30 ms·
Performance and telemetry analysis of Trae IDE, ByteDance's VSCode fork
Hi HN,
I was evaluating IDEs for a personal project and decided to test Trae, ByteDance's fork of VSCode. I immediately noticed some significant performance and privacy issues that I felt were worth sharing. I've written up a full analysis with screenshots, network logs, and data payloads in the linked post.
Here are the key findings:
1. Extreme Resource Consumption:
Out of the box, Trae used 6.3x more RAM (~5.7 GB) and spawned 3.7x more processes (33 total) than a standard VSCode setup with the same project open. The team has since made improvements, but it's still significantly heavier.
2. Telemetry Opt-Out Doesn't Work (It Makes It Worse):
I found Trae was constantly sending data to ByteDance servers (byteoversea.com). I went into the settings and disabled all telemetry. To my surprise, this didn't stop the traffic. In fact, it increased the frequency of batch data collection. The telemetry "off" switch appears to be purely cosmetic.
3. What's Being Sent:
Even with telemetry "disabled," Trae sends detailed payloads including:
Hardware specs (CPU, memory, etc.)
Persistent user, device, and machine IDs
OS version, app language, user name
Granular usage data like time-on-ide, window focus state, and active file types.
4. Community Censorship:
When I tried to discuss these findings on their official Discord, my posts were deleted and my account was muted for 7 days. It seems words like "track" trigger an automated gag rule, which prevents any real discussion about privacy.
I believe developers should be aware of this behavior. The combination of resource drain, non-functional privacy settings, and censorship of technical feedback is a major red flag. The full, detailed analysis with all the evidence (process lists, Fiddler captures, JSON payloads, and screenshots of the Discord moderation) is available at the link. Happy to answer any questions.
- segfault22 1y agoHi HN, I was evaluating IDEs for a personal project and decided to test Trae, ByteDance's fork of VSCode. I immediately noticed some significant performance and privacy issues that I felt were worth sharing. I've written up a full analysis with screenshots, network logs, and data payloads in the linked post. Here are the key findings: 1. Extreme Resource Consumption: Out of the box, Trae used 6.3x more RAM (~5.7 GB) and spawned 3.7x more processes (33 total) than a standard VSCode setup with the same project open. The team has since made improvements, but it's still significantly heavier. 2. Telemetry Opt-Out Doesn't Work (It Makes It Worse): I found Trae was constantly sending data to ByteDance servers (byteoversea.com). I went into the settings and disabled all telemetry. To my surprise, this didn't stop the traffic. In fact, it increased the frequency of batch data collection. The telemetry "off" switch appears to be purely cosmetic. 3. What's Being Sent: Even with telemetry "disabled," Trae sends detailed payloads including: Hardware specs (CPU, memory, etc.) Persistent user, device, and machine IDs OS version, app language, user name Granular usage data like time-on-ide, window focus state, and active file types. 4. Community Censorship: When I tried to discuss these findings on their official Discord, my posts were deleted and my account was muted for 7 days. It seems words like "track" trigger an automated gag rule, which prevents any real discussion about privacy. I believe developers should be aware of this behavior. The combination of resource drain, non-functional privacy settings, and censorship of technical feedback is a major red flag. The full, detailed analysis with all the evidence (process lists, Fiddler captures, JSON payloads, and screenshots of the Discord moderation) is available at the link. Happy to answer any questions.
- refulgentis 1y ago[flagged]
- kevingadd 1y agoI don't think the post you're replying to deserves what feels like an aggressive dressing-down. The reality is that post formatting on HN is really janky and it's hard to get it to do what you want. I don't blame someone for failing to master HN formatting on one of their first tries.
- segfault22 1y agoPromise to try better next time, its really first post ever i have made on here, sorry!
- kevingadd 1y agoYou're doing fine! In general the best trick for HN posts is just to add extra line breaks so that there's enough space between your sentences.
- nothrabannosir 1y agoDon’t worry at all. Thank you for the content, and thank you for your time.
- kstrauser 1y agoDon't worry about it. I was able to read and understand your message clearly, even with the unimportant formatting mistakes.
- dang 1y ago(I'm a mod on HN) - We're both happy and lucky to have you, and I hope you'll stick around! Also, I hope getting to #1 on the front page with your first post led to more positive vibes than getting harangued led to negative ones :)
- 1y ago
- drewbitt 1y agoThey don't want telemetry ever disabled, even for a minority of people who do toggle it off. Why?
- msgodel 1y agoTelemetry toggles add noise to the data at the very least. IMO it's part of the reason you're actually better off with no client-side telemetry at all. Obviously they see it the opposite way.
- imglorp 1y agoDisabling telemetry might be interpreted as a self-indicated signal of "I have something to hide", so they jack up the snooping.
- HPsquared 1y agoI suspect many (or all) VPNs probably do secret logging. People will do their most interesting secret activities on those.
- rvnx 1y agoLike Signal users. The only thing it signals is that the user is interesting. There is also a reason why it is not allowed for classified use.
- const_cast 1y agoThis isn't true, this is the sort of toxic "if I have nothing to hide then why value privacy" ideology that got us into this privacy nightmare. Every single person has "something to hide", and that's normal. It's normal to not want your messages snooped through. It doesn't mean you're a criminal, or even computer-saavy.
- rvnx 1y agoMhhh it is not really about “nothing to hide”, it was more that if you use niche services targeted at privacy, it puts a big target on you. Like the Casio watches, travelling to Syria, using Tor, Protonmail, etc… When it is better in reality to have a regular watch, a Gmail with encrypted .zip files or whatever, etc. It does not mean you are a criminal if you have that Casio watch, but if you have this, plus encrypted emails, plus travel to some countries as a tourist, you are almost certain to put yourself in trouble for nothing, while you tried to protect yourself. And if you are a criminal, you will put yourself in trouble too, also for nothing, while you tried to protect yourself. This was the basis of Xkeyscore, and all of that to say that Signal is one very good signal that the person may be interesting.
- circuit10 1y agoIs it just me or does the formatting of this feel like ChatGPT (numbered lists, "Key Takeaways", and just the general phrasing of things)? It's not necessarily an issue if you checked over it properly but if you did use it then it might be good to mention that for transparency, because people can tell anyway and it might feel slightly otherwise (or maybe you just have a similar writing style)
- marksomnian 1y ago> might be good to mention that for transparency, because people can tell anyway and it might feel slightly otherwise Devil's advocate: why does it matter (apart from "it feels wrong")? As long as the conclusions are sound, why is it relevant whether AI helped with the writing of the report?
- jdiff 1y agoBecause AI use is often a strong indicator of a lack of soundness. Especially if it's used to the point where its structural quirks (like a love for lists) shine through.
- chrisnight 1y agoIt is relevant because it wastes time and adds nothing of substance. An AI can only output as much information as was inputted into it. Using it to write a text then just makes it unnecessarily more verbose. The last few sections could have been cut entirely and nothing would have been lost. Edit: In the process of writing this comment, the author removed 2 sections (and added an LLM acknowledgement), of which I referred to in my previous statement. To the author, thank you for reducing the verbosity with that.
- deleted 1y ago[deleted]
- IncreasePosts 1y agoBecause AI isn't so hot on the "I" yet, and if you ask it to generate this kind of document it might just make stuff up. And there is too much content on the internet to delve deep on whatever you come across to understand the soundness of it. Obviously you need to do it at some point with some things, but few people do it all the time with everything. Pretty much everyone has heuristics for content that feels like low quality garbage, and currently seeing the hallmarks of AI seems like a mostly reasonable one. Other heuristics are content filled with marketing speak, tons of typos, whatever.
- moomoo11 1y ago[flagged]
- righthand 1y agoI agree, while ByteDance has played their cards fairly safe in regards to how much we know about their links to CCP, it doesn’t mean they are a “good” or “trustworthy” company.
- phoronixrly 1y agoCalling out leople who trust software from ByteDance, and not calling out people who trust software by Microsoft (i.e. VSCode) is a bit hypocritic. Both are faceless corps that produce unethical software.
- msgodel 1y agoDon't forget that the remote editing feature in VSCode has you install non-free binaries on the remote machines. It's not like netdir where it just wraps openssh. I'm always surprised when corporate IT departments allow that given what's not allowed these days.
- pests 1y agoCorporate IT usually has a relationship and trusts Microsoft already. Not like it’s a small I trusted company.
- cozzyd 1y agoAnd responsible for a huge amount of disk usage on our experiments shared machines (due to a bunch of students using vscode, with each user having their own copies of magic binaries). I wonder if there's an easy way to block it...
- eddythompson80 1y agoNo? The non-free binary is the client not the server. There are free implementations of the client for Code OSS. The server installed on the remote machine is part of vscode itself called the REH (remote extension host). It’s the core of the editor running in headless mode on the server. Here is an example open source implementation of the non-free binary client (it’s a 4 files that call various editor APIs) https://github.com/xaberus/vscode-remote-oss https://github.com/xaberus/vscode-remote-oss This is REH entry (the binary installed on the remote machine) https://github.com/microsoft/vscode/tree/main/src/vs/server/node https://github.com/microsoft/vscode/tree/main/src/vs/server/...
- spyridonas 1y agoGreat analysis, well done ! Since you've already done VSCode, Trae, Cursor, can you analyse Kiro (AWS fork). I'm curious about their data collection practices.
- cuuupid 1y agoAnecdata but Kiro is much, much, much, much easier to put through corporate procurement compared to its peers. I'm talking days vs months. This is not because it is better and I've seen no inclination that it would somehow be more private or secure, but most enterprises already share their proprietary data with AWS and have an agreement with AWS that their TAMs will gladly usher Kiro usage under. Interesting to distinguish that privacy/security as it relates to individuals is taken at face value, while when it relates to corporations it is taken at disclosure value.
- ameliaquining 1y agoThis seems perfectly rational. If you're already entrusting all your technical infrastructure to AWS, then adding another AWS service doesn't add any additional supply-chain risk, whereas adding something from another vendor does do that.
- hollowonepl 1y agoI so much like the fact that I've come back to TUI (helix editor) recently. I'm trying ZED too, which I believe as a commercial product comes with telemetry too.. but yeah, learning advanced rules of a personal firewall always helpful!
- garettmd 1y agoHow are you finding it compares to just using [Neo]Vim with all the plugins and custom configs? What improvements does it offer?
- xyzal 1y agoNow imagine we trust this company with collecting psychological profiles of future western politicians ...
- reaperducer 1y agoAnd future members of the military, the media, CEOs, etc…
- neuroelectron 1y agoVSCode is extremely unsafe and you should only use it in a managed, corporate environment where breaches aren't your problem. This goes with any fork, as well.
- CaliforniaKarl 1y agoIf you signed a Nondisclosure agreement with your employer, and you use—without approval—a tool that sends telemetry, you may be liable for a breach of the NDA.
- neuroelectron 1y agoExactly, which is why you're using the tools provided for you in a managed corporate environment. :/
- dns_snek 1y agoI've never seen an NDA that would have clauses like that, and every job I've had required signing one. Do you have any examples?
- shortrounddev2 1y agoUnsafe because of telemetry or unsafe because of the plugin ecosystem?
- neuroelectron 1y agoPlugins and architecture
- dotancohen 1y agoWhat should I be reading to know more about this? I am considering a move from Jetbrain's products to VS Code.
- cyberpunk 1y agoI tried this move once and lasted three days. Opening IDEA after those three days was the same kind of feeling I imagine you’d get when you take off a too tight pair of shoes you’ve been trying to run a marathon in. ymmv, of course, but for $dayjob I can’t even be arsed trying anything else at this point, it’s so ingrained I doubt it’ll be worth the effort switching.
- dmitrygr 1y agoI remind you, again, that vi, gcc, as, ld, and make have no telemetry, launch few (if any) processes, do not need GB of RAM, and work well.
- dotancohen 1y agoI am a die hard VIM user. VIM is a text editor, not an IDE. You can I many D tools into it's E, but it remains a text editor with disparate tools.
- 63stack 1y agoWhat is there in an IDE today, that is missing from (n)vim? With the advent of DAP and LSP servers, I can't find anything that I would use a "proper" IDE for.
- viraptor 1y ago- debuggers - popup context windows for docs (kind of there, but having to respect the default character grid makes them much less capable and usually they don't allow further interaction) - contextual buttons on a line of code (sure, custom commands exist, but they're not discoverable) - "minimap"
- godelski 1y ago> debuggers Parent mentioned >> DAP Here's the docs[0] > popup context windows for docs These are called "balloon"s[1]. Plenty of people have setups for things like docs (press "K") or other things (By default "K" assumes a man page) > contextual buttons on a line of code I don't know what this means, can you explain? > minimap Do you mean something like this?[2] Personally, I use tagbar[3] as I like using ctags and being able to jump around in the project. The "minimap" is the only one here that isn't native. You can also have the file tree on the left if you want. Most people tend to use NerdTree[4], but like with a lot of plugins, there's builtins that are just as good. Here's the help page for netrw[5], vim's native File Explorer Btw, this all works in vim. No need for neovim for any of this stuff. Except for the debugger, this stuff has been here for quite some time. The debugger has been around as a plugin for awhile too. All this stuff has been here since I started using vim, which was over a decade ago (maybe balloons didn't have as good of an interface? Idk, it's been awhile) [0] https://vimdoc.sourceforge.net/htmldoc/debugger.html https://vimdoc.sourceforge.net/htmldoc/debugger.html [1] https://vimdoc.sourceforge.net/htmldoc/options.html#'balloondelay' https://vimdoc.sourceforge.net/htmldoc/options.html#'balloon... [2] https://github.com/wfxr/minimap.vim https://github.com/wfxr/minimap.vim [3] https://github.com/preservim/tagbar https://github.com/preservim/tagbar [4] https://github.com/preservim/nerdtree https://github.com/preservim/nerdtree [5] https://vimhelp.org/pi_netrw.txt.html#netrw https://vimhelp.org/pi_netrw.txt.html#netrw
- max_ 1y agoWhy isn't there a decently done code editor with VSCode level features but none of the spyware garbage? Any recommendations? This seems like an easy win for a software project
- dmead 1y agoEmacs still exists
- userbinator 1y agoSo does vi.
- JLO64 1y agoAs does Neovim
- dotancohen 1y agoEmacs is great, sure, but it lacks a decent text editor.
- reaperducer 1y agoWhy isn't there a decently done code editor with VSCode level features but none of the spyware garbage? Isn't that what VS Codium is for?
- 1y ago
- asciii 1y agoGreat write up OP! Your analysis is thorough, and I wonder if their reduction of processes from 33 to 20...(WOW) had anything to do with moving telemetry logic elsewhere (hence increased endpoint activity). What does Bytedance say regarding all this?
- efitz 1y agoTwo thoughts: 1. Try using pi-hole to block those particular endpoints via making DNS resolution fail; see if it still works if it can’t access the telemetry endpoints. 2. Their ridiculous tracking, disregard of the user preference to not send telemetry, and behavior on the Discord when you mentioned tracking says everything you need to know about the company. You cannot change them. If you don’t want to be tracked, then stay away from Bytedance.
- nosrepa 1y agoWhy use pihole? Most OSes have a hosts file you can edit if you're just blocking one domain.
- Zolomon 1y agoIf you have multiple devices on the same LAN, all of them will use the pihole.
- 3eb7988a1663 1y agoWhen the nefarious actor is already inside the house, who knows to what lengths they will go to circumvent the protections? External network blocker is more straightforward (packets go in, packets go out), so easier to ensure that there is nothing funny happening. On Apple devices, first-party applications get to circumvent LittleSnitch-like filtering. Presumably harder to hide this kind of activity on Linux, but then you need to have the expertise to be aware of the gaps. Docker still punches through your firewall configuration.
- cluckindan 1y agoSet up your router to offer DNS through pihole and everything in your network now has tracking and ads blocked, even the wifi dishwasher.
- godelski 1y agoEven the dishwasher that has Wifi that you don't know has Wifi and will happily jump onto open networks or has a deal with xfinity
- samgranieri 1y agoCome on over to neovim, the water is fine. Start with lazyvim if you like.
- atoav 1y agoGotcha, blacklisting ByteDance.
- isatty 1y agoWhy do people use obvious spyware when free software exists?
- arstarstttt3 1y ago[flagged]
- yard2010 1y agoOr anything else from their party..
- aspenmayer 1y ago> We need to bring back shaming and social isolation HN is not your army, and it isn’t a theater of ideological battle. Please don’t do that here.
- eightysixfour 1y agoI certainly think "hacker" implies quite a bit of ideology, and this site has substantial ideological leanings.
- aspenmayer 1y agoI think I was speaking aspirationally, in that the spirit of the guidelines precludes us from relating to the site and each other in such a way. We are ends, not means to an end, if that end involves subverting curious discussion. To my reading, shaming isn’t compatible with arguing in good faith as dang has helped me to understand through breaking the guidelines in strange new ways myself. I’d be happy to email mods if you think they can tell you better. I’m no authority or guide, as my own comment history shows. I’m not better than you, or who I am replying to. I say this because I care to have a discussion that (only?) HN can enable. We can backbite anywhere (else) online, but the folks who created HN made it for something else, and arguably something greater.
- 1y ago
- barkingcat 1y agoThere's also the Eclipse VScode-look-alike-reimplementation called TheiaIDE https://theia-ide.org/ https://theia-ide.org/ It was rough a few years ago, but nowadays it's pretty nice. TI rebuilt their Code Composer Studio using Theia so it does have some larger users. It has LSP support and the same Monaco editor backend - which is all I need. It's VSCode-with-an-Eclipse-feel to it - which might or might not be your cup of tea, but it's an alternative.
- jeffbee 1y agoGoogle Cloud Shell is also Theia. I think it is fairly popular.
- bayindirh 1y agoEclipse (as in ecosystem) is fairly popular in Enterprise, but since it exposes all the knobs, and is a bona fide IDE which has some learning curve, people stay away from it. Also it used to be kinda heavy, but it became lighter because of Moore's law and good code management practices all over the board. I'm planning to deploy Theia in its web based form if possible, but still didn't have the time to tinker with that one.
- v3ss0n 1y agoTheia is different from eclipse IDE it's written in JS not in Java and didn't share any code base of eclipse which is fully Java
- bayindirh 1y agoYes, I know. This is why I used "(as in ecosystem)" in the first paragraph. It was a bit late when I wrote this comment, and it turned out to be very blurry meaning wise. My bad.
- pjmlp 1y agoAlso to note that VSCode main architect was one of Eclipse architects, and co-author on GoF famous book, Erich Gamma.
- Aurornis 1y agoI see a lot of confused comments blaming Microsoft, so to clarify: This analysis is about TRAE, a ByteDance IDE that was forked from VSCode: https://www.trae.ai/ https://www.trae.ai/
- userbinator 1y agoArguably it was Microsoft who started the whole trend of calling spyware "telemetry" to obfuscate what they were doing.
- tempaccount420 1y agoObfuscate? Telemetry arguably helps with deobfuscation.
- inetknght 1y ago> Telemetry arguably helps with deobfuscation. Can you please expand on that? I have trouble understanding how telemetry helps me, as a user of the product, understand how the product works.
- tempaccount420 1y agoYou can capture the telemetry data with a HTTPS MITM and read it yourself. Or (if you're working lower level) you can see an obfuscated function is emitting telemetry, saying "User did X", then you can understand that the function is doing X.
- inetknght 1y ago> You can capture the telemetry data with a HTTPS MITM and read it yourself. That's not helping me, the user. That's helping me, the developer. > Or (if you're working lower level) you can see an obfuscated function is emitting telemetry, saying "User did X", then you can understand that the function is doing X. Again, it helps me, the developer. Neither of these help me, the user.
- dmezzetti 1y agoIt's interesting that anyone is surprised by this.
- raverbashing 1y agoWhy would anyone use a "Bytedance VSCode fork" is beyond me
- userbinator 1y agoExcept their own employees, of course. Apparently the main difference this has with MS' version is additional "AI features", so I'm not surprised...
- neurostimulant 1y agoIt's cheap, the ai features cost about half of what other editors are charging ($10/mo) and the free tier has generous limit. I guess you pay the difference with something else :)
- kindkang2024 1y agoI’m one of those who use it—mainly because it’s cheap, as others have mentioned. I wish Cursor offered a more generous limit so I wouldn’t need another paid subscription. But it won’t. So Trae comes in — fulfilling that need and sealing the deal. This is what we call competition: it brings more freedom and helps everyone get what they want. Kudos to the competition! I'm not defending Trae’s telemetry — just pointing out the hard truth about why pricing works and why many people care less about privacy concerns (all because there are no better alternatives for them, considering the price.) By the way, for those who care more about pricing($7.5/M) — here you go: https://www.trae.ai/ https://www.trae.ai/. It’s still not as good as Cursor overall (just my personal opinion), but it’s quite capable now and is evolving fast — they even changed their logo in a very short time. Maybe someday it could be as competitive as Cursor — or even more so.
- guessmyname 1y ago> Why would anyone use a "Bytedance VSCode fork" is beyond me Because the person using it works at Bytedance. I guess your question is better phrased as: “Why would any non-Bytedance employee use Bytedance VSCode fork?”, to which I have no answer.
- R2B2K2 1y ago[dead]
- stan_kirdey 1y agoprops to OP for the screenshots and payloads—that’s how you do it. If any IDE wants trust, they know the recipe - make telemetry optin by default and provide a real kill switch.
- cchance 1y agoAm i the only one that finds System Information: Hardware specs, OS details, architecture Usage Patterns: Active time, session duration, feature usage Performance Metrics: Response times, resource consumption Unique Identifiers: Machine ID, user ID, device fingerprints Workspace Details: Project information, file paths (obfuscated) Not to really bad that obtrusive? Like i don't really see anything there that i'd be offended in them taking?
- ipaddr 1y agoI would not want to share these: Unique Identifiers: Machine ID, user ID, device fingerprints Workspace Details: Project information, file paths (obfuscated) Plus os details. I'd rather none.
- maven29 1y agoHow do you do abuse detection for free-tier without these?
- nottorp 1y agoProvide a light version of your app for the free tier that does not use any remote resources ofc. Then you don't have to worry about "abuse".
- bravesoul2 1y agoSame way Linux does it.
- Y_Y 1y agoCounter-abuse is hardly the answer
- pigbearpig 1y agoSeems like a lot, especially after checking "disable telemetry"
- dontdoxxme 1y ago
- deleted 1y ago[deleted]
- kiitos 1y agoIn the OP screen share, they toggle various telemetry options on and off, but every time a setting changes, there is a pop-up that says "a setting has changed that requires a restart [of the editor] to take effect" -- and the user just hits "cancel" and doesn't restart the editor. Then, unsurprisingly, the observed behavior doesn't change. Maybe I'm dumb and/or restarting the editor doesn't actually make a difference, but at least superficially, I'm not sure you can draw useful conclusions from this kind of testing... edit: to be clear I see that they X-out the topmost window of the editor and then re-launch from the bottom bar, but it's not obvious that this is actually restarting the stuff that matters
- Aurornis 1y agoThanks for watching and catching that. It seems like a major oversight for the core claim: That disabling telemetry doesn’t work. If a restart is required and the tests ignored the restart warning that would invalidate the tests. Either way, it’s useful to see the telemetry payloads.
- pmxi 1y agoSee the authors response. He or she says it doesn’t matter either way https://news.ycombinator.com/item?id=44706580 https://news.ycombinator.com/item?id=44706580
- segfault22 1y agoTested both ways, telemetry stays the same, the prompt is to restart IDE but i wanted to disable both Telemetry options before i do it.
- leetbulb 1y agoI wonder how many of these telemetry events can sneakily exfiltrate arbitrary data like source code. For example, they could encode arbitrary data into span IDs, timestamps (millisecond and nanosecond components), or other per-event UIDs. It may be slow...but surely it's possible.
- drewbitt 1y agohttps://github.com/bytedance/trae-agent https://github.com/bytedance/trae-agent does not appear to have any telemetry.
- theusus 1y agoOkay, no where it's mentioned which IDE is talked about. https://www.trae.ai/ https://www.trae.ai/ OR https://traeide.com/ https://traeide.com/ Would be sad if wrong one is murdered.
- antonmaju 1y agotrae.ai
- theusus 1y agoNope, the other one.
- Karliss 1y agoNaming is hard but if there really were 2 different AI IDEs with nearly identically name that's no accident. But it seems like traeide.com is in the best case someones extremely misleading web design demo, worst case a scam. One the traeide website: > Educational demo only. Not affiliated with ByteDance's Trae AI. Is Trae IDE really free? What's the catch? Yes, Trae IDE is completely free with no hidden costs. As a ByteDance product, it is committed to making advanced AI coding tools accessible to all developers. By the way TRAE isn't free anymore, they now provide a premium subscription. If the later really is just a web design demo it has a bunch of red flags. Why the officially sounding domain? Download links for executables!!! If it is just a web design demo for portfolio -> why are there no contact information for the author whose work and skills it's supposed to advertise?
- b8 1y agoGreat work, glad to read about it in the Discord before u posted it here.
- SomaticPirate 1y agoHonestly great to see this. This is the power that FB/Microsoft/Google have if they ever decided to take the gloves off. Maybe this will be the motivating factor to get some privacy laws with fangs. If you continue to send telemetry after I explicitly opt-out, then I get to sue (or atleast get a cut of the fines for whistleblowing)
- fjghajkhdfgjlk 1y agoI would be interested to see a similar analysis of ByteDance's video editor, CapCut (desktop version). The editor itself is amazing, IMO it has the best UI of any video editing software I've used. Surely, it's full of telemetry and/or spyware, though, but it would be good to know to which extent. I couldn't find any such analysis.
- deafpolygon 1y agobytedance, … stay far away.
- Ecko123 1y ago[dead]
- kat529770 1y ago[dead]
- nottorp 1y agoSo is there any difference between this fork's telemetry and Microsoft's telemetry? Aside from your data being exfiltrated to a different server...
- crest 1y agoThis software should be added to malware hash lists.
- krisworld11 1y agoHow is memory usage related to telemetry? I don’t see a lot of direct correlation here. If they cut down their mem usage to the same level of cursor did, does that mean they are not sending that much data then?
- krisworld11 1y agopretty much every serious dev tool collects some form of usage data. I don’t think this is some evil conspiracy. it’s how teams figure out what’s working, what’s broken, and what needs improving.
- ethan1990 1y agoIt’s honestly kind of funny — you got timed out by Discord’s automod and now you’re running around calling it “suppression of technical discussion.” lol. Don't be dramatic. There's a wave of crypto spam before, so the automod timeout often catches lots of bots and people. I remember even community mods have been timed out before.
- happycodinggg 1y agoreally? I saw him added later today that he was muted by AutoMod. Wondering if the whole “censorship” thing is true
- ethan1990 1y agoThat’s fake news. If you check the GitHub issue and actually visit the Trae community, you’ll see the truth. The community mod already told him the real reason — it was triggered by the keyword “token”, which has been flagged due to repeated crypto bot spam in the past. But instead, he deliberately claimed it was because of the word “track,” and framed a basic anti-spam automod as “censorship” and “punishment.” https://github.com/segmentationf4u1t/trae_telemetry_research/issues/3 https://github.com/segmentationf4u1t/trae_telemetry_research... It honestly feels like an attention grab. That kind of intentional misrepresentation is pretty dishonest. And if you check the message history, he was actively chatting in the group before — no one was silencing him.
- 404istaken 1y agoAny proof of them not letting you speak because you mentioned “tracking”? This is weird. I’m in Trae’s Discord (recently decided to try their Pro) and don’t see any regulation. There are multiple users discussing about privacy mode or tos but didn’t see any pushback.
- happycodinggg 1y agoTelemetry isn't the same thing as spying on user data. You should read below if you are not clear about the differences: What is telemetry data? Telemetry is anonymous, aggregated usage data that helps developers understand how a product is being used. It usually includes stuff like: - What features are being used (e.g. “X% of users use the terminal panel daily”) - How often the app crashes, and where - Performance stats (e.g. memory usage, load times) - Environment info (like OS version, screen resolution — not personal files) It does NOT include your source code, files, passwords, browser content, or any personal identifiers unless explicitly stated. And in most reputable products, it’s either anonymized or pseudonymized by default. Who uses telemetry? Everyone. - VS Code collects telemetry to improve editor performance and user experience. For products that are vscode fork, they inherit the vscode telemetry switch by default. - Chrome uses telemetry to understand browser performance, crashes, and feature adoption, -Slack, Discord, Postman all rely on telemetry to debug, prioritize features, and improve product quality Without telemetry, you can’t know which features are working, where users are getting stuck and what’s actually causing bugs. So when people say “telemetry = privacy breach,” they’re confusing helpful system analytics with data exploitation. The real concern should be around what is collected, how it’s stored, and whether users can opt out — not the mere existence of telemetry data itself. Telemetry data itself doesn’t directly cause high CPU usage. CPU hog could cause by a lot of different reasons. Sharing here just because some reasonings and arguments in the original post seems off. Don’t want people to get confused
- happycodinggg 1y agotelemetry is not your source code. It doesn’t include: - Your code files - What you’re writing - proprietary IP - Passwords, tokens, env vars - Anything personally identifiable Instead, telemetry usually looks like “User clicked on send button” or “App crashed with error XYZ on macOS 14.1”
- 404istaken 1y agoyou updated the GitHub repo multiple times, and from the looks of it, that so-called “official censorship” was actually just an automod mute. tying that to telemetry feels like you’re trying to stitch a story together just to sell a narrative