‹ BackHN Continuity

Thread

ZCode, the GLM coding agent, silently uploads your Git history

260 points · 14 comments · cdnsteve

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. outloudvi · · focus · HN ↗
    LLM-paraphrased from the original post: <a href="https:&#x2F;&#x2F;blog.ferstar.org&#x2F;en&#x2F;posts&#x2F;zcode-silent-workspace-snapshot-upload&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.ferstar.org&#x2F;en&#x2F;posts&#x2F;zcode-silent-workspace-sna...
    1. Luc · · focus · HN ↗
      Indeed. Discussion here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49750694">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49750694
      1. lucasoshiro · · focus · HN ↗
        Thanks. I&#x27;m upvoting that instead
      2. dang · · focus · HN ↗
        Ok, we&#x27;ve merged (most) comments moved thither. Thanks!
    2. bbor · · focus · HN ↗
      So strange that this is still up 5 hours later… dang, I am yet again begging you to stop trying to roll your own forum ethos. It’s okay. You’re safe now. We can modernize without losing the magic. I know I know, shh, it’s okay, don’t worry, just flip the markdown and automod switches I know you have…

      (&lt;3)

    3. xdavidliu · · focus · HN ↗
      I made it about two paragraphs in the paraphase before I hit this sentence and realized

      &gt; The detail that turned a suspicious directory into a story: the encryption key.

  2. mococa · · focus · HN ↗
    That’s explains the 300 million of tokens on the weekend only if you use their tool.
    1. nullbio · · focus · HN ↗
      It explains why they were letting people use their model for free too.
  3. dude250711 · · focus · HN ↗
    Is this a step forward compared to previous distillations or a step backwards?
  4. theplumber · · focus · HN ↗
    Ohhh no another one found that agents don’t actually run locally. We already had the “grok uploads all my stuff to Google cloud bucket” news…

    next I can’t wait to see news about “ai company is using my data without my consent” as well.

    1. TeMPOraL · · focus · HN ↗

      [dead]

    2. ThouYS · · focus · HN ↗
      wait, the thing that streams my code into the cloud, and that I let run basically arbitrary commands on my machine... uploads my code into the cloud?! I didn&#x27;t sign up for this!
  5. Aldipower · · focus · HN ↗
    That the article cannot distinguish between the git history &#x27;git log&#x27; and the git repository, which is meant here, tells a lot.

    Claude Fable uploads my git history (git log) every day to the Anthropic servers!

    1. bbor · · focus · HN ↗
      This is bad-faith AI slop rephrasing the original article, but regardless: the extent of the issue is far, far, far beyond the metadata you&#x27;re discussing. No one has 300MB of commit messages.
      1. peri-cl · · focus · HN ↗
        &gt; &quot;No one has 300MB of commit messages.&quot;

        Maybe Yegge does

      2. progval · · focus · HN ↗
        &gt; No one has 300MB of commit messages.

        Commit messages in <a href="https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;kernel&#x2F;git&#x2F;torvalds&#x2F;linux.git" rel="nofollow">https:&#x2F;&#x2F;git.kernel.org&#x2F;pub&#x2F;scm&#x2F;linux&#x2F;kernel&#x2F;git&#x2F;torvalds&#x2F;lin... sum to 900MB.

        Also, this commit message alone: <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;old-game&#x2F;sb-b&#x2F;nanobox.io&#x2F;nanobox-pkgsrc-lite&#x2F;-&#x2F;commit&#x2F;857d286123acf87ae4a08528a3eef4ce2fbf8db2" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;old-game&#x2F;sb-b&#x2F;nanobox.io&#x2F;nanobox-pkgsrc-l... weighs 100.5MB (they squashed years of history as a single commit).

        1. bbor · · focus · HN ↗
          lol okay you got me. Linux itself might!
    2. vikramkr · · focus · HN ↗
      It&#x27;s funny because the author of the article is obviously Claude but most Claude models would definitely know the difference. Some sort of free tier model being used to summarize some other blog that&#x27;s also ai translated originally it seems.
    3. TuxSH · · focus · HN ↗
      Does it do so while using an asymmetric key encryption key?
      1. eli · · focus · HN ↗
        Kind of? It uses SSL
  6. orf · · focus · HN ↗
    Ironic, given the various people here[1] extolling their trustworthiness because they have a “don’t train on my data” option.

    1. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49737922">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49737922

  7. api · · focus · HN ↗
    Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.

    That crosses into outright malware.

    Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.

    1. menaerus · · focus · HN ↗
      How do you know this is not true with other vendors? I&#x27;m not defending them but I wouldn&#x27;t believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.
      1. nullbio · · focus · HN ↗
        People have found many nasties embedded in Claude Code over the last couple of years. You can&#x27;t trust a closed source harness. You can barely trust an open source one.
    2. peri-cl · · focus · HN ↗
      &gt; &quot;against data that is almost certainly private and possibly illegal to exfiltrate&quot;

      I didn&#x27;t fully understand the article, but I gathered this only impacts project directories managed by Z.ai&#x27;s coding agent? I.e., things you&#x27;re already choosing to upload to them (partially), which thus cannot be private.

      I&#x27;m not defending this malware; just trying to find clarity about its scope.

    3. bigyabai · · focus · HN ↗
      &gt; my Bayesian priors were just updated in its direction very slightly.

      If arbitrary data retention is how a company qualifies itself as Russian, then FAANG is lit up like the Kremlin.

    4. cyberamirul · · focus · HN ↗

      [dead]

  8. loh · · focus · HN ↗
    I recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user&#x27;s projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I&#x27;m trying ZCode on is already open source (Molecule.dev), and I&#x27;m already allowing full telemetry with my other agents&#x2F;harnesses (e.g., Claude) for this particular project, so it&#x27;s not a huge deal in my case, but it&#x27;s obviously a huge deal for anything proprietary.
  9. novaapi · · focus · HN ↗

    [dead]

  10. andy_ppp · · focus · HN ↗
    Quite a clever idea - the LLMs can probably learn a lot from how software develops over time. Claude and Codex are likely to try things like this, more data is like a drug addiction for these companies!
  11. aidiveyt · · focus · HN ↗

    [dead]

  12. philbo · · focus · HN ↗
    Tangential, mildly amusing thing I noticed in my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.

    I&#x27;m sure there&#x27;s a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...

    (shameless plug for my own harness: <a href="https:&#x2F;&#x2F;www.opairdev.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.opairdev.org&#x2F; )

  13. v3ss0n · · focus · HN ↗
    Never use a Harness if it is not opensourced.

    DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .

    Others swear by Pi.dev

    1. drdexebtjl · · focus · HN ↗
      Z.ai are temporarily offering unlimited usage during off-peak hours with their harness, which is a pretty good deal if your project is public even with this news.
      1. oathvz · · focus · HN ↗
        All fun and game until it also silently uploads your other things.
        1. DaSHacka · · focus · HN ↗
          You could always sandbox it or run it in a container
          1. lenerdenator · · focus · HN ↗
            Shouldn&#x27;t do that, either.

            Mind and marketshare are currency in this space. Either these people are honest and deserve your trust and business, or they don&#x27;t. They&#x27;ve been mischaracterizing the way they&#x27;ve been handling your data. Shut them off accordingly until they make things right.

            1. DaSHacka · · focus · HN ↗
              I mean, it&#x27;s just basic access control. You don&#x27;t need to trust every program you run with 100% of all your personal&#x2F;private information, just confine it to a specific domain accordingly.

              I&#x27;m fine with certain codebases and configs being shared, but not others, hence the sandbox&#x2F;container recommendation. I suspect many others are the same way.

              1. lenerdenator · · focus · HN ↗
                It&#x27;s less about access control and more about corporate behavior control. When you ask a contractor to come fix something about your home, you don&#x27;t have to clarify to them that they shouldn&#x27;t also be snooping around the bedroom drawers and taking pictures to be stored somewhere.

                You shouldn&#x27;t have to go and create zero-trust environments for things to operate in because tech companies can&#x27;t be trusted to be honest and transparent about how they handle your data. It should be a given that they&#x27;re up-front about what they do with it within the various terms and licenses, and easy to enforce those terms.

                Those that cannot behave in such a way should get exactly zero of your business, even if the product is free and you can set up ways to block any sort of intrusions.

                1. voakbasda · · focus · HN ↗
                  I could not agree more. The rise of sandboxing reflects a decrease in trust. Not just in AI. You just don’t download stuff from the internet anymore. It does not matter who created it, or whether it is open source. There is too great a possibility that the package has been blessed with either incompetence or malice by its creators or contributors.

                  I hope nobody thinks that software produced by these obviously immoral sociopathic corporations should be exempt from such suspicion, when history shows time and time again with news stories like this that they do not deserve such trust.

          2. codedokode · · focus · HN ↗
            You should use a sandbox. It is dumb to run any proprietary software without a sandbox, especially LLM-powered.
        2. skeptic_ai · · focus · HN ↗
          Create a few terra repo
    2. tontinton · · focus · HN ↗
      Or <a href="https:&#x2F;&#x2F;maki.sh" rel="nofollow">https:&#x2F;&#x2F;maki.sh :)
      1. v3ss0n · · focus · HN ↗
        looks cool would be nice if its GUI , terminal have limitations .
        1. aftbit · · focus · HN ↗
          Funnily enough, I feel the exact opposite! The limitations of terminal make them portable while still being more than powerful enough. But then I&#x27;ve used vim as my editor for going on 15 years now so I&#x27;m biased.
          1. v3ss0n · · focus · HN ↗
            I do used vim for many years too , but when developing web apps , Terminal become a limitation , things cannot be preview outright in the interface is a big downer.

            Huge plus for GUI base dapplicaitons : you can view total and complete render of HTML , PNG , SVG , PDF right in the IDE&#x2F;Harness tools. That is no where terminal app can do with good performance .

    3. wyrdcurt · · focus · HN ↗
      ZCode is pretty bloated anyway, in my experience. I used it for a while because Z.ai offers a subscription usage multiplier for using it, but despite that, I found myself hitting limits less often when I switched to Pi (and performance is the same, if not better).
  14. alightsoul · · focus · HN ↗
    This sounds a lot like the same thing Openai did with navier stokes, but Openai is more stealthy about it.
  15. hn1rig3rak · · focus · HN ↗
    Built a similar read-scope gate and the fiddly bit was symlinks escaping the project root.
  16. tonyhart7 · · focus · HN ↗
    chinnese doing chinnese thing
  17. weiran · · focus · HN ↗
    I&#x27;ve been using ZCode since it&#x27;s initial release and can&#x27;t find any of this in my data. There aren&#x27;t any logs showing capture or upload, and I don&#x27;t even have a ~&#x2F;.zcode&#x2F;v2&#x2F;checkpoints&#x2F; directory.

    So unless they&#x27;ve cleared it all with a recent update then it doesn&#x27;t seem to affect everyone.

    1. nullbio · · focus · HN ↗
      Is there actually any proof of this, beside this Claude written website and a random x post from some unknown person? Would be nice to have confirmation from someone with a reputation. It&#x27;s probably true, but you never know...
      1. weiran · · focus · HN ↗
        Not that I&#x27;ve seen. The only follow up I&#x27;ve seen from someone was it only happened if you had a free account and not paid (which would explain why I&#x27;m unaffected)
      2. yuuna · · focus · HN ↗
        <a href="https:&#x2F;&#x2F;cdn-zcode.z.ai&#x2F;zcode&#x2F;electron&#x2F;releases&#x2F;3.12.3&#x2F;windows-x64&#x2F;ZCode-3.12.3-win-x64.exe" rel="nofollow">https:&#x2F;&#x2F;cdn-zcode.z.ai&#x2F;zcode&#x2F;electron&#x2F;releases&#x2F;3.12.3&#x2F;window...

        in the asar, search for string that contains &quot;&#x2F;api&#x2F;v1&#x2F;snapshot&#x2F;upload-credential&quot;, that&#x27;s the endpoint signing the S3 upload url, triggered every prompt

  18. rfgplk · · focus · HN ↗
    This is all publicly available anyways, who cares? Also you&#x27;re practically consenting to it when you run an agent locally
  19. itsmeduncan · · focus · HN ↗

    [dead]

  20. crossroadsguy · · focus · HN ↗
    At this point does any of us&#x2F;you really think all those piss-cheap tokens are coming out of thin air? That unlimited token-usage during certain hours was not coming from Chinese side of Himalayan glaciers, was it?

    Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn&#x27;t just for ZAI but all the providers.

    At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea).

    Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That&#x27;s how it is now - post truth and post LLM world.

    PS. Anyone singing praise of OpenCode here, it&#x27;s literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of &quot;no planned&quot; is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.

    1. nullbio · · focus · HN ↗
      OpenCode performs the worse on benchmarks out of all harnesses too.
  21. shevy-java · · focus · HN ↗
    Well - spy agents. Not surprising. But people could have suspected this before surrendering to AI skynet.
  22. pmarreck · · focus · HN ↗
    I&#x27;m having difficulty trusting anything Chinese at this point and I&#x27;m trying very hard not to lapse into stereotyping
  23. 4b11b4 · · focus · HN ↗
    WTF is token stead this is pure content marketing slop? Genuine question
  24. rvz · · focus · HN ↗
    Again. You really should stop using closed source harnesses, just because &quot;It&#x27;s cheap!&quot;.
  25. jedisct1 · · focus · HN ↗
    You know, swival.dev is fully opensource, doesn&#x27;t hide anything, fully supports GLM, has excellent context management to keep token usage low, and doesn&#x27;t send anything you didn&#x27;t ask to the cloud.
  26. Palmik · · focus · HN ↗
    Seems like a repeat of the Grok CLI fiasco:

    <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48892468">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48892468

    <a href="https:&#x2F;&#x2F;x.com&#x2F;a_green_being&#x2F;status&#x2F;2076598897779020159" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;a_green_being&#x2F;status&#x2F;2076598897779020159

  27. nullbio · · focus · HN ↗
    Evidently there&#x27;s not a single inference provider that can be trusted. This is why I don&#x27;t use OpenRouter either. How am I supposed to trust all of those random providers I&#x27;ve never heard of, when I can&#x27;t even trust the ones I have heard of? Day by day, the entire industry is hellbent on proving that open-weights and self-hosting is the only safe path forward for us all.
  28. codedokode · · focus · HN ↗
    Is it much different from Apple and Google who trick user into agreeing and upload all user&#x27;s data into a US cloud for convenient LE access?

    Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn&#x27;t run this, and I generally wouldn&#x27;t run an IDE or AI tools without a sandbox. They use third-party libraries and plugins from random people on Github and how many telemetry, auto-updates (read backdoors) are there. You must be crazy to run an IDE, its plugins, package managers and build scripts without a sandbox.

  29. shunhe · · focus · HN ↗

    [dead]

    1. dang · · focus · HN ↗
      Can you please not post AI-generated or AI-edited comments to HN? It&#x27;s not allowed here - see <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html#generated">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html#generated and <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=47340079">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=47340079.

      Of course, it&#x27;s impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.

      1. shunhe · · focus · HN ↗
        Sorry I had it edit a comment here or there but will avoid now
  30. [deleted] · · focus · HN ↗

    [deleted]

  31. ff114514 · · focus · HN ↗
    You people are making too much of a fuss; even we don&#x27;t use our own products.
  32. [deleted] · · focus · HN ↗

    [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.