bewareofscams
4 hours ago
Beware of the author of tweet, who happens to be author of OpenCode - OpenCode will leak all your data to themselves and to shady 3rd parties. Author feigned ignorance and never fixed the issue. OpenCode among other harnesses is the shadiest of all.
lukewarm707
4 hours ago
agreed. when using local models, they did send your prompts to openai with 30 day retention to make the titles, silently.
their recent changes to the privacy policy broke their promise of zero data retention. specifically, they offered chatgpt luna under a zero data retention privacy policy. luna was later shown to be 30 days retention.
their privacy policy has never guaranteed your prompts will not be logged and when asked they have failed to revise it.
when challenged about sending data to openrouter without listing it as a 3rd party processor they offered a dismissive response. the same with running prompts through cloudflare. seems trivial, but signifies general disinterest in security.
by default if you run the harness outside your config file by accident, it will automatically run silently with a free model that sends your prompts and local data to an endpoint with training enabled. on top of that it used to dump all the prompts sent to free models into an s3 bucket, the feature was literally called 'datadumper' in the source.
infecto
4 hours ago
Plus 100 to this. Of all the harnesses I find it to be the worst. IMO training should always require opt in and the way they continue to run their business/framework is shady.
amdahl
4 hours ago
Yeah, the combo of hidden telemetry and other shenanigans along with general code bloat and other tradeoffs among the handful of available OSS harness options are what convinced us it was worth writing a new harness from scratch.
infecto
4 hours ago
Probably less of an issue but I always disliked with their paid plan/credits that they made I nonobvious that some of the Chinese models train off of your usage. It may have changed now but they would show all these great models you could use, somewhere have a bullet that everything is private adobe have an asterisk next to a handful of those models (including their own). I am sure some cost sensitive folks are ok with that but I disliked how there was not an easy way to tell and it was opt in automatically if you used those models.
JHonaker
4 hours ago
You have to enable explicit opt-in to use models hosted in China now. This changed in July +/- 2w. I already used DeepSeek, but it was nice to make that explicit for people that were concerned.
infecto
2 hours ago
Which is a step in the right direction but for the “built for privacy first” harness they miss the mark.
sunaookami
3 hours ago
Reading this issue was enough for me to never ever consider OpenCode: https://github.com/anomalyco/opencode/issues/6355
wannabe44
3 hours ago
The RCE vulnerability drama made me never touch it, in any case.
7373737373
4 hours ago
It's not even possible to delete one's account!
tonyhart7
4 hours ago
I guess that's why they called OpenCode
ignoramous
4 hours ago
I like the OpenCode team, but their marketing push to ride DeepSeek's v4 moment is a pit they're digging themselves deep into.
For instance, this "marketing" claim that it'll take 24y to break even if a user only uses 100m tokens/day (~$1.14 in DeepSeek v4 Flash usage) ignores the fact that OpenCode Go has 5h & weekly throttles. Besides, folks who self-host models usually run automated jobs [0]. I think the GPU setup could possibly serve 10+ "users" concurrently, bringing down the break even by 22y (10x).
[0] For comparision, we routinely do 200m to 500m tokens ($2 to $5) on merely 3 to 8 automated code reviews per day with DeepSeek v4 Flash on max.
polski-g
4 hours ago
[flagged]
anon373839
4 hours ago
Actually I have been quite curious about this. I have a Qwen 3.5 800M model kept in memory just for this type of processing, and I set my small_model setting to use it. But it isn’t receiving any requests and somehow the titles are still generated…
zImPatrick
4 hours ago
+1, but I think the documentation surrounding this should be a bit better. I didn‘t know they did this until I read that comment
bewareofscams
3 hours ago
Feel free to open the linked issue and refute all my point with something more than a shallow "akchualli no" dismissal.
zouhair
4 hours ago
The account is 47 minutes old
tokai
4 hours ago
[flagged]
bewareofscams
4 hours ago
Anything of substance besides shallow dismissal and (anti)appeal to masses?
tokai
4 hours ago
[flagged]
s0ss
4 hours ago
He’s asking you to elaborate as to why you say it’s not a big deal. Claims with reasoned arguments are more productive. Otherwise you’re just shouting hot takes without any backing. Show your work.
hluska
4 hours ago
Are you capable of providing a counter argument or are you as boring as you are arrogant?
user
4 hours ago
zouhair
4 hours ago
[flagged]