Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Very sad, what is happening in here... :(Very sad, what is happening in here... :(
Previous
 
Next
New Post
1/16/2014 8:37 PM
 
Wes, a cursory glance at the code shows the following:

string url = "";
if (Host.CheckUpgrade && version != new Version(0, 0, 0))
{
....

In other words, the scenario you describe only occurs if "Check for Updates" is enabled. If DNN really wanted to harvest information, they wouldn't make it so easy for users to disable such a feature would they?

The NewsletterSubscribeEmail value is not stored under the portal settings; it's stored under the host settings so not on a per-portal basis. As for it being sent to DNN regularly, I imagine DNN would probably want to send their newsletters to people whose instances were live/in-use and who had specifically requested the newsletter subscription in the first place... and that's exactly what the code in question does; no more, no less.
 
New Post
1/16/2014 9:46 PM
 
fwiw - check for updates is turned on by default - its running on every newly installed hosting the first time you log in as host
- its not something you need to turn on - its there when the platform is installed - it requires a direct action to turn it off.
- and it fires before you have the chance to opt out of it.

All I'm describing is what is actually going on in the server - sure yes okay the email address is in a different table on the database - i went back to change some typos but the forum server timed out before i could hit save - but not exactly sure what different that makes - its still information that is being used in a way that is possibly not explained to users before they enter it.

If you can show or demonstrate where a user that has just installed dnn and subscribed to a newsletter - gives permission for that email address to be used in any other way than to add their name to a newsletter list - then well its not an issue - but as far as I am aware that permission is not given.

AS for using an email address to keep a newsletter fresh when an automated call home to a server for some other purpose 'checking for available updates' is triggered - hmm - pretty sure that's a form of profiling that a person might need to give permission for - but sure that's something for lawyers to fight over the validity of.

But by way of your own arguement that its not a reliable way of collecting data because it can be easily turned off
- all I was suggesting is that the sending of the the email should be turned off
- and since its so easily defeat-able that should not be an issue since its of little value or reliability if that is in fact what it was being used for.

Ironically pretty sure this is actually the sort of thing that microsoft and a few companies got in huge trouble over with in early versions of their online update services/

Seems like there needs to be at least one action taken
- either a clearly displayed privacy and usage statement that explains to the user what they are actually opting into - and how that email address may be used
- or stop sending the email each time a hosting calls home to check for available updates.

Westa
 
New Post
1/16/2014 9:56 PM
 
cathal connolly wrote:
The only time an email get's transmitted from your install to us is when the host fills in the newsletter signup (i.e. on the screen that appears when you log in), this is clearly what happened (alternatively your client has registered with dnnsoftware or purchased something on the store, in which case they've also provided us with their email)

Hay Cathal - FWIW - that email address not NOT transmitted just ONCE -  its being re-transmitted back to the dnn update server every time a person logs in as a superuser and the check is done to display the UPDATE image

<img src="http://update.dotnetnuke.com/update.aspx?core=070200&amp;version=070200&amp;type=Framework&amp;name=DNNCORP.CE&amp;id=F045C5AC-26AE-4D42-A5D0-919846EE9710&amp;email=wtatters%40outlook.com&amp;no=1&amp;os=0603&amp;net=0400&amp;db=1100" alt="Upgrade" title="Click Here To Get The Latest Version">

Any idea why that would be the case ?

Westa

 
New Post
1/17/2014 1:50 AM
 

Any identifying piece of information has no business being in a version checking url, regardless of turning some option on or off. I am  interested to know why it's there in the first place.

 

 

 

 
New Post
1/17/2014 3:33 AM
 
Tony Henrich wrote:

Any identifying piece of information has no business being in a version checking url, regardless of turning some option on or off. I am interested to know why it's there in the first place.



Aye! +1
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Very sad, what is happening in here... :(Very sad, what is happening in here... :(


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out