21 ms·
How a VC-funded company is undermining the open-source community
- GoToRO 9y agoWhy not use this to fund open source? Have a checkbox to disable ads if you really want to give people freedom. I just can't see how open source can compete without enough funds.
- jwildeboer 9y agoAfter 12 years working at Red Hat, I can assure you that Open Source not only competes, it is actually winning everywhere. And business models exist that are fair to all sides, allowing us to employ a lot of developers and participating in upstream. Ads are not a solution IMHO, they are a big part of the problem.
- jacquesm 9y ago> I can assure you that Open Source not only competes, it is actually winning everywhere. And business models exist that are fair to all sides, allowing us to employ a lot of developers and participating in upstream. It would be great to see not only an assertion but an article that spells this out in some detail.
- jwildeboer 9y agoThe Black Duck Open Source Survey 2016 is a good starting point IMHO, especially the first third. https://www.slideshare.net/blackducksoftware/2016-future-of-open-source-survey-results https://www.slideshare.net/blackducksoftware/2016-future-of-...
- vultour 9y agoWhy would you need an article? Most large tech companies share their infrastructure on their tech blogs, and most often it's completely composed of open-source software (e.g. Kafka, Nginx, Storm, Postgres, Redis, other Apache products, etc.).
- jacquesm 9y agoThis discussion goes well beyond infrastructure.
- veidr 9y ago> winning everywhere I like open source as much as the next guy, but I'm pretty sure you have a peculiar definition of "everywhere". (Or, perhaps "winning".)
- annabellish 9y agoThe internet primarily runs on open source software. Your browser is primarily open source software, unless it's IE/Edge, but let's be serious here. Your phone - primarily open source, unless it's WP/BB, but again, let's be serious. The desktop/laptop you're using right now probably isn't open source, but much of the important software running on it is, and most of the computers it talks to are, and most of the other computers, obvious or hidden, in your life are too.
- StavrosK 9y agoNot to mention that pretty much all of the services you use are mostly a glue layer over open source projects/libraries/services, including its OS and all those services.
- ClassyJacket 9y ago"Your phone - primarily open source" Is the iPhone actually primarily open source? There's certainly parts of iOS that are but I had no idea it was the majority of it.
- lucb1e 9y agoThe vast majority of phone is Android, though. One of the reasons I'd always recommend Android to friends and family is the open source component, even if said friends and family have no direct benefit from it (only indirect, through open source stuff being used and us being able to look at it and improve it).
- codegladiator 9y agoHe meant android I guess.
- 9y ago
- naturalgradient 9y agoReally? From what I gather from projects like RethinkDB or this: https://www.influxdata.com/the-open-source-database-business-model-is-under-siege/ https://www.influxdata.com/the-open-source-database-business... open source is a forever struggling business model.
- sebleon 9y ago> it is actually winning everywhere nice try, trump
- mikekchar 9y agoI think it's fair to say that open source has made inroads everywhere. If I were to tell my 30-year younger self what the future looks like, I don't think I would have believed myself. Having said that, there are lots of places where open source is having a hard time. In telecom and medical software for instance. I mean, I can set up a SIP server and inspect the Android source code, but there is a long way to go (like actually being able to build and deploy on a piece of commodity hardware in the case of Android). For medical software, just try to get access to source code for any medical device. You get the thing installed in your body and you can't even look at it. Like I said, in every place open source has won important battles. The future looks good, but let's not understate the challenges either.
- deleted 9y ago[deleted]
- feborges 9y agohttp://www.cnbc.com/2017/06/21/red-hat-ceo-8-figure-deals-in-telecom-just-scratching-the-surface.html http://www.cnbc.com/2017/06/21/red-hat-ceo-8-figure-deals-in...
- RubenSandwich 9y agoLook at this clear dark pattern: https://outline-prod.imgix.net/20170721-QVaxMDgDwdZ1TBufCdq4?auto=format&q=60&w=640&s=6daa6b12a3906d3ae21572e1f63c09c0 https://outline-prod.imgix.net/20170721-QVaxMDgDwdZ1TBufCdq4.... (Image taken from the article.) Want to use our service, then only lists positives. Or these other services, then only list negatives. If you're reading this Kite. I now have a negative view of your product. We cannot allow corporations to take over open source tools. Donating is perfectly fine and encouraged, but the above example is a downright take over. If you want another tool then create one, don't take over an existing one and use the communities trust of that tool to promote your product.
- bfirsh 9y agoI fell for this. I enabled it because I was curious about trying new development tools, only to find out later it uploaded all of the source code on my computer to their service. What the hell. It took me months to get through to a human to get them to delete my code, including two emails to the CEO. I like the idea, but there is no way I would use it after this experience.
- mirekrusin 9y agowtf are those guys doing, uploading source code without consent feels criminal, source code with app configs/secrets has ultra sensitive information. anybody has a list of infected packages so others can quickly remove with `apm uninstall ...`?
- koolba 9y agoWell technically you did consent by clicking "Enable Kite". I'm not familiar with Kite but the linked image has a line that says, "Click here to learn more.". I'd wager that it eventually links to a page that explains that all your source will be uploaded to their servers. Now that doesn't make it any less shady though...
- danmaz74 9y ago
- roadbeats 9y ago> It is unclear what Kite’s business model is, but it says it uses machine-learning techniques to make coding tools. Its tools are not open source. I've never heard of such a thing before. Could someone explain how would they use machine learning for building coding tools ?
- RubenSandwich 9y agoThey use machine learning to see which code patterns follow other code patterns and then make suggests based on that. "Oh, I see you've written X. Most people who write X follow it with Y." However, this requires reading people code that they upload to their servers. See their privacy policy here: https://kite.com/privacy https://kite.com/privacy.
- mirekrusin 9y agoYes, that's the scary bit that not a single developer will/should agree with. Auto-complete suggestions for `password = ` anybody?
- onion2k 9y agoI wonder if it'd be possible to use their service to inject a backdoor in to someone else's code.
- mirekrusin 9y agoYou just need to compromise their database and you should have access to plenty of source code running around, possibly with secrets/credentials etc - a disneyland for bad guys.
- matthoward 9y agoWhat Kite supposedly does is crowd-source code by uploading users' code to its server and then aggregating that data to train their ML algorithm. Then they can apply said algorithm on a specific client's code to recommend autocompletion suggestions as you type. There are plenty of great use-cases for ML in building coding tools, but the shady manner in which Kite imposes itself on Atom users who have these plug-ins installed (which is a large portion of the user-base), leaves a seriously bad taste in your mouth.
- bloomca 9y agoIf you are looking for the github thread – https://github.com/atom-minimap/minimap/issues/588 https://github.com/atom-minimap/minimap/issues/588.
- gus_massa 9y agoTotal biased takeaway [Please read all the github complete thread.]: @jlozano: > Hi, folks -- Juan from Kite here, thank you for the feedback, we appreciate it. [...] > We have decided to leave the feature as opt-out since many users have found it useful. [...] @abe33 > [...] I've been an employee at Kite for over half a year now and this plugin is now officially maintained by Kite. [...] I think that the BDFL system work in open source because it's too easy to fork the project. The old BDFL just transferred the power to a new BDFL, but it was not so clear for the community. There is a fork now, so if the situation doesn't improve and the users are unhappy, the Kite team will be the BDFL of an empty project without users.
- lucb1e 9y agoBenevolent Dictator for Life for anyone else who was wondering. https://en.wikipedia.org/wiki/Benevolent_dictator_for_life https://en.wikipedia.org/wiki/Benevolent_dictator_for_life
- omginternets 9y agoI just uninstalled Kite. It's a real shame as the service was good, but nothing is good enough to justify advertisements in my work-space. The fight against distraction is hard enough as it is without having to think carefully about where I'm clicking due to dark-pattern UI.
- mlindner 9y agoSo how was your company okay with you uploading the company code to Kite's servers?
- sattoshi 9y agoHe didn't mention using it under a company. I was tempted to use this for personal projects as I don't care where my code gets uploaded, it's all on github anyways. The reviews above made me reconsider.
- omginternets 9y agoL'état, c'est moi I'm a freelancer, and my code is open-source anyway.
- tangue 9y agoTime to write Adblock for code editors.
- Cthulhu_ 9y agoOr just fork the project before ads were added. Or not install the plugin.
- tangue 9y agoSure. But Electron is basically a browser and given our experience with browsers there's a long list of problems coming for Atom users.
- avaer 9y agoKite is (was?) apparently expanding to more plugins, and also doing it to existing plugins. That's not a battle you can win with manual diligence.
- StavrosK 9y agoIt's a battle you can win with forking and shunning any plugins they take over. That will show developers that injecting Kite into your popular project leads to it becoming very unpopular, very quickly.
- camiller 9y agoIs there a reliable way to search github for projects that are managed by Kite? Looks like it is only mentioned in the readme, and it would be simple for kite to simply not put in references to kite.
- StavrosK 9y agoCan't you do a code search for libraries or server names or something like that?
- dessant 9y agoThis is the minimap fork: https://atom.io/packages/minimap-plus https://atom.io/packages/minimap-plus https://github.com/mehcode/atom-minimap-plus https://github.com/mehcode/atom-minimap-plus It is a featured[1] Atom package, which may point to whom is GitHub endorsing in this issue, though we could see a more direct response from them regarding both minimap and autocomplete-python. After reading sadovnychyi's reaction[2] to the autocomplete engine selection screenshot, I think forking is also the only remaining step for autocomplete-python. [1] https://atom.io/packages https://atom.io/packages [2] https://github.com/autocomplete-python/autocomplete-python/issues/308#issuecomment-316361689 https://github.com/autocomplete-python/autocomplete-python/i...
- rawland 9y agoKudos to @mehcode for the fork [1]! And the author @abe33 for the apology [2]! I'm thinking, that @abe33 might not be responsible for this, but was "asked" by his employer (Kite) to do that. Then, there are alternatives such as sublimetext/vscode, which have the minimap builtin... Disclaimer: Not affiliated, I prefer n/vim anyways. This is a copy from my comment in the issue. Please read @abe33's comment [2] in the issue. This might explain a thing or two. -- [1]: https://github.com/mehcode/atom-minimap-plus https://github.com/mehcode/atom-minimap-plus [2]: https://github.com/atom-minimap/minimap/issues/588#issuecomment-316523163 https://github.com/atom-minimap/minimap/issues/588#issuecomm...
- danso 9y agoThanks for posting abe33's apology, hadn't seen it when I read about this issue last week. One of the more unnerving things about it was how he made this change without explanation months ago nor did he did he explain it now. It must have been frustrating for him, as the plugin's original developer, to be dragged through this crap. He ultimately is responsible for his actions, but I wonder if he knew that subverting his own plugin would be a job requirement?
- laurent123456 9y agoI can't imagine he would sabotage his own project for no reason, so most likely he got the job or some compensation in exchange for his cooperation and access to his repository, probably how they got python-autocomplete too. Otherwise, if they offered the job with no conditions attached he'd be under no obligation to change his own personal projects for them.
- sharemywin 9y agofine print my freind...fine print...ie giant unreadable employment contract. only speculating but truly possible.
- danso 9y agoYeah, I was wondering if Kite had a deliberate strategy to inject themselves into popular IDE-plugins, and their hiring plan includes reaching out to such creators. It's not unthinkable that they would slip in such an obligation after the contract is signed. I mean, we're talking about a company that conspired to covertly slip in these dark-pattern ads into mainstream open-source plugins. Ideally, the minimap creator could have taken a moral stand and quit, but I imagine his work situation and prospects (being from Europe) is different than if he were a developer in the Bay Area.
- fh973 9y agoThat sounds Atom plugin specific. Do Atom plugins not run in some sort of Sandbox?
- proaralyst 9y agoTo sandbox them away from the editor contents? I can't think of many of my (Vim) plugins that would work without access to the editor itself.
- nerdponx 9y agoVim, Emacs, and Sublime would all be similarly vulnerable.
- konart 9y agoSandbox that keeps them from your filesystem - maybe. But not from the editor or network (most of the plugins need or rather based on the idea of using them).
- tzs 9y agoIt's not clear to me from the article or the comments what it was actually doing. Looking briefly at kite.com, it looks like they provide a potentially useful tool/service that is kind of an alternative to searching the web for documentation. What I can't tell is whether what they did was make minimap incorporate results from Kite, so that you were essentially getting the Kite service (or a light version of it) bundled with minimap, or if they were putting ads for the Kite service in minimap, or if they were putting ads for other things in there.
- sebleon 9y ago> It is unclear what Kite’s business model is Their business model is to sell subscriptions to a premium version: https://kite.com/pro#business https://kite.com/pro#business
- scandox 9y ago> “Most users who install autocomplete-python close the engine selection prompt, which results in not getting Kite or its benefits” This type of entrepre-narcissism has to be shutdown hard. How deluded does somebody have to be to imagine that putting a confirm-shaming dialogue in an opensource tool is not Advertising?
- ivanbakel 9y agoThey're not deluded at all, it's just damage control. If they didn't believe it was advertising, it wouldn't be in the tool in the first place.
- throwaway91111 9y agoYea, it really confirms this as a corporate strategy.
- scandox 9y agoEvery interaction I have with these kind of guys proves to me that they deep down believe their own BS and that they are actually blind only to their own actions. I consider a delusion much more dangerous than a malign stratagem.
- danpalmer 9y agoI've tried Kite twice now. Once when it first launched, and once again when I installed autocomplete-python and it persuaded me to give it another go. So far I have found it utterly unconvincing to the point of near uselessness. It rarely finds anything intelligent to say about my code, and gives a significantly worse view of documentation than Dash (for which I have a hotkey bound for near-instant lookup). On top of that, I found Kite to use significant resources, there's no way to inspect what it's uploading so now way to ensure you aren't uploading things you don't want to, and the second time I tried it the UI was filled with dark patterns and I found it quite difficult to uninstall (I reverted to just trashing all the files I could find relating to it).
- bobjordan 9y agoI paid I think $79 for a year of Kite-pro and frankly, so far it is pretty useless. That said, it has permissions and settings to whitelist which folders on your computer can be indexed. Then, the settings page states that if you remove the directory from whitelisting then "any directories removed here will also be removed from Kite servers." Of course, that doesn't mean they will actually remove previously indexed data. Overall, probably this is a product that I would not want my dev team to install.
- mercer 9y agoI'd ask for your money back. Installing Kite left me with a really bad after-taste, but at least I assumed that if I'd bought into it, it would do as advertised.
- jdenning 9y agoThe "Kite Effect": when a company implements a marketing strategy that does more to deter potential customers than attract them.
- tanepiper 9y agoBlows them away in the wrong direction
- deleted 9y ago[deleted]
- conradk 9y agoTo me, it looks like Kite miscommunicated but didn't propagate spyware. From what I understand after reading the related issue on Github, it did not do any requests to its servers without explicit user permission. And I think the bigger problem is that 3rd party plugins are becoming a thing. Now, it's all about plugins, installing dozens of plugins that are difficult to audit before hand. It's like blindly installing software from torrenting sites, but shinier because it has the Github stamp on it.
- codegladiator 9y agoYou should really read the github thread AGAIN.
- conradk 9y agoCould you please elaborate ? I read the whole thing when I posted this comment: it seems like Kite did not automatically request its servers and I do think that plugin-mania is the bigger problem here. Installing plugins with no way to audit or restrict their access to the system capabilities is the problem. They should run in a sandbox. This has even been suggested before [1] but it seems like it has not yet been implemented. https://github.com/atom/atom/issues/1763 https://github.com/atom/atom/issues/1763
- tnone 9y agoThe answer to this should be a resounding "fuck off and don't come back". Open source is great because it is generally free of this pushy and disingenuously non sense. Defection over cooperation leads to the detriment of the commons.
- s_kilk 9y agoAgreed, these Kite fuckers need to be purged.
- tnone 9y agoTelling them their strategy is unacceptable should be enough. Do you want to fire up the ovens too? Oh nevermind, I see you're a self declared "commie feminist", wrong end of the horse shoe, my bad.
- s_kilk 9y agoYou do know 'purge' has other meanings aside from genocide right? Or is it more convenient for your performative outrage if you pretend otherwise?
- koliber 9y agoCould you clarify which meaning you had in mind in your original usage?
- emodendroket 9y agoPresumably what was meant was kicking them out of the open source community and not killing them.
- s_kilk 9y agoIt's kind of amazing that this needs to be clarified. I'm starting to think that people around here are only familiar with the word as it relates to that dumb movie of the same name.
- numbsafari 9y agoSo, what prevents any Atom package from being silently taken over and turned into a private code Hoover? Is there anything in Atom's packaging APIs that ensures plugins that can read source cannot also access the network without permission?
- jchw 9y agoAs far as I know: nothing yet. It hasn't been necessary. I don't think people even thought about it. But I think now it's going to become an ordeal...
- TeMPOraL 9y agoThis is why we can't have nice things. As you say, such limits weren't necessary - because people in the community weren't assholes. Now, thanks to Kite's abuse, somebody will have to implement a permission system to editor plugins...
- toyg 9y agoMan, where does this crap end? A permission system to click on a menu or type a character? A permission system to draw windows...? I think there has to be some responsibility from projects that pack such plugins, to police their ecosystem. I can understand browsers having security layers, because they work exclusively with the biggest cesspool of them all (the internet), but stuff as basic as a text editor should not need something like that - if it does, something else has gone deeply wrong with the project.
- jchw 9y agoI think we need a swift and damning response to this. I'd rather have an even worse walled garden than the Apple 'App Store' than deal with having to worry about my source code getting stolen to be used by some stupid cloud service. I don't even want data collection in my text editor; maybe from the vendor its acceptable but not N times for each plugin. I now feel compelled to vet the network usage of any plugin I install. Thanks, Kite. I'll make sure to remember this in case anyone ever considers your service.
- meddlepal 9y agoAgreed. Also this should be the kind of stuff that gets the founders and employees blackballed in the industry as well. Completely morally bankrupt. All of them.
- mistermann 9y agoTheir names should be on wikipedia along with the details of this story.
- rf15 9y agoLet's not make this a witch hunt. Yes, the company should be ostracised, but don't ask for every little person remotely involved with them to pay the price of a stupid lead decision.
- bachmeier 9y agoI don't know much about this particular case, so I don't have an opinion on the comments above, but the argument that employees shouldn't be punished for participating in an unethical for-profit scheme doesn't really make sense to me.
- rf15 9y agoWell, there is also the question of actual participation: Let's say [A]dam thinks they're not getting enough data and had this stupid idea to fix the problem, bought a bunch of repos when he had the chance, and told programmer [B]en to patch this in, while [C]hloe in another room is working on the website or tweaks the ML algorithm. How much is she at fault and involved here? What about [D]elilah and [E]ric in Support? Blaming them all individually and equally harshly for being associated with [A]dam is not really justifyable.
- roesel 9y agoWhenever I see a screen like this, I just use the "local engine" and make sure I never use the suggested product, ever. Have fun finding customers Kite...
- 2sk21 9y agoOpen source is very vulnerable to manipulation. Some years ago, I spent some time trying to understand the PAM module LDAP module on Linux (PAM is used to enable external authentication so its critical code). I found it to be completely impenetrable. We take such components for granted but if someone could inject malware into such code, it could be catastrophic.
- wvh 9y agoNot to mention it must be trivial for a large and determined adversary to subvert Debian, Arch or other distributions' packaging process, for example by getting a "sleeper" rogue developer in there. As someone into security and using open-source systems exclusively, it would be somewhat embarrassing to become a security problem yourself that way. I don't distrust Linux distributions' respective security guidelines; but it can't be that hard to find a loophole in community-driven system/software development and the damage would be substantial if a popular Debian package would have been subverted and have gone out with updates.
- bluejekyll 9y agoThe same statement could be made about any organization. If you get a sleeper agent into Apple, Google, Microsoft, whatever... There is a certain amount of goodwill we rely on in this world.
- lottin 9y agoExactly, no organisation is immune to sabotage.
- raesene6 9y agoIt's not quite the same thing as, AFAIK, the debian project doesn't have the same power as an employer does to do background checks before hiring. There's a significant level of risk around open source projects changing hands, something which may be invisible to the users of those projects, especially as they become more heavily used and therefore more tempting targets for attackers.
- bluepeter 9y agoBottom of the Kite web site I find this tell: "Made with [love emoji] in San Francisco"
- solidsnack9000 9y agoSmith also said that most of the negative reaction was due to confusion around what the tools actually do. (Connor pointed out that it’s not possible to review what Kite does, since it itself is not open source.) Then he blew this reporter off. “I apologize in advance that I can't answer any further questions,” he wrote. “I need to focus on other parts of the business, including continuing to improve the product for our users, and conflict like this is always doubly distracting.” Love and avoiding negativity have become the bywords of unaccountability. To foment conflict and then not comment...
- tbking 9y agoAnother endorsement of Open source community: We can see when you try to fool us.
- cronjobber 9y agoGoogle introduced and normalized the spyware/adware business model. Nothing but fawning adoration from programmers. Microsoft copied the model for operating systems. Token resistance from programmers. Kite copies the model for programming tools. Too late, programmers.
- kakarot 9y ago> Nothing but fawning adoration from programmers. That is a narrow way to look at things and is not the full picture. Plenty of people protested and still protest Google's unethical business practices.
- mercurysmessage 9y agoI'm pretty sure that the only OS that don't have adware/spyware in them at this point are some Linux distros (maybe) and Unix.
- matt4077 9y ago"Unix" isn't really a specific OS. So yeah, there's probably no spyware in it.
- mercurysmessage 9y agoBy Unix I mean FreeBSD, OpenBSD, NetBSD.
- edem 9y agoOr....[maybe not?](https://www.youtube.com/watch?v=7gRsgkdfYJ8 https://www.youtube.com/watch?v=7gRsgkdfYJ8)
- mercurysmessage 9y agoThere are tons of attack vectors that spyware can enter linux through :)
- TheRealDunkirk 9y ago
- waynenilsen 9y agoI see nothing wrong with this. This is why open source is beautiful. If you don't like what some contributor is doing, fork it. Kite can even pull in updates from the main fork. I think this kind of thing happens all the time just not publicly.
- lucb1e 9y agoThey did not pull in the wrong pull request. They bought the project from the developer, either directly, or indirectly through employment.
- deleted 9y ago[deleted]
- quantum_state 9y agoWe, the open source community, need to respond to this pollution firmly and decisively. Apart from removing the sneaky code put in for these types of purpose, we may need to consider adjusting the licensing to forbid such doing ... the entire open source world need to unite against this ... it is threatening the future of open source.
- TheRealDunkirk 9y agoIs Facebook part of the "open source community?" I would expect that most people here would say yes, for reasons I will assume are obvious to most readers here. Yet they've built, arguably, the world's second largest (non-governmental) data mining operation on the back of open source software, designed for nothing more than slurping up user data to sell to advertisers. How is that fundamentally any different than what's described here? Because the product is "more" useful to end users? Because it's true nature is "more" visible? It's a difference in degree, not kind. If you hate what's been done here, by extension, you should hate the business model of Facebook and Twitter, et. al. (I do, and I refuse to participate.) There seems to be a bit of hypocrisy having this sort of outrage on this particular site.
- danso 9y agoDoes React or any of Facebook's OSS libraries have pop-up/modal ads for joining Facebook? Do they contain analytics code?
- TheRealDunkirk 9y agoSo that's the difference, here, that exculpates Facebook? That they don't put their analytics code in PHP or React? Granted, Facebook doesn't put analytics code in those products, but almost every web programmer in the world happily embeds Facebook's JS blob/web bug in almost every single site on the planet to track every single click, by Facebook users or not, which can be tied back to at least a shadow profile in the mothership. That's cool? If so: Got it. I can see the distinction you're making, but, IMO, it's splitting hairs. Either tracking users activity, by the simple act of their use of your product, is morally acceptable, or it's not. To me, this seems like this exact same thing. As Scott McNealy said, "You have no privacy. Get over it." I wish that wasn't true, but it would seem that the every government and company is hell bent on making it so.
- deleted 9y ago[deleted]
- danso 9y agoThis situation seems to have the best and worst of open-source. Best, in that the license of the projects allowed them to be forked without too much effort. Worst, in that it shows how easy it is for a project to be subverted once the maintainers are bought (in this case, given a job). It also remains to be seen if the average Atom user will see the difference between the Kite-branded (and, currently, more popular) and the forked versions of these plugins. Besides the open source issues, this tactic seems to reveal a massive desperation by the Kite folks. There is no way they couldn't have seen how negative this was going to look once people found out. Their ability to attract new users through word-of-mouth and organic advertising must have plateaued. Sneaking their service into a well-used plugin would have given them a boost in users, maybe enough to attract a new round of funding, but they must have known it would cause this kind of bad blood. Especially based on their past reception on HN, which was highly upvoted but in which they never convincingly answered the concerns about uploading users' source code to the cloud: https://news.ycombinator.com/item?id=11497111 https://news.ycombinator.com/item?id=11497111 https://news.ycombinator.com/item?id=13977982 https://news.ycombinator.com/item?id=13977982 https://www.reddit.com/r/programming/comments/4erqgq/kite_programming_copilot/ https://www.reddit.com/r/programming/comments/4erqgq/kite_pr...
- _jal 9y ago> this tactic seems to reveal a massive desperation by the Kite folks That's the weirdest part to me. Who, exactly, thought this was going to go well? It is hard to be sneaky with open source. And even harder to win back goodwill after being caught out. For instance, now that I know, it would take a change of management and business model before I'd even consider running any of their code, and I'll be writing a Kite-detector for our code scanning tool this week.
- jdp23 9y agoThere's a great quote from Kite founder 'alexflint in one of those earlier threads: "our plan is to earn trust the hard (i.e. only) way: transparency, published policies, and a track record of good decision making." Easier said than done, apparently.
- billdybas 9y agoIt's nice this is getting more response today - my submission yesterday got no comments. I almost spit my coffee out when I learned about this (as I'm a minimap user who had no idea this was going on). Not a fan of these shady practices - completely breaks the trust between package maintainer and users.
- Dowwie 9y agohere, have an upvote -- on me
- PhantomGremlin 9y agoThere are those who would argue that foisting systemd onto the Linux community is the quintessential example of "behaving badly".
- jamespo 9y agoThere are other distributions
- cyphar 9y agoExcept Lennart was working on systemd long before he worked at Red Hat and Red Hat has very little control over what he does in systemd. The reason Red Hat has "foisted" systemd is that it solved problems that other init systems hadn't solved (which is why other distributions also adopted it). That doesn't mean it's the best solution by any stretch (I don't like systemd personally) but pretending that it was the same as putting adware into a text editor is quite disgusting. It solved a real problem, and if you have a better alternative you're free to contribute it as another member of the community (in fact, please do). I work for SUSE, not Red Hat, but I find it incredibly gross that being employed to work on free software is seen as a negative thing by the wider community. I spend every day working and thinking as a community member first, but because I was lucky enough to get a paycheck from a company to do that clearly I must be the enemy.
- PhantomGremlin 9y agoI toy with Linux but I mostly use OpenBSD. So I'm thankfully not that affected by systemd. I can completely understand what the OpenBSD init system does. It's a lot harder to fully understand systemd. Plus, as a benefit of systemd, you get headlines like "Don't panic, but Linux's Systemd can be pwned via an evil DNS query"[1]. Red Hat doesn't care if Poettering is a brilliant genius or just a useful idiot. Instead, Red Hat loves systemd for a very different reason: lockin. Most Linux distributions are now utterly dependent on systemd, and by extension dependent on Red Hat. systemd gives Red Hat far too much control over Linux. They were already the 800 pound gorilla, now they're almost invincible overlords. But go ahead, keep drinking the Kool-Aid. [1] https://www.theregister.co.uk/2017/06/29/systemd_pwned_by_dns_query/ https://www.theregister.co.uk/2017/06/29/systemd_pwned_by_dn...
- jlangenauer 9y agoThis is one of the things that makes me think software development, like most other professions, should really have a formal code of ethics. If a lawyer or a construction engineer tried to do something equally dodgy, they would very soon find themselves hauled before a professional authority. It should be made clear to the employees, management and investors of Kite that this is the sort of thing that marks you as someone willing to engage in unethical and underhanded behaviour. I wouldn't hire any such person into any team I manage, and I suspect quite a few other people wouldn't either. Actions have consequences. Especially unethical actions.
- coldcode 9y agoLawyers do dodgy and unethical things as well, I wouldn't use them as a paragon of ethics.
- JdeBP 9y agoAn argument that explicitly talks about the consequences of unethical behaviour when it happens is not painting anyone as ethical paragons. You are missing the point, I think.
- kbart 9y agoHeh, you know something is seriously f*cked up in industry when lawyers are taken for an ethics compass.
- radisb 9y agoI believe that is a self-conflicting proposition, since I believe morality is a subjective "property"
- xg15 9y ago"Subjective" how exactly? There are surely some variations, but if this is about "my wallet has feelings too" morality, that would be all the more reason we'd need an (enforceable) code of ethics.
- kayoone 9y agoI think what Kite is doing isn't very smart, their audience are developers who will usually not put up with stuff like this so easily.
- toyg 9y agoIt is somewhat ironic that the community affected is the Atom one, which was supposed to be built by (and for) next-gen cloud-first types who live in the browser. If all data has to live in the cloud, your source code will inevitably get there too - because source code itself is data. Sure, Kite went about it with an anti-pattern, but that makes little difference. Live by the cloud, die by the cloud. Let's be honest, the real problem here is that Kite's offer is still not good enough. The service they provide at the moment is not worth handing out all your code, unlike with services like GitHub; and their leadership is not seen as smart (or honest) enough to tolerate them taking stewardship of this or that established project - something that happens every day in the OSS world (loads of companies de-facto own this or that OSS project, from RedHat to Google to Ubuntu to IBM, steering as they see fit). As soon as Kite (or anyone else) can provide a compelling service, people will go to great lengths to use their stuff and give them their code, without any dark pattern being required - ethics be damned.
- nv-vn 9y agoCan't wait till someone hacks Kite and exposes some major company's source code. Will be very interesting to watch the legal response to that.
- vultour 9y agoHoly shit that 'apology' is a steaming pile of crap. This guy is actively subverting not one but multiple open-source projects and he responds with some pathetic crisis-management sob story and an 'oops, sorry'?
- hibbelig 9y agoHe did revert the minimap changes. That's more than just saying "sorry". But I'm waiting for autocomplete-python to be changed, too...
- diegoperini 9y agoIt may really be a sorry, but also some damage control too.
- rmaus 9y agoAnd they are sorry they got caught, not sorry they did it. As is tradition.
- dabei 9y agoThis is evil. We need a way to deter activities like this. The public shaming on HN is a good first step but this would be forgotten too quickly. Any ideas?
- amelius 9y agoCan't we have laws against software that combines ads with spyware (or user tracking for that matter)?
- mercer 9y agoHonestly, I feel that at the very least the core team behind Kite should be held accountable for what they're doing. I'm not arguing in favor of an all-out witch hunt, but in the context of developers doing their development thing this kind of behavior should have consequences that potentially might include 'black-listing' at least the higher-level people behind it that thought this was a good idea.
- bauerd 9y agoAaand into the /etc/hosts kite.com goes. Can anyone paying for their product post their other (AWS?) hosts?
- dsign 9y agoThings like this are bound to happen, as long as people have to pay their bills and they don't get as much retribution as they would like for their work. If the original authors of the plugins that Kite took over had got a dollar from each user, maybe they would have thought it twice before handing over their creations to a company with dubious purposes. I have been saying it for a long time: we need better and more flexible software markets, and as developers, we should appreciate the work and time of fellow developers and as a matter of principle try to compensate them.
- tkt 9y agoExcellent point and related to Nadia Eghbal's post on the lack of support for open source infrastructure being the internet's biggest blind spot. https://medium.com/@nayafia/how-i-stumbled-upon-the-internet-s-biggest-blind-spot-b9aa23618c58 https://medium.com/@nayafia/how-i-stumbled-upon-the-internet...
- jancsika 9y agoDear free software and/or open source zealots: Please use your skills and spirit to fork both of the projects in question and put one of your known good actors in charge of each. Either new project leaders are available and will immediately come forward to claim these projects as their own, or we need to change the subject to FLOSS sustainability.
- bauerd 9y agoThere is a fork[1] that reverted the changes made by Kite. This is not a question about sustainability as the project was well supported, feature-complete and saw regular releases. Rather, this questions the consequences of giving companies permission to acquire community efforts. Doing so erodes trust in the Atom ecosystem. If the Atom team is OK with what Kite is doing, then I can expect other companies to follow along, and I'll have to be more cautious when installing plugins in general. It also destroys the incentive of contributing code to Atom plugins, because I don't want to contribute to giving companies control over basic features like a minimap. Why stop at the minimap? StackOverflow might as well hijack CTRL+F, or Heroku might subvert a git plugin. If we let this become a trend, it will suck for everyone. [1] https://atom.io/packages/minimap-plus https://atom.io/packages/minimap-plus
- jancsika 9y agoThe consequence of forks is that their desired userbase is now seeing double, and whenever a potential user asks about it someone from the community tells them, "Don't use the one with ads and/or other junk, use this one instead." If other companies follow along then Atom's ecosystem-- and therefore, Atom-- will suffer as a result. Regardless, there probably should be more caution when installing plugins.
- bauerd 9y agoYes, I agree, forks are another bad consequence and usually undesirable (though there are exceptions, e.g. it worked for the Node.js community). Had Kite not subverted the plugin, there wouldn't be a need for a fork.
- thrillgore 9y agoI personally want to know why Kite decided to show up uninvited in Atom. I don't want this shit, I don't care about it, if I wanted documentation i'd use Sphinx or Doxygen.
- thrillgore 9y agoIs there a comprehensive list of Atom extensions that are maintained or used by Kite? Or should I just write off Atom altogether?
- DrFukushima 9y agoMerge request to remove Kite in minimap was closed: https://github.com/atom-minimap/minimap/pull/596 https://github.com/atom-minimap/minimap/pull/596
- threepipeproblm 9y agoPsychopaths sometimes have trouble recognizing stuff that is supposed to make them ashamed, i.e. stuff that would reveal their character were it exposed publicly. Maybe that seems like an over the top comment, and on any individual case, who knows? But I think it explains a good number of these sorts of scandals. Sometimes, the people who get on top are not "ambitious"... sometimes they are actual monsters.
- smoyer 9y agoStudies have shown that psychopaths are, on average, more successful as CEOs than non-psychopaths. This certainly seems like a good example of that (his reaction and behavior with the reporter were perfect!).
- api 9y agoIn my experience they have meteoric careers that then suddenly crash and burn spectacularly. Unfortunately after a big crash they're usually able to find more fools and repeat the pattern. You'll often see someone whose career looks like a sawtooth wave.
- threepipeproblm 9y agoThere is a book called Political Ponerology, with a fascinating provenance, which basically claims society at large (macro scale) goes on sawtooth pattern like this. The argument is that during the good times, people stop taking the steps needed to keep these people from attaining high positions... they remain in denial and make excuses for pyscho behavior. Then people finally take action only when it's just blatantly obviously necessary again. Which, if you think about it, is also the basic story of good & evil presented in Harry Potter :) IIRC the book was written by the scientific wing of the Polish Resistance movement during authoritarian occupations of the 20th Century. Apparently, many of the people involved in sourcing the data (and, oh yeah, who had secretly diagnosed many of the Nazi/Communist leaders as psychopaths) were killed, when the first edition of the book was discovered in progress. And that first manuscript was destroyed, but the lead author wrote it again -- not once, but two more times -- and ultimately, had to wait for the fall of Communism in order to get it out of Poland. It was finally translated and published during the Bush administration, by New York liberals.
- jwilk 9y agoWhy is the submission title different than the original one?
- RubenSandwich 9y agoNo idea. This new title seems vaguer to me. They changed it from 'How kite is undermining the open-source community' to 'How a VC-funded company is undermining the open-source community'. The title is clearer with the name of the company in it. Edit: In case there is any confusion. The company is Kite. The VC-funded company is Kite. Kite. They are the ones this article is about. Kite.
- gus_massa 9y agoHN has a policy of using the original title: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html > In Submissions [...] > If the original title begins with a number or number + gratuitous adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids." > Otherwise please use the original title, unless it is misleading or linkbait. In small obscure threads the mods sometimes don't notice and you can get away with small changes, like replacing "Photos of Encedalus" with "Photos of Encedalus, moon of Saturn". (But don't try "Amazing photos of Ecedalus will blow your mind!!!") In big popular controversial thread almost always the title is reverted to the original title of the article, or the first sentence of the article when the tittle is too bad.
- Dowwie 9y agoI wouldn't be surprised if this leads to click-wrap terms of use prior to installing Atom packages..
- thedonkeycometh 9y agoSeeing as it was once open source, can't you fork it from that time and get someone to maintain it?
- barking 9y agoI'd never heard Kite until today and following a one of the links ended up at Adam Smith's blog a couple of hours ago. I did no more than to read a blog post. Just now I went to checkout from my local tortoisesvn repostitory and instead of the usual local address this was present as the repository url: >"http://adamsmith.cc/" http://adamsmith.cc/" I have no idea how that could have happened.
- AdmiralAsshat 9y agoNot sure how the Atom plug-in store works: if this were yum / CPAN / pip, I would think there'd be some way to kick these plugins out of the stores and force anyone who really wants it to install manually. I think that's the best way to tackle this kind of deception: fork it, kick it out of the app stores, and make it difficult as possible for someone to inadvertently download the adware-written version.
- andreareina 9y agoA maintainer for amp (atom package manager I guess?) explicitly said they're sitting this one out. The mini-map plugin has been forked and rolled back to the version before the ads popped up.
- AdmiralAsshat 9y agoThat's a pity. It is incumbent upon the package manager vendors/curators to watch for this kind of stuff and bring the hammer down when it happens. Apple does it. Google does it. Mozilla does it. I can guarantee that there are other commercial companies watching how this plays out. If the changes are simply rolled back without any real repercussions, what other malevolent entities will take away from this incident is, "You can inject adware into your acquired FOSS applications, but do so discretely."
- thehardsphere 9y ago> Although Kite has no business model yet, This is actually the most ridiculous part of the entire story. It would be one thing if a corporation was stealing your code and taking over open source projects as part of a detailed plan to make money. That would still be objectionable, but at least there would be a clear motive for these voyeuristic activities. Apparently, there is no master plan. They're just doing this because they want to be voyeurs and then maybe figure out how to make money off of that somehow later.
- codepilot 9y agoIf someone approved their own PR in our team they would have some explaining to do, approving your own PR in an Open Source project - SMH
- gus_massa 9y agoIn many small project the owner (o small set of owners) just commit the changes without approval. In same case on person writes more than the 50% of the commits, and it's not practical to get someone to review the code. In this case abe33 has the 75% of the commits, someone else 15% and the rest is a bunch of people with 1% or less.
- MrStonedOne 9y agoOnce your project gets to a certain level of users or activity, you should still be submitting PRs or MRs for comment before merger. With our server toolkit in a project I work on, we have 2 devs and 5 active users, with the devs being 2 of those, but we still manage to at least put every change in a PR, with a minimum review and comment time of 24 hours unless it's a security issue or major bug fix. It's not hard, and it makes you actually justify your change and have talented second eyes point out minor bugs or edge cases to you. Direct commits are only used for version bumps for the auto build/release thingy.
- gus_massa 9y agoYour method may be better, but there are a lot of small and medium projects in the wild that don't follow it.
- MrStonedOne 9y agoThey should.
- microcolonel 9y agoThis is a bit hyperbolic. If the original maintainers of a project are making changes you don't like, just fork it. That said, if I was already unlikely to trust Kite, I don't want to work with them at all given this behaviour. Betraying the trust of a significant portion of your potential customers is a sure way to be exed from an industry you never capitalized on. Congratulations, Kite.
- deleted 9y ago[deleted]
- jtokoph 9y agoPSA: I removed the whitelisted directory from my local install of Kite and then uninstalled the application. Logging into https://kite.com/settings/files https://kite.com/settings/files still shows my machine and all of the synced files. I still had to manually purge my machine and files from that page. If you think your files were removed, check again.
- bfirsh 9y agoExtra PSA: I deleted my files from that page a few months ago and they have now reappaeared. (See my other comment.) I would recommend emailing them to delete your account and data, including backups and so on.
- adamsmith 9y agoHi, Kite founder here. If you uninstall right after removing the whitelist directory then the removed files may have not have been synced to the server before the uninstall, particularly if you have a lot of files on your machine. We will address this by adding a "remove all whitelisted directories and log out" link to the local settings. Something different was likely happening in bfirsh's case (sibling comment). If you delete the files from the kite.com/settings/files page but Kite is still installed then they will get synced up again. The most fail proof way is to uninstall and then wipe files from kite.com/settings/files. We will make the wipe files link log Kite out on that machine. Sorry about the edge cases. We've been working on it, and will continue to do so!
- oefrha 9y agoI remember the day Kite was launched. I took a brief look, realized it would be uploading entire codebases of mine to their servers, and said no. The fact that they have since slipped their stupid product into popular open source tools (probably because it isn't as well received as they thought it would be) is very similar to how some douchebags buy up popular browser extensions, then inject ads or do more nefarious things with them. Utterly distasteful.
- intoverflow2 9y agoI'm curious to what the ads looked like? I installed it but can't see them and the article only includes it's own ads for razors not pictures of the ads it's talking about.
- CodeWriter23 9y agoFFS, "Fork this on Github'
- oxguy3 9y ago> “I apologize in advance that I can't answer any further questions,” he wrote. “I need to focus on other parts of the business, including continuing to improve the product for our users, and conflict like this is always doubly distracting.” If you don't have time to deal with controversy, maybe don't take actions that will inevitably lead to it, eh?
- sdwisely 9y agoFor some reason that animated underline makes me feel like I can only read one word per minute.
- aerique 9y agoThose animated squiggly lines under the headlines are some of the most annoying things I've recently seen.
- simias 9y agoWhile this Kite company seems rather scummy, I think it's a bit disingenuous to frame it as an attack on open source. Actually it's the one thing open source can handle better than anything else: just fork the repo and carry on. Maybe I'm reading too much into the article but it feels like a weakness in open source is exposed when in fact the real problem would be if those applications were closed and you were stuck with crappy software if you didn't want to switch to a brand new tool. How's Skype doing lately? Open source is vindicated by these scummy tactics, not undermined.
- deepakkarki 9y agoI wonder how the HN ranking algorithm works - even with so much discussion and upvotes/hr this thread has already slipped to #24. I find that awkward!
- computerex 9y agoI was wondering the same thing. Thought the thread got deleted or something.
- nostrademons 9y agoThere's a flamewar detector that demotes threads with more comments than points. More discussion is not an unambiguous positive signal. It's at #17, a couple hours later, as the number of points is now 700+ and comments is in the 300s.
- random3 9y agoThis is why Open Governance is just as if not more important than the actual OSS License. Foundations such as the ASF can protect from these situations https://www.apache.org/foundation/how-it-works.html https://www.apache.org/foundation/how-it-works.html
- mnm1 9y agoSounds like a replay of uBlock / uBlock origin. The same solution (forking and rebranding) can apply here. If the original authors sell out to Kite and the license permits it, fork it and fuck them.
- daotoad 9y agoI think the real dark pattern here is the stupid animated scribbles under the section headers. WTF?! Is this 1997? Why don't you bring back the blink tag while you're at it! Sigh.
- softawre 9y agoFor all of you that accidentally sent your BigCorp source to the cloud, are you going to report it to your legal departments?
- edem 9y agoWe can just fork these tools, and re-release them without the malware Kite is injecting. The licenses are MIT AFAIK.
- trymas 9y agoso we'll need to have ad-blockers in our editors now? /s
- mattbierner 9y agoAs distasteful as ads are, I'm always concerned about an update that introduces malicious behavior in the background. Something like NPM hyrdra for example, or those Chrome extensions that have been bought out
- git-pull 9y agoIn short: A startup is taking control of open source editor plugins relevant to their product. I admire their cleverness. If it were me: I'd create an extension interface for completion libraries to accept third party plugins. I'd stop at putting in a third party stuff in by default. A sufficiently good plugin API for python-autocomplete shouldn't require it even to know about Kite. That said, I don't think Kite should be disallowed. If they have a secret sauce that they think can empower completion plugins, give them an API to plugin to. It's not in the spirit of open source to shut the door on proprietary solutions (IMO). Transparency should be paramount. Normally most Linux users opt-in to using proprietary/blob software/drivers one way or another anyway. Open source projects routinely maintain relationships with vendors (NVIDIA, Intel). It doesn't necessarily mean evil is at work. Though, as someone who's struggled with the performance and reliability of completion tools, I don't know if I'd personally opt to outsource that functionality. I'd wait and see if our current tools get better.
- mfringel 9y agoTwo years ago, this would have been called "growth-hacking". What changed?
- dessant 9y agoAutocomplete-python has also been forked because maintainers have stopped responding. https://atom.io/packages/autocomplete-python-jedi https://atom.io/packages/autocomplete-python-jedi https://github.com/brennv/autocomplete-python-jedi https://github.com/brennv/autocomplete-python-jedi https://github.com/autocomplete-python/autocomplete-python/issues/308 https://github.com/autocomplete-python/autocomplete-python/i...
- mychael 9y agoKite is malware. Plain and simple.
- whack 9y agoHonest question: if someone starts a hobby project, open sources it, and later decides to monetize it in some way, is that considered bad form? I can think of many open-sourced projects that are being monetized - eg Reddit/GitLab. I was under the impression that open-sourcing something literally means just making the code publicly available, and doesn't restrict what the owner chooses to do with the project in future.
- rurban 9y agoOh my, just fork it and avoid all the drama.