3 ms·
> I don't care if there's a buried flag that enables or disables this behaviour. I want a binary that doesn't have this capability in it at all. That's a rathe
by TheCoreh 2y ago
> I don't care if there's a buried flag that enables or disables this behaviour. I want a binary that doesn't have this capability in it at all.
That's a rather absurd way of approaching the threat model of data exfiltration on a terminal app.
By its very definition a terminal needs the ability to spawn unsandboxed processes and send/receive input from/to them, including processes that have network access. Even if the binary doesn't contain specific logic to do this it could invoke curl, or a variety of other binaries that do, either on purpose or accidentally. In addition, it links against AppKit, which includes NSURLRequest. Is that off-limits too?
If one's this allergic to OpenAI, that even an opt-in feature is a concern, they're better off using a firewall like Little Snitch, or blocking it at the DNS level.
Additionally, if you don't trust the developer with this, why would you trust a binary from them without this feature?
- bangaladore 2y agoAgreed. This issue thread makes it apparent why many open source developers give up.