Live data from Hacker News

Updates to GitHub Copilot interaction data usage policy

github.blog

181–190 of 193 posts

Re: Updates to GitHub Copilot interaction data usage policy

#181

Fun fact: Copilot gives you no way to ignore sensitive files with API keys, passwords, DB credentials, etc.: https://github.com/orgs/community/discussions/11254#discussi... So by default you send all this to Microsoft by opening your IDE.

Fun fact: you shouldn't have sensitive files with API keys, passwords, DB credentials, etc. in your repo

It’s fine to have them in your repo if they’re encrypted and the private key isn’t in there as well!

Re: Updates to GitHub Copilot interaction data usage policy

#182

Earlier quoted context omitted.

I actually don’t seem to have this option on my GitHub settings page, which leads me to wonder if this only applies to Americans.

I actually did have to manually disable this from Germany, so it might be a different reason you don't have it?

Dunno! I would have expected Germany and Norway to be the same.

Re: Updates to GitHub Copilot interaction data usage policy

#185

Earlier quoted context omitted.

only big companies have access to the legal system. nobody else can afford it

Most of the world aren't American and we can afford our legal systems ;).

Thankfully shariah court is free. Inshallah

Re: Updates to GitHub Copilot interaction data usage policy

#186

Earlier quoted context omitted.

It breaks GDPR easily: GDPR enforces you to comply with opt-out by default, no workaround by prefilling before hitting submit. While some think this applies only to personal data, then yes. But it takes only one line of code to use my phone number for testing while I test locally a register form in the application I'm developing. Once it gets sent to Copilot I can threaten with legal action if they are not taking it…

Has there ever been a GDPR fine that actually exhausted all applicable legal challenges within a sufficiently short delay from initial violation to actually matter?

https://www.enforcementtracker.com/

Short delay: depends on your DPA, I doubt any country is fast enough. On the other hand, this is the legitimate interest of GitHub, so it would require investigation, maybe even litigation.

Re: Updates to GitHub Copilot interaction data usage policy

#189

This is terrifying. Github was the one provider I did not expect to make such an action. We're now playing whack-a-mole with vendors to try and ensure that our company IP doesn't end up being used to train a model.

> Github was the one provider I did not expect to make such an action

There is no Github anymore in any meaningful way. It's Microsoft. Github doesn't have a CEO anymore.

Re: Updates to GitHub Copilot interaction data usage policy

#190

This is terrifying. Github was the one provider I did not expect to make such an action. We're now playing whack-a-mole with vendors to try and ensure that our company IP doesn't end up being used to train a model.

> Github was the one provider I did not expect to make such an action There is no Github anymore in any meaningful way. It's Microsoft. Github doesn't have a CEO anymore.

[flagged]
Post reply on HN