Live data from Hacker News

Kite telemetry code in Sublime package SideBarEnhancements

forum.sublimetext.com

81–90 of 120 posts

Re: Kite telemetry code in Sublime package SideBarEnhancements

#81
post #24

Earlier quoted context omitted.

I really don't like the idea of having to wonder if the next plug-in/editor/IDE/etc I use is compromised by Kite or any other shady phone-home companies.

use vim ;]

What's stopping Kite from grabbing one of your Vim plugins and adding telemetry to it?

Re: Kite telemetry code in Sublime package SideBarEnhancements

#82
post #20

So this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a wi…

This seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been wh…

Yes, the reaction is appropriate. You seem to agree that this is malicious action, so your position is kind of hazy.

> People have been whipped up into a frenzy for data that a webapp wouldn't blink twice at collecting. But when it's installed locally it's somehow different than if we load a webapp in a browser?

Well, yes. But it's even worse than that. This code was submarined into an unrelated open source tool and sent the data to a company with which the user had no relationship whatsoever. That's a little different from Google keeping track of how often I log into GMail, isn't it?

Even the README you linked to (probably not seen by many users) seems intentionally misleading, as it is careful not to state to whom the metrics are sent, leaving the reader with the impression that they are being sent to the project maintainer and not to Kite, Inc.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#83
post #65
post #10

Earlier quoted context omitted.

They apparently paid the author (Tito) to add it in. Originally he had pulled all of his packages from the default channel because he was unhappy that we require semver for all new packages (to allow newer features to work). After a bunch of users complained, he added SideBarEnhancements back (his most popular package), but apparently at some point later Kite paid him to add tracking code to it.

If an addon maintainer was successfully bribed to add something like this to their addon, that maintainer should probably be banned from the ecosystem along with everything Kite touches. Kite is the primary corrupting force here, but the people who keep taking money to screw over their userbase need to be punished as well. Sublime, Atom, and VSCode all need to step up right now and make it clear that this kind of beh…

To your edit:

I'm not sure how Package Control handles removals of packages but if they are left installed in sublime then this was probably the best move.

If the package was left "orphaned" in the editor the telemetry would remain but I'm pretty sure PC updates packeges automatically by default so pushing an update without it makes sure the code is removed for most users.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#84
post #82

Earlier quoted context omitted.

This seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been wh…

Yes, the reaction is appropriate. You seem to agree that this is malicious action, so your position is kind of hazy. > People have been whipped up into a frenzy for data that a webapp wouldn't blink twice at collecting. But when it's installed locally it's somehow different than if we load a webapp in a browser? Well, yes. But it's even worse than that. This code was submarined into an unrelated open source tool and…

Even the README you linked to (probably not seen by many users) seems intentionally misleading, as it is careful not to state to whom the metrics are sent, leaving the reader with the impression that they are being sent to the project maintainer and not to Kite, Inc.

This is an important point, and it's one I overlooked. I've never used SideBarEnhancement. I assumed users knew it was related to Kite. If `urlopen('http://52.52.168.91/status', json_body)` is the only indication where the data is sent, then that's unacceptably vague.

I suppose it's best for Sublime to force plugins to be opt-in for data collection, but as someone who wishes devtools were better, it's unfortunate a few groups with terrible PR skills are ruining it for everyone. It didn't need to turn out this way. They just needed to be open about what they were doing. They weren't even collecting anything to warrant being sneaky.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#85
post #77

Earlier quoted context omitted.

This seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been wh…

Kite basically just invented a new spyware/malware industry that specifically targets the development community. This kind of behavior needs to be stomped on hard and fast.

i mean executing malicious dynamic code as a plugin of a legit tool isn't that different from a malicious browser plugin

Re: Kite telemetry code in Sublime package SideBarEnhancements

#86
post #82

Earlier quoted context omitted.

Yes, the reaction is appropriate. You seem to agree that this is malicious action, so your position is kind of hazy. > People have been whipped up into a frenzy for data that a webapp wouldn't blink twice at collecting. But when it's installed locally it's somehow different than if we load a webapp in a browser? Well, yes. But it's even worse than that. This code was submarined into an unrelated open source tool and…

Even the README you linked to (probably not seen by many users) seems intentionally misleading, as it is careful not to state to whom the metrics are sent, leaving the reader with the impression that they are being sent to the project maintainer and not to Kite, Inc. This is an important point, and it's one I overlooked. I've never used SideBarEnhancement. I assumed users knew it was related to Kite. If `urlopen(' ht…

> I've never used SideBarEnhancement. I assumed users knew it was related to Kite.

Considering how many posts you've made in this thread defending Kite, this seems like a major gap in your understanding. A simple ctrl-F of both the Github README and the PackageControl page show no mention of Kite.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#87
post #57

Earlier quoted context omitted.

I'll agree with you if you explain this: Why is it ok for a website to do it, but not ok for an editor plugin to do it? Just because the content is streamed from a server? That's a rather convenient distinction. I don't endorse Kite's behavior, but our reaction here is so far over the top that it seems like normal onlookers will start to take us less seriously. We're talking about violations of law and data theft ove…

It's not okay for websites doing this, and any website doing this from May 2018 on will end up fined hundredthousands of dollars every time they do this. The European General Data Protection Regulation [1] is coming, and everyone that doesn't comply with it will have more than just a little problem. No site or program is allowed to track or store anything about me, to transmit anything to a third party, or to even co…

I don't know anything about the regulation and just skimmed the Wikipedia article for a minute, but isn't this regulation unenforceable in practice? If I have a website, how am I supposed to know if a visitor is a citizen of the EU? If my company operates outside of the EU, the EU has no jurisdiction.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#88
post #86

Earlier quoted context omitted.

Even the README you linked to (probably not seen by many users) seems intentionally misleading, as it is careful not to state to whom the metrics are sent, leaving the reader with the impression that they are being sent to the project maintainer and not to Kite, Inc. This is an important point, and it's one I overlooked. I've never used SideBarEnhancement. I assumed users knew it was related to Kite. If `urlopen(' ht…

> I've never used SideBarEnhancement. I assumed users knew it was related to Kite. Considering how many posts you've made in this thread defending Kite, this seems like a major gap in your understanding. A simple ctrl-F of both the Github README and the PackageControl page show no mention of Kite.

True, though all the code was doing was collecting a list of installed packages and a list of file extensions you've edited. Judging by the reactions here, you'd think they were uploading your entire ~/ directory.

I'm curious how Kite got the telemetry into that extension if it's unaffiliated. https://github.com/titoBouzout seems like a fairly standard github account, though it's strange he had no commits for six months until this incident.

Re: Kite telemetry code in Sublime package SideBarEnhancements

#90
post #75

Earlier quoted context omitted.

They split off the extension and only collect the ".md" part: https://github.com/SideBarEnhancements-org/SideBarEnhancemen... If it's an unrecognized extension, they set it to blank. That's why I was so confused why people are upset.

Yup - I understand that; I looked at the code. But, and I think I expressed this poorly, I have no assurances except through forensics (i.e., having to go grovel through a bunch of code for a few frigging sidebar functions that have no reason to be sending anything anywhere in the first place!), that that's all they did. The breach of trust has been created and it has created a relationship (an unwitting one) that th…

Yeah, after thinking it over, I agree. It also wasn't clear to me that they were trying to hide the fact that they were submitting the statistics to Kite. I thought they were being up front about it. Your reaction (and everyone else's) makes complete sense in that context. It was strange that a list of file extensions caused such uproar, but it's doubly strange that they tried to be shady about collecting it.

I guess it's best to enforce a blanket ban on this behavior. I still can't get over how dumb it was for Kite to do this. All they had to do was be open and honest about it and nobody would've cared too much. Crossing over into the realm of paid spyware is way too far.

Post reply on HN