Show HN: Kite, copilot for programmers, available for Python
kite.com
kite.com
They also run a background process that needs to be manually killed to be able to uninstall. It feels like a quarantine. This is an editor plugin, is there really no simpler way to provide uninstall capability?
Unfortunately on Mac you have to quit Kite before it can be dragged to the trash. You can do that from the menubar icon or by killing "Kite Engine". (You don't need to quit Kite Helper to drag to the Trash.) See instructions here http://help.kite.com/article/6-how-do-i-uninstall-kite. We'll be improving this on Mac shortly.
Might be worth it for you guys to get ahead of this, and address these issues explicitly on the home page and during installation. It will lower short-term usage & install numbers, but probably won't hurt long-term retention and word of mouth sharing.
We've worked really hard to make sure we're clearly communicating what's happening (transparency), and adding fine grained controls. We have a very clear step during the install flow that talks about how Kite works, and we will prompt for whitelisting within each of the editor plugins that can work without the sidebar (Atom, ST3, PyCharm).
We also have a security page (https://kite.com/security) that points to our various resources related to this, including more details about our control mechanisms—including .kiteignore—and how we think about security (our four principles).
We also know that some companies need on-premise Kite to make this work. We're exploring that now with customers, and would love to chat with you if it's something you need. (https://kite.com/enterprise)
I know none of these are silver bullets. Thanks for your comment as we work with users to figure out how to make this work.
We hope you'll give Kite a spin when you can—we think it's pretty transformative—and we hope to be able to address all of your concerns soon! : )
I don't mind code being sent to a server, but it needs to be a server I control.
Github and PaaS do not have any direct benefit of storing my lines of code forever. There is no logical comprehension of doing so. If they are caught, they will lose customers forever. In a service like this, however, it can always be claimed that the storage was done in order to make the service smarter. Which would be true. But it would be dangerous.
It is also worthy to note that this is a live tool. With other services, one has a chance to clean their code before upload. With this, even playing around with an API with embedded keys in your code has already put you at risk.
Wow that is a really good point.
"Fine-grained privacy controls modeled after the .gitignore file format means that you can selectively and precisely decide which files and folders Kite indexes"
2. It's completely unacceptable to upload code to the cloud.
In addition the instructions you posted on the web site do not work. There are two running processes shown in Activity Monitor: a KiteHelper and a KiteEngine. Killing them both does not work, they are resurrected by some process.
I had to manually rm -rf Kite.app, and reboot the machine to get rid of the pesky KiteHelper and KiteEngine processes. Totally unacceptable "uninstall" procedure.
* launchctl list | egrep kite
* launchctl remove :KITE_LABELS
When we launched Kite here on hackernews almost a year ago we were blown away by the enthusiasm for our smart copilot vision. Over 65,000 of you signed up for Kite in the first 72 hours, and over the past year we've been working with many of you to deliver that vision. It's taken a momentous effort, but today we're ready to take off the wrapping paper and open up Kite to the world.
Here's what we've been working on:
* Deep editor integrations: to make Kite better for smaller screens and more integrated into the coding workflow. You no longer have to dedicate a sidebar of your screen to Kite; instead, recommendations from Kite replace your editor’s autocompletions and hover results.
* Fine-grained privacy controls modeled after the .gitignore file format means that you can selectively and precisely decide which files and folders Kite indexes.
* Next generation type inference engine that uses both static analysis and statistical inference over Github. Kite beats PyCharm and Jedi by 32% on a typical Django project, offering more completions when you need them.
* Ranked completions which put the most relevant completions at the top of the autocomplete box using techniques traditionally used in web search.
* Kite for Windows. (And Linux in testing!)
Check it out at kite.com.
I'm find with an editor or sidekick that can search stack overflow or duckduckgo or google quickly with a hotkey-- maybe keep snippets you can tag and easily reference-- but sending all my code as I type to a web service is something I'm not willing to do and something most companies won't allow.
Sorry.
One of the big things we've worked on over the past few months is giving users fine grained control of which files are indexed by kite:
- Kite only indexes directories that you have explicitly enabled
- You can create a .kiteignore file (same semantics as .gitignore) to exclude specific files / patterns.
Why not? that's a _tiny_ amount of data for a modern computer.
I'd rather have a few gigabytes on my machine than have all the code I write automatically in the cloud.
1) kite is useless (or at least substantially less useful) if you explicitly disable files/directories.
Example: Customer says: This fridge I bought, poisons my good. Company: If you don't put your food into fridge its not poisoned. Yeah, but it also not frozen afterwards, which was the reason for the fridge! And no files/directories/lines/whatever policy does solve that problem. Partially because of 2)
2) Human errors will kill this. Just google for number of problems around security tokens, sshkeys and other thing commited to github by mistake.
The only solution is LOCAL index only.
"* Fine-grained privacy controls modeled after the .gitignore file format means that you can selectively and precisely decide which files and folders Kite indexes."
Any system that relies on people following best practices is doomed in the real world :(
There are things like GitFS, but I imagine those aren't part of an average developer's workflow.
If I'm testing an app and I want to hard code an API key for testing, and I'm using Github, it's not a problem. I have to explicitly commit that file. Now, I have to both remember that Kite uploads everything, and avoid using that workflow at all, and use the .kiteignore thing (which is another random dotfile in my repo, great).
I can 'git add .' and commit my life away, but that requires much more intention and explicitness than clicking enable on a prompt and continuing your standard workflow (ie: a simple 'vi super_seceret_file.py')
I can see where you might want to index all of my code to add to your store of information about how frequently various functions are used, because "more is better" in terms of training data, but there are plenty of open-source projects that could be polled instead. For my own code, why not simply analyze my existing projects on my own machine without sending it elsewhere?
It's pretty laughable that when one clicks through to the security page, the very first thing beyond the heading of "Security. Built in." is "Kite is Cloud Powered." as though that were a feature instead of a liability.
While directory whitelisting and a .kiteignore seem like decent ways to prevent code from leaking, it's only one small bug away from disclosing a company's proprietary secret sauce to unknowns entities.
Seriously, could just send the object type being "autocompleted"along with the other object types in the same file and gotten better results without the privacy backlash.
The other thing is that a proper 12-factor app separates secrets and keys into environment variables that are not committed to Github or your PaaS. They are added after a deployment which this "product" just scoops up. For reference, here's what a AWS key being leaked on Github leads to (https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...). Now, imagine that project that is running in production having to be brought offline because this company leaks thousands of AWS keys that were used in development. It's dangerous, sloppy and stupid, three things I generally try not to mix.
Can you not have it just cache locally based on the requirements.txt or the import lines at the top of the file? Then all you know is what I am importing, and I would be fine with that. Anything more, and sorry, can't do it.
Two things come to mind, apologies if they're already addressed:
The sidebar jumping around in the corner of my eye sounds really distracting, I wonder if there's some way to manually tell it to "update" or some other UX trick to ameliorate that, because the concept is great.
I work in the healthcare sector, and I hope you guys do or will have the reams of datasec declarations and certifications needed for this to be usable in such a regulated context.
We've done two things to address the sidebar motion issue:
1) We've improved the sidebar's motion with an updated layout that creates fewer visual changes, and
2) We've been building deeper integration into the editors, with new UX around completions and looking things up.
Check out the new demo video on the homepage—we think you'll like it! : )
Regarding datasec, unfortunately we haven't gotten to that level of security certifications yet, but we hope to get there soon!
Awesome!
Only in February 2017 I noticed that the whole package had changed right under me because of an error traceback window caused by their metrics collection going wrong. I looked at the package settings and IIRC there was a checkmark set for the "Use Kite" option which I'm pretty sure I did not set myself.
The telemetry collection alone is a deal breaker for me. But I also don't like the sneaky way they practically took over the package without clear notice and consent. The package README still makes no mention of Kite and the package is running under the innocently looking 'autocomplete-python' GitHub org instead of their 'kiteco' org. To me it's a very fishy 'growth hacking' strategy.
It sends your code to the cloud. You have not addressed people's concerns who asked about keys embedded in source code, not entire files to ignore. The uninstall process looks and feels a lot like stopping a rogue process that keeps respawning. You've silently integrated with an unrelated project (autocomplete-python) to collect data.
I applaud the idea and UX in the video. I'd love to use a tool that does all that. That said, I completely condemn everything else about you. I strongly recommend anyone who has installed Kite to remove it from their computers immediately as it seems that the people behind it don't have the community's best interests in mind.
Not saying I disagree with your main idea, but the uninstall process linked to above seems pretty standard to me.
[0] (Yes, I know launchctl obviates the need to reboot, but their instructions say reboot and that's what we are commenting on here).
This reason applies to a lot of todays web apps. with the emphasis of recurring revenue.
So, given that these indices could be obtained as needed, I'm not sure I buy this argument anymore.
If we can justify the download of a 20mb for a set of plugins, I think that we can justify a 2mb download to document the entirety of a language's standard library.
As a few points of comparison, Atom's download is around 80MB, Docker 110MB, PyCharm is around 175mb, and a ctags file that covers over 8,000 source files (including boto2/3, aws-sdk-go, the python standard library (both 2.7 and 3.5), the go standard library) is about 6 MB compressed.
[0] I know this, because it's a complete pain to use class files which have been stripped of debug data. Suddenly autocompletes look like "someFunction(String arg0, Thing arg1)" with no other supporting information.
EDIT: Just took a look, the indexes for a few workspaces I have are all under 50MB.
JavaScript projects tend to have more dependencies, but those tend to be smaller and will have a smaller index.
Solving this 'problem' would lose Kite money, so I don't fault them for not attempting it.
I think it really boils down to: what happens when their servers are compromised; how much liability will Kite assume for the lost IP? My guess is: None.
They don't even have a discoverable privacy policy, just a blog post! Going into the purchase pipeline, there's no service contract, just a "sign up for an account and give us your CC".
also, "The short answer is: we don't index anything on your computer that you don't explicitly ask us to" you should say that on /security that's a pretty important point.
I read in last year's HN post that you collect user's terminal commands. Is that still true?
Over the last year we've focused on knocking out the core product experience. We're now going to focus more on Kite Enterprise (https://kite.com/enterprise); if on prem is of interest please get in touch.
As mentioned we are also exploring Kite Enterprise now that we've gotten the core product more
- Kite only indexes directories that you have explicitly enabled
- You can create a .kiteignore file (same semantics as .gitignore) to exclude specific files / patterns.
There is a lot of publicly available source code which Kite can scrap and use. Expecting that users will be happily uploading their code into a private cloud is weird.
Anything that sends all my code to the cloud is automatically disqualified.
EDIT: thanks for the downvote btw.
Kite is a breach of privacy for 80% of professional software developers that work on a private codebase. You are sending your code directly to a third party, without even any ways for you to prevent that. At least asking on SO you can change your code so it isn't 100% obvious what you're doing.
The fact that this remote upload is mentioned nowhere on the landing page and can only be inferred from the Kite Enterprise very short description is a bit worrying.
However, starting a few Python projects myself soon, this looks like a great extension. I suppose the suggestion for VS Code has been made dozens of times already though.
Uploading all of your code to the cloud is a massive liability. To top this, the people interested in "something magical that codes for me" are not the good developers, their users are very most likely beginners, bootcamp coders, junior engineers, etc...
I think they're abusing trust through obscurity, people have no idea that their code is being uploaded. Making this the default for a very common python-autocomplete in atom is even worse... see this: https://github.com/autocomplete-python/autocomplete-python/i...
No matter how much I code, I'll always have to look at documentation. This is just faster documentation, I really don't see the problem from that perspective.
Doing software development is mostly reading code and documentation. Obviously one also writes code and for sure one can't memorize every function or package name, but searching for it isn't that much of a bottleneck? Some time ago I wrote Java using Eclipse (which had/has reasonable auto-complete), but when I switched to different languages, I also switched my IDE and mostly use plain text editors these days. There are auto-completion tools for text editors, but I just never invest the time to activate or configure them and AFAIK there aren't completion tools which work well across different languages.
Maybe I revisit them at some point, but at the moment I do not really miss auto-completion.
I think, in the future, ideally, you will be able to do a programming interview, using a tool like kite, in a language you don't know and feel comfortable.
So when I am learning a new language, I don't want to have to look up if the length of a vector is len(), length(), .len, .len(), .length() and so on. In fact, I don't want to do this for languages that I do "know".
aCollection.<TAB>
list of all the method on given collection pops up. If it's short, just skim it and choose something which appropriate. If it's long: aCollection.l<TAB>
check if there's something similar to length/len, use it, otherwise: aCollection.l<BACKSPACE>c<TAB>
check if there's something similar to count then use it, if not: aCollection.l<BACKSPACE>s<TAB>
check if there's something similar to size and use it. Finally, if all the guesses failed, defer to documentation or google.Basically, (semantic) auto-complete is an inline quick-search facility for docs. Very, very useful if you know how to use it effectively.
I get your point though and there are cases where completion might be useful, but for me the context-switch to a search engine is just not that much of a hassle, but maybe I never enjoyed a good completion engine, so I might give it a try.
import module
module.<TAB>
and: def meth(self, ...):
self.<TAB>
and even: foo = Foo()
foo.<TAB>
It doesn't work for all possible cases, but as you said, you can always consult Google. It's just that I prefer not to leave my editor if I don't really have to.OTOH, I work with a lot (10+) of different languages and find even the dumb, basic autocompletion (which only offers to autocomplete words already present in the file) helpful. As other commenters noted, writing aLongAndDescriptiveFunctionNameToCall from memory every time may be inconvenient for two reasons: a) was it aLongAndDescriptive... or aDescriptiveAndLong...? and b) writing this much text takes time, and the more letters you have to type the more probable a typo gets.
Anyway, I think you should give a try to a few different auto-completion plugins/systems and see for yourself. You should probably spend a little time to configure such a plugin so that it doesn't get in your way when it fails (ie. has no good completion to offer), but once you make it so the auto-complete may become really helpful to you. Or it may not, but I think it's worth checking out.
In 5 years, once average computers are very fast, you will get something like.
len -> did you mean size()
based on the fact that so many other people have entered that.
I am sure there are other ideas besides that haven't even occurred to us.
But you need some user testing, and maybe some ML.
I mean, the machine needs to train enough to know that when the user types "string.len" they really mean "size(string)" and it can't just follow the alphabet anymore.
Of course then you have to deal with the case where the suggestion is subtly wrong (e.g. amount.add(increment) was intended to mutate the amount, while Number.plus is a pure function) and the programmer might not spot it, if they were unfamiliar with the correct usage in the first place. Now we are firmly in research territory, I think.
1. Do it in the cloud somewhere. You probably want to do this anyway so you can learn from everyone.
2. Now you can't indefinitely keep everyone's code in the cloud (as kite is learning), so you take the most common use cases and privacy minded coders can download those to their desktop.
3. Of course languages are constantly evolving so the "cloud archive" will always be live and learning from everyone
By the way, you would "learn" a mapping when someone searches for "len, length, .len" and so on but they finally settle on "size" so you would have the input and the correctly labeled target from people's code. You do have to watch them programming in practice though.
For the subtle variations, it would hopefully give you a list of suggestions in order of usage.
When I left IDEs for a terminal-based dev setup (Vim + CLI), this was what I thought. I rapidly discovered how incredibly wrong that was.
A big factor, for me, was that autocomplete kept me from making typos. Even with a rapid feedback loop, those typos build up. Plus, the reduced cognitive overhead that comes from being able to bang out code faster also lets me stay much more focused.
Intelligent autocompletion is a nice-to-have that I don't think I really miss, but straight-up dumb autocompletion has been a huge boon for my productivity.
No. It's programmers' dyslexia which leads to typos being repeated again and again.
The problem is that many programmers don't read their own code, and even if they do they don't know how to read it critically/carefully. It's incredibly frustrating.
There are a lot of similarities between writing code and writing prose. Many programmers are unaware of this. Even today, many programmers write code for machines to execute, not for other people to read. I feel that it's deeply wrong approach and that "creative writing" course (or something equivalent) should be mandatory for programmers.
I think we need a large shift in how introducing spelling and grammar errors into the code is seen. Namely, it should be viewed exactly the same as introducing bugs - it's that damaging in the long run. Please don't do this. Please use spell checkers and please learn your orthography.
Typing just the first or few random letters of veryDescriptiveLongMethodName and completing it with space/tab will always be faster. Using stuff like templates, smart completion, emmet, refactoring tool, constructor/method generators will always be faster, if you know your tools well.
I feel like with Java it makes a lot of sense to have smart completion, because you end up with incredibly deeply nested identifiers and such. A whole lot of typing. But, I don't code in Java, in the general case (aside from occasionally tinkering with Android APIs, with thoughts to some day making an app). For many more concise languages, it feels like a solution looking for a problem.
I could be wrong. This could be a thing that would provide clear value, if I were to put in the time to learn how to use it correctly. But, so far, I just feel vague frustration when I have the feature turned on.
That said, having docs available as you type is something I can see clear value in. I have to have API docs open 100% of the time when coding...having it jump to the right function as I'm typing it would be awesome. It seems like Kite does this, too, which is probably enough reason for me to use it. I've been poking at Python again lately (after many years away from it), because of Tensorflow and Keras, so I'll give this a go.
I wish they had a Linux version. I rarely work in Windows (though ConEmu and WSL has made it so I'm not terribly unproductive in Windows anymore, as I once was).
Regarding features, there's actually more than just autocomplete and docs: https://kite.com/tour/atom
It doesn't matter how well you know library X or the stdlib.
Some made up examples:
userRepository.findUsersWithPlan(planName);
customer.sendPaymentLateEmail(...);
Having powerful IDE assistance reduces the barrier between your thought and the computer.
When I think "send email to customer" I just want the shortest path to achieving that. I don't want to fiddle around or context switch.
Another advantage is that it can guide you into picking the correct option.
I have been burnt many times when looking things manually because you may find one option but not be aware that other options exist.
It's nice for the IDE to communicate to the human "now here's a list of valid things you can choose from".
If you look up from your text editor even a second, it will take several seconds to get back into context. So even if the page you want is already in your browser, and you just switch windows, you lose. Also autocomplete has three purposes: prevents unnecessary typos, is faster than writing it out, and lets you find API/docs.
How long it takes to find a relevant piece of code in your code base obviously depends on what tools you have for searching your local code, how much code it is and how good the search is. How long it takes you to find something online depends on how good the docs are etc.
How much value autocomplete is also depends on the strength of the type system of course. For C or Javascript there isn't much autocomplete can do with the contextual information, but with Java there is a ton to be gained (Long method names are norm, and object-dot notation feels almost invented for autocomplete). So if I were using something with a functional flavor, or a weak or dynamic type system I'd probably have a different opinion. But for strongly typed OO (C++, Java, C#, ...) the value for autocomplete is enormous to me.
Without autocomplete you can always make longer descriptive type/variable names because the time taken to write a type name isn't proportional to the length, only to the unique prefix or unique camelcase signature of the type name. E.g. for a DefaultUIRenderer I could write DUIR-Tab and know I had the right type (Insert obligatory Java joke about ContextFactoryProviderFactoryDecoratorVisitor here). How much you gain on this depends on how good a typist you are obviously. I have an error rate of around 1/10 chars being backspace, and you might argue it's because I do auto complete, I don't know...
> There are auto-completion tools for text editors, but I just never invest the time to activate or configure them
Me neither. That's why I think any reasonable IDE should be either a) working out of the box. I.e. hope that you can find an editor/IDE that ships with batteries included, or b) that it's at most a matter of selecting one plugin from a menu to activate support for language X in the editor. If I have to start configuring something with a text file somewhere then someone failed, either the makers of the language or the editor or both. Even in "plain" editors like VS code or Sublime you can usually just get a plugin these days.
> AFAIK there aren't completion tools which work well across different languages.
There are efforts to do this, but the name escapes me - that is, an effort to remove N languages times M editors and make a standard for syntax highlighting, autocomplete etc. that makes at an M+N problem instead.
Aside from intellectual policy problems, in large codebases mistakes happen, including api keys being committed and pushed. You see it even in open source projects, and tools like gitrob[1] exist to exploit that.
You can see how both of those example issues are problematic, if even a snapshot of your codebase is being pushed off-site.
I think this is a crucially important feature for any large enterprise that has a codebase that is a significant effort of R&D resources.
Don't get me wrong, there are cloud services like github being used by medium to large shops, but the missing visibility into those decisions is that those choices are often regularly heavily vetted by security, legal, and engineering resources.
okay, so I am excited about this, don't mind some code in the cloud, but I am having trouble with a quick start.
Downloaded it, had trouble launching it (expired certificate).
Once I did launch it there are no instructions.
I went into the tray and went to settings. It was trying to map my WHOLE USER FOLDER.
I turned that off, and whitelisted a smaller folder for it to use. Set up a small test python file. Opened up a sublime file.
Can you include some instructions about how Kite is supposed to integrate with anything? I see this cool video but it is not obvious how I am supposed to get it to work for myself.
Thanks for trying Kite. Would love you get you up and running!
In the mean time, check out http://help.kite.com/article/6-how-do-i-uninstall-kite
rm -rf /Applications/Kite.app then kill the engine and helper
Jesus, what a nice way to piss people off: 1. upload all code to cloud. 2. be hard to get rid off.
Later finding out it .. uploads your code to them.. it's really an insane thing, I think it's such a huge invasion of your machine and your privacy it should have been removed from the HN front page unless those facts were put immediate front and center.
The content does not seem dynamic, so a simple HTML page should work.
[1] https://amiunique.org/ [2] https://github.com/ben174/hsts-cookie [3] https://github.com/diracdeltas/sniffly
On the security point, there are some answers out there relating to javascript in tor [0]. Basically it's not a risk per se, but it does increase your risk surface area.
[0]:https://security.stackexchange.com/questions/40620/why-is-ja...
Already disliking this software...
No thanks, I'd like to have SOME privacy. What I punch into my editor shouldn't be public until I git push.
We're comfortable with sending our closed-source code to GitHub and our secrets to Google Cloud and AWS so I can see a path towards being more comfortable with uploading code to Kite as well. Some guarantees around privacy and the ability to delete our code and derived data could help assuage concerns.
In the meantime, perhaps you could highlight that the code uploading is opt-in on a per-file or per-directory basis (though one issue with this is that our open-sourcing system allows for private subdirectories within public parent directories and we'd want finer control)? I'd feel good about having clarity around what's uploaded and what's kept local.
In any case this seems really cool for open-source projects to start with. I'd definitely give the JavaScript version a try. And do you think you could add a VS Code extension?
Is stack overflow ok with having their answers inside an IDE? This decreases the number of pageviews on SO for each installed client. Is that something you guys checked?
http://stackoverflow.com/help/licensing
https://meta.stackexchange.com/questions/272956/a-new-code-l...
Both are attribution-required.
Bonus again if you get a major snippet from a third party library with an incompatible license.
Good luck with privacy.
Bonus points for accidental license violations.
404 Not Found
Code: NoSuchKey Message: The specified key does not exist. Key: index.html RequestId: 759C55C7EA94F7D8 HostId: 2i2HH8A3vp5KFvhHhHeoQ+6AiFL/kjd5iByJy6Ouo/pbKwE2xaKP8Es4SU3//1/P7M/5KWJXQv8=
404 Not Found Code: NoSuchKey Message: The specified key does not exist. Key: index.html RequestId: 7928D2D3EE5313F6 HostId: 2iAqS6E1PciR/++frE0wVXo/jlBhK24kopo93WRvVieuepmCctk1v+m+yOAIZZz1q5qIA6HVH9w=
Does the Sublime integration support packages installed in the current virtual environment (that might not be publicly available)?
Aside: The pricing page is broken on iOS.
Did you address the issue which came up multiple times last time when this was on HN about cloud indexed code by default?
Is it just on HN or are there very few people now who use Linux as their main dev machine? With some of the build quality of the new Dell Machines I would have assumed any dev tool would be Linux first, since almost everyone is using some form of 'nix on the servers.
I've never had much trouble installing the latest Ubuntu on any of XPS series(except the 'suspend' feature is weird).
EDIT: nvm i see from another comment that the Linux version is in testing. But still weird to see Mac devs outnumber Linux ones(or maybe they're just a vocal minority :-) )
Most Popular Articles
and the first one How do I uninstall Kite?
I guess I will passThere's not even a mention on kite.com about how data is handled that I can find anywhere. What is the method of transport? What stands between skids and my code? The server my data goes to, is it shared VPS hardware waiting to get pwned by your neighbor, xtremecrackz.zyx or is it on private servers guarded by a three headed puppy named Κέρβερος, 13 ninja, and biometric security? Does the page even mention this is a cloud service somewhere? I see support for VS Code, but not MSVS proper, emacs but not specifically GNU/Linux yet; Mac support but not Linux in spite of at least $4M USD in seed and 3 years of development (source: crunchbase [1])? The Windows download page gives instructions for bypassing SmartScreen warnings meaning your code signing certificate has no reputation with Microsoft yet if I understand correctly. Frankly, I didn't think "Adam Smith" was even a real person until I checked it out. LOL, sorry bro but it sounds kinda generic to someone skeptical I guess. Maybe you assume trust since you travel in the circles you do, but we nutjobs like stuff in writing, and trust assumptions without verification are bad practice anyhow -.-
(on trust) Your investor who may or may not provide the same or similar "Kite" software discussed in GCHQ leaks as a "correlates-anything" solution, Palantir Technologies, has been standing in the suspiciously shadowy center of a maelstrom in some circles. I like them supporting our warfighting - but not working against the people of the United States, or anyone's civilians for that matter, however that's an argument for the agencies they contracted with. I've watched my brothers bleed out defending the rights their software has helped undermine, I'm not sure how to feel about them at all right now. Do I want to give my code to their creepy software? No, not really, since I'd have to consider that if they got a contract they might, without even knowing the end use, build software to guide Terminators to hunt down and kill civilians who write bad code or wear plaid socks. Seriously though: eyebrow raised.
(advice) I would add more clear information about how this all works. A link to security answers should come up before the footer IMO, given the nature of this product. Going out of my way to look for it, I guess it seems like security was an afterthought. I can appreciate your blog post about security [2] and the main security page which links to that article (merge these?), but they fail to answer almost all of my questions. They imply that the service isn't really ready for the spotlight, but do not explicitly say anywhere to safeguard sensitive stuff or not to trust everything just yet, but it seems softly implied to me.
(bigFoilHat) This might sound far out to some, feel free to ignore or laugh, but if I were an evil puppet master, I'd have my cybersecurity and intelligence contractor who provides access to mission critical software or monetary capital for a startup attempt to leverage this relationship to gain information about code in the wild and specific targets' code using this service, perhaps to have software look for opportunities to steal parts of keys, suggest code changes to enable exploitation, forward copies of code from persons of interest to investigators. I might ask them to approach them as patriots in the interest of the GWOT and all things decent, to tacitly and deniably or perhaps even expressly cooperate with legally and morally grey-area surveillance operations. Perhaps if there is no cooperation or just to keep it quiet, I might suggest they infiltrate Kite.com and gain the ability to intercept data clandestinely by using their trust and rapport with company leadership. "Plz send all code to spies and disable security stuffz kthxbai" I can weaken my own PRNGs and send copies of my code for spooks to analyze by myself without assistance thanks. Again, I'm attempting to honestly characterize how it makes me feel, just sayin'. I simply have no way to even fool myself into thinking I can know what goes on with my data after it leaves my PC. How do I even build rules for my firewalls? What are the parent processes which need communication, on which ports, using what protocols? Which servers will it upload to? Can we blacklist certain destinations by region or other attributes? I think you need a more robust explanation on the site before us crazy people are satisfied.
(bigFoilHat Q) HN: what say you, am I just being paranoid here in thinking that users' analyzed code may end up being displayed on an alphabet soup agency wiki somewhere along with download links for tools to suprisebuttsecks us being passed out to every malware hoarding contractor who accidentally skated past the SF-86? Maybe I'm just having a bad bout of Stallman Syndrome. One might argue "99.99% of users' code will be useless fluff and bizcruft, who cares if they copy my der.py code?" but finding that 0.01% relevant signal in the noise is exactly what Palantir does for customers, isn't it? So how can I flippantly dismiss the notion?
(Q) Do you sell, gift, trade, share, or otherwise disclose or make available knowingly any information about users' personal data or source code, even if anonymized or generalized in reports and detached from identifying information, to other parties? Can/will/do these parties include your investors? Does Palantir Technologies store, use, or have access to at any time, our source code or any information about it or ourselves?
That said, it sounds cool as phrack and I would love to see this in many languages and editors, but only if it can be trusted somehow. I'll be watching and investigating, thanks for sharing this on HN,
-Ax
[1] https://www.crunchbase.com/organization/kite-com/ [2] https://kite.com/blog/thoughts-on-security
Please correct anything I am mistaken about, I admit I could be completely off the mark here.
Curious how they could possibly quantify that.
Getting a good setup is something I can't do twice. What fork of ghcimod do I need this week and how many CPUs will she be pegging?
Please flag this submission.
I think allowing users to submit code examples could dramatically increase the value. Maybe even microservices.
The ideal (and perhaps impossible) version would look at my code structure and suggest replacements for components from people who are better programmers than I am.
I'd love to use a self-hosted version though.
I work in finance, and source code in the cloud could get me some prison time.
SEC_ERROR_UNKNOWN_ISSUER
I suspect others will have this issue. (On my windows 10 machine)