boot-repair does not warn users it's going to make their boot configuration public on the internet

Bug #1487362 reported by Junien F
34
This bug affects 7 people
Affects Status Importance Assigned to Milestone
Boot-Repair
Fix Released
Wishlist
YannUbuntu

Bug Description

Hi,

Based on https://askubuntu.com/questions/406275/i-would-like-to-delete-an-accidental-post-i-did-on-paste-ubuntu-com-while-using and http://ubuntuforums.org/showthread.php?t=2144024, it appears the "create BootInfo" option that boot-repair offers does not explicitly ask users for confirmation that they want to post their boot configuration on the Internet.

Could this behavior be changed ? At the very least, a warning should be displayed and mention that the boot configuration is going to be made public on the Internet.

Thanks !

Revision history for this message
YannUbuntu (yannubuntu) wrote :

hi Junien
thanks for the report.
Your statement is correct, but you do not explain why this is an issue.
We try to avoid the software popup useless things, so this won't be added unless there is a good reason.

Changed in boot-repair:
importance: Undecided → Wishlist
status: New → Won't Fix
Revision history for this message
Junien F (axino) wrote :

Hi Yann,

Thanks for getting back to me. This issue is mostly about trust : people have to trust that the software they run will not expose anything on the Internet unless requested/agreed to do so. An example that comes to mind is the popup that appears the first time you run VLC.

I was merely suggesting the popup as a possible solution, by the way. Another acceptable solution (for me at least) would be to change the text of the option to something more explicit. For example : "post my boot configuration on Internet so that others can help me". Or display this is in a small text under the "create BootInfo" option.

And have it disabled by default, of course, so that the boot config will be pastebin'ed only if the user chooses to.

Thanks for your time.

Revision history for this message
Artyom (artyom-d) wrote :

The software that you maintain, shares the user's drives' serials, LUKS headers, user name, UUIDs and more without even telling it to the user. How is that not an issue. It doesn't even say something about this while the user is adding the paa.

Please provide an easy way to opt out, and tell the user about this behavior of the software before it has been shared it to the public.

By the way, could you please run the boot-repair on your personal, encrypted device and post the log here?

Revision history for this message
Junien F (axino) wrote :

Hi Yann,

We still get requests to remove unwanted paste.ubuntu.com posts generated by boot-repair. In lights of the above, can you please reconsider your position, and change the default or make the user aware that his boot configuration is going to be posted publicly on Internet ?

Thanks

Changed in boot-repair:
status: Won't Fix → Confirmed
Revision history for this message
Neale Pickett (neale) wrote :

Could you maybe have it email the information? I agree that for some very security-conscious people, discovering that their boot information has been posted on a public page on the Internet could be very disconcerting.

YannUbuntu (yannubuntu)
Changed in boot-repair:
assignee: nobody → YannUbuntu (yannubuntu)
status: Confirmed → Fix Committed
Haw Loeung (hloeung)
Changed in mbr (Ubuntu):
status: New → Confirmed
Revision history for this message
Michael (m-michaex-z) wrote :

I am one of the people who complained to Ubuntu about this.

Uploading potentially private info to the internet, without asking to do so, is not obvious behavior.

If a tickbox, or popup isn't feasible, maybe changing the description of the function to "Upload boot info to pastebin" would work?

Revision history for this message
YannUbuntu (yannubuntu) wrote :

Fixed in boot-repair 4ppa35 via a popup question.

Changed in mbr (Ubuntu):
status: Confirmed → Invalid
Haw Loeung (hloeung)
no longer affects: mbr (Ubuntu)
YannUbuntu (yannubuntu)
Changed in boot-repair:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.