial up).


If you're not running AppleTalk as a WAN-routed protocol, you would be
right.

However, Quark has a well earned rep of bringing up AppleTalk WAN links
to see if there is anybody else on the AT WAN using the same copy. I
found this out the hard way after I got the ISDN bill from my former
company's CEO. He had BRI ISDN at his house (this was well before xDSL
and cable modems) and we were routing both AT and IP between his house
and work. Anytime anybody in our office or his house launched Quark
Xpress, it would bring up the WAN ISDN link to see if there were any
other copies running.

I stand by my earlier statements.

--Mike

kr...@my-deja.com

unread,
Sep 1, 2000, 2:59:56 AM9/1/00
to
In article
<chz1-FDB3FF.1...@nntp.iglou.
com>,
Hank Zimmerman <ch...@cornell.edu>
wrote:

> I have not set iCab to reject all cookies, does
that make me in the
> ignorant 90%? I would hope not, I am a
persn who examines what the
> cookie data actually is before
accepting/rejecting. How could you do
> online shopping (or any other activity like
that) without cookies?

Ask Amazon. You can navigate a purchase (or
at least you could) without cookies.

> Blindly rejecting all cookies is just as
ignorant as not knowing what
> they are.

I merely set my cookies to only be set if the
cookie is being set for the server I am on. No
doubleclick cookies!

I also wipe them frequently.

kreme at some mail service hosted by apple.
Want to email me? Figure it out.


Sent via Deja.com http://www.deja.com/
Before you buy.

kr...@my-deja.com

unread,
Sep 1, 2000, 3:05:31 AM9/1/00
to
In article
<nospam-A4ACF9....@enews.newsguy.com>,
Michael Wise <nos...@nospam.net> wrote:> Great, but

Qualcomm not only did not tell people how to turn it off, but
> they didn't even document that it existed in the first place. In fact,
> they tried to deny it when confonted on it. They told us how to turn
it
> off only after scores of people cmplained about it.

Now wait a second. I just pulled up the original discussion about
this in um... May? there were about a dozen posts total. the
separating between the initial post onthe subeject on the 13th and
Someone from Qualcom telling you how to disable it was, IIRC, a
day.

Now... do i think Qualcomm dropped the ball on this one a little?
Yeah. They should have used the standard Version checking
protocol that Interarchie (neé anarchie) use. very stright forward,
available, standard, etc.

Fine. They didn't. But they did tell you how to disable it, and it did
not involve scores of people complaining about it.

Gregory

unread,
Sep 2, 2000, 10:14:59 AM9/2/00
to
In article <8onkfl$n00$1...@nnrp1.deja.com>, <kr...@my-deja.com> wrote:

: In article

I went to link on Eudora and the setting is for Windows, doesn't work
for Mac Eudora 5.0b. I don't have Alt-key and I expect dual-platform
explanations. Not "be nice, bend over backwards" 2nd class citizen Mac
user. <x-eudora-option:DontShowUpdates=1>

PC World just posted/wrote an article on Eudora and their little
logo-ads (3Com). Delayed response of the publishing world.

<http://www.pcworld.com/shared/printable_articles/0,1440,18335,00.html>

Add that to the Word.doc security item that "phones home" to an
embedded 1-pixel graphic on a web page, and you have a paranoid's worst
nightmare imaginable. So you can track a document. Clever, useful, and
totally "spy-ware."

Camellion and Echelon and Microstuff...

I wasn't using Eudora in May, I was back to Outlook.

When I pay, I want clear preferences. There are hundreds of special
settings!

I don't trust or use Apple's Software Update to DO the update - I rely
on versiontracker. I don't use NAV, iCab's or Intego NetBarrier to
auto-update OR inform. The fact Netscape had a useless "smart update"
that did transmit some data doesn't help.

Who needs upgrade notification?

I know lots of people that don't know how to manage and update their
software one bit, they're online but don't check, don't try or know how
to download/install and haven't upgraded Stuffit Expander in years.
Maybe this is great for those people.

Scenerio:

Someone sends me a Word doc with embedded graphic that links to a web
site, I have Eudora (wrongly) set to display html and graphics etc. and
"1000 of web-enabled apps and you have a nightmare of "spying."
This week's stock hoax news.

Technocracy?

Net-centric: where a telephone logs calls for NSA of every call to
Isreal. Fridge calls the store to order milk 'n eggs.

License agreements to use or download or install. No blanket agreement.
And still be able to use the software w/o the feature/option.

Gregory

John Purlia

unread,
Sep 2, 2000, 4:14:03 PM9/2/00
to
In article <020920000914598334%greg...@mac.com>, Gregory

<greg...@mac.com> wrote:
> I went to link on Eudora and the setting is for Windows, doesn't work
> for Mac Eudora 5.0b. I don't have Alt-key and I expect dual-platform
> explanations. Not "be nice, bend over backwards" 2nd class citizen Mac
> user. <x-eudora-option:DontShowUpdates=1>

Unfortunately, much of the computing press seems to fail to realize that
there are multiple platforms in the world, so quite often links to Mac
tips and instructions are ignored.

In this case, go to:

<http://www.eudora.com/techsupport/kb/2058hq.html>

for the Eudora Tech Support information about how to disable the update pages.

Michael Wise

unread,
Sep 2, 2000, 5:03:12 PM9/2/00
to
In article <8onkfl$n00$1...@nnrp1.deja.com>, kr...@my-deja.com wrote:

> In article
> <nospam-A4ACF9....@enews.newsguy.com>,
> Michael Wise <nos...@nospam.net> wrote:> Great, but
> Qualcomm not only did not tell people how to turn it off, but
> > they didn't even document that it existed in the first place. In fact,
> > they tried to deny it when confonted on it. They told us how to turn
> it
> > off only after scores of people cmplained about it.
>
> Now wait a second. I just pulled up the original discussion about
> this in um... May?

Incorrect. The original discussion about this (which I provided a Deja
link to) was in March. There were far more than a dozen posts about it,
and Qualcomm spent several days clouding the issue by repeating their
stance that no user data was being sent w/o the user's consent.
Basically, they kept giving the "UsageStats" response to question about
jump.eudora.com connections. These are two very separate issues.

> there were about a dozen posts total. the
> separating between the initial post onthe subeject on the 13th and
> Someone from Qualcom telling you how to disable it was, IIRC, a
> day.
>
> Now... do i think Qualcomm dropped the ball on this one a little?
> Yeah. They should have used the standard Version checking
> protocol that Interarchie (neé anarchie) use. very stright forward,
> available, standard, etc.
>
> Fine. They didn't. But they did tell you how to disable it, and it did
> not involve scores of people complaining about it.


Sure it did, go back further and read a little closer.


--Mike

Michael Wise

unread,
Sep 3, 2000, 3:45:48 PM9/3/00
to
In article <syth-72192A.1...@news.uswest.net>, Cerebus91
<sy...@mac.com> wrote:


> > > Michael Wise <nos...@nospam.net> wrote:> Great, but
> > > Qualcomm not only did not tell people how to turn it off, but
> > > > they didn't even document that it existed in the first place. In
> > > > fact,
> > > > they tried to deny it when confonted on it. They told us how to
> > > > turn
> > > it
> > > > off only after scores of people cmplained about it.
> > >
> > > Now wait a second. I just pulled up the original discussion about
> > > this in um... May?
> >
> > Incorrect. The original discussion about this (which I provided a Deja
> > link to) was in March.
>

> OK. March. The link I followed was the link you provided. I don't see
> the scores of people or the dozens of messages

The link I provided was to just one thread about the topic. There were
several threads going on about it.

--Mike

Robert D. Reynolds

unread,
Sep 16, 2000, 3:00:00 AM9/16/00
to
In article <brianb1-032DA2.17590816092000@news>, Brian Barjenbruch
<bri...@home.com> wrote:

> > In your Eudora Folder (in the System folder) you will find a file called
> > "UsageStats".
>
> [snip]
>
> If you want to stop Eudora from spying on you like this, all you have to
> do is create a *folder* named UsageStats and then lock it. Eudora won't
> be able to replace a folder with a file, and it will leave it alone.

How do you "lock" a folder?

--
=====
mailto:Robert.D...@ASU.Edu
http://www.asu.edu/cfa/music/
http://www.public.asu.edu/~reynolds

0 new messages