8 ms·
I looked into the issue tracker and gosh, its getting so toxic there. https://gitlab.com/gnachman/iterm2/-/issues/11470 https://gitlab.com/gnachman/iterm2/-/is
by eriri 2y ago
I looked into the issue tracker and gosh, its getting so toxic there.
https://gitlab.com/gnachman/iterm2/-/issues/11470 https://gitlab.com/gnachman/iterm2/-/issues/11470
- bloopernova 2y agoFrom reading that issue, it sounds like some people are worried about compliance with security policies (whether personal or corporate) I'm very happy with iTerm2, its features are useful to me, but I can't see myself using the AI chat feature when I have copilot in VS code. I could see a use case for people unfamiliar with certain commands, something like "please sort this output by the first then fourth columns". But if I'm writing a script or small Python utility, then VS code will be where I do it. For compliance though, the AI integration could be a separate binary that you can access via the command line, although as pointed out in a reply, that's the same as a code path that isn't used. However, it is easier to block a separate binary, so maybe that's the thinking there? Instead, maybe the people who have an issue with this feature would be happy with an optional setting "assign this keyboard shortcut to the AI binary". Or a feature flag that says "do not access the network under any circumstances".
- nulld3v 2y agoI get the compliance perspective but it feels stupid to bring it up now, especially since iTerm2 has already had integrated network features for a long time. Agreed on the "do not access the network" feature flag though, every program should have that. Or really it should just be a toggle in the OS on a per-app basis.
- nomel 2y ago> Agreed on the "do not access the network" feature flag though, every program should have that. I would claim that is not the responsibility of the app. That should be the sandbox/OS responsibility, to make sure it's actually true, rather than an app providing a checkbox that potentially does nothing.
- derefr 2y agoI dunno about "do not access the network" — sounds like the wrong granularity. I want an app like e.g. Evernote or Calendly, to sync to its own cloud backend (or better, to my configured server.) I just don't want them sending my data off anywhere else. Annoyingly though, in that scenario, the desire to not have my data processed by third-party vendor APIs, would need to apply to both the client (which I can control through technical measures, e.g. LittleSnitch) and to the cloud backend it talks to (which I fundamentally cannot control.) So such a config flag can't be purely a technical measure, but also has to be something communicated to the backend, ala "Do Not Track." And unlike HTTP, most of the other application-layer protocols we use today don't have anything like a standardized way to communicate "user-imposed constraints on how they want you to process their request, while still giving the same result".
- 9dev 2y agoTechnical measures are the wrong lever to this problem. I can always send your precious data to my backend and proxy it to whatever third party vendor from there, and there’s nothing you can do to prevent that. Instead, a legal solution like the GDPR offers better means of protection. The way the fines are structured, vendors have a clear incentive to not exfiltrate your data in the first place.
- derefr 2y ago> Instead, a legal solution like the GDPR offers better means of protection. I mean, yes, that was my point — that there'd need to be some legal thing like GDPR. But that thing would very likely need some kind of explicit user-driven policy choice (ala how websites are now forced to ask for a user-driven cookie-handling policy.) To comply with such a law, it would be likely that every application-layer protocol that could in theory involve a backend that relies on the use of third-party ML vendors, would have to be modified to somehow carry that policy choice along with requests. It'd be a huge boondoggle.
- 20after4 2y agoGiven that the "do not track" header is almost universally disregarded, I'm not sure what value we'd gain from implementing more instances of disregarded user preferences.
- adamomada 2y agoI use little snitch to get this system-wide feature and imho it’s absolutely worth the money for insight on how your apps communicate
- oreilles 2y ago> From reading that issue, it sounds like people are worried about compliance with security policies (whether personal or corporate) This is incredibly stupid. If they don't trust iTerm to respect their privacy, why were they using it in the first place? For all they know it very well could have been sharing all their data without telling them from the very beginning. Alas, the tool is open source they could just audit instead of yelling at clouds but hey.
- meatmanek 2y agoThey trusted it before; now things have changed, and they have lost that trust. Previously there was no reason to believe that iTerm would send your terminal input or output to a 3rd party.
- oreilles 2y agoiTerm still do not send anything to a third party, you do, by willingfully using a feature that explicitely states so. If you have concern that iTerm would do something behind your back, then you shouldn't be using it in the first place.
- wrs 2y agoSure there was. If you cmd-click on an URL in iTerm2, it launches the browser, thus sending your output to a third party.
- iLoveOncall 2y ago> For compliance though, the AI integration should probably be a separate binary that you can access via the command line. Maybe with an optional setting "assign this keyboard shortcut to the AI binary". There's no difference at all between a code path that's never called and another binary that's never called. You are simply wrong for even trying to argue about privacy concerns when it is a feature that is entirely off by default (and also doesn't send anything that you don't enter in the box dedicated to it). It makes absolutely 0 sense to have any concern about this but not have concerns about the capability of the terminal to perform any other call over the network.
- bloopernova 2y agoI'm not trying to argue any position. I'm just trying to understand what misgivings some people appear to have. The way I phrased it might be why you're misunderstanding me. I'll try to clean it up.
- CameronBanga 2y agoI think the issue that people here are expressing are not necessarily their personal concerns, but concerns that their employers may now have if they learn about the feature.
- iLoveOncall 2y agoConcerns that are still 100% unfounded. If they're worried about your terminal calling OpenAI servers if you ask it to call OpenAI servers, why are they not worried about all the many more damaging things you can do with your terminal when you ask it to? Guess what? My terminal has always been able to call ChatGPT, even before this curl wrapper was released :O
- vundercind 2y agoAlmost. The never-called code path may nonetheless reside in memory under control of a process with certain privileges, which does make it a tad less secure than a binary resting on disk. It’s also far more likely to be invoked by mistake (a bug) and you can’t totally remove it or take away its execute flag to drop that risk to basically zero.
- derefr 2y ago> From reading that issue, it sounds like some people are worried about compliance with security policies (whether personal or corporate) The right thing to do, then, would be for the OS to have a group policy setting like: "Disable application features that rely on processing documents, data, or application state using remote third-party inference APIs." ...and then for apps to look for it and respect it; and for corporations concerned about this to set it as part of MDM. Then apps could offer these features as available by default, but also forcibly disabled when relevant.
- kstrauser 2y agoEh. I was the CISO at a HIPAA-covered healthcare company, and I have no problem with the way iTerm handles this. Nothing gets sent from your terminal, other than what you type into the separate AI prompt window. You have to manually enter your ChatGPT key. You have to manually choose to open the AI prompt. I see this as not substantially different from a programmer having a browser tab open where they could type questions and get answers, just more convenient. If I didn't want my coworkers doing that at all, I'd push out a device policy adding a firewall block for OpenAI's API servers and then not worry about it at all.
- dcow 2y agoIf you can use vscode in a compliance environment then you can use this new release of iterm2.
- hiatus 2y agoWith gems like this: > +1 to the people who'd like to donate 50$ for a version which does not send my input anywhere. Okay, previously I never donated the project. But use the iTerm2 for ~10yrs and would like to continue. So, this person has been using iTerm2 for 10 years without paying, and would only consider donating if this feature is removed?
- tedunangst 2y agoInteresting incentive system being created here. You're going to give me $50 to remove an AI feature if I add one to another project?
- dmix 2y ago> a version which does not send my input anywhere clearly hyperbole Even when it's turn on you have to manually engage it Rage posters always gloss over details in their rush to tell the world how mad they are
- phillipcarter 2y agoHah! Just another turn of the wheel, this time with AI. Lots of entitled developers out there who sure do have a lot of time on their hands to complain.
- eriri 2y agoEven more dramatic: > it is a very unwelcome statement of disagreeable values. Adding OpenAI integration, as optional as it is here, makes it clear that you don't stand against OpenAI and the whole "AI" industry. Imagine the crime of maintaining a free and open source terminal emulator in one's spare time... how hideous.
- sixhobbits 2y agoIt's hard to believe that some of these comments aren't trolling. Do they also consider the fact that iterm can call out to tools like `wget` and `curl` a privacy risk and slippery slope that might share their data if used wrong?
- mixmastamyk 2y agoChoosing a network capable download command is different than an option to send all commands to the cloud for processing. And we know defaults get changed at times, sometimes on purpose (hi facebook!). We also have decades of experience and culture around how to use network commands properly, especially for FLOSS tools. Considering that newbies will be attracted to these cloud tools, the risk of information leakage sounds a lot higher in the second instance.
- kstrauser 2y ago> an option to send all commands to the cloud for processing. iTerm doesn't have that. It has a separate pop-up window where you can type questions and get answers. If it had a feature like you describe, I'd be there with my pitchfork. Thankfully, it doesn't.
- mixmastamyk 2y agoOk, however there are several new-gen terms headlining this kind of feature. We're far into frog-boiling territory, who knows where it will lead.
- JasserInicide 2y agoComplete whataboutism. If I fat finger bad data, that's expressly my fault. This is a case where I now need to worry about tools I use that never sent my usage data somewhere now sending it somewhere.
- wrs 2y agoWhy do you need to worry about that? That’s not what this feature does.
- mrozbarry 2y agoI think this issue is actually two issues 1. A terminal shouldn't be able to ask some resource on the internet what to type and auto-execute it. 2. AI fear/fatigue/??? I think point 1 is reasonable to an extent, but it should be taken in context. iTerm2 is a free app, and as far as I can tell, not even remotely required on any mac platform, since there is technically a default dumb terminal, which can be customized. I think the context issue is from the video demos I've seen, nothing directly types into your terminal, it's up to the user to review/copy/paste the generated code snippet. The underlying tech has been in iTerm for a while, from the best I can see. Auto-fill also enables things like the 1password integration, and anyone can open a chatgpt client and copy/paste shell code from there in the same way the iTerm2 integration works. I understand point 2, I have never cared for any AI hype, it has near-zero interest for me, and doesn't affect my work. Almost every editor has some capacity to ask the internet for data and paste it in, from AI or otherwise, and no one is really sounding a major alarm bell around that. You could argue there is a big push for these integrations to train models, but even that requires a key.
- lxgr 2y ago> 1. A terminal shouldn't be able to ask some resource on the internet what to type and auto-execute it. Every Linux shell can do that, regardless of your terminal emulator, and arguably that's by design: curl https://givemesomecoolshellcommands.com | sh What iTerm can do is essentially just some GUI sugar around that capability. If you don't like it, just don't do it :)
- whimsicalism 2y agoNietzsche wrote about this sort of stuff, we're currently in an AI ressentiment period.
- octernion 2y agoi'm sure 95% of the people are just trolling - they can't be that dense about what the change actually is as developers. just silliness.
- eriri 2y agoOne of the participants is calling for a "dogpile" on Mastodon and I'm not even joking.