10 ms·
iTerm 3.5.1 removes automatic OpenAI integration, requires opt-in
- coldtea 2y agoAmen! Speaking for apps but also of OSes, all that crap (AI integration, "Abobe Cloud" integration, and so on etc) should be not just opt-in, but also invisible once switched off (as opposed to some icon or banner nagging you about it in the UI, or ocassional popups asking you if you want to "enable it").
- ta988 2y agoI think this was not the case here they weren't nagging about anything. And it wasn't working unless you did set up a token. But it is always the right move to refactor code like that into optional plugins especially for enterprise users where you want to be sure nothing could leak if a user had their personal token.
- coldtea 2y agoFor iTerm yes, don't remember them nagging. But other apps and services (from Apple, Adobe, MS, etc) yes.
- sneak 2y agoIf you pirate Creative Cloud then use Little Snitch to ensure it never phones home, it never bugs you about the internet. Or so I heard from a friend.
- pier25 2y agoThe Adobe Cloud stuff is featured prominently all over their products even if you've disabled it in Adobe CC. It's disgusting.
- teruakohatu 2y agoI feel for the developers who work for free on an open source project but got a lot of criticism and hate thrown at them for introducing an optional feature. It’s not a feature I would use, but not using it was an simple as not entering an LLM API token.
- throw10920 2y agoIt was a hate bandwagon born out of sheer ignorance with no actual problem behind it.
- infecto 2y agoI mostly agree with this but I believe there was a valid discussion around corporate use of the product.
- rincebrain 2y agoIt's not, actually, solely that. If you're using a product that does not make API calls externally with your data previously in a corporate environment that has very strict controls, and they add a feature that is part of the base install package, even if opt-in, that allows it to do that, and they do not have something like Group Policy hooks to forcibly disable it from on high, then they will block the product globally until the functionality is more contained to something their compliance systems can prevent, be it via a group policy hook or blocking the install at all. Companies take "we might make an external call with your data" very seriously, and regardless of how much you trust the external entity, adding that in is rightfully seen as a very serious concern in some environments.
- throw10920 2y agoThis is not universal. I work in a company that uses many different products that (attempt to) make external API calls with extremely sensitive data, and none of these products are blocked from installation, because we block all their requests at the network level, instead. Yes, the corporate management is useful, but not critical, and the lack of it absolutely didn't justify the generated outrage.
- rincebrain 2y agoe: You changed this from "This is not true." to "This is not universal." in the time when I was writing this response, which is fine, but I wasn't claiming this is universally the case, I was claiming that in some environments, this is how the logic works. It's more or less the same outcome and rationale as when JetBrains had theirs in a "plugin" that you couldn't effectively block even if it was a noop because it required an API key. Sure, in an environment where external access is not necessary or can be easily allowlisted, that works fine. But on someone's interactive workstation, where they might need to access parts of the internet without getting explicit allowlisting of every web site, then it's a different set of tradeoffs, and not every company implements this the same way.
- swiftcoder 2y ago[flagged]
- lenerdenator 2y agoThey work on people without the resources to sustain operations without income. Sadly, the people that most need boycotting have effectively unlimited resources.
- throw10920 2y agoYou're wildly mistaken about what's going on - the feature was already opt-in. The feature literally didn't work unless you went into settings and manually entered an OpenAI key. That is literally the definition of "opt-in".
- ceejayoz 2y agoThe linked release notes appear to be appropriate tweaks; a blockable plugin and needing admin rights to enable are important adjustments for corporate environments. Just because I opt-in doesn't mean my company wants me to opt-in on their behalf.
- throw10920 2y agoYes, these are useful improvements for corporate management of software - but that's not what most of the outage was about. Also, if there wasn't a firewall that would have blocked iTerm from hitting the OpenAI APIs, then there wouldn't have been anything preventing users from just directly accessing it.
- kgeist 2y agoNo one stops me from opening chatgpt.com in the browser and pasting corporate stuff there. Could'nt admins just ban all access to chatgpt.com and openai.com when accessed from the corporate network? That would be a solution for all software, not just iTerm.
- 2y ago
- submeta 2y agoI just want to say thank you to the maintainers and developers of iTerm. It’s one of the tools I use most on my Mac, alongside Emacs, VS Code (heresy!), Obsidian, and Keyboard Maestro. So, thank you!
- svennidal 2y agoI don’t think I would enjoy my work if I didn’t have iTerm and Vim.
- deleted 2y ago[deleted]
- CraigJPerry 2y agoDoes iTerm give you anything over vanilla Terminal? To my eye there's a subtle delay, it must be in the order of 50-100ms in iTerm rendering that's not present in Terminal. Non-scientific measurement - i'm just going by perceived latency and comparing to something i know is a 50ms delay. That's for interactive use, startup time is slower for iTerm2 but i don't care about that because i basically never quit the terminal. In both iTerm2 (when i used it) and Terminal, i have a colourscheme enabled and a custom font - both of which i'm assuming have potential to slow things down.
- galleywest200 2y agoIf you are getting 100ms delay with iTerm then something may be wrong with your setup.
- CraigJPerry 2y agoI'm pretty sure everyone (at least on M1 macs) are getting that 50-100ms delay. There's a perceptible lag vs Terminal.app - in the grand scheme of things it means nothing. But once you notice it... you can't unsee it!
- 2y ago
- joshstrange 2y agoThis was discussed yesterday: https://news.ycombinator.com/item?id=40657890 https://news.ycombinator.com/item?id=40657890
- infecto 2y agoThis got way more hate then it deserved. I believe the real and valid discussion was how do corporate networks treat this. The outcome here makes a lot of sense in that regard. But all the negative hype around AI was too much.
- add-sub-mul-div 2y agoIt makes you realize what a bubble sites like this one are, if this AI stuff is so wildly unpopular among the developer/iTerm community as a whole.
- miki123211 2y agoIt's wildly unpopular among a different bubble of the developer community, mostly concentrated around Mastodon and the fediverse. Edit: It's worth noting that it's one of the most vocal and well-organized communities in the tech world, very prone to outrage, seeing the world in black-and-white, mob justice and piling on whatever is currently unpopular.
- phist_mcgee 2y agoNo it isn't, how dare you
- add-sub-mul-div 2y agoSo it's just axiomatic that people who disagree with you are coming from (any of) a list of fundamentally illegitimate motivations that you can think of? That makes life easier for you?
- lolinder 2y agoDo you have any evidence whatsoever that this AI stuff was unpopular among the wider community? These kinds of cases where open source maintainers cave to pressure are almost never the result of consensus among all users. It's usually the result of a small number of people brigading the issue tracker until the maintainer gives up and does it to shut them up. Unfortunately the result is often against the interests of the wider community.
- freedomben 2y agoI think it's important to recognize what actually changed here, because the headline makes it seem like a complete reversal, but it really isn't. It was always opt-in, but they made it more blockable/opt-in. The commit message is very useful here[1]. Excerpt: > This release adds some safety valves to eliminate the risk of private information leaving the terminal via the AI endpoints. While an API key and explicit user action were always needed to use AI features, some users asked for an impenetrable firewall for safety and regulatory purposes. [1]: https://iterm2.com/downloads.html https://iterm2.com/downloads.html
- frou_dh 2y agoReacting to the AI kerfuffle is all in a day's work for Mr. Nachman. He also fixed an unrelated bug I reported by the time I got up the next day. What a beast!
- nottorp 2y agoI'm curious. If you do opt-in, what does it send to OpenAI? Everything you type, including passwords, tokens, pasted keys, internal IP addresses etc?
- kernelsanderz 2y agoNo, there's a configurable system prompt which is: Return commands suitable for copy/pasting into \(shell) on \(uname). Do NOT include commentary NOR Markdown triple-backtick code blocks as your whole response will be copied into my terminal automatically. The script should do this: \(ai.prompt) And then you type your prompt in, and it returns the answer. And then you can choose to edit the command that gets returned or execute it directly. So essentially what you'd do if you were using the API directly, just more convenient.
- PreInternet01 2y ago> While an API key and explicit user action were always needed to use AI features, some users asked for an impenetrable firewall for safety and regulatory purposes Yes, some users are truly experts at driving Open Source developers to the point of burnout. I use iTerm2, in pretty sensitive environments, where 'OK, you didn't enable this feature', closely followed by 'not that we had Internet access here anyway, LOL' were (though-experimentally, as are all the 'concerns' of 'some users') eclipsed by 'hey, why is it a thing to enter sensitive data on command lines anyway -- should we not have ways to avoid that?'
- mbauman 2y agoIronically, so many of these users are those _with corporate support_. And demanding "IT" support from the open source project. Without consideration.
- PreInternet01 2y agoOh, sure. But for me, the lack of self-awareness in "my command line inputs include extremely sensitive identifiers all the time, and this is fine, if it weren't for your optional AI plugins" is especially grating. So, like, if I ever happen to execute 'history' in any session of yours that I manage to get access to, I hit the jackpot?
- gaws 2y ago> I use iTerm2, in pretty sensitive environments Like where?
- bearjaws 2y agoIs there a good local llm that can be used for helping with CLI commands e.g. "how do I kill all processes using port 9000" I haven't tried any, but if one exists it would be cool to see iterm use that LLM.
- kstrauser 2y agoI started playing with ollama + codellama recently and it’s been fun and easy to get running.
- eknkc 2y agoIt is weird that everyone has been bashing these features. What is all the negativity? I myself do not like pushing AI into everything but I think this is a great use case for LLMs. And it was already opt-in. Just tried "find all pdf files larger than 10MB" and it came up with "find . -name "*.pdf" -size +10M". Maybe this was easy but I don't know all arguments of all cli commands by heart and it works beautifully.
- wpm 2y agoTry it for macOS specific things and it chokes. It’ll hallucinate commands, send you shit for Linux, or give you stuff that worked 20 years ago. Find is an old, nearly universal command (good luck on any of the other GNU-utils commands that are 15 years newer than the binaries shipped in macOS). I have not found an LLM that knows any of that. When I need a find command, I open `man find` and read and learn.
- blinkingled 2y agoGot rid of it, switched to Kitty. I will miss the password manager from iTerm but that's ok - I can chill knowing AI won't upload my passwords someplace.
- camdenreslink 2y agoCouldn't you have just not opted-in to using this feature? It requires you entering your creds to work at all.
- kstrauser 2y agoNot one for reading before making decisions, are you.
- blinkingled 2y agoThat'd be you sir because the change log says and I quote - > This release adds some safety valves to eliminate the risk of private information leaving the terminal via the AI endpoints. If it's still not clear - I don't want my terminal to even have the possibility of leaking my data.
- kstrauser 2y agoIt didn’t before, either. This is theater to appease people who didn’t understand how the opt-in feature worked in the last version.
- soraminazuki 2y agoYou just omitted the very next sentence. > While an API key and explicit user action were always needed to use AI features, some users asked for an impenetrable firewall for safety and regulatory purposes.
- blinkingled 2y agoSo you are saying I can rely on API key being always required by AI overlords and there would be no point in the future where somehow things leak out without needing the key? You see if you don't meddle with my terminal data in the first place I would feel much better that I am in control of my data, and not reliant on. 3rd parties to accidentally drop guard and leak my data out.
- dathinab 2y agoIt's a grate example of people listening to their community (less grate for how they where treated). Anyway thanks for listening and changing things.
- kelsey98765431 2y agoHello! I really appreciate the sentiment you shared and just wanted to let you know that "grate" should be "great" in this context. I am assuming you didn't notice while using a speech to text tool or you are not a native english speaker. No hate, love to have you here, not trying to be the spelling police but your sentiment is very kind and appreciated so i thought i would let you know that a grate is a type of metal grill used mostly in filtering large masses from liquids, such as a drainage grate for flood waters. Enjoy your day and please keep sharing your positive outlook!
- joshstrange 2y agoI'll say the same thing I said [0] on yesterday's thread [1] about this: I didn't care for the feature (I have no issues with AI/LLMs but it just wasn't useful IMHO) but the backlash was ridiculous and embarrassing for everyone complaining about an opt-in feature. The comments on the GitLab ticket and here on HN were examples of some of the worst people (or people at their worst) in our industry. [0] https://news.ycombinator.com/item?id=40658290 https://news.ycombinator.com/item?id=40658290 [1] https://news.ycombinator.com/item?id=40657890 https://news.ycombinator.com/item?id=40657890
- spmurrayzzz 2y agoThe grandstanding definitely got in the way of otherwise legitimate feedback/concerns about the feature, as sadly tends to be the case in open source software when the mob descends.
- kelsey98765431 2y agoI actually am a large supporter of AI enhanced development workflows and I hated this feature. I use macos SOLELY for iterm2 because of tmux integration. I was very excited for this feature. You have to literally click the button. It's a command Y to bring up the modal, you start typing, then you have to remove hands from keyboard and mouse to the confirm button. What the hell? No command enter, no command shift enter, maybe I missed it or did it wrong but it is literally faster to type pipx run llm prompt than control y my command mouse and click. Just fix that one part and I would have been in heaven, also the pop up modal seems like a bad choice when it could have been directly integrated into the shell with the new overlay they introduced alongside the feature. Bad implementation, and PLEASE if anyone knows any foss alternative to iterm2 with tmux integration please dress me down on the fool i have been and steer me towards the path of the light again.
- dcow 2y agoIn the face of the Apple Intelligence macOS Sequoia announcement yesterday, anybody who is still trying to argue that moving the web request to a separate binary makes the product more secure or compliant is absolutely disingenuous and frankly malicious.
- ChrisArchitect 2y ago[dupe] More discussion: https://news.ycombinator.com/item?id=40657890 https://news.ycombinator.com/item?id=40657890
- jpitz 2y agoThe headline implies that "requires opt-in" is new to 3.5.1. that's not the case. The OpenAI integration always required opt in and an API token to function. Can we fix the headline?
- deleted 2y ago[deleted]
- soraminazuki 2y ago> iTerm 3.5.1 removes automatic OpenAI integration, requires opt-in This is an editorialized title. It was opt-in from the very beginning. Here's all the steps that was originally required: 1. Open settings, go to the General tab, click on the AI button. 2. Enter a paid API key 3. Close the settings 4. Click "Toolbelt" on the menu bar, and click on "Codecierge" 5. Click "Toolbelt" on the menu bar again, and click "Show toolbelt" 6. In the toolbelt, there's a textbox that you can type questions into. The textbox won't be shown if you didn't enter an API key. Only after submitting the question will the OpenAI integration be activated, and as I understand it, only for the current session. https://github.com/gnachman/iTerm2/blob/a3122c0100d8900a15cb46def59429849d7991e1/images/Onboarding/Onboarding-AI.png https://github.com/gnachman/iTerm2/blob/a3122c0100d8900a15cb... The initial implementation already took many many clicks to run. I literally had to do nothing to not use the feature and not once was I reminded about the feature after I chose to ignore it. Despite that, people were spreading rumors that entering an invalid API key would instantly cause iTerm to send all data to OpenAI. It's a straight up lie started by people who actually tested the feature and posted their findings on the GitLab thread about this feature. https://gitlab.com/gnachman/iterm2/-/issues/11475 https://gitlab.com/gnachman/iterm2/-/issues/11475 https://gitlab.com/gnachman/iterm2/-/issues/11470 https://gitlab.com/gnachman/iterm2/-/issues/11470 It gets worse, people in the GitLab thread were calling for dogpiles and fantasizing about inflicting violence on Mastodon. Towards the sole maintainer of a popular free and open source software developed in his spare time. https://web.archive.org/web/20240613165712/https://archive.is/https://tau-ceti.space/@ics/%2A https://web.archive.org/web/20240613165712/https://archive.i... Some of the things you see online... I have no words.
- classified 2y agoHad I still been an iTerm user by then, I would have uninstalled it immediately -- again. This is a terminal app and not a fucking coffee machine. Stop plugging endless "features" into it.