How a VC-funded company is undermining the open-source community
theoutline.com
theoutline.com
If you're reading this Kite. I now have a negative view of your product. We cannot allow corporations to take over open source tools. Donating is perfectly fine and encouraged, but the above example is a downright take over. If you want another tool then create one, don't take over an existing one and use the communities trust of that tool to promote your product.
It took me months to get through to a human to get them to delete my code, including two emails to the CEO.
I like the idea, but there is no way I would use it after this experience.
That is why developers should be very careful what applications they install on the corporate computer and what cloud services they use.
That sounds crazy, so I reviewed their privacy policy[0]. It looks like Kite now requires users to whitelist the directories it indexes and automatically purges files you remove from the local index.
The Privacy Policy says that:
> When you use our services, we may collect [...] Any source code files on your computer's hard drive that you have explicitly allowed our services to access. To learn how to control access to your source code files, please visit our FAQ.
The FAQ[1] says
> Kite only uploads files that:
>
> 1. Have a .py file extension,
> 2. Are children of a whitelisted directory,
> 3. And are not ignored by a .kiteignore file.
That doesn't seem like "any source code file on your computer" to me - unless it whitelists root by default, which would be a hella dark pattern.
Also, removing a file from the local index should remove it from the server as well [2]
[0] https://kite.com/privacy [1] http://help.kite.com/category/30-security-privacy [2] http://help.kite.com/article/10-how-do-i-delete-files-from-k...
I was actually questioning myself when I realised what had happened -- I thought, "perhaps I just messed up". But after I saw this story about their other dark patterns, I'm convinced they just deceived me.
https://web.archive.org/web/20161231231542/https://kite.com/...
Seems similar enough to current version.
Easy to see very intelligent and circumspect people interpreting "where enabled" to mean "when I ask for autocomplete" and "your code" to mean "that specific snippet" because who the hell would actually think it's cool to just carte blanche upload other people's workspaces?
Maybe you are thinking only for your self. What about the majority of the users of minimap/(other hacked plugins) who doesnt know this is going on, and they are not aware that some files need to be deleted from someone elses server.
ps. i know "hacked" is not the proper term here ,but you get the idea.
[0] https://github.com/atom-minimap/minimap/commit/16c11d82b889c...
I have zero faith this page actually works though. A few months ago I deleted all of my data and I checked back today and it has reappeared. (I uninstalled the client and deleted my login token back then too, so as far as I can see it's their issue.)
I have sent them a stern email to delete my data. If you want your data deleted too, I would recommend doing the same rather than trusting their web interface. None of the emails on their website seem to work, though. Emailing the CEO does work eventually, but I don't want to start a witch hunt. My email is in my profile if you want his email.
anybody has a list of infected packages so others can quickly remove with `apm uninstall ...`?
Now that doesn't make it any less shady though...
Even without that, basic contract law in many places requires a degree of mutual understanding for the contract to be valid in the first place. You can't just bury a surprising term with a huge effect deep inside a long legalese document and expect it to actually stand up in court, and if you're doing something dubious and relying on that as your defence then you might be in for some disappointment.
Obviously this would a be a terrible thing to do and no one should.
It didn't ask? Sounds like malware, and meets the definition of theft. Inviting someone into your house does not give them permission to steal things in your home, and leave with them.
I believe about every company that develops software has some clauses about what software is allowed to be installed on the corporate computers and who has to initial any request to install a new program on the computer.
I don’t know how much I agree with that statement in general. There are several major open source projects with corporate “control” – Mozilla, Google and Apple control/heavily influence Firefox, Angular and Swift respectively and there are probably a dozen others. The idea that corporations are “bad” is a tired trope. Some corporations are bad, some are good, some are in the middle.
But I agree with your actual actual sentiment though – corporate involvement in open source should be as benevolent as possible.
I don't think we need to bring morality to the discussion and complicate the issue.
Corporations are organized around profit, open-source is not. With only that in mind you can predict what will happen in most of the cases.
To put Mozilla, a not-profit, in this context, in the same set that Google and Apple is not fair, by the way.
All three of these statements seem like nonsense.
First, "Corporations are organized around profit". No, they are legal entities, organized around articles of incorporation. These have a purpose statement. Often, those purpose statements are directed toward lawful business goals. But you do not have to be.
Non-profit vs profit corporations can, quite literally, have the same set of purposes. The only difference between the two is what you can do with profits.
"open-source is not".
I'm not even sure what you are trying to say here. Very large amounts of popular open source, is, in fact, produced by for-profit companies, and has been since the beginning of open-source. The term was even created by a group of people at a for-profit company. So ....
"With only that in mind you can predict what will happen in most of the cases."
No, you can let whatever biases you seem to have stoke your imagination and prognosticate. You can't actually predict what will happen. There are plenty of happy, well functioning for-profit companies in open source that have been helping open source for many many many years. There are also plenty of non-profits that have harmed open source greatly.
It takes a lot of blindness to see this stuff as simply black and white.
Red-Hat main worry is to be profitable. That's is above any other concern.
You can be sure that, if their bottom line was threatened, they will be pushed, in order to survive, to change their business model and they will not be beyond behaving in a "bad" (but legal) way if they don't see other way around the problem.
If fact, we can argue, that Red-Hat management, being it a public company, is forced by law to do that.
For instance, you call Mozilla a non-profit. But it is a non-profit corporation, a legal entity that has organized itself in a certain way and applied for special tax treatment.
The goals and the incentives are very different.
With just this information and no other, I think I'd predict corporations to make better software than open source. I take it that's not what you had in mind.
(This is for similar reasons that I expect for-profit companies to provide better service than government-run ones. I don't particularly want to get into a debate right now about whether that actually happens, just trying to explain my intuitions.)
Also Internet Explorer is infinitely better than Chrome and Firefox.
What I mean is this: If you mix open-source with a for-profit entity, don't be surprise when that entity try to extract profits even in orthogonal ways to the original intention of the project.
Of course, in practice, and by the nature of open-source, this is a very difficult to do and, normally, can be prevented, but the trend is there and should be take into account.
I beta tested the Kite product when it first launched maybe two years ago. I don't use it today but I would try it again. Since then they've only tightened down on permissions and made things clearer.
Kite was also not the first to run ads in an IDE plugin (Wes Bos has sponsored several), at least not in Sublime. Personally it's not my preference to have ads either but ultimately this is up to the maintainer of each repo. The tool is still free to use. It clearly states that using the cloud engine will upload your code to do analysis in the cloud. It's 2-3 sentences, not like it's buried in some long EULA.
Shame on the article for labeling inserting an ad as "taking over" and labeling an ad as "spyware"… pure clickbait targeting non-devs.
The new Kite engine also clearly states it is a cloud-based service and they build integrations for their service. The whole industy works the same way. You don't have to use their engine to use autocomplete-python and its opt-in too.
https://github.com/atom-minimap/minimap/issues/588#issuecomm...
Your comments are such a poor defense of a dubious feature I wonder if you have a connection to Kite.
I think you're overlooking the diagram linked above which shows enabling the Kite engine is an opt-in button click. The CEO also states that it is opt-in in the article: "Most users who install autocomplete-python close the engine selection prompt, which results in not getting Kite or its benefits," [the CEO] said in an email.
https://outline-prod.imgix.net/20170721-QVaxMDgDwdZ1TBufCdq4...
As I stated above, I beta tested the Kite product early on and have used it in Sublime through a similar add-on. I am not a current customer / user, but I do make my own dev tools. It was always completely transparent to me that they are sending code to their server to run a cloud analysis platform. Based on that, I still maintain that the community is massively overreacting to something that was made explicit upfront.
It's a slippery slope, similar to the controversies over using BitKeeper for the Linux kernel or adding DRM to HTML5 (both justified, I think). The openness in open source needs to be defended.
I genuinely don't understand why this service is getting a disproportionate amount of backlash relative to the plethora of cloud based services out there that analyze one's entire codebase. Maybe it's because they're interacting with the code from the dev machine directly vs integrating with repos on the git server? Would that make it different to you?
When I sign up for a service like Code Climate it's very clear that I am giving them access to some of my code. I also have easy control over what code they can see. They are honest and upfront about what they are doing and why.
Kite has been trying to hide what they are doing, with the goal of tricking developers into doing things they otherwise wouldn't. They're taking advantage of the huge amount of trust in the open source community. Kite must know that abusing this trust has a high chance of hurting the community, but they don't seem to care, as long as they can make a quick buck or two for themselves.
A lot of people here really cherish that trust and goodwill among strangers in the open source world, and are understandably pretty pissed when someone comes along and messes with it.
The bottom line though is being honest and upfront with developers. I suspect Kite could have been a bit more forward about what they were doing and the developer community would have reacted with much less outrage.
One misrepresentation that I wanted to quickly highlight is that the autocomplete-python install flow has three steps, not just the one linked in to in the screenshot above. The other two are:
Enter their email address - https://user-images.githubusercontent.com/87728/28395016-dc7...
Read a warning, decide if they want to whitelist any files - https://user-images.githubusercontent.com/87728/28395021-e04...
Small technicality: these screenshots say that Kite is installing but it's actually only downloading the installer binary to memory; the actual install doesn't happen unless the user goes through all three steps.
It's also worth noting that if the user clicks "Add Later" no code is sent to the Kite servers for analysis until they whitelist a directory.
It's funny seeing this now to see where I tripped up. When you say "enable access in /Users/ben", I guess 6-months-ago-me assumed it meant "enable access to code in /Users/ben when I am working on it". It felt a bit like an iOS permissions dialog, where I was giving you access to my filesystem. Parsing it now, I realise that the text above the button says "where enabled, your code is sent to our cloud".
You could argue I should have read that more carefully, but that copy doesn't scream to me "I'm about to upload all of the source code on your computer including proprietary stuff and secrets". Because that button was the default highlighted button, I assumed it wasn't going to do anything drastic like that. (It's like Ryanair having a big red "YES I WOULD LIKE INSURANCE" button, hiding the "no I don't want to spend $100" button somewhere in the small print.)
Above all, you certainly shouldn't have included that as a shady update to some Atom extension I was using.
From the article:
> Smith also said that most of the negative reaction was due to confusion around what the tools actually do. (Connor pointed out that it’s not possible to review what Kite does, since it itself is not open source.) Then he blew this reporter off. “I apologize in advance that I can't answer any further questions,” he wrote. “I need to focus on other parts of the business, including continuing to improve the product for our users, and conflict like this is always doubly distracting.”
The above sounds like you were given the opportunity to explain things but shrugged it off as a distraction.
If it deserves a more thorough response, why hasn't that been given? Even in this reply you only "quickly highlight" one point.
Why not fork the original autocomplete-python with one that has Kite enabled instead? Then users who want Kite or use Kite are able to do so, without screwing over everyone else who have no idea what Kite is and dont want anything to do with it.
Reminds me of software downloaded in the past that comes with some random search toolbar that gets installed in browsers. Annoying. Shady. Not cool.
Besides the open source issues, this tactic seems to reveal a massive desperation by the Kite folks. There is no way they couldn't have seen how negative this was going to look once people found out. Their ability to attract new users through word-of-mouth and organic advertising must have plateaued. Sneaking their service into a well-used plugin would have given them a boost in users, maybe enough to attract a new round of funding, but they must have known it would cause this kind of bad blood. Especially based on their past reception on HN, which was highly upvoted but in which they never convincingly answered the concerns about uploading users' source code to the cloud:
https://news.ycombinator.com/item?id=11497111
https://news.ycombinator.com/item?id=13977982
https://www.reddit.com/r/programming/comments/4erqgq/kite_pr...
That's the weirdest part to me. Who, exactly, thought this was going to go well? It is hard to be sneaky with open source. And even harder to win back goodwill after being caught out.
For instance, now that I know, it would take a change of management and business model before I'd even consider running any of their code, and I'll be writing a Kite-detector for our code scanning tool this week.
"our plan is to earn trust the hard (i.e. only) way: transparency, published policies, and a track record of good decision making."
Easier said than done, apparently.
Then, there are alternatives such as sublimetext/vscode, which have the minimap builtin...
Disclaimer: Not affiliated, I prefer n/vim anyways. This is a copy from my comment in the issue. Please read @abe33's comment [2] in the issue. This might explain a thing or two.
--
[1]: https://github.com/mehcode/atom-minimap-plus
[2]: https://github.com/atom-minimap/minimap/issues/588#issuecomm...
First, he focuses heavily on how much stress the backlash has caused him. Then he tries to paint it as a "misunderstanding" on behalf of the users. None of this strikes me as the behavior of someone taking full responsibility for their actions.
Further, I keep seeing people trying to justify his actions with the pathetic excuse that he was probably just doing as told by his employer. Sorry folks, that's not how being an adult works. There's a reason virtually every formal code of ethics stresses personal responsibility. Take, for instance, 8-b from https://www.nspe.org/resources/ethics/code-ethics
Engineers shall not use association with a nonengineer, a corporation, or partnership as a "cloak" for unethical acts.
Or the very first point from http://www.acm.org/about/se-code Software engineers shall act consistently with the public interest. In particular, software engineers shall, as appropriate:
1.01. Accept full responsibility for their own work.
Just because we're in the comparatively-"lower stakes" profession of web development, that doesn't mean we can use the sorry-ass excuse of "my boss told me to do it." Unless they held a gun to his head, he had a choice, and his choice should stick with his reputation for better or worse. Now his name is going to be attached this dumpster fire of a PR mess because he didn't have the will or integrity to say no, and smart people within the community will have a very good reason to no longer trust his judgement, much less his future contributions.Otherwise, if they offered the job with no conditions attached he'd be under no obligation to change his own personal projects for them.
Secondly, even if it may seems to come late, we've heard you and decided
to revert all the changes related to the python links feature. The next
release will no longer show anything. I'll also make sure that the relation
between Kite and the minimap package are as clear as possible. I've been an
employee at Kite for over half a year now and this plugin is now
officially maintained by Kite.only speculating but truly possible.
> It must have been frustrating for him, as the plugin's
> original developer, to be dragged through this crap.
Completely agree.Then, this sets a precedent. It reminded me of Google injecting some binary code into Chromium [https://news.ycombinator.com/item?id=9724409]. However, we have a single person here. I can wholeheartedly imagine, that this can cause quite some stress. Also, it could have happened to many, I think...
Edit: I'm happy about the discussion here. At least, this won't happen again, anytime too soon.
So far I have found it utterly unconvincing to the point of near uselessness. It rarely finds anything intelligent to say about my code, and gives a significantly worse view of documentation than Dash (for which I have a hotkey bound for near-instant lookup).
On top of that, I found Kite to use significant resources, there's no way to inspect what it's uploading so now way to ensure you aren't uploading things you don't want to, and the second time I tried it the UI was filled with dark patterns and I found it quite difficult to uninstall (I reverted to just trashing all the files I could find relating to it).
https://atom.io/packages/minimap-plus
https://github.com/mehcode/atom-minimap-plus
It is a featured[1] Atom package, which may point to whom is GitHub endorsing in this issue, though we could see a more direct response from them regarding both minimap and autocomplete-python.
After reading sadovnychyi's reaction[2] to the autocomplete engine selection screenshot, I think forking is also the only remaining step for autocomplete-python.
[2] https://github.com/autocomplete-python/autocomplete-python/i...
This type of entrepre-narcissism has to be shutdown hard. How deluded does somebody have to be to imagine that putting a confirm-shaming dialogue in an opensource tool is not Advertising?
It's a real shame as the service was good, but nothing is good enough to justify advertisements in my work-space. The fight against distraction is hard enough as it is without having to think carefully about where I'm clicking due to dark-pattern UI.
The reviews above made me reconsider.
I'm a freelancer, and my code is open-source anyway.
I still had to manually purge my machine and files from that page.
If you think your files were removed, check again.
I would recommend emailing them to delete your account and data, including backups and so on.
Something different was likely happening in bfirsh's case (sibling comment). If you delete the files from the kite.com/settings/files page but Kite is still installed then they will get synced up again. The most fail proof way is to uninstall and then wipe files from kite.com/settings/files. We will make the wipe files link log Kite out on that machine.
Sorry about the edge cases. We've been working on it, and will continue to do so!
I almost spit my coffee out when I learned about this (as I'm a minimap user who had no idea this was going on). Not a fan of these shady practices - completely breaks the trust between package maintainer and users.
Thanks, Kite. I'll make sure to remember this in case anyone ever considers your service.
Completely morally bankrupt. All of them.
I gave up hope for such things after seeing staff, investors, and speculators tripping over their own dicks to invest in Brendan Eich's latest venture (Brave) and its ICO, with full knowledge of his revolting and public bigotry against gay people.
Money trumps morals, it seems.
So was the people calling for him to resign.
Kite's business model is just as legal as Eich's free speech money. But people still think it's wrong, and so they try to find ways to discourage others to act similarly.
I'm not completely sure if such punishment works, but I'm pretty sure that if it works for Each, it will work for Kite, and vice versa.
I think your claim of "bigotry" is a bit overstated and I don't really care about people's political views in this context.
Microsoft copied the model for operating systems. Token resistance from programmers.
Kite copies the model for programming tools. Too late, programmers.
If you can't see the distinction between this and the examples you mention, you really don't qualify to make sarcastic comments.
HN is specifically geared towards people who make a living coding things in the new "surveillance economy." This particular example (to go along with the dotnet command line issue) is just a difference in degree, not kind. They're mad that someone else is abusing their trust and privacy.
Welcome to the party, pal!
That is a narrow way to look at things and is not the full picture. Plenty of people protested and still protest Google's unethical business practices.
But I'm waiting for autocomplete-python to be changed, too...
I don't distrust Linux distributions' respective security guidelines; but it can't be that hard to find a loophole in community-driven system/software development and the damage would be substantial if a popular Debian package would have been subverted and have gone out with updates.
There's a significant level of risk around open source projects changing hands, something which may be invisible to the users of those projects, especially as they become more heavily used and therefore more tempting targets for attackers.
In theory, Debian or any organization could do the same background check, but is that the best use of their limited resources? And would they want to do it anyway given the ideals of the general OSS community?
Open-source projects often have random people "from the internet" working together with a great deal of individual autonomy (authority doesn't go down well when you are contributing for free). This ad-hoc style works well for open-source development, but it does make some kinds of code/system subversion a lot easier and we'd do well to keep that in mind.
Besides, I'm into open-source and security exactly because I don't want to rely on the goodwill of Apple, Google and Microsoft. ;)
OSS teams could spend the time and money running these tests, but this seems like a good area where governments and companies can step in to help.
pam_sss is easier to understand and its functionality expands upon it, but it was a redesign.
I admire their cleverness.
If it were me: I'd create an extension interface for completion libraries to accept third party plugins. I'd stop at putting in a third party stuff in by default. A sufficiently good plugin API for python-autocomplete shouldn't require it even to know about Kite.
That said, I don't think Kite should be disallowed. If they have a secret sauce that they think can empower completion plugins, give them an API to plugin to.
It's not in the spirit of open source to shut the door on proprietary solutions (IMO). Transparency should be paramount. Normally most Linux users opt-in to using proprietary/blob software/drivers one way or another anyway. Open source projects routinely maintain relationships with vendors (NVIDIA, Intel). It doesn't necessarily mean evil is at work.
Though, as someone who's struggled with the performance and reliability of completion tools, I don't know if I'd personally opt to outsource that functionality. I'd wait and see if our current tools get better.
Simply put; if some unethical corporation can hijack projects like this, then a much more malicious actor can as well. One that isn't as easy to detect, and does much more harm (like harvesting any code or input that looks like it could be private data such as credit cards numbers, SSNs, email and passwordish strings found near each other, etc.).
Extensions, plugins, and what have you are cool, but straying outside of the fairly monitored confines of you OS's controlled packages carries a risk.
I think there has to be some responsibility from projects that pack such plugins, to police their ecosystem. I can understand browsers having security layers, because they work exclusively with the biggest cesspool of them all (the internet), but stuff as basic as a text editor should not need something like that - if it does, something else has gone deeply wrong with the project.
@jlozano:
> Hi, folks -- Juan from Kite here, thank you for the feedback, we appreciate it.
[...]
> We have decided to leave the feature as opt-out since many users have found it useful. [...]
@abe33
> [...] I've been an employee at Kite for over half a year now and this plugin is now officially maintained by Kite. [...]
I think that the BDFL system work in open source because it's too easy to fork the project. The old BDFL just transferred the power to a new BDFL, but it was not so clear for the community. There is a fork now, so if the situation doesn't improve and the users are unhappy, the Kite team will be the BDFL of an empty project without users.
It should be made clear to the employees, management and investors of Kite that this is the sort of thing that marks you as someone willing to engage in unethical and underhanded behaviour. I wouldn't hire any such person into any team I manage, and I suspect quite a few other people wouldn't either. Actions have consequences. Especially unethical actions.
Here's a great explanation and strategy for applying to software development: https://www.theatlantic.com/technology/archive/2016/10/infor...
You could say for yourself "I personally don't believe in private property, so I don't see any objection with theft" but my hunch is that this argument wouldn't do much to calm the victim of your theft.
That proposed code of ethics in software seems like an attempt to create exactly such an agreement.
I have been saying it for a long time: we need better and more flexible software markets, and as developers, we should appreciate the work and time of fellow developers and as a matter of principle try to compensate them.
If you don't have time to deal with controversy, maybe don't take actions that will inevitably lead to it, eh?
I've never heard of such a thing before. Could someone explain how would they use machine learning for building coding tools ?
There are plenty of great use-cases for ML in building coding tools, but the shady manner in which Kite imposes itself on Atom users who have these plug-ins installed (which is a large portion of the user-base), leaves a seriously bad taste in your mouth.
Moreover, they could have trained their suggestions to actually be useful before throwing this out there as a feature set they thought people would want to use.
Plus then it'd make sense for people to open up their code, as a "local dictionary" of sorts that could be prioritized over generic suggestions. But at least then it would have had demonstrated value.
However, this requires reading people code that they upload to their servers. See their privacy policy here: https://kite.com/privacy.
I can see the distinction you're making, but, IMO, it's splitting hairs. Either tracking users activity, by the simple act of their use of your product, is morally acceptable, or it's not. To me, this seems like this exact same thing.
As Scott McNealy said, "You have no privacy. Get over it." I wish that wasn't true, but it would seem that the every government and company is hell bent on making it so.
How far do you want to take the sins-of-the-creator argument? Does everyone who writes or executes JS become an abettor to Brenden Eich's beliefs on same-sex marriage? How many Internet users are linked to U.S. war actions given DARPA's large role in creating the Internet?
An argument about whether Facebook and Google are evil is out of scope for this thread, but pretty much argued daily in various other daily threads. I think it's possible for people to like corporations and open source, yet find it disturbing when corporations violate community standards of open source.
They're often solving problems that affect large numbers of developers (initially, inside their company). And, because of the scale of a company like Facebook, they can afford to work full time on these projects.
They then open source them because there's no strategic value to keeping them private, and significant upside to building a community around them (and not undermining that).
I'd argue that some of the best open source projects come from large companies - due to the sheer number of developer hours they can throw at them. Small dev shops can't afford it, there are very few OSS foundations, and there just aren't that many people (relatively) that can devote enough time on the side to compete.
Have fun finding customers Kite...
It's at #17, a couple hours later, as the number of points is now 700+ and comments is in the 300s.
That's not a battle you can win with manual diligence.
https://atom.io/packages/autocomplete-python-jedi
https://github.com/brennv/autocomplete-python-jedi
https://github.com/autocomplete-python/autocomplete-python/i...
Their business model is to sell subscriptions to a premium version: https://kite.com/pro#business
Maybe I'm reading too much into the article but it feels like a weakness in open source is exposed when in fact the real problem would be if those applications were closed and you were stuck with crappy software if you didn't want to switch to a brand new tool. How's Skype doing lately?
Open source is vindicated by these scummy tactics, not undermined.
This is actually the most ridiculous part of the entire story.
It would be one thing if a corporation was stealing your code and taking over open source projects as part of a detailed plan to make money. That would still be objectionable, but at least there would be a clear motive for these voyeuristic activities.
Apparently, there is no master plan. They're just doing this because they want to be voyeurs and then maybe figure out how to make money off of that somehow later.
I can guarantee that there are other commercial companies watching how this plays out. If the changes are simply rolled back without any real repercussions, what other malevolent entities will take away from this incident is, "You can inject adware into your acquired FOSS applications, but do so discretely."
Let's be honest, the real problem here is that Kite's offer is still not good enough. The service they provide at the moment is not worth handing out all your code, unlike with services like GitHub; and their leadership is not seen as smart (or honest) enough to tolerate them taking stewardship of this or that established project - something that happens every day in the OSS world (loads of companies de-facto own this or that OSS project, from RedHat to Google to Ubuntu to IBM, steering as they see fit).
As soon as Kite (or anyone else) can provide a compelling service, people will go to great lengths to use their stuff and give them their code, without any dark pattern being required - ethics be damned.
In this case abe33 has the 75% of the commits, someone else 15% and the rest is a bunch of people with 1% or less.
With our server toolkit in a project I work on, we have 2 devs and 5 active users, with the devs being 2 of those, but we still manage to at least put every change in a PR, with a minimum review and comment time of 24 hours unless it's a security issue or major bug fix.
It's not hard, and it makes you actually justify your change and have talented second eyes point out minor bugs or edge cases to you.
Direct commits are only used for version bumps for the auto build/release thingy.
Please use your skills and spirit to fork both of the projects in question and put one of your known good actors in charge of each.
Either new project leaders are available and will immediately come forward to claim these projects as their own, or we need to change the subject to FLOSS sustainability.
This is not a question about sustainability as the project was well supported, feature-complete and saw regular releases.
Rather, this questions the consequences of giving companies permission to acquire community efforts. Doing so erodes trust in the Atom ecosystem. If the Atom team is OK with what Kite is doing, then I can expect other companies to follow along, and I'll have to be more cautious when installing plugins in general. It also destroys the incentive of contributing code to Atom plugins, because I don't want to contribute to giving companies control over basic features like a minimap. Why stop at the minimap? StackOverflow might as well hijack CTRL+F, or Heroku might subvert a git plugin.
If we let this become a trend, it will suck for everyone.
If other companies follow along then Atom's ecosystem-- and therefore, Atom-- will suffer as a result.
Regardless, there probably should be more caution when installing plugins.
Looking briefly at kite.com, it looks like they provide a potentially useful tool/service that is kind of an alternative to searching the web for documentation.
What I can't tell is whether what they did was make minimap incorporate results from Kite, so that you were essentially getting the Kite service (or a light version of it) bundled with minimap, or if they were putting ads for the Kite service in minimap, or if they were putting ads for other things in there.
I have no idea how that could have happened.
The fact that they have since slipped their stupid product into popular open source tools (probably because it isn't as well received as they thought it would be) is very similar to how some douchebags buy up popular browser extensions, then inject ads or do more nefarious things with them. Utterly distasteful.
I was under the impression that open-sourcing something literally means just making the code publicly available, and doesn't restrict what the owner chooses to do with the project in future.
That said, if I was already unlikely to trust Kite, I don't want to work with them at all given this behaviour. Betraying the trust of a significant portion of your potential customers is a sure way to be exed from an industry you never capitalized on. Congratulations, Kite.
Smith also said that most of the negative reaction
was due to confusion around what the tools actually
do. (Connor pointed out that it’s not possible to
review what Kite does, since it itself is not open
source.) Then he blew this reporter off. “I apologize
in advance that I can't answer any further questions,”
he wrote. “I need to focus on other parts of the
business, including continuing to improve the product
for our users, and conflict like this is always doubly
distracting.”
Love and avoiding negativity have become the bywords of unaccountability. To foment conflict and then not comment...WTF?! Is this 1997? Why don't you bring back the blink tag while you're at it!
Sigh.
Open source is great because it is generally free of this pushy and disingenuously non sense. Defection over cooperation leads to the detriment of the commons.
Edit: In case there is any confusion. The company is Kite. The VC-funded company is Kite. Kite. They are the ones this article is about. Kite.
> In Submissions
[...]
> If the original title begins with a number or number + gratuitous adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids."
> Otherwise please use the original title, unless it is misleading or linkbait.
In small obscure threads the mods sometimes don't notice and you can get away with small changes, like replacing "Photos of Encedalus" with "Photos of Encedalus, moon of Saturn". (But don't try "Amazing photos of Ecedalus will blow your mind!!!")
In big popular controversial thread almost always the title is reverted to the original title of the article, or the first sentence of the article when the tittle is too bad.
Maybe that seems like an over the top comment, and on any individual case, who knows? But I think it explains a good number of these sorts of scandals. Sometimes, the people who get on top are not "ambitious"... sometimes they are actual monsters.
Internet threads are like tag-team wrestling: the first guy drags a metal chair into the ring and then the second guy bashes a third guy over the head with it. Keep the chair out of the ring.
We detached this subthread from https://news.ycombinator.com/item?id=14837253 and marked it off-topic.
This is a phenomenon that studies show occurs at something like 2-3% in the population at large... but more common among CEO's. https://www.theguardian.com/technology/2017/mar/15/silicon-v... Interesting how you ban my argument because I don't have a credential (do you even know which logical fallacy that is?) but when an article in which experts take the same opinion, HN bans it with a different excuse.
Do you think that, just perhaps, this could have an effect on the amount of abuse of people by some companies, that we see day-to-day? Especially when it seems to go to an absurd point, as in this case?
It doesn't require a degree to detect people who are willing to treat those around without scruple, as long as they're not exposed. It's a fairly simple definition and these people disproportionately cause abuse... so censoring mention of this, or suggesting that a degree is needed to even contemplate recognizing this sort of bad actor, means you are acting to ensure people are ignorant about it, to their potential harm. I hope you never encounter one of these people close up, dang.
I'm not all that surprised that HN's despicable form of soft-censorship was used here... as I realize the statement I made was sort of controversial. But I'm looking forward to more people realizing how rotten you guys have become at censorship, at which point the interesting conversation will finally move elsewhere. Unfortunately, you can't keep doing it with such a heavy hand and have people not catch on, over the long term.
In fact, the level of censorship has gotten so high here (or I have finally noticed how bad it is) that I don't want to participate anymore. Maybe this is a marginal case, but I've realized you guys are just rotten overall. I don't really think it's ethical to participate in a form that's so dramatically manipulated, especially so often in the direction of SV companies. I'm going to kill my account, if that's possible.
Or, since it looks like HN is too arrogant implement this feature https://news.ycombinator.com/item?id=7841742 I'll just, you know, stop using it and monitor the potential security hole for the rest of my life.
IIRC the book was written by the scientific wing of the Polish Resistance movement during authoritarian occupations of the 20th Century. Apparently, many of the people involved in sourcing the data (and, oh yeah, who had secretly diagnosed many of the Nazi/Communist leaders as psychopaths) were killed, when the first edition of the book was discovered in progress. And that first manuscript was destroyed, but the lead author wrote it again -- not once, but two more times -- and ultimately, had to wait for the fall of Communism in order to get it out of Poland. It was finally translated and published during the Bush administration, by New York liberals.
I work for SUSE, not Red Hat, but I find it incredibly gross that being employed to work on free software is seen as a negative thing by the wider community. I spend every day working and thinking as a community member first, but because I was lucky enough to get a paycheck from a company to do that clearly I must be the enemy.
I can completely understand what the OpenBSD init system does. It's a lot harder to fully understand systemd. Plus, as a benefit of systemd, you get headlines like "Don't panic, but Linux's Systemd can be pwned via an evil DNS query"[1].
Red Hat doesn't care if Poettering is a brilliant genius or just a useful idiot. Instead, Red Hat loves systemd for a very different reason: lockin. Most Linux distributions are now utterly dependent on systemd, and by extension dependent on Red Hat.
systemd gives Red Hat far too much control over Linux. They were already the 800 pound gorilla, now they're almost invincible overlords. But go ahead, keep drinking the Kool-Aid.
[1] https://www.theregister.co.uk/2017/06/29/systemd_pwned_by_dn...
Personal swipes are not ok on HN, so would you please not post like this? Your comment would be much better without that last bit.
Red Hat conspiracy theories are quite interesting, but you might want to provide evidence for the claim that a unified init system somehow locks people into Red Hat. You do realise that you can have the exact same .service file work on RHEL just as well as it works on openSUSE or Debian? I will reiterate that I don't like systemd by any stretch of the imagination, but a unified init system makes life so much simpler for any user.
Rather than bashing systemd, the community should be working on alternatives. GNU Shepherd is a viable alternative, maybe we should work on that rather than sitting around complaining about what systemd is doing.
This was unnecessary.
Ads are not a solution IMHO, they are a big part of the problem.
I like open source as much as the next guy, but I'm pretty sure you have a peculiar definition of "everywhere".
(Or, perhaps "winning".)
The desktop/laptop you're using right now probably isn't open source, but much of the important software running on it is, and most of the computers it talks to are, and most of the other computers, obvious or hidden, in your life are too.
It would be great to see not only an assertion but an article that spells this out in some detail.
https://www.slideshare.net/blackducksoftware/2016-future-of-...
Like I said, in every place open source has won important battles. The future looks good, but let's not understate the challenges either.
https://www.influxdata.com/the-open-source-database-business...
open source is a forever struggling business model.
nice try, trump
And I think the bigger problem is that 3rd party plugins are becoming a thing. Now, it's all about plugins, installing dozens of plugins that are difficult to audit before hand. It's like blindly installing software from torrenting sites, but shinier because it has the Github stamp on it.