iTerm2 removes AI feature from core, creates separate plugin
gitlab.com
gitlab.com
I get that a lot of us are tired of 'AI' being shoved down our throat at every possible turn. I get that a lot of us have privacy concerns. I get that maybe you don't want it in your terminal emulator.
But iTerm is a free (both as in gratis and as in libre) open source project. The developer released a feature that they were probably happy and excited about. It was off by default and didn't siphon data or do anything malicious. And a ton of reactions were as if iTerm had just added the devil incarnate or attacked people personally.
Disliking the feature is fine. Voicing your concerns and feedback is fine. But it should always be gracious and in good faith. I think this is a good change, if only to pacify the masses, and I applaud the developer for taking these steps, but I don't like how we got here.
EDIT: gnachman, if you're reading this, thank you for your tireless work on iTerm. It serves me extremely well whenever I'm on macOS and holds a special place in my heart. I bought a MacBook in 2013 and it was the first *nix system that I daily drove as a desktop for a long time. I installed iTerm 2 in my first week and it was a constant companion for many years.
I'd like to second this. I had to move to a mac for a bunch of reasons that I wasn't super thrilled with and iTerm2 was one of the first things I installed. It made the transition much more bearable and the system just that much more comfortable overall.
I'm sorry that people didn't take kindly to this feature. For what it's worth, I find myself wishing that `Konsole` had a plugin on the side that would allow me to interact with chatGPT and the like. If I ever end up back on a mac full time, I'll (probably) be a happy user of this new function!
Not that I blame the maintainers for using the approach they did, though! Usually you do want to be super obvious about new things.
I think for most people, it's not any one mole that's the problem, it's the overall game of whac-a-mole.
Whenever any software I use changes anymore, I instinctively expect it to get worse because the developer chose to add something unwanted. It's a sad state for software in general.
It's most likely the reason. Everybody wants to ride the hype wave with AI just like they did with NFTs, dApps, Web3, and so on and people are tired of it.
I'm not for or against AI if we can even call LLMs AI, but I genuinely can't find a use case for an AI prompt in a terminal emulator app. I know it's open-source and I can "take it or leave it", but this feature addition to me seems more like hype than anything else.
It has nothing to do with "pacifying the masses" and everything to do it with being the right product decision to make. It should never have been added to core and should have been offered as a 100% optional add-on in the first place. People had every right to be deeply upset.
We run into this problem constantly with cloud software where we have zero control over what features they add (aka AI) and often there's no way to opt-out. Thankfully we can expect better from a locally-executing open source terminal app.
Why do you get to decide that?
I should not be surprised really, but it is amazing how vehemently anti-AI some people are becoming. It is interesting that it is already creating such divides and rifts. Almost as if all those sci-fi writers predicting the upcoming AI schisms were surprisingly accurate.
Honestly I agree with their sentiments. iTerm should be a terminal app. Any of this stuff should be an extension/plugin, and not a core feature.
You could see how this is even more dangerous than a completely separate window to an API
The only difference is: in 2006 people online in general weren’t absolute shitheads
Perhaps, but it was IMO 100% predictable. You don't go walking in a crime ridden area of a big city waving around a bunch of cash and then be shocked when you get mugged, even when it's legally still not your fault.
This is why open-source maintainers burn out and we can't have nice things. Honestly, people, please consider the human on the other side of the toxic discourse.
That was the wrong way to do it. The feature should have been disabled with an actual, clear toggle that shows that it is. This blew up in the developers face for a good reason.
It doesn't do anything at all unless you actively engage with it. This is sophistry at its finest.
> Put anything in the box for the OpenAI key, valid or not, and the functionality to send data to OpenAI is active.
No it isn't. Nothing happens until you bring up the Codecierge toolbox and type in a question.
Also, from your later comment:
> 'prompt to use OpenAI' is not OpenAI specific, it is a new button in a previous function that you could use in earlier versions
You just made that one up, the Codecierge UI is entirely new.
If you leave the field empty (open to accident) and you don't press this button in this function that you may use for other things (open to accident) it doesn't send data where you didn't expect it to. This is functionally equivalent to you can accidentally send data you didn't mean to. This is simply prevented with a real toggle to disable the function.
I don't know about you, but I have clicked on things I didn't mean to because I lost where the mouse is, or because I'm giving a window focus again, it is not an accident that doesn't happen.
Who knows if there was a deal made under the hood
> I have two goals in this change: To allow developers in restrictive but technically incompetent organizations to continue to use iTerm2. That is, they disallow anything that could potentially exfiltrate data, but don't have their act together enough to implement MDM. So that people who hate AI can feel at ease that no AI will happen by accident without having to dig into the weeds of the implementation.
https://gitlab.com/gnachman/iterm2/-/issues/11470#note_19176...
The issue here is the existence of a terminal feature that can send your commands to a 3rd party server.
It could have no AI whatsoever; it is reasonable to not want this in an app that you might paste secret keys into.
Do the people who don’t like this feature have the same standards for ever app they use? Probably not, they’re probably being a little hyperbolic, but it sounds like a reasonable request.
That's called SSH.
With not many more characters than are needed for an API key, I could write a script in the very terminal provided by iTerm2 that sends all my commands to a 3rd party server!
are they? their position is basically that they don't trust iterm2 to work properly, but only in regard to this specific setting.
if you don't trust iterm2 to work, don't use it. if you do trust it to work, you should be able to trust that the ai feature that's off by default won't magically turn itself on.
The technology isn't the problem; It's the meatbags weaponizing it in the name of a quick buck who are the problem.
Before this recent flare-up in pro/anti-AI tribalism, I have not regularly been demanded to justify my distrust of a corporation. Suddenly I feel I am demanded to justify my lack of faith in corporations who happen to have some involvement in AI. I shouldn't have to say anything beyond simply gesticulating vaguely in the direction of end-stage capitalism; The problems should be readily apparent.
People aren't demanding you anything. You are.
My point is that I believe the reason people are still repulsed by it to such a high degree is not because they all have some irrational deep-seated hatred of the AI technology, but that they are repulsed by the idea of even accidentally engaging with the OpenAI corporation (who just announced a partnership with News Corp of all things...); They are terrified of some situation in the future where someone comes along with code or packet traces and says "Hey, look at this, OpenAI has all your data anyway, and there's nothing you can do about it but seethe and cope; sucks to be you!"
and this is not a reasonable complaint, or a justifiable reason to demand the removal of features. if you have an emotional reaction to the existence of openAI, that's an issue for you to address yourself, not a reason to demand that other people make changes to free apps you've decided use.
Then don't use the feature?
Have switched to alacritty. It’s basic but it does its job. It’s a terminal. Highly performant, no unnecessary bloat compared to iterm2.
Have moved my monthly donations away from iterm2.
I mean sure it was a brash way of putting it but he's not wrong. I contract with an org that basically shuts off access to anything that is in any way related to AI, we can't even visit the OpenAI website on our computers. If this feature was part of core iTerm2 then 100% they would have banned the use of iTerm.
Much like your SLAs are not my SLAs your risks are not my risks. iterm2 inserting a mechanism to talk to a new class of component is not a minor change.
I'm not sure what the matrix of organisations is that would ban a sideline feature like this through policy only, and not through technical means like MDN.
It's also a minor UX failure. The onboarding screens weren't loud enough about the need to provide an API key.
I really feel for the maintainers here. They added a cool thing to their popular-for-a-reason terminal emulator, and (from their perspective) people lost their minds over a misunderstanding or (again, from their perspective) unreasonable expectations.
It seems abundantly clear that people are being overly negative about a feature that realistically has no security concerns (even as originally developed). Many commenters did not even know how the feature worked (assumed all keystrokes were being sent by default, etc...)
One outright said that the feature should be removed because the developer must "stand against OpenAI and the whole "AI" industry."
To me this just seems like a lot of people whining and trying to inject politics and unfounded safety concerns into a good implementation of something that many people like. This is an opt-in feature. It has a separate panel to even interact with it. And you need to provide a valid openai API key to use it.
That's a rather absurd way of approaching the threat model of data exfiltration on a terminal app.
By its very definition a terminal needs the ability to spawn unsandboxed processes and send/receive input from/to them, including processes that have network access. Even if the binary doesn't contain specific logic to do this it could invoke curl, or a variety of other binaries that do, either on purpose or accidentally. In addition, it links against AppKit, which includes NSURLRequest. Is that off-limits too?
If one's this allergic to OpenAI, that even an opt-in feature is a concern, they're better off using a firewall like Little Snitch, or blocking it at the DNS level.
Additionally, if you don't trust the developer with this, why would you trust a binary from them without this feature?
But if there's something I am building into my personality, it is rejecting (and calling out) grift. That is what makes me seethe about this entire big picture. The hype, the cultural parasitism, and the callous, blasé "oh yeah if you're not using this already you're probably fucked" FUD/FOMO shit smoothie that generative-AI people seem entirely too comfortable dishing up.
People who even seem in a hurry to jump on that hype train are going to catch the same side eye.
Re: iTerm2 specifically: I don't use iTerm2. I didn't mind it when I did. I wish the developer luck; terminal apps always need more attention. And in this case I don't think a tickbox to switch something on would trouble me.
But if I really relied on a product, seeing its developer divide attention and start shoehorning in LLM APIs to gain a bit of contemporary relevance would at least slightly bother me.
Like when one of your least rigorous-thinking friends or relatives starts talking to you about some opportunity to do with Ethereum. Not often a positive sign.
(This Gitlab issue is not the silliest overreaction I've seen. At the height of the Apple/Samsung Android lawsuit proxy war, I once saw someone demand in a support thread that Wacom remove some Android connection tools that one or more of their smart tablets were using, because Android was "stolen property" or somesuch obviously Jobsian phrasing.)
But I'm really interested in finding a maximally-ethical way through it all. The MagPi magazine has just started an article series about applications of ethical, non-infringing models and on-device AI, so I think there must be an emerging trend line around that.
Though whenever I see people talking about ethical AI stewardship the debate seems to be about one specific corporation which is run by a guy who launched a "let us scan your iris and we'll give you crypto" business.
This claim implies that there's no utilitarian reason for this integration, but I don't think that is true. Shell scripting is notoriously arcane, and conversely LMs are pretty decent at unraveling that. You might notice that there are quite a few comments on the issue where users specifically state that they are using the feature and find it helpful. I was actually mildly skeptical when seeing it show up in the changelog for 3.5.0, but after giving it a try, I think this is exactly the kind of useful AI integration that I'd want to see more of (as opposed to how LLMs are being used most of the time).
It's just not quite what I had in mind. But what I wrote is still quite scrappy; that line is missing at least an "in general" to broaden that point out beyond iTerm 2 specifically. I need to slow down a bit more.
I don't really agree with you on the LLM side of the equation, and I am bothered by the idea that this is where we're all headed. But where I think this integration is not ridiculous is in doing this at the GUI level.
There is an argument for saying "why isn't this a utility at the remote (shell) end", but of course from the perspective of OpenAI API calls being added to everything and calling out from the command line, that would be worse, because you'd be installing it everywhere.
So if it belongs anywhere (colour me wholly unconvinced) it definitely belongs somewhere within the terminal client itself.
But as I say, I don't use iTerm 2. I did take this opportunity to look at what iTerm 2 offers, out of fairness to the author, and it is obviously an impressive bit of work. Maybe when I find a need for Python scripting like that I'll come back to it.
With regard to LLMs, for what it's worth, I'm not suggesting that people use them to routinely drive their shell. This is the kind of stuff that you use very occasionally, when it is time to use that one command that is immensely useful for very specialized things, and which you can never in your life remember the syntax for precisely because it's not something you do every day. The canonical examples there are ffmpeg, ImageMagick, and similar tools.
Remember https://linux.die.net/man/1/cdecl? This is basically like that, just based on tech that allows it to be better generalized.
Don't people make notes of that somewhere they can look it up?
I mean, you're not going to use this to generate command line arguments for commands you've never heard of before, you're likely not going to use it for commands whose outputs are crucial or behaviours unsafe, and if you do you're going to need to use your actual knowledge to check it hasn't hallucinated something dangerous before you run it -- which means consulting the manual and doing the work.
I get that man pages are a particularly rich, standardised form of training text, I just don't believe there is as much advantage in asking an LLM.
This is one of those areas where I think people project success onto LLMs where there is none. It's like the songwriting example. Sure it can write a bad song fast, but so can literally anyone half-skilled, and if you want to help it write a good song, you're going to have to redo half the work.
This is just like having a bad dishwasher.
Love how you just lump everyone who take their time to voice legitimate concerns about the ethical and privacy nightmare that is proprietary generative AI services into a category called "reactionary ninnies".
While I'm sure some comments went overboard, people had every right to be upset about this integration being added to iTerm—even as a configure-to-use-it feature. I'm glad this is being extracted out to a completely separate add-on.
I've said my piece on this many times over the last few days here on HN so I won't repeat myself but if you were one of the people complaining then I want you to know in no uncertain terms that you are what's wrong with open source and you are why people don't want to maintain open source projects, you should really be ashamed of yourselves.
> To allow developers in restrictive but technically incompetent organizations to continue to use iTerm2. That is, they disallow anything that could potentially exfiltrate data, but don't have their act together enough to implement MDM.
> So that people who hate AI can feel at ease that no AI will happen by accident without having to dig into the weeds of the implementation.
That sums this entire drama up pretty well.
People were and still are making claims that the initial implementation can make it easy to accidentally send all of your keystrokes to OpenAI. This is not how the feature works at all. It needs explicit user interaction to use. You open the "Codesierge" toolbox and type in a question, which is a lot of clicks and typing. Yet people are posting on Mastodon and elsewhere that "accidentally" setting the API key to a non-empty value in preferences is enough to make iTerm2 send every keystroke to a third party.
Worse yet, someone pointed out in the GitLab thread that there's a call for violence against the dev by one of the participants. And sure enough, there it was on Mastodon and it's quite horrific.
iTerm2 is a gift. The dev makes his ideal terminal and we can use it if we like it. Feedbacks are fine and from my past experience welcomed, but this is something else entirely.
BTW - I'm not complaining about whether AI is included or not, just pointing out that the title is incorrect. Here's the link to the plugin: https://iterm2.com/ai-plugin.html From the description: "It provides necessary functionality for iTerm2 to make network requests."
a) Putting an LLM into iTerm introduces almost no benefit that I can think of, other than "shiny new technology", and is a waste of time and resources. I've heard some people suggest that putting an AI prompt into the terminal could be helpful for generating commands for difficult applications like FFMpeg, but you can also do the same thing by just asking ChatGPT in your browser and copying/pasting, which is what we've always done
b) More importantly, I absolutely do not want there to be any code in the terminal that writes commands for me or on my behalf. The command line is intimately connected to the OS and has access to every file, environment variable and socket on my system. iTerm just had to patch a bug where its URL handling and link previews was causing a remote code execution, so I would have expected this "feature" to cause security issues in the same way
Terminals are also just a fundamentally conservative application. Shiny new technology has never been a clean fit into terminals. Imagine if iTerm decided to integrate NFTs and crypto, or optionally link your Meta account so you can use your terminal in Virtual Reality, would probably draw a similar negative response.
The whole point of software to reduce this kind of tedious manual work. You can also do the same when writing code instead of using Copilot, for example, yet the latter significantly improves productivity in practice precisely because it's one hotkey away.
> More importantly, I absolutely do not want there to be any code in the terminal that writes commands for me or on my behalf.
Have you actually tried to use this feature? At no point does it submit commands directly to the terminal. It has to be explicitly enabled, for starters, by setting it up with a valid API key or custom server URL. Then you need to activate a specific command to open a textbox where you type in your input. Then you get the result back, and you have to use yet another shortcut to actually run the resulting command.
There's just no way to trigger this stuff accidentally. You have to very deliberately carry out several steps to get to the point where there's any commands being generated at all, much less actually running on your system.
> Imagine if iTerm decided to integrate NFTs and crypto, or optionally link your Meta account so you can use your terminal in Virtual Reality, would probably draw a similar negative response.
Your examples are fundamentally different in that they don't add any clear utility to the core function of the terminal, which is interacting with the shell.
iTerm2 and AI Hype Overload
iTerm2 feature request: disable all AI-related features
> Increases the attack surface
No it doesn’t. It fork/executes the plugin in a different process AND verifies the signature. If an attacker can replace the binary and do things with it, you already have a much larger problem. Even if they do, all it does is pass JSON around, it doesn’t allow you to execute anything from within iTerm (afaik)
> It can be called by any process
It’s not like they were storing your OpenAI API keys in some encrypted format in the first place. If you’re that paranoid, you aren’t gonna be using the AI feature in the first place.
One valid concern I can think of is TCC escalation on MacOS since fork/exec is executed in the context of iTerm. I don’t know if signatures are verified before or after running but the binary probably won’t even run without being signed by a paying Apple Developer anyways.
Edit: commenting on the change, I think it was just fine as is. AI is annoying but it was off by default. Based on the author’s comments, they don’t seem to intend on pushing it in people’s face, just something fun and optional
It's before. You can code sign and verify macOS binaries with any certificate you wish, including a self-signed one (useful in case you want your private iTerm fork). Note the plugin should be signed with the same certificate as the iTerm app [1], just using a paid account won't work.
[1] https://gitlab.com/gnachman/iterm2/-/blob/b0e6b336a6be9bca00...
I'm at least quite glad that he listened and moved it into a separate plugin.
I've immediately uninstalled it as there is no way to disable it.
Funny because I experience the exact opposite. I see HN extremely negative about anything AI related while my personal acquaintance are excited and enjoying in their apps and tools they use
The expectation is that plugins need to be activated explicitly and that do not get installed or activated automatically. Even stronger, a common impression about plugins is, that they are often a pain to install and get working. I know that this expectation has been violated occasionally in one form or another but I doubt that many people are aware of that or could even come up with examples.
Built-in features on the other hand are completely different. The usual experience is they get moved around, enabled, disabled willy nilly without notification or consent with every (unrelated) update. iTerm2 is not like that and George has done a fantastic job to build a ton of trust over decades, but I don't blame anyone not knowing that and being cautious.
Speaking of attitude, iTerm2 is a gift, and some users (or maybe even non-users) appear to be in need of a reminding.
[*]: Your top level comment
If you are a Mac user and not using (or at least considering) iTerm2, you are doing yourself a disservice. It is by far the best terminal emulator available and runs circles around the built-in option.
If you are a not a Mac user, then the entire discussion is moot either way.
How so?
Before it I would recommend kitty or alacritty.
FWIW, they both seem extremely performant and would probably be a great fit if I daily-drove Linux.
It sounds like it's more about the extra features being included than the "batteries". What features does a terminal emulator need other than "lets a user enter stdin and displays stdout/err"?
I think the root of this issue here is trust and control. I work for a company with a restrictive IT department. It's not "overly-restrictive" because the data with we work with is sensitive. Banning all AI enabled products, which my company did, is absolutely the logical and safe thing to do. (We have self hosted hosted AI solutions and limited GitHub CoPilot access now.)
The AI stuff is disabled by default, the concerns are unfounded.