7 ms·
> Companies take "we might make an external call with your data" very seriously, and regardless of how much you trust the external entity, adding that in is rig
by fipar 2y ago
> Companies take "we might make an external call with your data" very seriously, and regardless of how much you trust the external entity, adding that in is rightfully seen as a very serious concern in some environments
Please don't take this as an attack to you, but one would think that environments where this is a very serious concern would also be environments that either buy software, or buy support contracts with open source developers, to make sure that what they install is compliant with their concerns.
- OskarS 2y agoTotally! People in these kinds of environments have no leg to stand on criticizing a free and open source project. If you don't like it, don't use it, but CERTAINLY do not demand of the developers that they honor your requests when you don't contribute to development.
- bunderbunder 2y agoMost employees in corporate environments do not get to set company policy. Most users of open source software do not have the skills necessary to modify said software. Complaining is the only recourse that most people have.
- ForHackernews 2y agoThey can take their fat corporate salaries and hire a therapist to listen to them complain. Leave the FLOSS maintainers alone.
- nerdponx 2y agoA lot of times the open-source software is used "unofficially", where IT/security turns a blind eye to it as long as it doesn't openly violate policies. And often the developer is not offering a support contract. They might even take umbrage at the idea of being bribed to make changes! A lot of open-source software usage in the workplace is the equivalent of bringing your own tools to a worksite, or bringing your own knife set to the kitchen. I obviously can't see the project's finances, but funding for tools like iTerm 2 can be heavily dependent on individual users acting as patrons, making monthly donations purely out of gratitude for bringing them joy and/or improving their personal work productivity.
- fipar 2y agoAll of what you said is true, but I just want to add a note that I mentioned a support contract with open source developers, not necessarily the authors of the open source software in question. It's like when a company buys a contract with an enterprise Linux distribution: the entity offering the contract didn't author the full stack (though I'd guess they have at least some kernel contributors on staff) but they can still support it in a way that keeps the compliance department of the buying company happy. Also, your kitchen knife set example is very relevant because, from personal experience, I know this happens but I also know problems (including accidents) resulting from using a personal knife set aren't attributed to the manufacturer of the knives but instead are treated exactly as if they happened using ones provided by the business that owns the kitchen.
- lolinder 2y agoNot to mention that an IT department that is truly concerned about this risk would just block the AI APIs at the network level and be done with it. A competent IT department with the concerns that OP is expressing would know that there's no way for them to keep track of all the software that is implementing AI features and would make the very easy change that would solve all of those concerns at once, not go on a witch hunt against iTerm2. This means that the only people that we're supposedly catering to here are incompetent IT departments, which doesn't seem worth the hassle for the maintainer or all of the other users. Or, more likely, this hypothetical IT department that cares enough to block iTerm2 but doesn't care enough to block on the network level is a fiction invented by people who just really hate seeing AI added to everything.