10 ms·
Kite telemetry code in Sublime package SideBarEnhancements
- sergiotapia 9y agoAgain? Is there no escape from these guys?
- yvesmh 9y agoI really don't like the idea of having to wonder if the next plug-in/editor/IDE/etc I use is compromised by Kite or any other shady phone-home companies.
- verdverm 9y agouse vim ;]
- yvesmh 9y agoWhat's stopping Kite from grabbing one of your Vim plugins and adding telemetry to it?
- sergiotapia 9y agoIt's not an editor thing, it's a shitty package creators thing.
- synaesthesisx 9y agoThis is why I use Little Snitch. If there are any rogue outgoing connections, I will know about it. I am extremely selective with the connections I allow my machine to make.
- sillysaurus3 9y agoSo for those of us who aren't selective with the connections we allow, is it feasible to start using Little Snitch? I'd be interested in trying, but it seems like there would be dozens if not hundreds of "strange" connections that you'd have to filter through which ultimately turn out to be innocent (e.g. OS X update checks).
- eropple 9y agoThe first day of using Little Snitch may drive you insane. It gets better rapidly after.
- kevindqc 9y agoHow does it work with browsers? You have to allow all outgoing traffic to port 80/443 regardless of host/ip? Or be asked every time you visit a different website if you want to allow it or not?
- wlesieutre 9y agoIIRC the default ruleset allows browsers to make any connections on 80/443. You could delete that rule and do it on a case-by-case basis, but it'd be painful. There are probably browser extensions better suited to restricting browser connections. Maybe run LS on top of one of those so the browser can catch most of them witout making a ton of popups.
- kevindqc 9y agoMakes sense. Thanks!
- toufka 9y agoIt provides and then remembers sane choices pretty well. It's easier if you have enough background to understand 'port', 'dns', and 'application', but once you spend a day or two teaching it your habits, it becomes a fantastic tool that is out of your way until the moment it notices something serious.
- jftuga 9y agoIs there something like this for Windows?
- xemoka 9y agoPerhaps Glasswire? http://glasswire.com http://glasswire.com
- dsl 9y agoI just started picking up Python and was installing popular useful looking addons from Atom. Surprisingly I got some Kite installer running from a syntax highlighting package. They seem to be very keen on paying addon developers to distribute their crapware.
- deleted 9y ago[deleted]
- eropple 9y agoSo this is something I'm not sure I've ever said before, but if you work for Kite, you need to quit. Like, I get working for even exploitative companies (though I won't)--economic insecurity is definitely a thing and we all gotta eat. But you can find a job that doesn't involve literally spying on the down-low. I promise you, you can. Abandon these jerks before they bring you down with them. They've demonstrated a willingness to screw people and even if you don't really care about them screwing other people, they'll screw you too. EDIT: Also, because it's on-topic and the post on HN seems to have gone ignored, somebody is typo-squatting `cross-env` on NPM and dumping environment variables to a Chinese server run by "HackTask", it probably deserves a signal boost: https://twitter.com/o_cee/status/892306836199800836 https://twitter.com/o_cee/status/892306836199800836 https://news.ycombinator.com/item?id=14901566 https://news.ycombinator.com/item?id=14901566
- yuhong 9y agoI wonder if part of the problem is VC demands in the first place.
- eropple 9y agoOf course it is! But "don't be a shithead" is a moral imperative that you need to uphold over your investors leaning on you. I mean, not being a shithead won't get your chief growth hacker's blog all hype, but words fail me (and they rarely fail me) when I try to express how little I care about that. That's also why I didn't try to say that the founders or the executive team should be better. I'm talking about the people who those founders and executives use to do bad shit and who they will screw whenever it makes a tiny bit of business sense to do so. Plenty of people work for literal sociopaths. It's rare that you can just point and go "...duh?" about it, though.
- deleted 9y ago[deleted]
- sillysaurus3 9y agoThis seems incredibly overblown. According to the diff, all they were collecting is time spent editing certain file extensions, along with a list of installed packages: https://github.com/SideBarEnhancements-org/SideBarEnhancements/commit/4d1d20cf7f4917cbe7dad0b3a9e8a8573162be6b#diff-01b294ac86b2009fd6c11bf4267bb0e7L65 https://github.com/SideBarEnhancements-org/SideBarEnhancemen... They're trying to figure out what languages people are actually editing on a day-to-day basis, and people here are calling for them to leave the company? Like, really? People have been whipped up into a frenzy for data that a webapp wouldn't blink twice at collecting. But when it's installed locally it's somehow different than if we load a webapp in a browser? I agree with you in principle, but it seems like people here didn't actually look at what was being collected. They just saw "data collection" and went absolutely nuts. Yeah, collecting installed package names isn't really great, but it's pretty harmless, right? It's a stupid decision, but people seem to be looking for reasons to get upset. They're not collecting filenames, and they take the sha1 hash of whatever could be personally identifiable. Why is any of this bad, or a violation of trust? They even say right in the readme that they're doing it and how to opt out: https://github.com/SideBarEnhancements-org/SideBarEnhancements/commit/4d1d20cf7f4917cbe7dad0b3a9e8a8573162be6b#diff-0730bb7c2e8f9ea2438b52e419dd86c9L29 https://github.com/SideBarEnhancements-org/SideBarEnhancemen... If they made it opt-in, no one would opt-in. I understand it's a slippery slope, but is this reaction appropriate?
- bajabaron 9y agothey're also obscuring who this log data is being sent to by just posting JSON to an ec2 IP address (52.52.168.91). The server tries hard to not let you know it belongs to Kite. You know someone is ashamed of what they're doing when they take efforts to mask who's doing it. But you can see kite's own installer uses the same ip address for its telemetry: https://github.com/kiteco/kite-installer/blob/master/ext/telemetry/telemetry.js#L9 https://github.com/kiteco/kite-installer/blob/master/ext/tel...
- bajabaron 9y agoIt might be worth searching every release in the package_control_repo for this IP address... https://github.com/wbond/package_control_channel/tree/master/repository https://github.com/wbond/package_control_channel/tree/master...
- mawalu 9y agoSeems not to be included in any other file on github: https://github.com/search?utf8=%E2%9C%93&q=%2252.52.168.91%22&type=Code https://github.com/search?utf8=%E2%9C%93&q=%2252.52.168.91%2...
- Artemis2 9y agoShouldn't this search find the kite-installer repo? The IP does not exist anymore in SideBarEnhancements but is still in this repo: https://github.com/kiteco/kite-installer/blob/master/ext/telemetry/telemetry.js https://github.com/kiteco/kite-installer/blob/master/ext/tel...
- deleted 9y ago[deleted]
- paradite 9y ago> This search took too long to finish; some results may not be shown. Shown when you hover over the question mark.
- digikata 9y ago
- omginternets 9y agoThe best course of action in such cases is to vote with your feet.
- numbsafari 9y agoThe question is: to where? Is there a single IDE with plugins that has a security model in place that would prevent plugins from being taken over by nefarious asshats? I love vim and emacs... but what's to keep them from being affected by the same thing? Who has time to read all the source code of every plugin/dependency that they use? It's all about trust and what Kite is doing is completely destroying the network of trust in each of the communities they choose to infect.
- wishinghand 9y agoI think the person you're replying to meant not using Kite.
- numbsafari 9y agoWhat keeps Kite from taking over another package?
- omginternets 9y agoA failing business model. Moreover, a valid solution doesn't have to solve every problem. Abandoning Kite is already a good start.
- dabber 9y ago/u/michael0x2a on Reddit put together a nice tl;dr[1] of the story arc for those that don't want to dig through the thread. tl;dr for that is basically: Kite has been collecting "anonymous" data from sublime users with the SideBarEnhancements plugin installed. This has been happening for atleast a year and the data collected included activeNonBundledPackageNames which is basically a list of packages installed via Package Control. It seems they were intentionally unclear about who the data was sent to and did not think to remove it from the plugin after the Atom Minimap incedent because: > the truth is we didn't remember [2] [1] https://www.reddit.com/r/programming/comments/6qwtfz/kite_injected_telemetry_into_the_third_most/dl0psv0/ https://www.reddit.com/r/programming/comments/6qwtfz/kite_in... [2] https://forum.sublimetext.com/t/rfc-default-package-control-channel-and-package-telemetry/30157/30 https://forum.sublimetext.com/t/rfc-default-package-control-...
- adamsmith 9y agoFor what it's worth, we didn't remember. There was no upside to keeping it there.
- frgtpsswrdlame 9y agoSure but you also put the code there in the first place. How much of your sketchy behavior is driven by VC demands?
- eropple 9y agoJust an upside to doing it at first, was it? I hate that we're even talking about your company and that we have to because it's a bad actor that's hurting people. Talking about what you're doing, even condemning this ratshit behavior most strongly, kind of empowers your company, and your company doesn't deserve press--even bad press. Kite deserves the equivalent of an unmarked grave.
- detaro 9y agoSo what's going on with the data collection? Do you still control the IP the system reports back to, or are users reporting their details to somebody else? Are you still using data arriving there?
- tradesmanhelix 9y ago/sarcasm Really looking forward to reading the Kite blog post this time around: "Staying Open (Still): Kite Responds To the SideBarEnhancements Issue." /sarcasm Sorry Kite - fool us once, shame on you. Fool us twice, shame on us. There's now a 0% chance of my ever using your products or services.
- fooey 9y agoKite is plainly a bad actor. Sublime and GitHub/Atom should be taking steps to permanently remove them and the things they're infecting from their respective ecosystems We now know of 3 different popular addons they've hijacked in various ways to snoop on code and to build up their business. If one company is doing this, it makes me very concerned what else is going on, and what else is coming.
- bajabaron 9y agothe sad thing is that this has been out for 9 months. If Kite was looking for stats to help inform their product development they already got all the data they need.
- wedowhatwedo 9y agoI modified the Stats.py file in the SideBarEnhancements.sublime-package on my computer to remove the line that references this IP address. I also made the file read-only so it won't get updated. Does anyone know if that will take care of the issue on my computer for now?
- wbond 9y agoA new version of SideBarEnhancements is out with the stats removed. You should get automatically updated the next time you restart Sublime Text or manually upgrade the package.
- yvesmh 9y agoThey have removed the file already https://github.com/SideBarEnhancements-org/SideBarEnhancements/commit/4d1d20cf7f4917cbe7dad0b3a9e8a8573162be6b https://github.com/SideBarEnhancements-org/SideBarEnhancemen... but I wouldn't be surprised if they compromised more plug-ins and we just haven't found out yet
- ivanbakel 9y agoDeeply concerning that this has been in place for "the better part of a year", and that they "didn't remember" about their telemetry collection - how careless have they been with the actual data, if they don't even claim to be able to keep track of gathering it? This is a complete destruction of their narrative from last week. They'll be sorry for being caught - again - and we'll have to be on continual lookout for this kind of thing in the future. I can't wait for the floodgates to open, once major tech companies figure out that there's not enough oversight to prevent this 100% of the time: I expect more than a few projects to be bought out similarly.
- AdmiralAsshat 9y agoI'd implement an industry-wide blacklist, personally. This is strike number, two? three? of this company subverting well-known packages with telemetry. Any package that is proven to be connecting to their servers should be removed, the authors should be banned, and the company should be thrown onto a list of Known Bad Actors to prevent any kind of package, add-on, or extension from ever accepting them again. You cannot fight this kind of malevolence with a finger-wag and a proposed solution that you simply inform the user next time before doing it. It will become buried inside the ToS and become ignored and commonplace. Stop it now and forever, while the spotlight is on it.
- fooey 9y agoSeriously. Sublime, Atom, VSCode, and every other platform that supports plugins should all be in crisis mode over the crap Kite's been caught doing. If we can't trust that an addon we installed yesterday is safe today, their platforms just turned into gigantic malware vectors that are totally wide open. This kind of exploitation needs to be stopped immediately.
- wbond 9y agoThis has definitely always been a concern among certain users of the Package Control community. Since the Sublime Text python environment is run as the user, without a sandbox, it is possible a rogue package would upload all of your data somewhere. So far we've operated under a model of requiring the end user trust the package developer, which isn't going to be the case 100% of the time. We are set up in such a way that the connection is required to be secure to prevent hijacking the connection and replacing packages with hacked versions. But if the package developer is choosing to add code, that is more of a policy issue than technology issue.
- AdmiralAsshat 9y agoI agree, completely. It is a policy issue. For that reason, I am imploring the maintainers of packaging communities like Sublime Text, pip, CPAN, etc. to put forth a firm stance in their policy that says No, we will not tolerate this, period. If you don't, it sends the message that this sort of scummy behavior is acceptable so long as you disclose it. I don't think that's okay, I don't think any sane end-user thinks that's okay. What little defense of this I've seen inevitably comes from other developers, who invariably have monetization in the back of their minds.
- paradite 9y agoOn the topic of tracking, you might want to check your browser extensions as well. I discovered tracking codes inside a browser extension back in 2013, and I doubt that it would be the last one: https://paradite.com/2013/12/07/solved-issue-with-vglnk-all-websites-having-a-script-related-to-vglink-attached-to-the-end/ https://paradite.com/2013/12/07/solved-issue-with-vglnk-all-... (Ironically by visiting my blog post you are contributing to tracking by Google Analytics)
- sbarre 9y agouBlock begs to differ ;-)
- verdverm 9y agoGrimd for the DNS blocker!
- paradite 9y agoI don't know if storing a plain text log of my browsing history is a good thing or not... https://github.com/looterz/grimd/blob/fc327b2f2993f762c8557c577d394960b1c82a87/handler.go#L84 https://github.com/looterz/grimd/blob/fc327b2f2993f762c8557c...
- kuschku 9y ago> (Ironically by visiting my blog post you are contributing to tracking by Google Analytics) That's interesting, where's the opt-in for that on your blog? I don't see a modal that asks me before transmitting any of my data, or even giving my IP to a third party, or doing any tracking, as is required by EU law.
- paradite 9y agoThanks. Didn't know that it was required for blogs. Added a WP plugin for that (inspected, no tracking code in the plugin).
- spdy 9y agoInteresting growth model by buying out developers of popular packages and add telemetry or the kite product. You just kill all credibility on the way and you will be outlawed by maintainers etc. We may be many but at certain bottlenecks ethics is still high and with OSS we are able to just fork packages. As companies start to exploit developers trust we have to rethink the security model inside our IDE`s and probably move to a smartphone like sandbox model.
- tradesmanhelix 9y ago> Interesting growth model by buying out developers of popular packages and add telemetry or the kite product. Sadly, I think it's what you might call "evil genius".
- TaizWeb 9y agoJust uninstalled the package, are there any alternatives available? I can live without it but it'd be nice if I had something to replace it with
- joshschreuder 9y agoThe current version on Github is clean (telemetry removed). You can always fork it yourself, or just download the repo files and add to Sublime Text 3\Installed Packages. If you have the .sublime-package file still, you can unzip it to that directory and modify the extension
- ekiminmo 9y agoIt looks like we need to sandbox packages and put a permissions system in place for atom/vscode/sublime. There's no reason why SideBarEnhancements needs access to the internet.
- thrillgore 9y agoAt this point I'm really thinking that Atom, Sublime et al are lost causes. If plugins makers will add their own telemetry I'll just go back to vim and be done with it.
- Ndymium 9y agoWhat is there to prevent a vim plugin author from adding the same kind of features?
- Gaelan 9y agoDisappointing. Kite looked like a really nice product.
- deleted 9y ago[deleted]
- hd4 9y agoWhat I find most amusing about this company is that they even attempted to get away with spying on people in an justly-paranoid/vigilant industry like ours. Like, did they not think that we wouldn't catch them in the act? Don't try to steal from thieves.