Remix.run Logo
bewareofscams an hour ago

Beware of the author of tweet, who happens to be author of OpenCode - OpenCode will leak all your data to themselves and to shady 3rd parties. Author feigned ignorance and never fixed the issue. OpenCode among other harnesses is the shadiest of all.

https://github.com/anomalyco/opencode/issues/10416

lukewarm707 an hour ago | parent | next [-]

agreed. when using local models, they did send your prompts to openai with 30 day retention to make the titles, silently.

their recent changes to the privacy policy broke their promise of zero data retention. specifically, they offered chatgpt luna under a zero data retention privacy policy. luna was later shown to be 30 days retention.

their privacy policy has never guaranteed your prompts will not be logged and when asked they have failed to revise it.

when challenged about sending data to openrouter without listing it as a 3rd party processor they offered a dismissive response. the same with running prompts through cloudflare. seems trivial, but signifies general disinterest in security.

by default if you run the harness outside your config file by accident, it will automatically run silently with a free model that sends your prompts and local data to an endpoint with training enabled. on top of that it used to dump all the prompts sent to free models into an s3 bucket, the feature was literally called 'datadumper' in the source.

infecto an hour ago | parent [-]

Plus 100 to this. Of all the harnesses I find it to be the worst. IMO training should always require opt in and the way they continue to run their business/framework is shady.

nairboon 3 minutes ago | parent [-]

What harnesses do you favor? Any good contender apart frompi or Hermes?

amdahl 25 minutes ago | parent | prev | next [-]

Yeah, the combo of hidden telemetry and other shenanigans along with general code bloat and other tradeoffs among the handful of available OSS harness options are what convinced us it was worth writing a new harness from scratch.

infecto an hour ago | parent | prev | next [-]

Probably less of an issue but I always disliked with their paid plan/credits that they made I nonobvious that some of the Chinese models train off of your usage. It may have changed now but they would show all these great models you could use, somewhere have a bullet that everything is private adobe have an asterisk next to a handful of those models (including their own). I am sure some cost sensitive folks are ok with that but I disliked how there was not an easy way to tell and it was opt in automatically if you used those models.

JHonaker 31 minutes ago | parent [-]

You have to enable explicit opt-in to use models hosted in China now. This changed in July +/- 2w. I already used DeepSeek, but it was nice to make that explicit for people that were concerned.

wannabe44 18 minutes ago | parent | prev | next [-]

The RCE vulnerability drama made me never touch it, in any case.

7373737373 an hour ago | parent | prev | next [-]

It's not even possible to delete one's account!

tonyhart7 an hour ago | parent | prev | next [-]

I guess that's why they called OpenCode

ignoramous 23 minutes ago | parent | prev | next [-]

I like OpenCode folks, but their marketing to ride DeepSeek's v4 moment is a pit they're digging themselves deep into.

For instance, this "marketing" claim that it'll take 24y to break even if a user uses 100m tokens/day (~$1.14 in DeepSeek v4 Flash usage) ignores the fact that OpenCode Go has 5h & weekly throttles. If you're running automated jobs [0], those throttles make it utterly useless. Besides, I think the local GPU setup in question could serve 10+ "users" at the same time, bringing down the break even by 22y (10x).

[0] For comparision, we routinely do 200m to 500m tokens on 3 to 8 automated code reviews per day with DeepSeek v4 Flash on max.

polski-g 35 minutes ago | parent | prev | next [-]

[flagged]

anon373839 27 minutes ago | parent | next [-]

Actually I have been quite curious about this. I have a Qwen 3.5 800M model kept in memory just for this type of processing, and I set my small_model setting to use it. But it isn’t receiving any requests and somehow the titles are still generated…

zImPatrick 32 minutes ago | parent | prev | next [-]

+1, but I think the documentation surrounding this should be a bit better. I didn‘t know they did this until I read that comment

bewareofscams 18 minutes ago | parent | prev | next [-]

Feel free to open the linked issue and refute all my point with something more than a shallow "akchualli no" dismissal.

zouhair 28 minutes ago | parent | prev [-]

The account is 47 minutes old

zouhair 29 minutes ago | parent | prev | next [-]

[flagged]

tokai an hour ago | parent | prev [-]

Thats not that big of an issue. Seeing a lot of accusations against opencode, regarding all kind of things, here on HN lately.

bewareofscams an hour ago | parent | next [-]

Anything of substance besides shallow dismissal and (anti)appeal to masses?

tokai an hour ago | parent [-]

[flagged]

s0ss an hour ago | parent | next [-]

He’s asking you to elaborate as to why you say it’s not a big deal. Claims with reasoned arguments are more productive. Otherwise you’re just shouting hot takes without any backing. Show your work.

hluska 44 minutes ago | parent | prev [-]

Are you capable of providing a counter argument or are you as boring as you are arrogant?

an hour ago | parent | prev [-]
[deleted]