4 ms·
I think the answer to your question is : "* Fine-grained privacy controls modeled after the .gitignore file format means that you can selectively and precisely
by StyloBill 10y ago
I think the answer to your question is :
"* Fine-grained privacy controls modeled after the .gitignore file format means that you can selectively and precisely decide which files and folders Kite indexes."
- Karunamon 10y agoUnfortunately, that means that a really simple app where a developer hardcoded something like an API key, and didn't put it in a separate file they told Kite to ignore, will get uploaded. Any system that relies on people following best practices is doomed in the real world :(
- Cyph0n 10y agoYou mean like Git?
- Karunamon 10y agoGit isn't generally configured to automatically upload your files as you type or as files are saved. There are things like GitFS, but I imagine those aren't part of an average developer's workflow.
- Cyph0n 10y agoMy point is that an inexperienced Git user can push their secrets to Github for example, just like a Kite user who doesn't specify a .kiteignore.
- Karunamon 10y agoMy point is that it's a lot easier to happen accidentally when the upload happens automatically and without intervention. With git, you directly specify what files you're committing (with the .gitignore as an additional safety net) and when that commit happens. It's all manual. If I'm testing an app and I want to hard code an API key for testing, and I'm using Github, it's not a problem. I have to explicitly commit that file. Now, I have to both remember that Kite uploads everything, and avoid using that workflow at all, and use the .kiteignore thing (which is another random dotfile in my repo, great).
- Cyph0n 10y agoAgain, I go back to your whole issue with how an inexperienced user of Kite can easily shoot themselves in the foot. The same applies to Git: 'git add .' and push.
- anonymousjunior 10y agoYes, you are correct in that an inexperienced Git user can mess up, I won't deny that. My issue here is that Kite requires you to proactively place a .kiteignore, before even whitelisting a directory. It also doesn't alert you that it's about to start indexing the files in the directory tree or that you need to add a .kiteignore to protect sensitive files before you whitelist them. At a minimum they should be respecting the existing .gitignore, and realistically they just be scrubbing all strings before sending any data. I can 'git add .' and commit my life away, but that requires much more intention and explicitness than clicking enable on a prompt and continuing your standard workflow (ie: a simple 'vi super_seceret_file.py')
- waisbrot 10y agoYou can run your own git repository (it's really easy). And most of the Git-service providers offer an "enterprise" version where you can self-host.
- Cyph0n 10y agoWhat happens when someone inexperienced pushes their SSH private key to Github? Isn't that same as not specifying a .kiteignore file?
- Twirrim 10y agoThat reads like "enabled by default, denied only on request"