Live data from Hacker News

Kite Responds to the Minimap and Autocomplete Issues

kite.com

31–40 of 75 posts

Re: Kite Responds to the Minimap and Autocomplete Issues

#31
> Staying Open: Kite Responds To The Minimap and Autocomplete Issues

I have two problems with that title:

1) Implies that you were open in the past, which Kite really wasn't, and 2) "Issues" is an understatement and borderline misleading. A more accurate term might be "debacle".

> Kite has been knocked around in social media (and the actual media)

"Knocked around" - sounds like victim language to me. You weren't knocked around - you were:

1) Caught red-handed, 2) Called on the carpet for your deceptive and bad business practices, and 3) Lost reputation and standing because of the choices you made.

If anything, it was you, Kite, who "knocked around" millions of minimap users by your irresponsible and unethical actions. In fact, reading the Github issue thread, it looks like your actions may have cost Atom some users.

Shame on you guys. The backlash wasn't anything that Kite's actions didn't warrant.

> How did we get ourselves here? We started Kite with the idea that machine learning....

Please don't attempt to turn your apology into an advertisement for your business. Maybe that's not what you intended, but that's how it reads to me. I'd feel better about this blog post if it talked less about how awesome Kite is and more about how awesome the open source community that held you accountable is.

-------------

While I appreciate that Kite is (somewhat) owning up to its mistakes, I'm concerned that, had there not been such a vocal community backlash, Kite would never have self-corrected this move.

I think hiring a Community Manager is a step in the right direction for Kite. Hopefully, he/she will work with the open source community to tell anyone else who tries to pull these types of shenanigans to, "Go fly a kite." [1]

[1] http://idioms.thefreedictionary.com/Go+fly+a+kite!

Re: Kite Responds to the Minimap and Autocomplete Issues

#32

I interviewed with Kite a number of years back. From that experience, I am entirely sure that they really had no malicious intent with any of this. That being said, I did tell them that IMHO they were severely underestimating the privacy concerns of developers. Looks about right.

They had no malicious intents? Like in they had no intentions of hiring open-source maintainers, taking over their codebases and quietly injecting their product?

Point is, if we don't consider this sort of behaviour malicious then we can expect to see this more and more often.

Re: Kite Responds to the Minimap and Autocomplete Issues

#33

An apology that starts with 4 paragraphs of self-congratulation is not a real apology at all. Nothing of the article reads as being genuinely regretful of the strategies taken - it's just sorry for being caught. >Unfortunately, while trying to make programmers’ lives a little less complicated, we instead made them more complicated. Barely an admission of guilt, and even that can't get past without patting themselves…

Buying a popular addon with the express purpose of subverting its original intent for commercial monetization seems like it should be against Atom's TOS

This instance is razor thin close to being malware

What's to stop the next enterprising company from intentionally uploading all your code to their servers? Modifying your code? Or holding your code hostage? Atom has git support backed in, so how likely is it an addon could inject code and commit it without you ever seeing that it happened.

Atom's automagic update approach to addons can't survive this kind of exploitation. If I have to re-vet every addon every time there's an update, their entire ecosystem just turned to shit.

Do we need virus scanners for Atom packages now? An addon that scans repos to see if the primary contributor suddenly changed?

Re: Kite Responds to the Minimap and Autocomplete Issues

#34
post #10

Earlier quoted context omitted.

On the one hand, I agree with the sentiment. On the other hand, if it is really that shady, it is on the open source developer to say 'no.' As described here, it doesn't seem that shady. There was a choice between Kite and Jedi for the one plugin, and for the other plugin, it was basically an AD. On the gripping hand, I really want open source developers to get paid, this seems like a way for open source developers t…

I'm in that boat as well. Initially, I was thinking this all was done with ill-intent. But now that we have heard Kite's side, it sounds more like just poor execution of a good idea.

It was good execution of a very bad idea.

Re: Kite Responds to the Minimap and Autocomplete Issues

#35

Earlier quoted context omitted.

The problem is that the screen was not clear enough. Users just press Continue, Continue, Agree, OK, Share all my user directory, Install, OK, Close. They never read the small or big letters, they just click the green button. The "Enable local engine" looks like a "Cancel" button. That's how you get installed an unwanted browser bar, a new amazing search engine, and the Norton security pack for 60 days. If you see th…

Once again, that sounds more like a fundamental flaw in the service/software and less like malicious intent. I'm probably not going to use their service any time in the future, but to imply they intentionally put users in the dark is kind of a stretch. More like, they failed to communicate how their service worked. Also, they failed to provide a clear distinction between the two options for completion engines that de…

Or, "hey, should we try to put our ads in the minimap package?"

It probably doesn't matter if it was intentional hostility or unintentional incompetence. Either way, it needs to be fixed.

Re: Kite Responds to the Minimap and Autocomplete Issues

#36
This comment is very sightly off-topic for this story, but 100% on topic for HN, and so many people might find it useful that I feel compelled to write it.

The first link in this write-up is to this story which gives the background:

  https://theoutline.com/post/1953/how-a-vc-funded-company-is-undermining-the-open-source-community
And I wanted to draw attention to something remarkable from that write-up. Without any irony, completely straight-faced, the writer nonchalantly included the line:

   >Although Kite has no business model yet, it’s widely
   >thought in Silicon Valley that having users is the
   >first step toward profitability.
The article had introduced the startup as:

   >a $4 million venture capital-funded startup
That's not a valuation but the size of the round.¹ The title and subtitle of the article are:

   > How a VC-funded company is undermining the open-source community
and:

   >A San Francisco startup called Kite is being accused
   >of underhanded tactics.
Now what I wanted to bring attention to in this comment is the fact that it is possible to nonchalantly mention that a startup has no business model, and is a $4 million VC-backed business, but this tells you nothing about the startup: except that it is based in Silicon Valley/San Francisco.

I really want to emphasize this geography to you, because people here are skeptical.

We had a recent article here on "Ways a VC says no without saying no". One person wrote ², in complete denial:

   >a few years ago when trying to raise a Series A. We
   >were getting the "location" excuse over and over. It
   >usually went something like, "we love what you are
   >doing, and we would probably invest in you, but your
   >location is a non-starter for us." The truth, as was
   >illuminated to me during, is that they just aren't
   >interested. If you were a compelling enough business for
   >the investor, your location would not be a factor. If
   >you can prove that you are succeeding in your location,
   >then the location obviously isn't an issue.
VC after VC after VC mentioned the exact words "your location is a non-starter" but this person is in denial.

I wanted to use this story to illustrate that you do not even need a business model in order to raise money in Silicon Valley/San Francisco. It is there in black and white and without comment, mentioned off-hand in a story about something different. Memorize these fourteen words. Memorize these words now: "A San Francisco startup"; "$4 million venture capital-funded"; "has no business model yet."

Just memorize it. It is the difference between the success and failure of your startup and if you read this comment carefully and take it to heart, this comment can become the most important one you will have read in the past five years.

¹ https://www.crunchbase.com/organization/kite-com

² https://news.ycombinator.com/item?id=14815785

Re: Kite Responds to the Minimap and Autocomplete Issues

#37
post #25

Earlier quoted context omitted.

> Company needs users. sure, that's fine > Plugin has users. Still no problem here. > Plugin does things company's flagship product _could_ do (and it is _free_). Yep, all kosher. > Company reaches out to Plugin developer and they come to an agreement to add support for the flagship product into the Plugin, but the new support is _not_ enabled by default. … and there's the problem, that's not what happened. First it'…

I get what you are saying, but I still don't see much of an issue here. The ultimate decision to actually _implement_ all of those changes in those existing open source projects lies with the project maintainers/owners.

In the first case, the project maintainer/owner was asked to make the change, and it's implied possibly paid to do so. But as previously stated, that particular case wasn't that bad, since the only thing shady there was the use of some dark patterns to bias people towards Kite while somewhat obfuscating that it would disclose their source code.

In the second case, because they hired the project maintainer/owner, that made Kite effectively the project owner, and as was established, the thing people are really angry about was the second case. So yes, Kite is 100% to blame as the project owner (via hiring the project owner).

I suppose there are probably two lessons to learn here. First, if something is a major open source project that's widely used, it would be a good idea to make sure there are multiple project owners/maintainers with veto powers to keep each other in check. That wouldn't stop a company from hiring ALL the owners/maintainers on a particular project, but it would at least increase the difficulty, particularly if they were geographical distributed potentially forcing the company to work out employment in multiple countries.

Secondly, when a company acquires an open source project, they are obligated to follow the norms and expectations of the open source community, at least if they don't want to have said community complaining about (and eventually forking) their newly acquired project. Since presumably they found value in the project, it's in their best interest to not upset the community thereby reducing or destroying that value. As such, any action they take that could be construed as giving favor to their commercial products over others (particularly other open source products), or which would introduce ads into the project, need to be considered VERY carefully and great care needs to be taken around how those sorts of things are implemented and introduced. In particular making sure all your ducks are in a row by making sure you get buy in from a significant portion of the products user base before rolling the changes out.

Re: Kite Responds to the Minimap and Autocomplete Issues

#38
post #14

> Let’s be clear: the absolute last thing we wanted was for someone’s code to get synced to our servers without their knowledge. I don't buy it. The UX was dark-patterned to enable this very thing, and this reads like damage control when it's clear it wouldn't fly under the radar. If it were the last thing Kite wanted, there would be a big warning that this option uploads your code to their servers. Or some mention o…

> Or some mention of the upload at all

The image they show in the post shows that they were fairly clearly saying "Where enabled, your code is sent to our cloud":

https://kite.com/static/media/autocomplete-python-flow.690d3...

Sure, it is not exactly hilighted there, but I wouldn't say that they were trying to hide that either.

Re: Kite Responds to the Minimap and Autocomplete Issues

#39

Earlier quoted context omitted.

The problem is that the screen was not clear enough. Users just press Continue, Continue, Agree, OK, Share all my user directory, Install, OK, Close. They never read the small or big letters, they just click the green button. The "Enable local engine" looks like a "Cancel" button. That's how you get installed an unwanted browser bar, a new amazing search engine, and the Norton security pack for 60 days. If you see th…

Once again, that sounds more like a fundamental flaw in the service/software and less like malicious intent. I'm probably not going to use their service any time in the future, but to imply they intentionally put users in the dark is kind of a stretch. More like, they failed to communicate how their service worked. Also, they failed to provide a clear distinction between the two options for completion engines that de…

I feel like part of the disconnect is that Kite uploads source code to servers. In a perfect world with perfect security and 100% honest people, this is no big deal. The world doesn't work like that.

The last thing that I or my employer wants is our source code sitting on someone else's server - even if it's for code completion. My employer's code is proprietary. Period. If I mistakenly enabled Kite when working on some of this source, it's a huge deal. That is grounds for termination, and I am sure there are many other programmers who are in the same boat.

It's probably not a big deal that someone's code is on there, but there are big implications. It doesn't matter that it probably won't be seen. If the source has been leaked to a 3rd party, it would be negative. My employer doesn't give two flips about fundamental flaws and malicious intent. They care if it did or did not happen.

Re: Kite Responds to the Minimap and Autocomplete Issues

#40
post #38
post #14

> Let’s be clear: the absolute last thing we wanted was for someone’s code to get synced to our servers without their knowledge. I don't buy it. The UX was dark-patterned to enable this very thing, and this reads like damage control when it's clear it wouldn't fly under the radar. If it were the last thing Kite wanted, there would be a big warning that this option uploads your code to their servers. Or some mention o…

> Or some mention of the upload at all The image they show in the post shows that they were fairly clearly saying "Where enabled, your code is sent to our cloud": https://kite.com/static/media/autocomplete-python-flow.690d3... Sure, it is not exactly hilighted there, but I wouldn't say that they were trying to hide that either.

As a third party to this debacle, all I have to go on is the comments people have made, but a few of them have asserted that that language was added later on and some initial versions of this change either outright lacked that warning, or else used styling tricks to make it difficult to notice. I lack the time and/or motivation to go digging through the commit history for that plugin, but maybe someone more enterprising could do so and verify if that warning was always present and presented in such a visible fashion.
Post reply on HN