mojira.dev
MC-244117

Violation of GDPR (telemetry is not optional)

Currently, there is no way to disable telemetry in Minecraft. Normally this wouldn't matter so much, however Microsoft also requests your player XUID which can easily be stolen by a MITM attack.

 

Please make changes so that either you won't collect player XUID and other identifying information, or preferably add an opt-out button.

 

By the way, https://www.minecraft.net/en-us/privacy/gdpr is not up to date anymore. 

Linked issues

Comments 7

Note that telemetry is done over HTTPS, greatly reducing the risk of MITM attack.

Duplicate of MC-237493, resolved as "Works As Intended".

Not a duplicate, that was about a snapshot and this is the live version. Also, did you just admit to a 'feature' breaking the rules of GDPR? 

Just because it was reported in an earlier version doesn't mean it's a different issue.
Additionally, helpers and moderators aren't Mojang employees, they're community volunteers they have no say over things being intended or not; Mojang resolved that report as intended.

"Also, did you just admit to a 'feature' breaking the rules of GDPR?"

Yes. That's exactly what they did. Not only is the snooper reactivated an intended thing, it seems that also the inability to disable it is intended. Since being unable to disable it is a blatant GDPR violation, it appears that Microsoft is literally BRAGGING ABOUT COMMITTING A CRIME!

@ampolive THIS DOESN'T WORK AS INTENDED!

  1. You are not informing us directy about it - we need to look to snapshot changelogs

  2. There is no way to disable it in not modified game

  3. It's sent in unencrypted and not anonymous way.

You have to change it AS SOON AS POSSIBLE!

The legal team has deemed it not to break the GDPR law(s), and it's not hidden anymore, everything send is visible in-game.

Youdontget myname

(Unassigned)

Unconfirmed

(Unassigned)

1.18

Retrieved