But it means that every string that looks like a domain is transmitted unencrypted over the internet.
If your software deals with private user data, you must consider the side effects of every API you are calling. You can’t just transmit data somewhere and hope that everyone will do the right thing. Network traffic is monitored on lots of networks. Unless the data is encrypted and you have reason to trust the receiver, don’t send it.
And whatever you do, don’t send private data without user action. Users expect web requests to be made when clicking a link. They do not expect data to be transmitted when hovering the mouse over URLs.
I completely agree that one must take into account how that feature fits with your product, user expectations, and privacy, but none of that means a feature that works as intended is a security flaw.
As others have said, prefetching pages has been done for years. Checking to see if it's a valid domain isn't an unreasonable feature for iTerm's URL highlighting, and for those who would prefer it not, he's changed that behavior, but let's not pretend that it was some absurd use of data that no one could have reasonably predicted.
And lastly, let's also stop clutching our pearls about "transmitting data". IT did a DNS lookup, and while technically that means there was a transmission, it wasn't taking what people traditionally call user data and transmitting it to a foreign third party. It's perfectly reasonable to check a domain name against a DNS server. Maybe unwanted, yes, but not even remotely irrational or irresponsible.
If you leak user data accidentally, saying “that wasn’t my intent” doesn’t help much.
The important thing that you don’t understand is that there is a difference between a search field / url box, and a Terminal.
I absolutely expect my browser to make DNS queries for stuff I paste into the URL box.
I don’t expect my terminal emulator to make DNS queries for random strings displayed on screen that happen to match a regex.
> What happened: iTerm sent various things (including passwords) in plain text to my ISP's DNS server
iTerm was accidentally transmitting passwords in plain text via the network.
I'm pretty sure transmitting passwords in plain text isn't "working as intended".
Sure, you can go blame the user for not knowing that iTerm makes DNS queries when you hold down the command key.
But if you want to make secure software, you can't just tell the user it's their fault. You need to make sure that accidentally disclosing private information is not something that easily happens.
I cringe just thinking about implementing something like that.
~ dig somerandomurlimadeup.com | grep 'Query time: '
;; Query time: 23 msecI'm not saying that this is the case universally, but for many the typical lookup time will be very fast.
n.b. for me, in iTerm2, I have to press cmd to make the links highlight before I can click on them - so there's little danger of accidentally opening something you didn't want to.
Doing any DNS before clicking on the links seems like overkill, though. My browser can tell me if the URL is garbage or not.