Live data from Hacker News

Show HN: Kite, copilot for programmers, available for Python

kite.com

211–220 of 257 posts

Re: Show HN: Kite, copilot for programmers, available for Python

#211
post #188

Earlier quoted context omitted.

My point is that it's a lot easier to happen accidentally when the upload happens automatically and without intervention. With git, you directly specify what files you're committing (with the .gitignore as an additional safety net) and when that commit happens. It's all manual. If I'm testing an app and I want to hard code an API key for testing, and I'm using Github, it's not a problem. I have to explicitly commit t…

Again, I go back to your whole issue with how an inexperienced user of Kite can easily shoot themselves in the foot. The same applies to Git: 'git add .' and push.

Yes, you are correct in that an inexperienced Git user can mess up, I won't deny that. My issue here is that Kite requires you to proactively place a .kiteignore, before even whitelisting a directory. It also doesn't alert you that it's about to start indexing the files in the directory tree or that you need to add a .kiteignore to protect sensitive files before you whitelist them. At a minimum they should be respecting the existing .gitignore, and realistically they just be scrubbing all strings before sending any data.

I can 'git add .' and commit my life away, but that requires much more intention and explicitness than clicking enable on a prompt and continuing your standard workflow (ie: a simple 'vi super_seceret_file.py')

Re: Show HN: Kite, copilot for programmers, available for Python

#212

Earlier quoted context omitted.

Thanks, we appreciate the constructive feedback! We've worked really hard to make sure we're clearly communicating what's happening (transparency), and adding fine grained controls. We have a very clear step during the install flow that talks about how Kite works, and we will prompt for whitelisting within each of the editor plugins that can work without the sidebar (Atom, ST3, PyCharm). We also have a security page…

Instead of on-prem to start, you could probably get away with VM appliances people could spin up in their own cloud provider or VPC. I don't mind code being sent to a server, but it needs to be a server I control.

Yes, absolutely. We plan to start with deploying to an AWS account the customer owns. We're pretty excited about it as the first step!

Re: Show HN: Kite, copilot for programmers, available for Python

#213

Earlier quoted context omitted.

/security has a broken link to /smart also, "The short answer is: we don't index anything on your computer that you don't explicitly ask us to" you should say that on /security that's a pretty important point. I read in last year's HN post that you collect user's terminal commands. Is that still true?

No we don't do anything with the terminal any more (and in particular we do not record terminal commands in any way)

You're alienating a huge portion of your market by not supporting Emacs and Vim

Re: Show HN: Kite, copilot for programmers, available for Python

#214

Adam from Kite here. Thanks for all the feedback and encouragement around the launch today. We're excited to be opening up Kite for everyone to download today. When we launched Kite here on hackernews almost a year ago we were blown away by the enthusiasm for our smart copilot vision. Over 65,000 of you signed up for Kite in the first 72 hours, and over the past year we've been working with many of you to deliver tha…

I know this is your baby and all, but how high was your team (high as a kite?) when they thought sending every line of code to your server was a good idea?

Seriously, could just send the object type being "autocompleted"along with the other object types in the same file and gotten better results without the privacy backlash.

Re: Show HN: Kite, copilot for programmers, available for Python

#215

Adam from Kite here. Thanks for all the feedback and encouragement around the launch today. We're excited to be opening up Kite for everyone to download today. When we launched Kite here on hackernews almost a year ago we were blown away by the enthusiasm for our smart copilot vision. Over 65,000 of you signed up for Kite in the first 72 hours, and over the past year we've been working with many of you to deliver tha…

[deleted]

Re: Show HN: Kite, copilot for programmers, available for Python

#216
Dear Kite, I really love this idea, but hell no I'm not using it yet. Here's why... I'll cut to the point here, so please forgive the bluntness as I mean no insult or accusation, just honest criticism, and I'm gonna try to cover a lot in as small a space as possible.

There's not even a mention on kite.com about how data is handled that I can find anywhere. What is the method of transport? What stands between skids and my code? The server my data goes to, is it shared VPS hardware waiting to get pwned by your neighbor, xtremecrackz.zyx or is it on private servers guarded by a three headed puppy named Κέρβερος, 13 ninja, and biometric security? Does the page even mention this is a cloud service somewhere? I see support for VS Code, but not MSVS proper, emacs but not specifically GNU/Linux yet; Mac support but not Linux in spite of at least $4M USD in seed and 3 years of development (source: crunchbase [1])? The Windows download page gives instructions for bypassing SmartScreen warnings meaning your code signing certificate has no reputation with Microsoft yet if I understand correctly. Frankly, I didn't think "Adam Smith" was even a real person until I checked it out. LOL, sorry bro but it sounds kinda generic to someone skeptical I guess. Maybe you assume trust since you travel in the circles you do, but we nutjobs like stuff in writing, and trust assumptions without verification are bad practice anyhow -.-

(on trust) Your investor who may or may not provide the same or similar "Kite" software discussed in GCHQ leaks as a "correlates-anything" solution, Palantir Technologies, has been standing in the suspiciously shadowy center of a maelstrom in some circles. I like them supporting our warfighting - but not working against the people of the United States, or anyone's civilians for that matter, however that's an argument for the agencies they contracted with. I've watched my brothers bleed out defending the rights their software has helped undermine, I'm not sure how to feel about them at all right now. Do I want to give my code to their creepy software? No, not really, since I'd have to consider that if they got a contract they might, without even knowing the end use, build software to guide Terminators to hunt down and kill civilians who write bad code or wear plaid socks. Seriously though: eyebrow raised.

(advice) I would add more clear information about how this all works. A link to security answers should come up before the footer IMO, given the nature of this product. Going out of my way to look for it, I guess it seems like security was an afterthought. I can appreciate your blog post about security [2] and the main security page which links to that article (merge these?), but they fail to answer almost all of my questions. They imply that the service isn't really ready for the spotlight, but do not explicitly say anywhere to safeguard sensitive stuff or not to trust everything just yet, but it seems softly implied to me.

(bigFoilHat) This might sound far out to some, feel free to ignore or laugh, but if I were an evil puppet master, I'd have my cybersecurity and intelligence contractor who provides access to mission critical software or monetary capital for a startup attempt to leverage this relationship to gain information about code in the wild and specific targets' code using this service, perhaps to have software look for opportunities to steal parts of keys, suggest code changes to enable exploitation, forward copies of code from persons of interest to investigators. I might ask them to approach them as patriots in the interest of the GWOT and all things decent, to tacitly and deniably or perhaps even expressly cooperate with legally and morally grey-area surveillance operations. Perhaps if there is no cooperation or just to keep it quiet, I might suggest they infiltrate Kite.com and gain the ability to intercept data clandestinely by using their trust and rapport with company leadership. "Plz send all code to spies and disable security stuffz kthxbai" I can weaken my own PRNGs and send copies of my code for spooks to analyze by myself without assistance thanks. Again, I'm attempting to honestly characterize how it makes me feel, just sayin'. I simply have no way to even fool myself into thinking I can know what goes on with my data after it leaves my PC. How do I even build rules for my firewalls? What are the parent processes which need communication, on which ports, using what protocols? Which servers will it upload to? Can we blacklist certain destinations by region or other attributes? I think you need a more robust explanation on the site before us crazy people are satisfied.

(bigFoilHat Q) HN: what say you, am I just being paranoid here in thinking that users' analyzed code may end up being displayed on an alphabet soup agency wiki somewhere along with download links for tools to suprisebuttsecks us being passed out to every malware hoarding contractor who accidentally skated past the SF-86? Maybe I'm just having a bad bout of Stallman Syndrome. One might argue "99.99% of users' code will be useless fluff and bizcruft, who cares if they copy my der.py code?" but finding that 0.01% relevant signal in the noise is exactly what Palantir does for customers, isn't it? So how can I flippantly dismiss the notion?

(Q) Do you sell, gift, trade, share, or otherwise disclose or make available knowingly any information about users' personal data or source code, even if anonymized or generalized in reports and detached from identifying information, to other parties? Can/will/do these parties include your investors? Does Palantir Technologies store, use, or have access to at any time, our source code or any information about it or ourselves?

That said, it sounds cool as phrack and I would love to see this in many languages and editors, but only if it can be trusted somehow. I'll be watching and investigating, thanks for sharing this on HN,

-Ax

[1] https://www.crunchbase.com/organization/kite-com/ [2] https://kite.com/blog/thoughts-on-security

Please correct anything I am mistaken about, I admit I could be completely off the mark here.

Re: Show HN: Kite, copilot for programmers, available for Python

#219

Adam from Kite here. Thanks for all the feedback and encouragement around the launch today. We're excited to be opening up Kite for everyone to download today. When we launched Kite here on hackernews almost a year ago we were blown away by the enthusiasm for our smart copilot vision. Over 65,000 of you signed up for Kite in the first 72 hours, and over the past year we've been working with many of you to deliver tha…

I know this is your baby and all, but how high was your team (high as a kite?) when they thought sending every line of code to your server was a good idea? Seriously, could just send the object type being "autocompleted"along with the other object types in the same file and gotten better results without the privacy backlash.

Is it really that much worse than having code on a private GitHub repository or pushing Python code to a paas platform like pivotal?

Re: Show HN: Kite, copilot for programmers, available for Python

#220
post #8

Earlier quoted context omitted.

Does Kite still send all your code to Kite servers as you type? I remember that being an issue the last time someone talked about Kite on HN. I'm find with an editor or sidekick that can search stack overflow or duckduckgo or google quickly with a hotkey-- maybe keep snippets you can tag and easily reference-- but sending all my code as I type to a web service is something I'm not willing to do and something most com…

(Copied from above.) Totally legit concern. when we started working on this we realized if we wanted to index tens of thousands of libraries, we wouldn't be able to ship the entire index along with the client. Hence the cloud-based architecture. We've thought a lot about privacy and written up our thoughts here: kite.com/security. The short answer is: we don't index anything on your computer that you don't explicitly…

> when we started working on this we realized if we wanted to index tens of thousands of libraries, we wouldn't be able to ship the entire index along with the client.

Why not? that's a _tiny_ amount of data for a modern computer.

Post reply on HN