3 ms·
I know this is your baby and all, but how high was your team (high as a kite?) when they thought sending every line of code to your server was a good idea? Ser
by AtheistOfFail 10y ago
I know this is your baby and all, but how high was your team (high as a kite?) when they thought sending every line of code to your server was a good idea?
Seriously, could just send the object type being "autocompleted"along with the other object types in the same file and gotten better results without the privacy backlash.
- ako 10y agoIs it really that much worse than having code on a private GitHub repository or pushing Python code to a paas platform like pivotal?
- AtheistOfFail 10y agoTrue, but Github and a PaaS platform tell you that your data is leaving your computer. It isn't something that happens in the background from a simple autocomplete application. The other thing is that a proper 12-factor app separates secrets and keys into environment variables that are not committed to Github or your PaaS. They are added after a deployment which this "product" just scoops up. For reference, here's what a AWS key being leaked on Github leads to (https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_github_crawling_with_keyslurping_bots/ https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...). Now, imagine that project that is running in production having to be brought offline because this company leaks thousands of AWS keys that were used in development. It's dangerous, sloppy and stupid, three things I generally try not to mix.