‹ BackHN Continuity

Thread

Inside ZCode: Silently uploading your Git history to the cloud

342 points · 115 comments · csmantle

  1. tancop · · focus · HN ↗
    Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.
    1. hypfer · · focus · HN ↗
      I wouldn't list Opencode as "good reputation".

      They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.

      Which, yes, does have absolutely nothing to do with that issue.

      I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.

      __

      Ref: <a href="https:&#x2F;&#x2F;github.com&#x2F;anomalyco&#x2F;opencode&#x2F;issues&#x2F;14925#issuecomment-4149189433" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;anomalyco&#x2F;opencode&#x2F;issues&#x2F;14925#issuecomm...

      among other issues.

      1. radio879 · · focus · HN ↗
        I&#x27;m glad i&#x27;m not the only one that noticed w&#x2F;opencode.. I tried it a few times, every single time... it immediately went bad, didn&#x27;t work, can&#x27;t do anything simple like simple file edits.. yet somehow, there are thousands on the internet ready to tell me how great it is! Opencode looks good in the terminal but that&#x27;s really the only good thing about it.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.