Sorry for using the term 'a matter of principle'. I was trying to differentiate between the ethical basis for rejecting proprietary software, and the possibilities for active abuse due to the user being denied control.
I accept that all proprietary software denies the four freedoms to the user, and this constitutes abuse. All proprietary software does this, and all proprietary software should be rejected just based on this is a consequence. This is real abuse, and I concur. There is, however, another dimension of abuse on top of this, which the nature of proprietary software allows the entity controlling the software to perpetrate- things like disregarding the privacy of users, and so on. There are two grounds on which to reject proprietary software- firstly, that it denies the user control of the program, enough in itself, and secondly, that the body behind the program can actively abuse the user due to the nature of proprietary code being closed and secret. In the same way, all SaaSS should be rejected, not necessarily because the server operator is selling the user's secrets to the NSA, but because (as with proprietary software) it denies the user control over the program doing the user's computing. This is clearly unethical, and as with proprietary software, it should be rejected solely due to that. On top of that, because SaaSS denies the user control, it opens up the possibility for active abuse by those controlling the server, because the user has no idea what's actually being done with her data. Your last paragraph contains something of a contradiction. You claimed that proprietary software, since it denies the user control over the program, is unethical and should thus be rejected (and I agree). However, in regards to SaaSS, even though it does the same thing (denying the user control over the program), you call this inconsequential. SaaSS and proprietary software are both unethical regardless of active harm perpetrated because they both deny the user the four freedoms in the first place.
