Kite: Thoughts on Security
kite.com
kite.com
If you're a contract developer, or a developer working full-time for a consulting firm, you might not have the authority to determine for yourself whether it's contractually allowable to upload code to Kite's servers. But if you're working for a pro shop, you can bet every dollar in your pocket that the contracts your firm has with its clients technically prohibit it.
Kite is really neat, but I'm a little uncomfortable with the idea that I'd have to remember to remind consulting vendors not to let their developers use it when working with my codebase.
Initially we've been focused on giving users control and transparency. We need to extend this to employers.
One quick idea that we'd love your feedback on: a .kiteignore file that can exclude Kite from responding to files that match a certain pattern (e.g. "secrets.py"). Presumably an employer could put a "[^.]*" in a repo-level .kiteignore file, and anyone working with that repo would have to explicitly delete that file to use Kite with it.
We'd love to hear any other ideas folks might have as well!
I'd need to ignore every file I have.
> If you're a contract developer, or a developer working full-time for a consulting firm, you might not have the authority to determine for yourself whether it's contractually allowable to upload code to Kite's servers. But if you're working for a pro shop, you can bet every dollar in your pocket that the contracts your firm has with its clients technically prohibit it.
As tptacek said, you might be prohibited and/or not have the authority to do so.
> Why does the device need to be on-premise? Would a Github Enterprise-like setup, where you have a dedicated Kite instance/VPS at their datacenter, work for you?
We run GitLab on-premise so I'm not familiar enough to answer. However, if by "their" you mean Kite? Yeah, that won't work as its essentially the same thing. [e.g. Disclosing it to a 3rd party outside of my control]
I can't use Kite if it's not on premise.
If you're in the position to make a judgment call on whether or not Kite would be allowed in your team, there's a real cost to being wrong about the trustworthiness and security of Kite as a whole.
I'm intrigued by the tech, but it'll likely be quite a while before I use this with any of my teams for anything other than trivial coding in pet projects that are already open source/public repos.
That said, I think this response is terrific. The value proposition was outlined well. Feedback loops are important and cloud services naturally have much tighter loops. Security considerations are no different than they are for GitHub, so those will not be insurmountable for many.
So, neat looking product and very nice response to initial feedback!
I would imagine a smooth update mechanism could allow you to update file indexes without loosing too much agility on feature development but come with huge security gains.
Admittedly I was thinking of an SSD + some caching in RAM when thinking of this timing. But I was always under the impression an HDD seek would be on the order of 10's of ms? I'd assume a query to a cloud service would be on the order of 100-200ms.
I think it's dishonest to not just simply post that 'if you're afraid of the cloud, you are not our target market, go away'. I guess it's a capitalism thing. Wouldn't look good to investors, or whatever.
I am sad because I have a beefy machine, and I want to use this, but I can't. I'd pay for it, you know? But I don't 'do' SaaS, the reasons are too long to list here.
More concretely, 32GB RAM is trivial, and preselecting my languages is... I've already pre-selected them! It takes months, years to learn a language :P
Kite looks really super cool.
I don't think Kite prompts you before uploading every time you open a file.
I'm looking forward to seeing Kite expand their security support and I can't wait to try it out on Linux.
Even though I trust you, there's no way anyone can guarantee that a hacker won't get into your database and get my proprietary source code.
I'm no security expert but one way I can think of is creating an encryption system which works like this: all my source code will be stored encrypted on your (non-ephemeral) databases. The decryption key will be stored on my computer, and it'll be transferred to the server when I run Kite and destroyed as soon as I quit Kite. The key will be stored in your server only in an ephemeral storage (in-memory database etc.) Do you have something like this in the works?
If you start with the assumption that a machine is compromised, then there's not really a way to guarantee secrecy of anything done on the machine. Homomorphic encryption resolves this, but (as far as I'm aware) it is too computationally expensive to be viable at present.
* Let us delete all of the data we have stored on your servers, whenever we want. * Let us see all of the data we have stored on your servers, whenever we want. I really don't care how you're manipulating it, but would like to see (and additionally delete) any information you have stored on me that I'm uncomfortable with.
It may be on magnetic tape backup in archives. Do they have to dig out each roll of tape each time for each customer who wants to erase a segment of their data?
It may be indexed or used as input to shape a larger or disconnected part of the software. It shows up in logs, and therefore in archived statistics analysis. It may have been copied and modified incrementally by a dozen other users. Should all these developments from user data be destroyed because they are based on old data with a delete request?
Perhaps an opt-in to a feature that doesn't back up or analyze your data for an hour could help prevent "committed the password to version control" accidents. But it would need to be opt-in, because the whole point of Kite is that your code is indexed in real time, right?
That's how it works, we all get it!
We recently built a virtual appliance. It's growing infinitely faster than our cloud solution ever did. Those numbers speak for themselves.
Certain products just need to have the virtual appliance option. I'm sure Kite will get there one day.
For now, I'm going to use it for personal projects because it's still a badass solution to a problem I have. :)
There is one thing missing: people use Google Maps, Waze etc simply because it's free.
I will probably never use it because it scares the crap out of me that I'll type my password in the wrong window though :-)
Convenience > Security
Laziness is both a curse and a blessing.You sign up for an invitation. I am curious to know how long that invite typically takes. I just signed up about an hour ago.
Excuse me? Why is that? It sounds like either they think they are programming wizards or they believe the CI folks are incompetent, none of which signals a company I would like to trust.