selenium icon indicating copy to clipboard operation
selenium copied to clipboard

[🐛 Bug]: Cannot opt out of telemetry, please don't enable it by default without user consent

Open ghost opened this issue 1 year ago • 10 comments

What happened?

I can't find a way of avoiding sending telemetry.

export SE_AVOID_STATS just does not work.

I also believe that it is not the best to enable telemetry by default and then let users disable as long as they find out...

It should be the other way around: If the user wants, they can opt-in.

I'm ~~not~~ entirely sure this is ok in EU.

How can we reproduce the issue?

## Testcase

export SE_AVOID_STATS; python main.py
trying proxy:xxx.xxx.xxx.xxx:4145

Error sending stats to Plausible: error sending request for url (https://plausible.io/api/event)

Relevant log output

Error sending stats to Plausible: error sending request for url (https://plausible.io/api/event)

Operating System

Debian

Selenium version

python 4.25.0

What are the browser(s) and version(s) where you see this issue?

Firefox 115.16.1esr

What are the browser driver(s) and version(s) where you see this issue?

geckodriver0.35.0

Are you using Selenium Grid?

No response

ghost avatar Oct 24 '24 10:10 ghost

@alithechemist, thank you for creating this issue. We will troubleshoot it as soon as we can.


Info for maintainers

Triage this issue by using labels.

If information is missing, add a helpful comment and then I-issue-template label.

If the issue is a question, add the I-question label.

If the issue is valid but there is no time to troubleshoot it, consider adding the help wanted label.

If the issue requires changes or fixes from an external project (e.g., ChromeDriver, GeckoDriver, MSEdgeDriver, W3C), add the applicable G-* label, and it will provide the correct link and auto-close the issue.

After troubleshooting the issue, please add the R-awaiting answer label.

Thank you!

github-actions[bot] avatar Oct 24 '24 10:10 github-actions[bot]

I just saw my mistake: it should be:

export SE_AVOID_STATS=true; python main.py

and not

export SE_AVOID_STATS; python main.py

My request about requiring user consent in order to collect data remains anyway.

ghost avatar Oct 24 '24 10:10 ghost

@diemol why not changing the --selenium-manager=true CLI switch to e.g. --selenium-manager analytics_agreed and --selenium-manager no_analytics? The same logic could be used for the RemoteWebdriverBuilder, this will ensure a user does explicit give his consent or not to analytics. I know it should default to true in Selenium 5, this can not be done in this case. I think adding propper documentation and a hint inside the exceptions should lead people to use the selenium-manager.

Another option might be to change the client API to enforce in setting the (dis)agreement and send it to the server inside a se:manager capability, defaulting to no_analytics (in case someone is using outdated client libs). The --selenium-manager flag could still be used to enable / disable the selenium manager feature on the server in general. In this case the --selenium-manager flag could default to true in Selenium 5.

joerg1985 avatar Oct 29 '24 08:10 joerg1985

Honestly:

  1. It happened that i saw the error about not being able to reach plausible.io DESPITE i set the environmental variable SE_AVOID_STATS=true;
  2. It is faster to put plausible in the hosts file with 0.0.0.0 ... honestly...

ghost avatar Oct 29 '24 09:10 ghost

It happened that i saw the error about not being able to reach plausible.io

Just become aware of Selenium's telemetry-by-default myself thanks to a similar error showing up in my test logs. I'd second the OP's opinion that telemetry should be by explicit opt-in consent only. In the meantime could someone point me to the relevant parts of Selenium's user agreement and to the docs which show how to opt out of telemetry, thanks.

MatzFan avatar Dec 01 '24 19:12 MatzFan

I'd be interested to know about the outcome of the #14880 as it seems it was moved into a private conversation over email. This is also a request for transparency.

Thanks in advance!

ghost avatar Apr 21 '25 07:04 ghost

We are in the process of hiring a GDPR-expert lawyer to assess the situation. We've found someone, and now the whole contracting process needs to happen before they can start the assessment.

We will share more details when they have their conclusions. These things take time.

diemol avatar Apr 22 '25 20:04 diemol

This is going far from my initial request: Do not enable telemetry without user consent.

I don't think you need a lawyer for that, you just need a privacy policy. In the end this is not really asking for much is it?

ghost avatar Apr 25 '25 13:04 ghost

This issue is stale because it has been open 180 days with no activity. Remove stale label or comment or this will be closed in 14 days.

github-actions[bot] avatar Oct 22 '25 20:10 github-actions[bot]

ping

MatzFan avatar Oct 22 '25 20:10 MatzFan