4 ms·
My terminal contents are not able to be sent out. We do have Siri disabled as part of our MDM profile, and legal feels that our protections are adequate for the
by upon_drumhead 2y ago
My terminal contents are not able to be sent out. We do have Siri disabled as part of our MDM profile, and legal feels that our protections are adequate for the os layer. We're extremely limited to what software we can install, and we have os level protections on what endpoints our devices can even communicate with on the wider internet.
Yes, it's overkill, but legal's stance is that anything that can possibly talk to a third party AI service is forbidden regardless of the other technical solutions in place preventing information leakage.
FWIW, anything that has telemetry to third parties (crash reports, usage stats) are also forbidden, with extremely limited exceptions that legal has approved.
- rkwasny 2y agoEverything you type into spotlight search is send to apple
- smrtinsert 2y agoThis must be the fastest legal team in the industry
- saagarjha 2y agoHow does legal check that the software that they’re using doesn’t send those out?
- upon_drumhead 2y agoLegal focuses on the software license terms, terms of usage, privacy policy, and what not. Every time that's updated, use of the software is frozen until reviewed again. Technical means, we monitor for every outbound connection attempt and DNS request and can trace it back fairly easily to a particular application. We've certainly caught software that was reporting back when it's stated otherwise in the privacy policy or website. Legal does feel better when there's an entity they can seek damages from in the event that a piece of software turned out to be malicious. They're less inclined to give free software the same benefit of the doubt.
- lurkersince2013 2y ago| "that anything that can possibly talk to a third party AI service is forbidden" So then your company just needs to block AI at the network level then? Within a few keystrokes you could already very easily communicate with third party AI services via terminal prior to 3.5 (curl... etc) This is a very weird over-reaction considering what iTerm2 and shells in general are already capable of.
- upon_drumhead 2y agoWe do block on the network level. You can argue that it's an over-reaction, but legal does see a difference between something embedded into a binary purpose built to transmit data to a third party and a general purpose tool that could be mis-used.
- lurkersince2013 2y agoI really just don't understand the outrage here, it's a terminal emulator, communication with external services has always been possible and has always been very easy. And iTerm2 itself has allowed for custom python scripts to be loaded for a long time [https://iterm2.com/python-api/ https://iterm2.com/python-api/] easily modifying the behavior (and also allowing outbound connections wherever...) If you work in a sensitive environment and outbound connections to OpenAI are already blocked on the network level (or even better iTerm is only able to communicate to whitelisted hosts, then problem solved... there really is no issue here for people to be so worked up about). Sounds like legal really needs to understand these tools better.
- hombre_fatal 2y agoYou can trot this hypothetical reactionary skittish legal team all the way out so that they are increasingly ridiculous, but at some point you're going to have to make the argument for why they should dictate the software made for the rest of us.
- upon_drumhead 2y agoI have done nothing of the sort. All I stated was what happened at my company. The developers are free to do what they wish and I haven't asked them to change in any forum, ticket, or issue tracker.