Live data from Hacker News

Gitlab cancels plan on tracking user behavior on GitLab.com

gitlab.com

191–200 of 285 posts

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#191

Earlier quoted context omitted.

Telemetry still sucks. I don't want it, and it should never be opt-out.

You opt in to first party telemetry by using gitlab. It is impossible for you not to send data to gitlab when using gitlab. Self-host it if you don't want it. I dunno what to tell you; at some point, the company does have to observe how people use their product, and they'll do so a lot more effectively by looking at how most people are using it, rather than … idk, send a survey or something. Not that they won't do th…

Self-hosting was going to have telemetry, which is simply a dealbreaker for many companies.

And it may still have it. I just don't trust GitLab's management anymore.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#192

Earlier quoted context omitted.

Telemetry still sucks. I don't want it, and it should never be opt-out.

Telemetry is necessary to be able to observe the system, and look for adverse impact. You should be more thoughtful to the people supporting the tools you use, because without telemetry they do a bad job keeping it working for you.

No, it is not. We have been selling software for decades without telemetry and it worked just fine.

I am more than willing to help GitLab, but telemetry in a VCS is simply a red flag (even a legal impediment in many cases).

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#193
post #177

Earlier quoted context omitted.

I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS. I left a comment on the feedback issue about this. It's not as comprehensive as a third party, but you can build your own analytics in house. There are a lot of managed services (like BigQuery) that make it significantly easier to implement it yourself, and you do g…

> I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS. I don’t think this is true, provided the third-party is GDPR compliant themselves. It’s the controller-processor relationship under GDPR. Presumably if there was not a cutout for this, AWS would not be able to exist.

I'm not talking about GDPR specifically, I'm talking about embedding a third party script (or sending data to a third party) from a company that I have no relationship with. Many companies would find that unacceptable, especially within their source control. Where all their IP is hosted.

The "can't" here isn't necessary legal, it could be internal.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#194
post #177

Earlier quoted context omitted.

I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS. I left a comment on the feedback issue about this. It's not as comprehensive as a third party, but you can build your own analytics in house. There are a lot of managed services (like BigQuery) that make it significantly easier to implement it yourself, and you do g…

> I think part of the issue was that there are many cases where you can't send potentially sensitive information to a third party, regardless of their TOS. I don’t think this is true, provided the third-party is GDPR compliant themselves. It’s the controller-processor relationship under GDPR. Presumably if there was not a cutout for this, AWS would not be able to exist.

Most companies won't allow telemetry nor arbitrary code fetched from the Internet in their private network.

It is common sense. Some are even legally required to ensure that.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#195
post #9

This comment, from the CFO, is particularly nasty: https://gitlab.com/gitlab-org/gitlab/merge_requests/14182#no...

You may or may not agree with that comment, but it is not nasty. What is nasty, on the other hand, is the vitriolic reaction to it. So far I count 16 "middle finger" emojis, including one with the subtitle "incompentent or malicious CFO". In what world does a disagreement over the right level of telemetry justify this kind of behavior? It's mind-boggling to me how entitled and aggressive the open-source culture is al…

It is not just nasty to customers.

It is public evidence of commitment to an illegal policy after the CFO was informed of the legal problems.

Not sure how you can do something worse.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#196
post #27

We received an apology email at the same time, well written, explaining what they did wrong, apologizing, promising to do a post-mortem, promising to not send to 3rd party trackers, and saying they did a mistake and waiting for feedbacks on the issue tracker. And with very little BS in the mail. Such level of transparency, of apologizing and clarity, especially written at the first person "I am truly sorry." is very…

Nice! An apology apology! Way to go GitLab!

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#197
post #143

Earlier quoted context omitted.

Sadly, that "F" means they pretty much have veto power over anything anybody (with the possible exception of the CTO and the board) wants to do.

Uh, that's not how it works. Legitimate veto power is usually based on a board and/or shares of the company. Not to mention most CFOs are appointed positions in startups, because they are usually not roles filled in the early days of a tech startups life (as opposed to CEOs and CTOs). Note - it is worth saying, CFOs are, generally speaking consider extremely important positions for many companies, even more-so than t…

"Oh, you're wanting to implement more 'privacy' for our users? Well it turns out that we've just done a reorg, and your whole department has no budget for the rest of the year."

As you say, whoever controls the money flow, ultimately controls the people, and can shut down any activity they desire...

Sure it's not "legitimate veto power", but ultimately it is the same thing.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#198

Earlier quoted context omitted.

Sadly, that "F" means they pretty much have veto power over anything anybody (with the possible exception of the CTO and the board) wants to do.

sadly? that the board failed to stop this (or was bypassed) is telling, but this doesn't seem like a failure of the corporate governance model or anything. money is basically essential to a corporation; engineering staff shouldn't be on the level of C suite, despite what many here would have you believe

"Sadly" because in this instance, it appears there's a CFO in power who's championing selling user's privacy out. Not a comment of whether or not a CFO in general has more influence than engineering (or other) staff, but that an ethically challenged CFO is potentially a toxic influence to a company culture and direction.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#199
post #27

We received an apology email at the same time, well written, explaining what they did wrong, apologizing, promising to do a post-mortem, promising to not send to 3rd party trackers, and saying they did a mistake and waiting for feedbacks on the issue tracker. And with very little BS in the mail. Such level of transparency, of apologizing and clarity, especially written at the first person "I am truly sorry." is very…

Yes. Wonderful. More like this!

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#200
post #75

Earlier quoted context omitted.

It was done. There even was those small banners that said something in the way of "if you have gmail I won't mail you" etc. Thing is, the broader public don't care. The difference between gitlab and gmail is primarily that developers care more about this stuff and value their code more than most people care about their email. They are also much more informed in the matter, most using gmail haven't got a clue.

"...developers care more about this stuff..." No, they only care when the tools they are using are targeted. Otherwise, they couldn't care less. We have tracking on websites and in apps on an industrial scale - built by developers in technology companies. We even have tracking of school kids courtesy of ChromeOS. When have developers ever shown any care about that? When have they ever spoken out about that? They're m…

If I had a guarantee from Gitlab that _they_ were scrubbing the data, I would have no problem. I get the sense they know what they're doing (naive, maybe)

However, giving a third party script, potentially unvetted, access to the crown jewels of the company I work for? No fucking way.

Different. Not a double standard.

Post reply on HN