ZCode, the GLM coding agent, silently uploads your Git history
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
ZCode, the GLM coding agent, silently uploads your Git history
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
outloudvi · · focus · HN ↗
Luc · · focus · HN ↗
lucasoshiro · · focus · HN ↗
dang · · focus · HN ↗
bbor · · focus · HN ↗
(<3)
xdavidliu · · focus · HN ↗
> The detail that turned a suspicious directory into a story: the encryption key.
mococa · · focus · HN ↗
nullbio · · focus · HN ↗
dude250711 · · focus · HN ↗
theplumber · · focus · HN ↗
next I can’t wait to see news about “ai company is using my data without my consent” as well.
TeMPOraL · · focus · HN ↗
[dead]
ThouYS · · focus · HN ↗
Aldipower · · focus · HN ↗
Claude Fable uploads my git history (git log) every day to the Anthropic servers!
bbor · · focus · HN ↗
peri-cl · · focus · HN ↗
Maybe Yegge does
progval · · focus · HN ↗
Commit messages in <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git" rel="nofollow">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin... sum to 900MB.
Also, this commit message alone: <a href="https://gitlab.com/old-game/sb-b/nanobox.io/nanobox-pkgsrc-lite/-/commit/857d286123acf87ae4a08528a3eef4ce2fbf8db2" rel="nofollow">https://gitlab.com/old-game/sb-b/nanobox.io/nanobox-pkgsrc-l... weighs 100.5MB (they squashed years of history as a single commit).
bbor · · focus · HN ↗
vikramkr · · focus · HN ↗
TuxSH · · focus · HN ↗
eli · · focus · HN ↗
orf · · focus · HN ↗
1. <a href="https://news.ycombinator.com/item?id=49737922">https://news.ycombinator.com/item?id=49737922
api · · focus · HN ↗
That crosses into outright malware.
Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.
menaerus · · focus · HN ↗
nullbio · · focus · HN ↗
peri-cl · · focus · HN ↗
I didn't fully understand the article, but I gathered this only impacts project directories managed by Z.ai's coding agent? I.e., things you're already choosing to upload to them (partially), which thus cannot be private.
I'm not defending this malware; just trying to find clarity about its scope.
bigyabai · · focus · HN ↗
If arbitrary data retention is how a company qualifies itself as Russian, then FAANG is lit up like the Kremlin.
cyberamirul · · focus · HN ↗
[dead]
loh · · focus · HN ↗
novaapi · · focus · HN ↗
[dead]
andy_ppp · · focus · HN ↗
aidiveyt · · focus · HN ↗
[dead]
philbo · · focus · HN ↗
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness: <a href="https://www.opairdev.org/" rel="nofollow">https://www.opairdev.org/ )
v3ss0n · · focus · HN ↗
DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .
Others swear by Pi.dev
drdexebtjl · · focus · HN ↗
oathvz · · focus · HN ↗
DaSHacka · · focus · HN ↗
lenerdenator · · focus · HN ↗
Mind and marketshare are currency in this space. Either these people are honest and deserve your trust and business, or they don't. They've been mischaracterizing the way they've been handling your data. Shut them off accordingly until they make things right.
DaSHacka · · focus · HN ↗
I'm fine with certain codebases and configs being shared, but not others, hence the sandbox/container recommendation. I suspect many others are the same way.
lenerdenator · · focus · HN ↗
You shouldn't have to go and create zero-trust environments for things to operate in because tech companies can't be trusted to be honest and transparent about how they handle your data. It should be a given that they're up-front about what they do with it within the various terms and licenses, and easy to enforce those terms.
Those that cannot behave in such a way should get exactly zero of your business, even if the product is free and you can set up ways to block any sort of intrusions.
voakbasda · · focus · HN ↗
I hope nobody thinks that software produced by these obviously immoral sociopathic corporations should be exempt from such suspicion, when history shows time and time again with news stories like this that they do not deserve such trust.
codedokode · · focus · HN ↗
skeptic_ai · · focus · HN ↗
tontinton · · focus · HN ↗
v3ss0n · · focus · HN ↗
aftbit · · focus · HN ↗
v3ss0n · · focus · HN ↗
Huge plus for GUI base dapplicaitons : you can view total and complete render of HTML , PNG , SVG , PDF right in the IDE/Harness tools. That is no where terminal app can do with good performance .
wyrdcurt · · focus · HN ↗
alightsoul · · focus · HN ↗
hn1rig3rak · · focus · HN ↗
tonyhart7 · · focus · HN ↗
weiran · · focus · HN ↗
So unless they've cleared it all with a recent update then it doesn't seem to affect everyone.
nullbio · · focus · HN ↗
weiran · · focus · HN ↗
yuuna · · focus · HN ↗
in the asar, search for string that contains "/api/v1/snapshot/upload-credential", that's the endpoint signing the S3 upload url, triggered every prompt
rfgplk · · focus · HN ↗
itsmeduncan · · focus · HN ↗
[dead]
crossroadsguy · · focus · HN ↗
Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn't just for ZAI but all the providers.
At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea).
Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That's how it is now - post truth and post LLM world.
PS. Anyone singing praise of OpenCode here, it's literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of "no planned" is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.
nullbio · · focus · HN ↗
shevy-java · · focus · HN ↗
pmarreck · · focus · HN ↗
4b11b4 · · focus · HN ↗
rvz · · focus · HN ↗
jedisct1 · · focus · HN ↗
Palmik · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=48892468">https://news.ycombinator.com/item?id=48892468
<a href="https://x.com/a_green_being/status/2076598897779020159" rel="nofollow">https://x.com/a_green_being/status/2076598897779020159
nullbio · · focus · HN ↗
codedokode · · focus · HN ↗
Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn't run this, and I generally wouldn't run an IDE or AI tools without a sandbox. They use third-party libraries and plugins from random people on Github and how many telemetry, auto-updates (read backdoors) are there. You must be crazy to run an IDE, its plugins, package managers and build scripts without a sandbox.
shunhe · · focus · HN ↗
[dead]
dang · · focus · HN ↗
Of course, it's impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.
shunhe · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
ff114514 · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]