Live data from Hacker News

Kite telemetry code in Sublime package SideBarEnhancements

forum.sublimetext.com

51–60 of 120 posts

Re: Kite telemetry code in Sublime package SideBarEnhancements

#51

On the topic of tracking, you might want to check your browser extensions as well. I discovered tracking codes inside a browser extension back in 2013, and I doubt that it would be the last one: https://paradite.com/2013/12/07/solved-issue-with-vglnk-all-... (Ironically by visiting my blog post you are contributing to tracking by Google Analytics)

> (Ironically by visiting my blog post you are contributing to tracking by Google Analytics)

That's interesting, where's the opt-in for that on your blog? I don't see a modal that asks me before transmitting any of my data, or even giving my IP to a third party, or doing any tracking, as is required by EU law.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#52
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

Reply to your npm edit: How do you know it is a Chinese server? it seems to be masked:

https://www.whois.com/whois/hacktask.net

Re: Kite telemetry code in Sublime package SideBarEnhancements

#53
post #48

Earlier quoted context omitted.

This seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been wh…

Collecting any data without request is unacceptable, and unlawful. In fact, it might violate more than a dozen of laws in the EU. This is a general matter of principle. You do not get to access anything that is mine without approval. If no one opts in, that's your problem, and you need to rethink your business model - and not break into users systems and steal their data. This is malware.

I'll agree with you if you explain this: Why is it ok for a website to do it, but not ok for an editor plugin to do it? Just because the content is streamed from a server? That's a rather convenient distinction.

I don't endorse Kite's behavior, but our reaction here is so far over the top that it seems like normal onlookers will start to take us less seriously. We're talking about violations of law and data theft over answering the question "Which language are you editing today?"

Zero tolerance is a rejection of "Let the punishment fit the crime."

Re: Kite telemetry code in Sublime package SideBarEnhancements

#54
post #41

On the topic of tracking, you might want to check your browser extensions as well. I discovered tracking codes inside a browser extension back in 2013, and I doubt that it would be the last one: https://paradite.com/2013/12/07/solved-issue-with-vglnk-all-... (Ironically by visiting my blog post you are contributing to tracking by Google Analytics)

uBlock begs to differ ;-)

Grimd for the DNS blocker!

Re: Kite telemetry code in Sublime package SideBarEnhancements

#55
post #46

Earlier quoted context omitted.

1) Principle is what matters. This behavior is utterly and completely indefensible; screwing with people's private code for your whatever-nobody-cares startup is absolutely unacceptable at any level. I don't care how big your Series A round was or who your investors are, you just don't do it and you don't hide it and you don't lie about "forgetting" about it (and it should be considered a lie until proven otherwise b…

Collecting file extensions bucketed by time plus a list of installed package names is spying on you? I doubt they even thought of the competitor angle. I wouldn't have. Startups don't win by worrying what every new company is doing. It wasn't a smart decision, but you're acting like they are uploading your entire source code tree. (I think someone even claimed that they were doing this at one point but was later show…

Man--I like you and I think you are a pretty awesome poster, so I'd like to go through an experiment with you. Upload the filenames of everything you've put through your editor in the last nine months. Pastebin it for me right now (and I say pastebin because I sure have no idea how secure Kite's stuff is so we're gonna be assuming that it's not, yeah?). The request is totally insane, right? Even beyond the pure principle of it, if you did that for half a dozen developers we'll find something you really don't want me to know about, be it business or personal. (Ever use, say, org-mode or vimwiki?)

I'm willing to be strident because heads on pikes are how you ensure this is not repeated in an amplified way. Kite might be dopey, stupid, careless, and mean instead of actively malicious. Doesn't matter. The next one will be if clear lines are not drawn.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#56
post #24

Again? Is there no escape from these guys?

I really don't like the idea of having to wonder if the next plug-in/editor/IDE/etc I use is compromised by Kite or any other shady phone-home companies.

use vim ;]

Re: Kite telemetry code in Sublime package SideBarEnhancements

#57
post #48

Earlier quoted context omitted.

Collecting any data without request is unacceptable, and unlawful. In fact, it might violate more than a dozen of laws in the EU. This is a general matter of principle. You do not get to access anything that is mine without approval. If no one opts in, that's your problem, and you need to rethink your business model - and not break into users systems and steal their data. This is malware.

I'll agree with you if you explain this: Why is it ok for a website to do it, but not ok for an editor plugin to do it? Just because the content is streamed from a server? That's a rather convenient distinction. I don't endorse Kite's behavior, but our reaction here is so far over the top that it seems like normal onlookers will start to take us less seriously. We're talking about violations of law and data theft ove…

It's not okay for websites doing this, and any website doing this from May 2018 on will end up fined hundredthousands of dollars every time they do this.

The European General Data Protection Regulation [1] is coming, and everyone that doesn't comply with it will have more than just a little problem.

No site or program is allowed to track or store anything about me, to transmit anything to a third party, or to even connect to a third party without my explicit authorization, and I have to be able to opt out of it all, and still be able to use it.

This is a simple moral principle of consent. You don't get to access anything that is mine without my explicit consent.

[1] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Re: Kite telemetry code in Sublime package SideBarEnhancements

#58
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

Reply to your npm edit: How do you know it is a Chinese server? it seems to be masked: https://www.whois.com/whois/hacktask.net

http://hacktask.net/ shows a "we'll be right back" message in Chinese. It could be misdirection, but I'm not exactly doing forensic analysis here.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#59
post #55

Earlier quoted context omitted.

Collecting file extensions bucketed by time plus a list of installed package names is spying on you? I doubt they even thought of the competitor angle. I wouldn't have. Startups don't win by worrying what every new company is doing. It wasn't a smart decision, but you're acting like they are uploading your entire source code tree. (I think someone even claimed that they were doing this at one point but was later show…

Man--I like you and I think you are a pretty awesome poster, so I'd like to go through an experiment with you. Upload the filenames of everything you've put through your editor in the last nine months. Pastebin it for me right now (and I say pastebin because I sure have no idea how secure Kite's stuff is so we're gonna be assuming that it's not, yeah?). The request is totally insane, right? Even beyond the pure princ…

Your posts are pretty good too! I completely agree that collecting filenames would be a blatant breach of trust. If they were doing that, I'd be the first one labeling the company as evil. But my hangup is that they didn't actually do that, and what they did do seems benign.

The thing is, market forces are pretty good at settling these issues. It's an open-source plugin, so everyone can see what they're doing. If they start being naughty, people can uninstall and switch to something else. But why are we punishing them before they did anything serious, along with locking down the ability of anyone else to ever collect any kind of usage data about their plugins? Even something harmless like "time spent trying to figure out the options screen"?

I hope it doesn't seem like I'm trying to defend spyware here. Collecting metrics about your product is the first step toward improving it. The motive seems like a positive one, not a negative greedy one.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#60
post #48

Earlier quoted context omitted.

Collecting any data without request is unacceptable, and unlawful. In fact, it might violate more than a dozen of laws in the EU. This is a general matter of principle. You do not get to access anything that is mine without approval. If no one opts in, that's your problem, and you need to rethink your business model - and not break into users systems and steal their data. This is malware.

I'll agree with you if you explain this: Why is it ok for a website to do it, but not ok for an editor plugin to do it? Just because the content is streamed from a server? That's a rather convenient distinction. I don't endorse Kite's behavior, but our reaction here is so far over the top that it seems like normal onlookers will start to take us less seriously. We're talking about violations of law and data theft ove…

> Zero tolerance is a rejection of "Let the punishment fit the crime."

There's to say though, as a counterpoint, that said principle always takes into account repeated offenses (recidivism), and they are at strike 3 or something.

Post reply on HN