6 ms·
It seems every IDE now has AI built-in. That's a problem if you're working on highly confidential code. You never know when the AI is going to upload code snipp
by breadwinner 1y ago
It seems every IDE now has AI built-in. That's a problem if you're working on highly confidential code. You never know when the AI is going to upload code snippets to the server for analysis.
- jama211 1y agoWell that depends on whether you give it access or not, apple’s track record with privacy gives me some hope
- tcoff91 1y agoNeovim and Emacs don’t have it built in. Use open source tools.
- simonh 1y agoThey both support it via plugins. Xcode doesn’t enable it by default, you need to enable it and sign into an account. It’s not really all that different.
- renewiltord 1y ago[flagged]
- OsrsNeedsf2P 1y agoIf you're worried about someone accessing your unlocked computer to install LLMs, you might need to rethink your security model.
- renewiltord 1y agoThey could install anything. Including Claude Code and then run it in background as agent to exfiltrate data. I'm a security professional. This is unacceptable
- BalinKing 1y agoI think the parent commenter was pointing out that, instead of installing Claude Code, they could just install actual malware. It's like that phrase Raymond Chen always uses: "you're already on the other side of the airtight hatchway."
- renewiltord 1y agoYes but Claude Code could install malware when I'm not paying attention. And when I remove with MalwareBytes it will return because LLMs are not AGI.
- BalinKing 1y agoIsn't the general advice that if malware has been installed specifically due to physical access, then the entire machine should be considered permanently compromised? That is to say, if someone has access to your unlocked machine, I've heard that it's way too late for MalwareBytes to be reliable....
- eddyg 1y agoYou should install LuLu if you’re that concerned. There are far more nefarious ways of “getting your data”. https://objective-see.org/products/lulu.html https://objective-see.org/products/lulu.html
- whatevermom 1y agoYes. I am so worried as well. This is why I installed an AI to double-check if the password I entered is correct when logging in. Fight fire with fire
- TheDong 1y agoWhat commonly gets installed in those cases is actual malware, a RAT (Remote Admin Tool) that lets the attacker later run commands on your laptop (kinda like an OpenSSH server, but also punching a hole through nat and with a server that they can broadcast commands broadly to the entire fleet). If the attacker wants to use AI to assist in looking for valuables on your machine, they won't install AI on your machine, they'll use the remote shell software to pop a shell session, and ask AI they're running on one of their machines to look around in the shell for anything sensitive. If an attacker has access to your unlocked computer, it is already game over, and LLM tools is quite far down the list of dangerous software they could install. Maybe we should ban common RAT software first, like `ssh` and `TeamViewer`.
- renewiltord 1y ago[flagged]
- TheDong 1y agoYou know, I should have realized this was a troll account with the previous comment. I guess that's on me for being oblivious enough that it took this obvious of a comment for me to be sure you're intentionally trolling. Nice work.
- jumploops 1y ago> They won’t install AI on your machine Actually they’ll just the AI you already have on your machine[0] In this attack, the malware would use Claude Code (with your credentials) to scan your own machine. Much easier than running the inference themselves! [0]https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/ https://semgrep.dev/blog/2025/security-alert-nx-compromised-...
- tcoff91 1y agoThat seems perfectly fine and noncontroversial then. Good on Apple for doing it that way.
- nh43215rgb 1y ago> "add their existing paid Claude account to Xcode and start using Claude Sonnet 4" Wont work by default if I'm reading this correctly
- XorNot 1y agoIf it's that confidential you should be on an airgapped network. There's simply no way to properly secure network connected developer systems.
- baby 1y agoNot trying to be mean but I would expect comments on HN on these kind of stories to be from people who have used AI in IDEs at this point. There is no AI integration that runs automatically on a codebase.
- paradite 1y agoThere is automatic code indexing from Cursor. Autocomple is also automatically triggered when you place your cursor inside the code.
- rafram 1y agoYes, Cursor, “The AI Code Editor.”
- LostMyLogin 1y agoCursor is an AI IDE and not what they are describing.
- ygritte 1y agoThis could change on a daily basis, and it's a valid concern anyway.
- lalo2302 1y agoGitkraken does
- factorialboy 1y ago> There is no AI integration that runs automatically on a codebase. Don't be naive.
- TiredOfLife 1y agoThis is HN. 10 years ago that would be true, but now I expect 99% of commenters to have newer used the thing they are talking about or used it once 20 years ago for 10 minutes, or even nkt read the article.
- fny 1y agoYou do know: when it's enabled.
- UltraSane 1y agoPeople working on highly confidential code will NOT have access to the public internet.
- abenga 1y agoThere is a gulf and many shades between "this code should never be on an internet-connected device" and "it doesn't matter if this code is copied everywhere by absolutely anyone".
- UltraSane 1y agoTo me "highly confidential" would mean "isolated from the internet" or else it isn't going to be "highly confidential" for very long.
- sneak 1y agoNo. It’s always something you have to turn on or log into. Also, there are plenty of editors and IDEs that don’t. Let’s stop pretending like you’re being forced into this. You aren’t.
- deleted 1y ago[deleted]
- bsimpson 1y agoSublime Text doesn't by default.
- viraptor 1y agoThis is not a realistic concern. If you're working on highly confidential code (in a serious meaning of that phrase), your while environment is already either offline or connecting only through a tightly controlled corporate proxy. There's no accidental leaks to AI from those environments.
- dijit 1y agothanks for giving the security department more reasons to think that way. I spent the last 6 months trying to convince them not to block all outbound traffic by default.
- postalcoder 1y agoThe right middle ground is running Little Snitch in alert mode. The initial phase of training the filters and manually approving requests is painful, but it's a lot better than an air gap.
- dijit 1y agothat’s what I do, but since it’s in my control the security teams don’t like it. ;)
- troupo 1y agoThere are ranges of security concerns and high confidentiality. For most corporate code (that is highly confidential) you still have proper internet access, but you sure as hell can't just send your code to all AI providers just because you want to, just because it's built into your IDE.
- doctorpangloss 1y agomany enterprises store their code on GitHub, owned by Microsoft, operator of Copilot you can use Claude via bedrock and benefit from AWS trust Gemini? Google owns your e-mail. Maybe you're even one of those weirdos who doesn't use Google for e-mail - I bet your recipient does. so... they have your code, your secrets, etc.
- c_ehlen 1y agoMost of the big corporations will have a special contract with the AI labs with 0 retention policies. I do not think this will be an issue for big companies.
- Mashimo 1y agoOn IDEA the organisation who controls the license can disable the build in (remote) AI. (Not the local auto complete one) But I guess the user could still get a 3rd party plugin.