They don't, since a long time ago. And for the short time they did, they documented exactly what was sent, to who, and how to turn it off (and you were able to verify that by looking at the source, recompiling yourself, etc.)
Please explain how to do any of those things on Windows - either the new 10, or the retrofitted-telemetry 7 which one has to retrofit with telemetry if they want security updates.
> and you were able to verify that by looking at the source
How much of Ubuntu has undergone a security audit by people who are looking for actively maliciously obfuscated code?
In a codebase the size of Ubuntu (and all its packages), "you can look at the source" is a mindgame, nothing more.
Also, you can look at Windows' source code. In addition to the numerous programs Microsoft has for licensing the code to universities, researchers (including security auditors!), well-known community members, etc. the source code has been leaked multiple times.
> How much of Ubuntu has undergone a security audit by people who are looking for actively maliciously obfuscated code?
You've just moved the goal posts from "we can look at what it's doing" to "we assume they tried to hide what it is doing" - which we know that e.g. Microsoft did bundling telemetry into Win7 security updates, but that Canonical never did. Nice.
I don't know how much has been gone through by people looking for underhanded code, but ... quite a few looking at the basic code. And if you expect underhanded code, I think you should just not trust the vendor.
> In a codebase the size of Ubuntu (and all its packages), "you can look at the source" is a mindgame, nothing more.
Actually, quite a few people diff ubuntu against debian to see the changes, and Ubuntu's original, independent code is not that huge - in fact, the community took over Unity, so there are a lot of people looking at it.
> Also, you can look at Windows' source code. In addition to the numerous programs Microsoft has for licensing the code to universities, researchers (including security auditors!), well-known community members, etc. the source code has been leaked multiple times.
Now, that's a complete joke.
Unlike ubuntu (which I have, in the very distant past 8.04 or 6.06 days rebuilt the base of, and which others regularly do), you have absolutely zero way to verify that the 400MB executable you installed does not include, in addition to the source you have, backdoors, telemetry etc.
When I was in Uni, I talked to one of the guys who get access to the source. It was view-only, can't rebuild, some critical parts missing. Maybe these days it is buildable, but I'd be surprised. And even if it is, you're not allowed to use it (except for auditing purposes), which goes back to the previous point - you have little idea what you're actually running.
> the source code has been leaked multiple times.
That's another joke. First, no professional would review _that_ because of legal ramifications.
I have a simple proof that you are completely, utterly, wrong in your assertions, and I would love for you to refute it.
If it's so easy to see what Microsoft is doing, how come there wasn't a single source for what Win10 actually sends home, for what the Win7/8.1 telemetry sends home, that was based on facts? In fact, the only semi-reliable (but not audited, or 3rd party confirmed!) source of what Win10 sends is from Microsoft, released over a year after Win10 was out. And it's frightening enough as it is.
I call bullshit on your claims. You're welcome to like Microsoft better than Ubuntu, but please stick to the facts.