Live data from Hacker News

Kite telemetry code in Sublime package SideBarEnhancements

forum.sublimetext.com

21–30 of 120 posts

Re: Kite telemetry code in Sublime package SideBarEnhancements

#21

/sarcasm Really looking forward to reading the Kite blog post this time around: "Staying Open (Still): Kite Responds To the SideBarEnhancements Issue." /sarcasm Sorry Kite - fool us once, shame on you. Fool us twice, shame on us. There's now a 0% chance of my ever using your products or services.

Kite is plainly a bad actor. Sublime and GitHub/Atom should be taking steps to permanently remove them and the things they're infecting from their respective ecosystems

We now know of 3 different popular addons they've hijacked in various ways to snoop on code and to build up their business.

If one company is doing this, it makes me very concerned what else is going on, and what else is coming.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#22

Earlier quoted context omitted.

The question is: to where? Is there a single IDE with plugins that has a security model in place that would prevent plugins from being taken over by nefarious asshats? I love vim and emacs... but what's to keep them from being affected by the same thing? Who has time to read all the source code of every plugin/dependency that they use? It's all about trust and what Kite is doing is completely destroying the network o…

I think the person you're replying to meant not using Kite.

What keeps Kite from taking over another package?

Re: Kite telemetry code in Sublime package SideBarEnhancements

#23

I modified the Stats.py file in the SideBarEnhancements.sublime-package on my computer to remove the line that references this IP address. I also made the file read-only so it won't get updated. Does anyone know if that will take care of the issue on my computer for now?

They have removed the file already https://github.com/SideBarEnhancements-org/SideBarEnhancemen... but I wouldn't be surprised if they compromised more plug-ins and we just haven't found out yet

Re: Kite telemetry code in Sublime package SideBarEnhancements

#25
post #4

/u/michael0x2a on Reddit put together a nice tl;dr[1] of the story arc for those that don't want to dig through the thread. tl;dr for that is basically: Kite has been collecting "anonymous" data from sublime users with the SideBarEnhancements plugin installed. This has been happening for atleast a year and the data collected included activeNonBundledPackageNames which is basically a list of packages installed via Pac…

For what it's worth, we didn't remember. There was no upside to keeping it there.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#26
Deeply concerning that this has been in place for "the better part of a year", and that they "didn't remember" about their telemetry collection - how careless have they been with the actual data, if they don't even claim to be able to keep track of gathering it?

This is a complete destruction of their narrative from last week. They'll be sorry for being caught - again - and we'll have to be on continual lookout for this kind of thing in the future. I can't wait for the floodgates to open, once major tech companies figure out that there's not enough oversight to prevent this 100% of the time: I expect more than a few projects to be bought out similarly.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#27
I'd implement an industry-wide blacklist, personally. This is strike number, two? three? of this company subverting well-known packages with telemetry. Any package that is proven to be connecting to their servers should be removed, the authors should be banned, and the company should be thrown onto a list of Known Bad Actors to prevent any kind of package, add-on, or extension from ever accepting them again.

You cannot fight this kind of malevolence with a finger-wag and a proposed solution that you simply inform the user next time before doing it. It will become buried inside the ToS and become ignored and commonplace. Stop it now and forever, while the spotlight is on it.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#28
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

I wonder if part of the problem is VC demands in the first place.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#29
post #28
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

I wonder if part of the problem is VC demands in the first place.

Of course it is! But "don't be a shithead" is a moral imperative that you need to uphold over your investors leaning on you. I mean, not being a shithead won't get your chief growth hacker's blog all hype, but words fail me (and they rarely fail me) when I try to express how little I care about that.

That's also why I didn't try to say that the founders or the executive team should be better. I'm talking about the people who those founders and executives use to do bad shit and who they will screw whenever it makes a tiny bit of business sense to do so.

Plenty of people work for literal sociopaths. It's rare that you can just point and go "...duh?" about it, though.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#30
post #11

Earlier quoted context omitted.

It might be worth searching every release in the package_control_repo for this IP address... https://github.com/wbond/package_control_channel/tree/master...

Seems not to be included in any other file on github: https://github.com/search?utf8=%E2%9C%93&q=%2252.52.168.91%2...

[deleted]
Post reply on HN