Live data from Hacker News

Gitlab cancels plan on tracking user behavior on GitLab.com

gitlab.com

241–250 of 285 posts

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#241
post #27

We received an apology email at the same time, well written, explaining what they did wrong, apologizing, promising to do a post-mortem, promising to not send to 3rd party trackers, and saying they did a mistake and waiting for feedbacks on the issue tracker. And with very little BS in the mail. Such level of transparency, of apologizing and clarity, especially written at the first person "I am truly sorry." is very…

Saying "I'm sorry" when you don't have to is worth praise. Saying it when your back is to the wall and your job is on the line - even cowards can do that.

I agree it's one of the best-written apologies I've heard in a while, and they deserve some praise for not letting the corporate ~bullshit~ PR department run loose all over it.

But still. I suggest that whoever is responsible should resign as a result of this Pendogate business. I feel that he has betrayed users' trust in a way where an apology alone is not sufficient. I personally consider the original plan - we'll lock you out of your accounts and disable the API until you accept our new TOS, if you don't like it there's the door - far worse than anything Brendan Eich ever did, for example. I don't want people who ever think that could be an acceptable idea in charge of a company I rely on day-to-day.

Replacing him would be a very strong signal from Gitlab's board that they are truly sorry and understand the severity of this scandal, and would also encourage future CFOs to take their users' views more seriously.

It is pathetic in a way that while lots of people were worried that Microsoft would "corporatise" github, it's gitlab that decided it was ok to threaten to lock people out from their accounts until they "consented" to this.

_EDIT: Paul Machle is CFO, Sid Sijbrandij is CEO and the person who sent the apology. I have removed names from the original post as I am not sure which of them signed off the original idea. I expect a CEO to take the attitude "the buck stops with me" though - they should be accountable even if they're not directly responsible._

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#242
post #155

Earlier quoted context omitted.

A lot of institutions used to run their own e-mail. Over the years I've watched as my e-mail addresses (both universities and my current employer) have been replaced by Gmail on the backend. All of them stopped being willing to manage e-mail themselves. None of them were willing to use a less surveillance-oriented provider. That choice wasn't made by consumers. It was made by the same kind of informed IT people. I su…

I remember when Dartmouth ran blitz mail... when google talk supported jabber... when people complained mostly about MAPI... It’s a shame that so many innovations are being squashed in communication because of the “free” price for cloud solutions. Google is learning so much about students thanks to this program.

I thought the main problem with e-mail specifically was spam, and the reputation model that's arisen to combat it: a medium-sized university running their own e-mail service runs a risk of getting their domain blacklisted, if a few accounts are compromised and start sending out mass mailings.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#243
post #235
post #27

We received an apology email at the same time, well written, explaining what they did wrong, apologizing, promising to do a post-mortem, promising to not send to 3rd party trackers, and saying they did a mistake and waiting for feedbacks on the issue tracker. And with very little BS in the mail. Such level of transparency, of apologizing and clarity, especially written at the first person "I am truly sorry." is very…

Given that any default opt-out is a clear violation of GDPR when it comes to data gathering, I wonder how it ever passed compliance/legal. Given the size of the company (valued ~ $3b) they should have some 'data protection officer' position. I recall they setup some blog page with explanations, so obviously they expected push back. Part of my work is making sure policies, code, etc. are compliant. Notifying complianc…

There is a comment on the issue tracker alleging that the CFO overrode concerns by the Director of Global Risk and Compliance.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#244
post #153

Earlier quoted context omitted.

Yeah, if the outcry continued even after their rollback & apology, _then_ it would be unwarranted. But everyone's happy now (well, arguably GitLab may not be, but they should surely be able to work out a solution with the community on how to collect telemetrics in a privacy-conscious way). I'm also glad the feedback was so strong, as the ad-tech industry has spent the past 15 years numbing the general populace to unw…

> Yeah, if the outcry continued even after their rollback & apology, _then_ it would be unwarranted. The outcry may stop but the trust is now gone and will take years to rebuild. Next time I'm considering/recommending on-premise git hosting I won't be recommending gitlab. I'm also considering moving my personal repos that I pay for. Generally I only interact through the CLI and don't think about the web interface muc…

Gitlab could restore some trust in my eyes by parting ways with whoever signed this off in the first place.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#245

Earlier quoted context omitted.

If a company does business in Europe, they must comply with GDPR. It' doesn't matter where they are located. It won't even go to US court, but to EU one.

The EU court needs to actually be able to enforce its decisions, which may require a US court.

Are you sure that American companies are immune to fines resulting from EU court sentences if they want to make business in EU?

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#249
post #235

Earlier quoted context omitted.

Given that any default opt-out is a clear violation of GDPR when it comes to data gathering, I wonder how it ever passed compliance/legal. Given the size of the company (valued ~ $3b) they should have some 'data protection officer' position. I recall they setup some blog page with explanations, so obviously they expected push back. Part of my work is making sure policies, code, etc. are compliant. Notifying complianc…

There is a comment on the issue tracker alleging that the CFO overrode concerns by the Director of Global Risk and Compliance.

wow, do you have a link for?

pushing through legal recommendation is quite reckless. GDPR is quite a hot topic and the regulation has real teeth (aside the public backlash)

Post reply on HN