Live data from Hacker News

Gitlab cancels plan on tracking user behavior on GitLab.com

gitlab.com

271–280 of 285 posts

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#271
post #205

Earlier quoted context omitted.

Were people really arguing for removal of telemetry altogether? I would think that many of us are comfortable with aspects of tracking. For me, the concern was the value of the content. It might as well have been my bank saying they were going to start embedding disqus threads.

Not everyone wants tracking, even if that means sacrificing software quality. Making it mandatory is never excusable.

It was opt-out, not mandatory.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#272
post #27

We received an apology email at the same time, well written, explaining what they did wrong, apologizing, promising to do a post-mortem, promising to not send to 3rd party trackers, and saying they did a mistake and waiting for feedbacks on the issue tracker. And with very little BS in the mail. Such level of transparency, of apologizing and clarity, especially written at the first person "I am truly sorry." is very…

No, there's nothing to praise here. When I delete all my repositories by hand, one by one, I expect to not find a joke in that email about how "this email is sent to you because you have an active repository on Gitlab". When I delete an account on Gitlab I expect to be deleted from all further mailings (especially ones I never subscribed separately to), yet I got this email today. How many more places do I have to de…

Hi GitLab employee, we used the same mailing list as the one we used for the first email, so that's why you still received it. If you deleted your account you won't get any future emails.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#273

Earlier quoted context omitted.

Here's a screenshot for people that don't feel like waiting for the page to load: https://imgur.com/a/uxaU0h8 How is GitLab still this slow?

It's a Rails app trying to load hundreds of different bits of data (emojis, comments, votes on comments, etc.), I'd honestly be more surprised if it were quick.

GitHub loads similar data and is also written in rails, but long GitHub PRs/issues are significantly faster to load.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#274

Earlier quoted context omitted.

Not everyone wants tracking, even if that means sacrificing software quality. Making it mandatory is never excusable.

It was opt-out, not mandatory.

Was it? My bad. I thought I read something about GitLab planning to block access to the platform until you accepted the new ToS but maybe I was wrong.

My point still stands though.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#275

Earlier quoted context omitted.

This assumes all participation is equal. This is not the case. It’s GitLab’s sandbox, their rules (including not being crass if desired). How is this different than what would be expected with a Code of Conduct? Must one call out “Don’t be a dick”? Vigorous debate is to be expected, being rude is not.

> It’s GitLab’s sandbox, their rules (including not being crass if desired). They can ban people who clicked on the "Reversed Hand With Middle Finger Extended" emojis. If it's against their rules, they should (otherwise there's no point in having rules in the first place). That said, if the emoji is in their system (and it's not there by accident), it probably serves a purpose. In this case, it accurately represents…

I am absolutely of the mind that Codes of Conduct have been weaponized, but there’s no reason for participants to be so overtly rude in the discussion, regardless of reactji availability.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#276
post #219

Earlier quoted context omitted.

I think that’s a fair point from a security standpoint, but there are clear technical solutions for sending telemetry data to third party scripts without allowing page access that are well established (e.g safeframes) yet the conversation isn’t about that. The conversation (more like coordinated uni-directional screeching) is instead an irrational moral panic which is not justified by the facts at hand. I don’t see t…

In the self hosted instances, which is what I was talking about, you do have a control over the backend. At last more than you do with the managed version. It pretty much boils down to this: Can something leak sensitive information to a third party. If so, then it's a no go. If you have a contract with that third party, and you deem that third party to be a safe harbour for your data (yes, that includes gitlab.org, A…

I see your point with respect to self-hosting. I get that most of the reason for running on-prem is data security and privacy and I can see why people might get annoyed at something they thought they were buying not really being there.

That said, while I'm not familiar enough with the details of how Gitlab supports self-hosting to comment on whether or not their particular case allows them control over the backend still or not, many self-hosted AWS solutions are implemented as marketplace AMIs for which the end-user can run in their VPC but still doesn't maintain control over what is running inside the AMI. It's not necessarily that odd for software implemented this way to still phone home with telemetry.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#277

Earlier quoted context omitted.

Are you in a contractual relationship with AWS for every service you use that uses AWS on the backend? How about Loggly? How about BigQuery/Snowflake? Intercom if they use that? Salesforce? Facebook and Google if they run ads? They may not do anything weird with your data now but how can you know that things won’t change over time?

GDPR.

You don't understand GDPR very well.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#278
post #219

Earlier quoted context omitted.

In the self hosted instances, which is what I was talking about, you do have a control over the backend. At last more than you do with the managed version. It pretty much boils down to this: Can something leak sensitive information to a third party. If so, then it's a no go. If you have a contract with that third party, and you deem that third party to be a safe harbour for your data (yes, that includes gitlab.org, A…

I see your point with respect to self-hosting. I get that most of the reason for running on-prem is data security and privacy and I can see why people might get annoyed at something they thought they were buying not really being there. That said, while I'm not familiar enough with the details of how Gitlab supports self-hosting to comment on whether or not their particular case allows them control over the backend st…

They indeed do have opt out instance wide telemetry. This is restricted to specific site-wide activity: number of merge requests created, users active, gitlab version, usage of feature X etc. It doesn’t send back any sensitive data (project names, namespaces, comment text, diffs), or give the potential to access that to a third party.

You can also view all the data it sends back in the admin console, and disable it.

Again, it’s the trust aspect. Sure, gitlab could just silently implement a phone home with all your private data (even by accident). They would be put out of business if they did, for breaking their contract with us and others. Nobody would trust them.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#279
post #245

Earlier quoted context omitted.

The EU court needs to actually be able to enforce its decisions, which may require a US court.

Are you sure that American companies are immune to fines resulting from EU court sentences if they want to make business in EU?

The EU could certainly stop them from doing business there. Beyond that, you can't be sure they could collect fines. It may depend on the technical details of what the fines are about, and how big they are. America has human rights that privacy regulations like California's CCPA are careful to waltz around.

Re: Gitlab cancels plan on tracking user behavior on GitLab.com

#280
post #143

Earlier quoted context omitted.

Uh, that's not how it works. Legitimate veto power is usually based on a board and/or shares of the company. Not to mention most CFOs are appointed positions in startups, because they are usually not roles filled in the early days of a tech startups life (as opposed to CEOs and CTOs). Note - it is worth saying, CFOs are, generally speaking consider extremely important positions for many companies, even more-so than t…

"Oh, you're wanting to implement more 'privacy' for our users? Well it turns out that we've just done a reorg, and your whole department has no budget for the rest of the year." As you say, whoever controls the money flow, ultimately controls the people, and can shut down any activity they desire... Sure it's not "legitimate veto power", but ultimately it is the same thing.

> whoever controls the money flow, ultimately controls the people, and can shut down any activity they desire

I never said this...

Post reply on HN