iTerm 3.5.1 removes automatic OpenAI integration, requires opt-in
iterm2.com
iterm2.com
If you're using a product that does not make API calls externally with your data previously in a corporate environment that has very strict controls, and they add a feature that is part of the base install package, even if opt-in, that allows it to do that, and they do not have something like Group Policy hooks to forcibly disable it from on high, then they will block the product globally until the functionality is more contained to something their compliance systems can prevent, be it via a group policy hook or blocking the install at all.
Companies take "we might make an external call with your data" very seriously, and regardless of how much you trust the external entity, adding that in is rightfully seen as a very serious concern in some environments.
I work in a company that uses many different products that (attempt to) make external API calls with extremely sensitive data, and none of these products are blocked from installation, because we block all their requests at the network level, instead.
Yes, the corporate management is useful, but not critical, and the lack of it absolutely didn't justify the generated outrage.
Sure, in an environment where external access is not necessary or can be easily allowlisted, that works fine.
But on someone's interactive workstation, where they might need to access parts of the internet without getting explicit allowlisting of every web site, then it's a different set of tradeoffs, and not every company implements this the same way.
I would argue that there's more nuance, but the feeling is reasonable - I would also be frustrated if a piece of software that I used and loved at work was in danger of being taken away because of the addition of a feature that I didn't want in the first place!
Put another way: if corporate policy blocks this app but not access to OpenAI, they are not solving the underlying issue. If they already block OpenAI they don't need the application control.
Many things, browsers are pretty configurable via group policy. One possibility is to force browsers to go through a proxy that inspects all traffic, for example.
It's just really hard to see the argument against the feature as anything other than an excuse for general anti-AI sentiments. Organizations that really care about this already have the tooling in place to stop all AI features in all products with just a few network-level rules. If they don't have that tooling, they're not taking it seriously and they're not going to start suddenly blocking iTerm2 because it added an optional AI feature.
Currently my employers inspect every network call made on my device, and while they do not block OpenAI, they do block us from running specific browsers that cannot have their built in “secure” DNS settings changed such that they won’t sidestep inspection.
I get emails if I visit the Eicar test file website.
Network level blocking is easier and more effective, so why should iTerm2 have to go to contortions to remove an already opt-in feature that would be easily blocked by a network block?
Please don't take this as an attack to you, but one would think that environments where this is a very serious concern would also be environments that either buy software, or buy support contracts with open source developers, to make sure that what they install is compliant with their concerns.
Most users of open source software do not have the skills necessary to modify said software.
Complaining is the only recourse that most people have.
And often the developer is not offering a support contract. They might even take umbrage at the idea of being bribed to make changes!
A lot of open-source software usage in the workplace is the equivalent of bringing your own tools to a worksite, or bringing your own knife set to the kitchen. I obviously can't see the project's finances, but funding for tools like iTerm 2 can be heavily dependent on individual users acting as patrons, making monthly donations purely out of gratitude for bringing them joy and/or improving their personal work productivity.
It's like when a company buys a contract with an enterprise Linux distribution: the entity offering the contract didn't author the full stack (though I'd guess they have at least some kernel contributors on staff) but they can still support it in a way that keeps the compliance department of the buying company happy.
Also, your kitchen knife set example is very relevant because, from personal experience, I know this happens but I also know problems (including accidents) resulting from using a personal knife set aren't attributed to the manufacturer of the knives but instead are treated exactly as if they happened using ones provided by the business that owns the kitchen.
This means that the only people that we're supposedly catering to here are incompetent IT departments, which doesn't seem worth the hassle for the maintainer or all of the other users.
Or, more likely, this hypothetical IT department that cares enough to block iTerm2 but doesn't care enough to block on the network level is a fiction invented by people who just really hate seeing AI added to everything.
No, they want to be seen taking it seriously, so they say that they take it very seriously. But if you will actually audit their system you will find they do not in reality and it was just a negotiation tactic.
This is a completely ridiculous strawman.
If a corporation needs strict controls then they don't allow for auto-updated software without vetting. They could have asked for a policy to disable the integration but they didn't, instead those people screamed about how they were going to have to completely block iTerm which showed their incompetence. This was in beta for quite a while and none of these "serious IT people" cared so either they are asleep at the wheel (not vetting beta versions) or they allow for auto-updates to software they don't control, either way it screams incompetence to me.
Also we are talking about a terminal here, a tool that can connect wherever the developer tells it to connect to. Are you telling me these companies lock down where a developer can SSH to but are too stupid to block traffic to OpenAI? Or they don't lock down where a developer can SSH and therefore don't talk to me about "strict controls".
Make it make sense. It just doesn't. This argument never held any water for me.
Some described company controls. Some described company policies without controls. Some described their own strong feelings.
Some had auto updated. Some had not. Some did not say.
Some supported their companies' policies. Some stressed the policies were out of their control. Some did not say.
Some asked how to make sure the integration was disabled. Some did ask for a setting an IT department could manage. Some demanded a plugin or separate build. Some said a plugin would work for them.
Many things don't make sense if you assume everyone you disagree with are a collective.
It was opt in, full stop. That should have been the end of this aside from IT managers asking for a group policy or a was to disable the feature (in a nice way).
Everyone complaining could either not update or move to a different tool and ask for a refund... oh wait... that's right, this was open source software. And people wonder why no one wants to maintain open source software. Just add this whole ordeal to the ever-growing pile of reasons why it's almost not worth doing. People are so entitled. My personal favorite were the people that said "If you remove this I'll start support you monetarily", which I assume 99% of those people were lying through their teeth based on the lack of spike in new donations to his patreon [0].
Some were IT managers. Some were users capable to speak for their IT managers. Some did not say. There was no reason comments should have been limited to identified IT managers.
Some asked how to make sure the feature was disabled. Some did ask for a group policy. Some asked for a plugin or separate build because a group policy would not satisfy their company's requirements. The maintainer solicited these requests even though he disagreed with the requirements.
Some blocked the update. Some rolled back. You must know unsupported software has costs.
Do people wonder why more people don't maintain open source software? Most people don't maintain open source software. They have reasons. I think they can imagine other people not maintaining open source software for the same reasons.
I maintained open source software. Attitudes like yours tired me more than the rude minority of users.
Patreon is 1 of 6 donation methods. And I don't think the people who offered to pay $50 meant monthly.
Unless those very strict controls include either blocking at the network level accesses to IP addresses not on a pre-approved list or removing a large number of programs and libraries that are standard on MacOS the person using iTerm will have plenty of readily available ways to use external services with that data if they want to.
Heck, the free version of ChatGPT can tell you how to access ChatGPT with curl if you don't know how [1].
I specifically asked about curl, but it would also work if I asked it to suggest a MacOS command like tool: "On MacOS what command line tools could I use to ask ChatGPT a question? Assume I have a ChatGPT API key". It suggests curl, httpie, and wget and shows how to use all of them. I updated the link below to include that too.
[1] https://chatgpt.com/share/00d9de15-4e43-497f-a116-bfe3972471...
1. Developers are forced to use Windows and given very little CLI access. And they certainly wouldn’t be using iTerm since it’s macOS only.
2. Developers are given a Windows corporate device as well as a MacBook Pro. The MBP doesn’t have access to any corporate systems
3. Developers can access corporate systems on MBP via jamf or InTune. The corporate side of the business accepts the risk that developers can access external (read: non-vetted) services but the business has access to all internet traffic logs from your device (usually pushed into some kind of security package that monitors for suspicious traffic) plus the ability to remote wipe it. So there is a degree of trust given to the developers.
Those that are stuck with option 1 are usually the unhappiest and least productive. So it’s not something most businesses like to entertain unless senior management is very corporate and the business is considered high risk.
If you download this plugin, instead of the feature being securely integrated into the main product binary, there’s a new binary on your system that takes arbitrary JSON and performs network requests. Yes I know curl exists, but thats the point: we don’t need another tool for this that’s way less scrutinized and now opens my system up for data exfiltration in ways that weren’t originally possible. It also suffers from the traditional IPC pitfalls present when not using secure XPC with app groups. It’s objectively worse.
Edit: I’m talking about the separate binary plugin when I call for George to revert. The secure defaults config that can be MDM managed is perfect, simple, and fit for purpose to secure iTerm as a product. Moving the network calls that talk to the configured openai-compatible api server a separate binary is a farce.
You might say that I am not a bright man, and I might agree, but the way the AI integration presented in 3.5.0 was not unequivocal. Literally nothing said “this feature is disabled unless you put an API key in”. It assumed a knowledge and understanding of how this shit works, one that I do t have because I have no interest in slop portals in any of my applications, let alone one in my terminal. Instead of a checkbox for “Enable/Disable”, one I could have left set to disabled and gone about my day, I got an empty text box for an API key. So what, does it attempt to make a network call to Sam Altman’s slop machine every time I hit enter, only to fail without an API key? YeAh bUt Go rEaD tHe sOuRCE, sure, but I’ve been using iTerm since Tiger without a need to go read the source (nor become a terminal application developer in five minutes so I could understand it) and had other shit to do that day.
Mind you, OpenAI.com is NXDOMAINed on my DNS servers at home, so I didnt give a shit either way when I upgraded to 3.5.0.
People’s reactions and comments to the dev were wrong, cruel, and uncalled for, but that doesn’t mean the feature couldn’t have been introduced and presented in a way more sensitive to people’s concerns about AI, right or wrong, real or fake. And sure, the dev has every right to do whatever they want with their open source project. They don’t owe us any emotional intelligence or respect or anything, but they also dont have a right to expect everyone to be like, totally cool and vibin with whatever they do. That doesn’t mean “everyone will put up with whatever” (which is not the same as “everyone is entitled to the project”). If the dev removed all themes except for neon pink on neon green and forced your font to be Comic Sans, would the dev be entitled to do that? Sure! It’s not illegal and they don’t owe anyone anything. Would users be entitled to go “uhh, what the fuck?” Sure! It’s not illegal and they don’t owe anyone anything! It only gets gross when people start flinging insults.
I personally didn't like the feature, but from reading through the other criticisms, it seemed like there were some genuine reasons why people didn't want this feature. I don't think it's quite as simple as you make it out to be.
Lies are lies. Lies about how this feature exfiltrates data without you knowing isn't genuine criticism either.
If you didn't like the feature, you could've done what the rest of us did and not use it. It's simple. We just carried on with our work just like we did before the update. Well, actually not exactly the same as before because we enjoyed the UI improvement that came with the update. We certainly didn't go out of our way to enable features that didn't personally interest us. Nor did we brigade the issue tracker to go on a bullying spree or posted lies after lies in public forums.
iTerm2 is a breath of fresh air compared to all the commercial crap prevalent in our industry nowadays. Trolls may have done immeasurable damage to the future of a valuable piece of software. Too bad they're not the type to take any responsibility for such actions.
I didn't like the feature, so I switched to another terminal emulator. I'm not upset and I didn't bully the dev. I wasn't a paying customer so I don't expect anyone to listen to me. I just found another product that suits the way I work much better, so I'm happy all round.
That's for interactive use, startup time is slower for iTerm2 but i don't care about that because i basically never quit the terminal.
In both iTerm2 (when i used it) and Terminal, i have a colourscheme enabled and a custom font - both of which i'm assuming have potential to slow things down.
You don’t need to know any tmux to use it either (except for how to launch the right mode, which is easy to script).
If you spend a lot of time SSHed to other computers, I would highly recommend trying it out.
But then i need to give up nested tmux on remotes https://github.com/craigjperry2/dotfiles/blob/main/dotfiles/... - it's super convenient to have tmux nested remotely for organising work and locally for broadcasting or just convenient context switching. Even when i was an iTerm2 user, i felt vanilla tmux was just way more comfortable (copy paste buffer for example)
* Recognize something in the output that looks like a Jira ticket and add a link to that ticket
* Have your ssh passwords in one place and automatically enter them upon prompt
* Connect to many servers and type the same command into all of them
* Make your screen red when in superuser mode
* etc. etc. etc.
(Some years ago, I refused a company-issued ThinkPad Carbon and byod'ed a Mac because ThinkPad couldn't do iTerm2.)
I switched to WezTerm awhile ago for my main terminal emulator, a decision I've been happy with. But I keep a copy of iTerm running so I can pull down the Quake terminal. Main uses are running homebrew updates, and, perhaps ironically given the topic of this thread, sgpt.
More advanced search with regex support, more advanced paste (can do character encoding transformations, deal with special characters, etc), smarter and configurable text selection, autocomplete (mixed bag, TBH - I use zsh for that), more advanced snippets for repetitive commands, and triggers to notify you when things happen (long running commands finish, certain words pop up eg "error" or "compile done").
It has a basic integrated password manager that allows me to paste passwords I commonly use in the terminal with a keycombo.
It can more tightly integrate with the shell/program. You can select a point with the mouse in vim or the shell and the text cursor will go there, for example.
Some of these may have since poked their way into the built in terminal, but these are some of the main reasons I use iterm. If you spend a lot of time in the terminal, you can enhance your productivity.
PS It can even record the keystrokes and play back.
Excerpt:
> This release adds some safety valves to eliminate the risk of private information leaving the terminal via the AI endpoints. While an API key and explicit user action were always needed to use AI features, some users asked for an impenetrable firewall for safety and regulatory purposes.
Yes, some users are truly experts at driving Open Source developers to the point of burnout.
I use iTerm2, in pretty sensitive environments, where 'OK, you didn't enable this feature', closely followed by 'not that we had Internet access here anyway, LOL' were (though-experimentally, as are all the 'concerns' of 'some users') eclipsed by 'hey, why is it a thing to enter sensitive data on command lines anyway -- should we not have ways to avoid that?'
So, like, if I ever happen to execute 'history' in any session of yours that I manage to get access to, I hit the jackpot?
Like where?
Speaking for apps but also of OSes, all that crap (AI integration, "Abobe Cloud" integration, and so on etc) should be not just opt-in, but also invisible once switched off (as opposed to some icon or banner nagging you about it in the UI, or ocassional popups asking you if you want to "enable it").
But other apps and services (from Apple, Adobe, MS, etc) yes.
Edit: It's worth noting that it's one of the most vocal and well-organized communities in the tech world, very prone to outrage, seeing the world in black-and-white, mob justice and piling on whatever is currently unpopular.
These kinds of cases where open source maintainers cave to pressure are almost never the result of consensus among all users. It's usually the result of a small number of people brigading the issue tracker until the maintainer gives up and does it to shut them up. Unfortunately the result is often against the interests of the wider community.
https://news.ycombinator.com/item?id=40669333
Though I wont be surprised if the majority of the hate was people who didn't understand the change.
Just tried "find all pdf files larger than 10MB" and it came up with "find . -name "*.pdf" -size +10M". Maybe this was easy but I don't know all arguments of all cli commands by heart and it works beautifully.
I have not found an LLM that knows any of that.
When I need a find command, I open `man find` and read and learn.
This is an editorialized title. It was opt-in from the very beginning. Here's all the steps that was originally required:
1. Open settings, go to the General tab, click on the AI button.
2. Enter a paid API key
3. Close the settings
4. Click "Toolbelt" on the menu bar, and click on "Codecierge"
5. Click "Toolbelt" on the menu bar again, and click "Show toolbelt"
6. In the toolbelt, there's a textbox that you can type questions into. The textbox won't be shown if you didn't enter an API key. Only after submitting the question will the OpenAI integration be activated, and as I understand it, only for the current session.
https://github.com/gnachman/iTerm2/blob/a3122c0100d8900a15cb...
The initial implementation already took many many clicks to run. I literally had to do nothing to not use the feature and not once was I reminded about the feature after I chose to ignore it.
Despite that, people were spreading rumors that entering an invalid API key would instantly cause iTerm to send all data to OpenAI. It's a straight up lie started by people who actually tested the feature and posted their findings on the GitLab thread about this feature.
https://gitlab.com/gnachman/iterm2/-/issues/11475
https://gitlab.com/gnachman/iterm2/-/issues/11470
It gets worse, people in the GitLab thread were calling for dogpiles and fantasizing about inflicting violence on Mastodon. Towards the sole maintainer of a popular free and open source software developed in his spare time.
https://web.archive.org/web/20240613165712/https://archive.i...
Some of the things you see online... I have no words.
I didn't care for the feature (I have no issues with AI/LLMs but it just wasn't useful IMHO) but the backlash was ridiculous and embarrassing for everyone complaining about an opt-in feature. The comments on the GitLab ticket and here on HN were examples of some of the worst people (or people at their worst) in our industry.
I use macos SOLELY for iterm2 because of tmux integration. I was very excited for this feature.
You have to literally click the button. It's a command Y to bring up the modal, you start typing, then you have to remove hands from keyboard and mouse to the confirm button.
What the hell? No command enter, no command shift enter, maybe I missed it or did it wrong but it is literally faster to type pipx run llm prompt than control y my command mouse and click.
Just fix that one part and I would have been in heaven, also the pop up modal seems like a bad choice when it could have been directly integrated into the shell with the new overlay they introduced alongside the feature.
Bad implementation, and PLEASE if anyone knows any foss alternative to iterm2 with tmux integration please dress me down on the fool i have been and steer me towards the path of the light again.
Can we fix the headline?
Return commands suitable for copy/pasting into \(shell) on \(uname). Do NOT include commentary NOR Markdown triple-backtick code blocks as your whole response will be copied into my terminal automatically.
The script should do this: \(ai.prompt)
And then you type your prompt in, and it returns the answer. And then you can choose to edit the command that gets returned or execute it directly.
So essentially what you'd do if you were using the API directly, just more convenient.
I haven't tried any, but if one exists it would be cool to see iterm use that LLM.
This is a terminal app and not a fucking coffee machine. Stop plugging endless "features" into it.
More discussion: https://news.ycombinator.com/item?id=40657890
Anyway thanks for listening and changing things.
Enjoy your day and please keep sharing your positive outlook!
> This release adds some safety valves to eliminate the risk of private information leaving the terminal via the AI endpoints.
If it's still not clear - I don't want my terminal to even have the possibility of leaking my data.
> While an API key and explicit user action were always needed to use AI features, some users asked for an impenetrable firewall for safety and regulatory purposes.
You see if you don't meddle with my terminal data in the first place I would feel much better that I am in control of my data, and not reliant on. 3rd parties to accidentally drop guard and leak my data out.
It doesn't "meddle or leak" your terminal data. OpenAI integration only kicks in after explicit user action. Looking at the screenshots, it appears to only become active for the current terminal pane.
https://github.com/gnachman/iTerm2/blob/master/images/Onboar...
Also, iTerm is developed by an actual respect-worthy person who actually cares about this kind of stuff, not by an "AI overlord." It's unfortunate that you instantly chose to make baseless spyware accusations in public forums instead of supporting him for creating the software that you've relied on.