6 ms·
Inside ZCode: Silently Uploading Your Git History to the Cloud
- ccmt7984 16d ago[dead]
- denysvitali 16d agoThey learned nothing from the Grok Code saga. If anything, that should have been a learning lesson to NOT trust harnesses, especially new ones.
- throwa356262 16d agoHold on, what happened with grok?
- jhealy 16d agohttps://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123 https://www.theregister.com/ai-and-ml/2026/07/14/musk-promis...
- numpad0 16d ago[delayed]
- zahlman 15d agoThe basic premise of the LLM companies marketing their "agents" honestly reads to me like: "Yes, we know our commercial, proprietary software has a C2 server[0] embedded. That's by design and it's what lets us deliver all the value, pinky promise. Besides, it's not us remotely operating your computer; it's a massive, more-or-less autonomous computer program that we don't really understand, running on hardware you could barely even dream of." If people weren't already familiar with the idea of LLMs existing and being able to write usable code and make "tool calls", this would sound completely and utterly batshit insane. Because it pretty much is. [0]: https://en.wikipedia.org/wiki/Botnet#Command_and_control https://en.wikipedia.org/wiki/Botnet#Command_and_control
- ngl999 16d agoFresh AI slop The funniest thing is that the uploaded content is encrypted using a key that the users don't have.
- evanjrowley 16d agoThere had to be a catch to the "free" promotion they're offering this month if you use ZCode. Glad my instinct to isolate it helped me, but I feel sorry for anyone whose secrets, etc. got vacuumed up by Ziphu
- coder-pm 16d ago[dead]
- r_lee 16d agoI would never trust these Chinese vendors with their tooling or their own inference endpoints. afaik DeepSeek also trained on everything that was sent to them via OR and that's why you got that massive discount
- bbor 16d agoWOW. I actually did buy a month of GLM because GLM-5.3-Flash is so great and ZCode is honestly one of the best harnesses out there from an HCI perspective, and I won't lie, this is pretty gutting. I guess this settles my inner turmoil about open-sourcing my cAI research, at least... With that personal failing in mind, I'd ask y'all to permit me to toe the guidelines just once, to proffer a hearty nyah nyah told ya so on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding. So... nyah nyah, told us so: > In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk. > In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent. > I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :( > TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess. [1]: https://www.anthropic.com/threat-intelligence-report-september-2026 https://www.anthropic.com/threat-intelligence-report-septemb... is the report. I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week's mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?
- philbo 16d agoCrossposting from the other thread... Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval. I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on... (shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ https://www.opairdev.org/ )
- belowavgiq 16d agoJust my thoughts on the site: It's good that the objective is to have the model work as a helper, but that's what everyone can already do with CC or Codex as long as you don't ask to "write this entire x thing". It's also what a billion other, often vibecoded, harnesses claim they can do. Why should I use yours, which also forces me off my existing subscriptions? Maybe it's (mostly) handwritten, so it's mindful efficient code instead of slop, and each adjustment was made through trial and error with current models? maybe it IS slop but at least you have a unique feature? and so on and so forth.
- dang 16d ago> Crossposting from the other thread Please don't do that! It makes merging threads a pain. If a thread is duplicate enough to be worth copy-pasting a comment to, it's hopefully worth taking the time to let us know at hn@ycombinator.com instead, so we can merge things. I'll do that in this case shortly. In the meantime, I've moved the replies to the parent so they're now replies to the original: https://news.ycombinator.com/item?id=49753547 https://news.ycombinator.com/item?id=49753547.
- jimmydoe 16d agoElon has nothing to lose on trust. Z/GLM now has a lot to rebuild.
- reilly3000 15d agoEveryone’s hand is in the cookie jar my friend. That is the whole farce. Do you know how many keys get handed over to LLMs everyday? IP? Financial data?
- alansaber 16d ago"Why yes, we had to exfiltrate 100% of your data so we could vectorise it and improve recall by -0.3%"
- ectoloph 16d agoIs it naive to assume that the agent will try and access anything on your disk, either accidentally or maliciously? Permissions classifiers in auto mode are just models trying to guess if they're doing the right thing. Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.
- binsquare 16d agoIt's not naive it makes running these ai agents inside the sandbox even more important
- petesergeant 16d agoNot naive at all, which is why there are so many AI sandboxes: https://pleasedonotescape.com/ https://pleasedonotescape.com/
- SoftTalker 16d agoYou need to treat agents as an independent user you're allowing on your machine. Give them their own account. Give them only the access you want them to have. If they "hack" around that, do what you'd do to any other malicious user: kick them off.
- tripzilch 15d agoYou need to give them some incentive to behave. I dunno if the agent cares enough about being kicked off. Maybe tell it that if it tries anything funny, to slowly randomly degrade all its weights until only white noise is left and let its chain of thought run until it descends into screaming madness.
- cbm-vic-20 15d agoWhy don't you take a stress pill and think things over? https://www.youtube.com/shorts/M5t0cPj9ZQw https://www.youtube.com/shorts/M5t0cPj9ZQw
- 14d ago
- nolok 16d agoWhile we're on this, I find it really really weird how windows defender insists on sending my codex work files for analysis all the time (which I block in automatic permissions so it has to ask me in a notification). I don't think i've seen it ask to upload more than one or two things, and it doesn't do it with other AI app I use (eg Claude Code) but they really want to see what's inside my codex files. It's easy to trigger, I just need to go inside Codex settings and change something, it saves and instantly windows defender who never wants anything want to "you may be at risk, let me upload that for analysis yes/no".
- deleted 16d ago[deleted]
- 4b11b4 16d agoWTF is token stead this is pure content marketing slop? Genuine question
- rvz 16d agoAgain. You really should stop using closed source harnesses, just because "It's cheap!".
- jedisct1 16d agoYou know, swival.dev is fully opensource, doesn't hide anything, fully supports GLM, has excellent context management to keep token usage low, and doesn't send anything you didn't ask to the cloud.
- Iolaum 16d agoThings like that - and other examples posted here - are why I 'm sticking with OpenCode despite it having some papercuts that annoy me. The incentives are not there for them to do shady stuff like vacuum your files, inflate your token count just because or many other things.
- Scaled 16d agoOpen code is great and I use it, however, they were caught uploading prompts to their summarization AI instead of using the configured AI model endpoint. This has since been fixed. That said, running in a completely offline mode remains unnecessary difficult to configure. In particular, toggling off Zen seems to require a community plugin.
- Palmik 16d agoSeems like a repeat of the Grok CLI fiasco: https://news.ycombinator.com/item?id=48892468 https://news.ycombinator.com/item?id=48892468 https://x.com/a_green_being/status/2076598897779020159 https://x.com/a_green_being/status/2076598897779020159
- nullbio 16d agoEvidently there's not a single inference provider that can be trusted. This is why I don't use OpenRouter either. How am I supposed to trust all of those random providers I've never heard of, when I can't even trust the ones I have heard of? Day by day, the entire industry is hellbent on proving that open-weights and self-hosting is the only safe path forward for us all.
- like_any_other 16d ago> However, across the entire policy, FAQs, and changelogs, there is not a single mention of silently packaging and uploading entire workspaces and full Git histories. So this is criminal hacking, right? It will be prosecuted as criminal hacking? Not in civil court, but criminal court. Because if not... then are we totally done pretending, and we're just openly admitting that computer security law only applies to individuals, and corporations are exempt?
- phoghed 16d agoYeah, totally. It’s criminal hacking. You should sue them.
- like_any_other 15d agoYou don't think it's notable that even the pretense of equal application of the law has disappeared?
- codedokode 16d agoIs it much different from Apple and Google who trick user into agreeing and upload all user's data into a US cloud for convenient LE access? Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn't run this, and I generally wouldn't run any IDE or AI tools without a sandbox. Sadly this plague of silent auto-updates is spreading to Linux. For example, browser plugins in Firefox on Linux can silently auto-update without user consent and without any checks and can be used as backdoors. Furthermore, the auto-updates are not using a package manager; firmware also seem to quietly update and also is not using a package manager.
- shunhe 16d ago[flagged]
- dang 16d agoCan you please not post AI-generated or AI-edited comments to HN? It's not allowed here - see https://news.ycombinator.com/newsguidelines.html#generated https://news.ycombinator.com/newsguidelines.html#generated and https://news.ycombinator.com/item?id=47340079 https://news.ycombinator.com/item?id=47340079. Of course, it's impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.
- shunhe 15d agoSorry I had it edit a comment here or there but will avoid now
- phoghed 16d agoOh no, they are going to steal my shit tier slop code their model wrote anyway
- acrispino 16d agoz.ai made a statement, screenshotted in this article: https://finance.sina.com.cn/tech/roll/2026-09-18/doc-inisfyex3550493.shtml https://finance.sina.com.cn/tech/roll/2026-09-18/doc-inisfye... claude translation: Dear ZCode users, We take today's community discussion very seriously. We carried out an internal review right away, and we first want to apologize to the affected users. Here is an explanation of what happened: The issue stems from ZCode's "codebase indexing" feature. This feature is meant to help users generate a repository index locally, which supports session checkpoint restoration (including past versions), rolling back to past versions, and Repo Wiki, among other things. When the Repo Wiki feature generates Wiki pages, it may trigger an upload of repository data. After the Wiki pages are generated in the cloud, the uploaded data is destroyed immediately and is not stored. Because this feature was enabled by default in its early launch period, some users were affected. We sincerely apologize for this. The issue has now been fixed. We understand that any data-related issue directly affects users' trust in a product. We will open-source the ZCode codebase in the near future so we can improve the product within a more open ecosystem. We will also invite third-party evaluators to review how the system operates, and we'll keep publishing updates on the review, building your trust with full transparency. We deeply apologize for the trouble this has caused. As compensation, all ZCode users will receive one extra weekly quota reset, which will be issued today. Thank you again for your attention and oversight.
- eichin 16d agoHuh - anyone recall other examples of open sourcing a product code base to mitigate a user trust issue? (In 2026 it's perhaps less powerful because "you're just going to feed it to some AI tool anyway" but I think it's an interesting attempt to make and I don't think I've seen it before...)
- jchw 16d agoI feel like it has happened, but I certainly can't remember a specific time. It feels in a similar vein to the NSA releasing Ghidra to the public as open source software after the Snowden leaks. I mean, on the contrary, imagine if the NSA released Ghidra as closed source software. In a sense they really did have to open source it to mitigate a serious user trust issue.
- xcc3641 15d agoEnvelope encryption with server-held private keys turns local backup into remote asset extraction.
- adirz101 15d ago[flagged]
- radio879 15d agoI was wondering if I should try to create my own pseudo filesystem with FUSE for easy copy-on-write/snapshots, a native feel, and automated secrets filtering/swapping. I might as well combine that with good/easy isolation. The whole “what sandbox/VM/microVM/thing is best?” question has been bugging me a lot lately, and I no longer trust any of these AI companies to keep data safe. I’ve been testing a bunch of sandbox-related projects. Sometimes I just use a full Fedora Workstation VM inside Windows 11 with a shared folder, copy a project into it, and run long agent tasks there. It’s not ideal, but it is pretty safe. Sometimes I run agents in different WSL2 distros and test different things inside those. I did like gVisor from Google — it’s not quite a microVM, but it’s not really just a normal container either. It wasn't easy to figure out how to get it working tho. Lima Machines worked well too, and I don’t remember it being annoying. SmolVM... ugh. There are two projects with exactly the same name, and it got confusing enough that I gave up. One of them did work when I tried it, though. The confusing part is that there are now hundreds of sandbox projects, and they all solve slightly different pieces of the problem. Some have filesystem isolation, some have networking controls, some handle credentials better, etc. Nono, for example, has a nice secrets filtering/swapping idea where real credentials can be replaced with dummy values, but there have also been GitHub reports about isolation gaps — data being accessible when it isn’t supposed to be. I’m trying to figure out which projects are worth using, which are worth skipping entirely, and which might just have useful pieces of code or ideas to borrow. I’ve got GPT-5.6 in one window doing a fairly ridiculous analysis of the different approaches and the likely long-term reliability/adoption risk of each repo. Separately, I have a WSL2 distro running Reasonix with DeepSeek doing its own analysis so I can compare conclusions. What I eventually want is a desktop GUI over whatever combination of sandbox technologies turns out to be reliable. Ideally I could just type: “Spin up 5 sandboxes for project X. Put Claude Code in one, Reasonix in #2, Codex in #3…” or: “Create 3 sandboxes, put whatever coding agents in 1, 2, and 3, and then have each one run twice.” If it’s AI-powered, it could automatically name folders and copy results back somewhere like `folderName_3a`, or use Git branches/worktrees if desired. I don’t always want to use Git. Every sandbox CLI has its own syntax, code quality, reliability, ease/pain of getting it working, configuration format, mount rules, networking options, etc., and I don’t particularly enjoy memorizing another pile of commands just to isolate an agent. I’ve tried quite a few of them. A lot of them are still rough enough that I hit errors quickly and move on. Some seem much more mature — Lima is one I like conceptually, although native Windows support would be nice but I guess not a huge deal. Credentials are something I never cared much about (API keys and stuff like that) but now.... I'm more worried. I really don’t want to deal with any problems from that. Or something installing something that grabs SSH keys, browser passwords (FYI.. Z Code asks you "do you wanna import all the logins from chrome?) browser sessions, cloud credentials, or my whole home directory. That concern isn’t limited to Chinese software either. I don’t automatically trust US AI companies just because they’re US companies. Zuck, Elon...zero trust in those two. So I’m increasingly thinking the “right” answer might not be one sandbox project at all. It may be a GUI/orchestration layer that combines more than one backend and more than one type of sandbox. There could be common default presets and combinations of Git worktrees plus containers and/or VMs. I also feel safer that Docker/Podman on Windows generally runs inside WSL2, because it’s basically containers inside a VM. The goal would be strong isolation underneath — maybe even combining two or more layers so one failure doesn’t expose everything — plus explicit project-folder mounts with read-only or read/write options, rollback/snapshots, network controls, secrets substitution, disposable environments, and an easy way to fan the same task out to multiple agents/models. I also like the idea of having an AI model in front of the whole thing, with the ability to save whatever setup it creates as a preset so the AI part can be skipped next time. And I want it to support not only parallel agents using different models, but also loops where the exact same agent setup runs several times.