Package: chromium
Severity: normal
Tags: patch

Dear Maintainer,

The current description [1] of 'chromium' in Debian is

  "Web browser that aims to build a safer, faster, and more stable
  internet browsing experience."

While that might be literally true in terms of the *aims* of some of
the original developers, it is misleading given the atrocious privacy
violations of Google's version Chrome [2]. Google itself controls the
development of Chromium, so even though it's free-licensed, the human
resources for fixing privacy violations are mostly under
Google/Alphbet's control. The current ungoogled-chromium.md patch list
in the Debian Chromium source [3] lists about 100 patches.  I'm sure
that the main reason why these are mostly not yet implemented (nor
rejected) by the Debian Chromium team is lack of time: each patch
needs to be carefully checked. Alphabet Inc is a multi-100-billion USD
corporation; Debian is not. And Chromium is a huge package with a huge
number of dependencies.

It seems to me that the Debian Chromium version very likely includes
many privacy violations, despite the best intentions of the team.

My suggestion is something like

   "Web browser running a code base that is partially shared with
   Google Chrome."

although ideally, as an ethical software distributor, we should include
something that effectively says the equivalent of

   "This browser will almost certainly violate your privacy even
   though if they had sufficient person-power, the Debian Chromium
   maintainers would very much like to implement patches to make the
   browser safe."

However, I don't see any brief way to say that, and I'm not sure
what the consensus is on how much we should warn people installing
unsafe packages. Maybe:

   "Web browser running a code base that is partially shared with
   Google Chrome; patches to improve privacy are welcome."

[1] https://salsa.debian.org/chromium-team/chromium/-/blob/master/debian/control
[2] https://contrachrome.com/comic/page01
[3] 
https://salsa.debian.org/chromium-team/chromium/-/blob/master/ungoogled-chromium.md

Cheers
Boud

Reply via email to