41 ms·
Wanted to give it a shot but got disappointed when I launched it and the following happened: - Outgoing request to googleapis.com - Outgoing request to segmen
by orastor 4y ago
Wanted to give it a shot but got disappointed when I launched it and the following happened:
- Outgoing request to googleapis.com
- Outgoing request to segment.io
- Outgoing request to sentry.io
- Requires sign up (only via Github, mind you)
I understand the first request is probably to get some dynamic configuration, even though I'd rather my terminal ship with static configuration. But then you have segment and sentry: not interested in sending telemetry from my terminal. Finally having user accounts for a terminal is such as strange concept.
I really wanted to like it, too. The screenshots look great
- systemvoltage 4y agoAlso, sorry if this is harsh but speaking my mind: why is important to mention what the underlying programming language is? It seems like misdirection and sleezy marketing. Products built with Rust are particularly susceptible to it.
- cors-fls 4y agoI cant use it either (mostly because it's Mac only and also because of the sign-in requirement), but at least they are transparent about it : https://docs.warp.dev/getting-started/getting-started-with-warp#logging-into-warp https://docs.warp.dev/getting-started/getting-started-with-w... https://docs.warp.dev/getting-started/privacy https://docs.warp.dev/getting-started/privacy
- tedivm 4y agoThat privacy policy is sketchy. It starts with this- > Our general philosophy is complete transparency and control of any data leaving your machine. This means that in general any data sharing is opt-in and under the control of the user, and you should be able to remove or export that data from our servers at any time. They then go on, further down the page, to say that this first paragraph is a complete lie- > However, for our beta phase, we do send telemetry by default and we do associate it with the logged in user because it makes it much easier to reach out and get feedback when something goes wrong.
- 130e13a 4y agois that even legal? or can you just write whatever you want into a privacy policy?
- doctor_eval 4y agoIt’s a policy - a set of rules. It’s only a problem if you say something and don’t do it. But even then, enforcement is most likely to come from interested parties like payment providers, who couldn’t generally care less as long as it’s not their data that’s compromised.
- alokedesai 4y agoI definitely understand the concerns. For our public beta, we do send telemetry and associate it with the logged in user because it makes it much easier to reach out and get feedback when something goes wrong. But we only track metadata, never console output. For an exhaustive list of events that we track, see here: https://docs.warp.dev/getting-started/privacy#exhaustive-telemetry-table https://docs.warp.dev/getting-started/privacy#exhaustive-tel.... Once we hit general availability, our plan is to make telemetry completely opt-in and anonymous.
- aaomidi 4y agoYou should do that now and just ask on startup. Honestly opting in by default is, at least in my opinion, not acceptable. People who would say no to that popup would not appreciate you randomly reaching out to them anyway.
- blktiger 4y agoI definitely will not try it if the analytics part are not optional, though I am glad to see you're documenting exactly what gets sent. I might consider trying it and even opt-in to the analytics once you make it optional.
- progbits 4y agoMaybe don't put this lie in the middle of the homepage? > Private & Secure > All cloud features are opt-in. Data is encrypted at rest.
- ASalazarMX 4y agoOr prefix it with a "Final product will be ..."
- jbverschoor 4y agoEncryption at rest is fun until the keys are leaked.
- runako 4y ago> we only track metadata, never console output It would be meaningful to indicate whether you track console input as well.
- asadlionpk 4y agoThis. I was excited to try it but I cannot use this on my work computer at all.
- pkaye 4y agoThat is the modern experience part.
- buro9 4y agoI'm not sure I'm ready to have SaaS models replace core utilities and tools locally. > Announcing Warp’s Series A: $17M to build a better terminal And just thinking about this... it's not clear to me what their moat will be as I suspect if there's a really compelling feature it will be available in OSS terminals quite quickly. Perhaps it's the product polish? But I'm not sure polish is what I want from a terminal, at least... it's not the top thing I want .
- heroHACK17 4y agoI wondered the same. Then I realized it sends out requests to googleapis, segment, and sentry. Imagine having data on every dev's terminal workflow? Ca$h.
- OOPMan 4y agoSounds more like a good way to get your product banned from a lot of workplaces.
- eterm 4y agoA lot of workplaces don't even bother to ban grammarly, which is literally a keylogger*, this won't even be on their radar. * I feel compelled to point out that Grammarly disagree with this definition because it doesn't send every single keystroke, just the ones in non-password text boxes.
- edgyquant 4y agoIs grammarly not correct here?
- bongobingo1 4y agoIf my plugin Passwordly, only sends the keystrokes inside password boxes, is or isn't that a key logger? It's only capturing a subset of your input, like Grammarly, so not a keylogger? If the argument is, it's not a keylogger because it's not logging sensitive information, well I type plenty of sensitive information into non-password textboxes.
- db48x 4y agoYea, I would never use a terminal that does any of that. If you want logging and crash reports, use Breakpad or something similar to send the crash report after a crash. No need to have telemetry reports going all the time.
- zhengt 4y agoIn addition to crashes, we also want to know things like: which features people are using so we can invest more in them, how much people are using the app so we know if we're doing in a good job. Totally understand if you're not comfortable with that though! It will be removed when Warp is out of the beta test.
- db48x 4y agoI know it sounds logical to you, but the further down that road you go the worse your software will be in the end. Make software with a coherent vision and you can pick and choose features based on how will they fit that vision without needing to spy on your users, or turn it into a popularity contest. Incidentally, you might be interested to know that in the last 8 hours my comment has gotten 25 upvotes; that’s a lot of lost customers.
- NateEag 4y ago> Incidentally, you might be interested to know that in the last 8 hours my comment has gotten 25 upvotes; that’s a lot of lost customers. No, that's a lot of people who upvoted your comment. I'd wager anyone who agrees with your perspective is unlikely to have been a Warp customer in the first place. (Speaking as one who tends towards your side of this discussion.)
- db48x 4y agoI don’t mean that my comment cost them customers, only that the upvotes on my comment measures the customers they had already lost by using pervasive telemetry.
- jacobsimon 4y agoCome on. You must realize VS Code and basically every website you use collects telemetry data, which is rarely for anything nefarious except product improvements. If GitHub/Microsoft had released this product, would you be raising the same concerns?
- daenney 4y agoWe can set the bar higher than “other people do this too so it’s fine”. > If GitHub/Microsoft had released this product, would you be raising the same concerns? Yes. It’s one of the reasons I use the open source build instead.
- fractalf 4y agoMe too. VSCodium FTW https://vscodium.com/ https://vscodium.com/
- exdsq 4y agoMaybe not but I'd trust Microsoft has a decent security and privacy team working on this more than a startup. What if they're logging the wrong stuff and my data is leaked?
- robertlagrant 4y agoGood point - Microsoft products practically created the modern security industry. They're experts.
- michaelmrose 4y agoDid you mean that old school Microsoft was so badly insecure that they created a massive opportunity for security professionals.
- robertlagrant 4y agoI did mean that, yes.
- qbasic_forever 4y agoWait, you _have_ to have a github account to even open this terminal? Yikes.
- Mister_Snuggles 4y agoI remember an iOS email client many years ago that required a Dropbox login for some reason. It made no sense that an email client would require me to log in to a cloud file storage/syncing service - in my mind these two things are completely unrelated. That email client ended up disappearing. I expect that a terminal program which requires a login to a completely unrelated service will end up meeting the same fate as that email client did.
- runlevel1 4y ago> an iOS email client many years ago that required a Dropbox login for some reason. IIRC, that was Mailbox. Dropbox bought them a month after launch and then, sadly, killed it off two years later.[^1] [1]: https://www.theverge.com/2015/12/8/9873268/why-dropbox-mailbox-shutdown https://www.theverge.com/2015/12/8/9873268/why-dropbox-mailb...
- Mister_Snuggles 4y agoYes, I believe that's the one. Thanks! I couldn't remember it, but with a generic name like Mailbox that's not a surprise.
- rubyist5eva 4y agoyeah I just block all of those domains in my dns reverse proxy now, idgaf
- jnovek 4y agoAlso: security? I expect my terminal to be a much more secure environment than my web browser. When an application starts communicating with the internet, I have no choice but to treat it with the same level of scrutiny as my browser. Even making telemetry opt-in means that it has the capability to send information to the internet that I don’t know about, which means that I have to treat it like an application that can do that. Honestly, this freaks me out. It’s an angle I’ve never considered before. Now I need to make sure my current terminal emulator (kitty) isn’t sending information to the internet without my permission.
- warent 4y agoAgree, this is a pretty bad deal breaker for me. Big business people doing short-sighted big business things, salivating at cramming a product full of telemetry. All without transparency around it? In a terminal of all things?? Indescribably off-putting and catastrophically damages my trust in the product and the CEO. EDIT: To be fair there is some transparency in the original post. I was looking through the landing page for it (where it is not mentioned). Also, imho it should still be opt-in even for beta. Not everyone is going to read the wall of text to parse out the buried note on telemetry
- ushakov 4y agoor they actually listen to our feedback, remove forced telemetry, remove sign-in in the next release, then i'd be more happy to give their product another chance although no guarantee they'll not turn evil at some point in the future...
- encryptluks2 4y agoIf they start out evil, then don't expect them to change.
- nicce 4y agoUsually the practice in these scenarios is to try out all possible ways to make out money and then go a little backwards once the public outcry is big enough. At some point you find the most profitable balance situation, before you have expelled all customers.
- baby 4y agoI knew this was too good to be true :( I feel bad for the engineers who worked on this, as this is really awesome but probably will not find market fit
- faldore 4y ago1) installed it 2) login required 3) uninstalled it try again
- jbverschoor 4y agoThank you!
- stormbrew 4y agoIt's just.. an incredibly bad look to have this be the top comment on a post about this while the website claims that "cloud stuff" is opt-in. It's more essential to be honest about this during the beta period than after, so "oh it will be opt in" is a cold comfort, alongside the approximately never-true "we'll open source it some day." Not touching this with a ten foot pole. Not for something as essential to my day to day work as a terminal.
- spiderice 4y agoFurther down in the thread, they claim that Warp is nearly as fast as Alacritty. Then a user points out that it isn't even close and their response is basically, yeah, we know that. We want to fix it. How does a company expect lying on HN to work out well for them? I'm sure they're doing their best, and are excited about their launch. But they are coming off as so shady because they're trying to fool people.
- zachlloyd 4y agoWe tried to be really upfront in the privacy policy: https://www.warp.dev/privacy https://www.warp.dev/privacy Opt-in refers to anything that sends any contents of a terminal session to our servers (as opposed to telemetry which is metadata and never contains any terminal input or output). But we hear the feedback and appreciate it.
- RL_Quine 4y agoThat doesn't fit people's normal expectations. You're being intentionally deceptive.
- good_good 4y ago
- oneepic 4y agoI was confused by your wording, but I think this section of the link is very relevant: >When Warp comes out of beta, telemetry will be opt-in and anonymous. >But for our beta phase, we do send telemetry by default and we do associate it with the logged in user because it makes it much easier to reach out and get feedback when something goes wrong.
- traceroute66 4y ago> Wanted to give it a shot but got disappointed when I launched it and the following happened Yup, well, that's what happens when you take money from VCs or other third party investors, you need to monetise / demonstrate ROI / need numbers for your investor slide-decks. I'll stick to my old-fashioned spyware free terminal thanks very much. Why overcomplicate things that don't need to be complicated.
- doctor_eval 4y agoYep. In my last project one of the key USPs was privacy. The product vision was built around it and it was fundamental to our positioning in the market. But I made the mistake of letting investors share executive control of the company, and pop there goes the pro-privacy policy. In defence of founders everywhere, however, I will say that the investors didn’t just say “no”. They strung me along for almost a year, insisting we would be meeting about it, recording decisions where we apparently agreed, even pointing out those decisions while they flagrantly violated them in practice. So who knows what’s happened here. A lot of the messaging sounds like what happened to me. “Yes we know privacy is important and in the future mumble mumble.”
- Pr0ject217 4y agoJust curious, what tools do you prefer to use to identify network requests from recently installed applications such as this?
- asadlionpk 4y agoI also would like to know this.
- battles 4y agoOn the mac there's Little Snitch.
- okamiueru 4y agoOn Linux there is OpenSnitch. A bit rough around the edges, but does what it needs to do well.
- Pr0ject217 4y agoThank you.
- _jal 4y agoI can't imagine using a Mac without Little Snitch: https://obdev.at/products/littlesnitch https://obdev.at/products/littlesnitch Among other things, it is disturbing how chatty a lot of things are. (Did you know Apple Mail keeps track of which account you email different people with and wants to send that to configuration.apple.com, even if you have carefully disabled everything Icloud related?) There's a similar tool for Linux, but I usually keep a networkless VM around for playing with potentially sketchy things.
- jcranberry 4y agoHow do you check which requests its making? Do you just use tcpdump or something?
- Fnoord 4y agoYou could use a layer 7 firewall for this purpose. I use Little Snitch on macOS and Opensnitch on Linux. Given this application is macOS only right now, I would bet OP used LS since its popular on macOS.
- jcranberry 4y agoThank you. Im dual booting osx and linux right now so those will both come in handy.
- wildmanx 4y ago> I really wanted to like it, too. The screenshots look great Agreed! Let's just wait for a FOSS alternative to pop up that has a few similar fundamental features. Don't need the cloud-multi-user-account-based stuff.
- privacyonsec 4y agowell, they gotta pay back those $17M to investors !
- ZoomZoomZoom 4y ago> Warp is a blazingly fast, rust-based terminal reimagined from the ground up to work like a modern app. Well, at least they didn't lie. As of my personal position: I want less products in my computing environments, not more. I hope more people would ponder on possible ramifications of going in the opposite direction.
- gxt 4y agoWe exists, but it's complicated. A complete solution has more edge cases than what "stacks" have tools to work with. My gut feeling is that the contemporary approach to solving information problems is crazy nonsense. I'm working on something to prove myself wrong. If I'm not I'll make something available for a fee
- resonious 4y agoI'm not sure I care very much about which piece of software is a "product" or not (I have no qualms with devs asking for money), but I definitely agree that calling a piece of software "modern" actually carries negative connotations nowadays. I think most would agree that apps developed within the last 4 years are often more resource-intensive and slower than the equivalents from 15+ years ago. Warp looks really cool as a tool and I intend to try it as soon as it's available on Linux, but it was pretty bold of them to include outgoing network requests by default before presenting directly to HN. I saw the post about "everything is opt in, where 'everything' means 'sending terminal contents'" - as if people read privacy policies before trying out a new dev tool.
- bogota 4y agoYeah. From a developer standpoint my terminal is the one sacred thing i have still. Im unfortunately not using something that is going to randomly break or make external calls every time I open it. Looks cool but I will never even give this a try.
- jnovek 4y agoI nearly also used the word “sacred” in my comment above. I gave up MacOS for Linux because I felt like Apple wasn’t letting me operate my own computer anymore. Even Ubuntu has eroded the transparency and control I have over my computer over the last decade, at least that’s my perception. I feel like the only part of my computer that I understand anymore is what happens in the terminal. I don’t categorically hate having magic happen on some remote server that makes computing easier for me in some way… but I really need to have a space that I understand and control and — over time — that place has slowly been compressed into the command line.
- deleted 4y ago[deleted]
- mrtweetyhack 4y ago
- deleted 4y ago[deleted]
- jedisct1 4y agoYes, but it's written in Rust.
- ilovecaching 4y agoIt’s a closed source paid spyware development tool that you rely on every day to get work done, what’s not to love about this idea?
- BarbaPeru 4y agoYep, I can pay money for a piece of software so important for my workflow, but no telemetry, no login and other stupid stuff even in opt-in/opt-out fashion.
- drcongo 4y agoI just downloaded it, but then thankfully read this comment before running it. No way do I want my terminal sending stuff to Google.
- drdaeman 4y agoExactly the same, clicked "comments" as I was downloading it, saw the first comment, deleted the installer. I'd be supportive of "report issue" buttons (I'd use them, yes), and occasional "Hey, you've used this app for a week/two/month, may we send some telemetry? We need it to better understand how the app is used. Here's the data, is it OK to upload it?" prompts. Yes, as long as I don't see anything sensitive in the payload - it sure is okay, you respect me and I respect you (with bonus points for politely asking); and I'll be sure to reaching out if I'd see anything sensitive. Phoning home from the get-go for anything but an anonymous update check and requiring some account is a hard "no".
- supramouse 4y agoyeah, hard pass edit: no windows or linux support ???
- deleted 4y ago[deleted]
- epolanski 4y ago> I really wanted to like it, too. The screenshots look great My thoughts exactly. I don't use potential keyloggers on my browser (think grammarly or similar), I'm not going to install a terminal making requests or getting my data as I use it.
- lprd 4y agoYup, that's an immediate deal-breaker for me. Shame because this looks really interesting :/
- krick 4y agoTo be honest, for terminal not being open-source is enough for me. I'm not Stallman, but, terminal, seriously…
- wallfacer120 4y agoWhat is your tool of choice for intercepting outgoing requests like this?
- hestefisk 4y agoNot touching it with a 10-foot pole.
- SLWW 4y agoThey have a "layman's terms" section where it states that for now, in beta, telemetry is going to be on regardless https://www.warp.dev/privacy https://www.warp.dev/privacy They promise that after beta you won't need Github, and telemetry will be optional. Though imo this is just as easy to read and understand: https://assets-global.website-files.com/60352b1db5736ada4741b380/60b7f8d410ec2b9fc2a45af9_privacy-notice.pdf https://assets-global.website-files.com/60352b1db5736ada4741...
- kovac 4y agoThere's no reason for a terminal emulator to connect to the internet or collect telemetry opt-in or not. None whatsoever.
- zachlloyd 4y agoAs the author of the post, I think this is totally reasonable feedback and something we have discussed quite a bit on the team. The general stance on telemetry that we have is that a) we are just starting and it's really helpful to see which of our product ideas are useful to our users (e.g. does anyone use AI Command Search? Should we continue to invest in it) b) we tried to be very explicit about what we are and are not sending - it is only metadata and never command input or output (you can see the full list of events we track here: https://docs.warp.dev/getting-started/privacy#exhaustive-telemetry-table https://docs.warp.dev/getting-started/privacy#exhaustive-tel... c) if you aren't comfortable with telemetry, then please don't use the product just yet - we will make telemetry opt-in when we have a large enough sample size that we can be confident extrapolating what's going on For googleapis - this is for login. We use firebase as our auth provider. For segment - this is for temeletry, as you point out. For sentry - this is for crash reporting. As for why we have accounts, it's because we are starting to add features for teams and it's important in that context that there is some type of identity associated with the user. But like I said at the start - the feedback is totally reasonable and we are trying to figure out how to balance concerns here while still being in a good place to iterate on and improve the product.
- btown 4y agoAs a Sentry user (for a web app where people are not placing sensitive IP!) - it is INCREDIBLY easy for it to be configured to suck up massive amounts of PII and sensitive IP in the context of its crash reports. If I am running `kubectl create secret --from-literal` and something crashes, can you guarantee that the contents of that command will not be loaded into Sentry? Breaching this guarantee would be as simple as having some code somewhere in your stack (including a parsing library) format an Error with the command contents, miles away from anything Sentry-specific. I'd be much more trustful of your product (and indeed, I do desperately need a better terminal!) if you were to: - make Sentry crash reporting opt-in (or at the very least have a popup that occurs with the content of what will be sent to Sentry before anything is sent to Sentry), AND - clarify in your event telemetry documentation, and explicitly in your Privacy Policy, that ONLY the event ID/name, timing, and the user ID are sent to Segment, nothing else. But I simply cannot use a terminal where my keystrokes might be logged to anyone's Sentry or Segment account - even if it were our company's own Sentry account. The risk of partner-entrusted credential leakage into an insecure environment is simply too high.
- rschachte 4y agoUI looks great to me too. Thanks for the comment, I'll skip on downloading this though because of the outgoing requests
- baggiponte 4y agoThat’s concerning - I am also wondering if iTerm too sends this data…
- hoechst 4y agolol
- sofixa 4y agoJust FYI, sentry is error capturing and reporting tool, not "telemetry". It could be potentially abused to collect "telemetry", but there are far better tools for that so it'd make little sense IMHO. I've used it extensively for error management in a previous job and it worked very well, correlating with env, release, etc. and it was great ( it was the self-hosted version, but still). Not affiliated in any way, just a happy "customer" ( never paid so not really a customer).
- w1nk 4y agoAs a user of sentry technically, you're also aware of how difficult it is to keep user information out of those errors and stacktraces. Just paths are enough to start leaking information about you and your system that just shouldn't leak from your terminal to the internet.