Live data from Hacker News

Gitlab cancels plan on tracking user behavior on GitLab.com

gitlab.com

181–190 of 285 posts

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#181
post #177

This is incredibly dumb. Both Pendo and Snowplow are analytics providers, meaning they both have in their TOS that the company remains the owner of the data in question and that the services only exist to facilitate analysis of the data in question. Effectively this is users complaining that Gitlab wants to simplify their data analysis overhead. Presumably nothing precludes them from sending the exact same data to th…

I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS. I left a comment on the feedback issue about this. It's not as comprehensive as a third party, but you can build your own analytics in house. There are a lot of managed services (like BigQuery) that make it significantly easier to implement it yourself, and you do g…

> I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS.

I don’t think this is true, provided the third-party is GDPR compliant themselves. It’s the controller-processor relationship under GDPR. Presumably if there was not a cutout for this, AWS would not be able to exist.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#182

This is incredibly dumb. Both Pendo and Snowplow are analytics providers, meaning they both have in their TOS that the company remains the owner of the data in question and that the services only exist to facilitate analysis of the data in question. Effectively this is users complaining that Gitlab wants to simplify their data analysis overhead. Presumably nothing precludes them from sending the exact same data to th…

What about running third party scripts on the page, which would have access to all code on the account you’re logged in with? How do organisations audit these scripts, and how can they audit new versions of these scripts when gitlab controls the release strategy of these scripts?

You’d be moving from one (possibly two if you include the cloud provider) vendors having theoretical access to all of your code to four vendors having potential access.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#184
post #95

Earlier quoted context omitted.

That sounds like they are going to roll out a first-party service, which is better, but not great for the self-hosted deployments.

Telemetry still sucks. I don't want it, and it should never be opt-out.

You opt in to first party telemetry by using gitlab. It is impossible for you not to send data to gitlab when using gitlab.

Self-host it if you don't want it. I dunno what to tell you; at some point, the company does have to observe how people use their product, and they'll do so a lot more effectively by looking at how most people are using it, rather than … idk, send a survey or something. Not that they won't do the latter anyway, nothing prevents them from doing that, but it's a very different type of data.

I'm a privacy nut by the way, and nothing in that field pisses me off more than people who vocally shit on telemetry. "I hate you, you should just GUESS what I want rather than do real work to figure it out" sort of thing.

What is it about telemetry you don't like, exactly? And I do say "telemetry" in general, because you're saying it sucks in general. So no specific examples like Windows 10's abhorrently overreaching telemetry, privacy invasions that look at PII, etc.

Telemetry generally is things like "97% of users have visited the issue tracker. 66% of projects with an issue tracker enabled have at least 1 issue. new issue rate on public repositories climbs by 15% if the new issue button is orange instead of green. users spend 30% more time on the new issue page if there's a new issue template. issues with a template have a commit/mr associated with them at a 8% higher rate than issues with empty templates".

By choosing to die on this hill, you're taking both good-will and attention away from much more severe issues of telemetry abuse, such as "let's collect the precise geoloc of all our users in our gay dating app at 5 minute intervals, store it for 3 years and not care one ounce about security".

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#187
post #95

Earlier quoted context omitted.

That sounds like they are going to roll out a first-party service, which is better, but not great for the self-hosted deployments.

Telemetry still sucks. I don't want it, and it should never be opt-out.

Telemetry is necessary to be able to observe the system, and look for adverse impact. You should be more thoughtful to the people supporting the tools you use, because without telemetry they do a bad job keeping it working for you.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#189
Long story short, if Gitlab were to use a open source & self hosted platform (like Countly) with a clear mentioning of what to collect and what not, clarifying that nothing is collected which is not anything unknown to them, there would be no problems. Gitlab CEO has provided the right response with the right tone, which is something we don't usually see in big corps. I again would like to stress that such platforms not use 3rd party analytics providers but a self hosted and/or in-house solution.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#190
post #84

Earlier quoted context omitted.

Lesson learned here - the CFO is not and should not be responsible for a company's tracking policies and communication thereof.

Sadly, that "F" means they pretty much have veto power over anything anybody (with the possible exception of the CTO and the board) wants to do.

[deleted]
Post reply on HN