Live data from Hacker News

Kite telemetry code in Sublime package SideBarEnhancements

forum.sublimetext.com

101–110 of 120 posts

Re: Kite telemetry code in Sublime package SideBarEnhancements

#101
post #67

I'd implement an industry-wide blacklist, personally. This is strike number, two? three? of this company subverting well-known packages with telemetry. Any package that is proven to be connecting to their servers should be removed, the authors should be banned, and the company should be thrown onto a list of Known Bad Actors to prevent any kind of package, add-on, or extension from ever accepting them again. You cann…

Seriously. Sublime, Atom, VSCode, and every other platform that supports plugins should all be in crisis mode over the crap Kite's been caught doing. If we can't trust that an addon we installed yesterday is safe today, their platforms just turned into gigantic malware vectors that are totally wide open. This kind of exploitation needs to be stopped immediately.

I work on VSCode. We are aware of the possibility of bad plugins or even good plugins that go bad. The real nightmare scenario would be what's happened with some Chrome plugins, where a widely used plugin is either co-opted or bought out and becomes malicious (even worse if it disguises its maliciousness).

All of these package ecosystems are similar to NPM in that they are built on trust and community policing. This is not enough. One possible way forward is to move towards an security model more like iOS's or Androids where apps need to explicitly get the user's permission before performing potentially dangerous operations like making network requests.

I'd be interested to hear how other platforms have tried tracking these sort of concerns

Re: Kite telemetry code in Sublime package SideBarEnhancements

#102
post #24

Earlier quoted context omitted.

I really don't like the idea of having to wonder if the next plug-in/editor/IDE/etc I use is compromised by Kite or any other shady phone-home companies.

use vim ;]

It's not an editor thing, it's a shitty package creators thing.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#104
post #103

This is why I use Little Snitch. If there are any rogue outgoing connections, I will know about it. I am extremely selective with the connections I allow my machine to make.

Is there something like this for Windows?

Perhaps Glasswire?

http://glasswire.com

Re: Kite telemetry code in Sublime package SideBarEnhancements

#105
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

This seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been wh…

So, to use an analogy:

"Yeah, we broke into your house and rummaged through your stuff, but it's okay, we were only there to count how many spoons you had.

Yes, I know, we could've asked you before we broke into your house, but we tried that before, and for some reasons we had no takers. And it was really important to our researchers that we get a good idea about the number of spoons!"

Re: Kite telemetry code in Sublime package SideBarEnhancements

#109
post #67

Earlier quoted context omitted.

Seriously. Sublime, Atom, VSCode, and every other platform that supports plugins should all be in crisis mode over the crap Kite's been caught doing. If we can't trust that an addon we installed yesterday is safe today, their platforms just turned into gigantic malware vectors that are totally wide open. This kind of exploitation needs to be stopped immediately.

I work on VSCode. We are aware of the possibility of bad plugins or even good plugins that go bad. The real nightmare scenario would be what's happened with some Chrome plugins, where a widely used plugin is either co-opted or bought out and becomes malicious (even worse if it disguises its maliciousness). All of these package ecosystems are similar to NPM in that they are built on trust and community policing. This…

Explicitly asking the user before a plugin can make a network request would be great! I don't know what "sidebar enhancements" is/was, but it doesn't sound like that would need network access.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#110
post #47
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

Kite is a small fish in the bond... everyone working for FB and Google should be ashamed of themselves for working spy machines. I mean it. It sounds harsh but that's the way it is. But I guess money trumps morals.

You forgot the other top 5 companies. Although Apple has plausible deniability.
Post reply on HN