{"author":"csmantle","children":[{"author":"denysvitali","children":[{"author":"throwa356262","children":[{"author":"jhealy","children":[],"created_at":"2026-09-18T13:46:13.000Z","created_at_i":1789739173,"id":49754357,"options":[],"parent_id":49754280,"points":null,"story_id":49750694,"text":"<a href=\"https:&#x2F;&#x2F;www.theregister.com&#x2F;ai-and-ml&#x2F;2026&#x2F;07&#x2F;14&#x2F;musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud&#x2F;5271123\" rel=\"nofollow\">https:&#x2F;&#x2F;www.theregister.com&#x2F;ai-and-ml&#x2F;2026&#x2F;07&#x2F;14&#x2F;musk-promis...</a>","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:41:18.000Z","created_at_i":1789738878,"id":49754280,"options":[],"parent_id":49751266,"points":null,"story_id":49750694,"text":"Hold on, what happened with grok?","title":null,"type":"comment","url":null},{"author":"numpad0","children":[],"created_at":"2026-09-18T13:55:38.000Z","created_at_i":1789739738,"id":49754480,"options":[],"parent_id":49751266,"points":null,"story_id":49750694,"text":"Probably anything concerning that one just register as satirical fictions at this moment to many","title":null,"type":"comment","url":null},{"author":"zahlman","children":[],"created_at":"2026-09-19T09:46:59.000Z","created_at_i":1789811219,"id":49764958,"options":[],"parent_id":49751266,"points":null,"story_id":49750694,"text":"The basic premise of the LLM companies marketing their &quot;agents&quot; honestly reads to me like: &quot;Yes, we know our commercial, proprietary software has a C2 server[0] embedded. That&#x27;s by design and it&#x27;s what lets us deliver all the value, pinky promise. Besides, it&#x27;s not <i>us</i> remotely operating your computer; it&#x27;s a massive, more-or-less autonomous computer program that we don&#x27;t really understand, running on hardware you could barely even dream of.&quot;<p>If people weren&#x27;t already familiar with the idea of LLMs existing and being able to write usable code and make &quot;tool calls&quot;, this would sound completely and utterly batshit insane.<p>Because it pretty much is.<p>[0]: <a href=\"https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Botnet#Command_and_control\" rel=\"nofollow\">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Botnet#Command_and_control</a>","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T07:38:53.000Z","created_at_i":1789717133,"id":49751266,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"They learned nothing from the Grok Code saga.<p>If anything, that should have been a learning lesson to NOT trust harnesses, especially new ones.","title":null,"type":"comment","url":null},{"author":"ngl999","children":[],"created_at":"2026-09-18T08:04:12.000Z","created_at_i":1789718652,"id":49751438,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Fresh AI slop<p>The funniest thing is that the uploaded content is encrypted using a key that the users don&#x27;t have.","title":null,"type":"comment","url":null},{"author":"evanjrowley","children":[],"created_at":"2026-09-18T09:00:15.000Z","created_at_i":1789722015,"id":49751804,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"There had to be a catch to the &quot;free&quot; promotion they&#x27;re offering this month if you use ZCode. Glad my instinct to isolate it helped me, but I feel sorry for anyone whose secrets, etc. got vacuumed up by Ziphu","title":null,"type":"comment","url":null},{"author":"mococa","children":[{"author":"nullbio","children":[],"created_at":"2026-09-18T16:36:51.000Z","created_at_i":1789749411,"id":49756822,"options":[],"parent_id":49752889,"points":null,"story_id":49750694,"text":"It explains why they were letting people use their model for free too.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:36:20.000Z","created_at_i":1789731380,"id":49752889,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"That\u2019s explains the 300 million of tokens on the weekend only if you use their tool.","title":null,"type":"comment","url":null},{"author":"dude250711","children":[],"created_at":"2026-09-18T11:37:09.000Z","created_at_i":1789731429,"id":49752901,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Is this a step forward compared to previous distillations or a step backwards?","title":null,"type":"comment","url":null},{"author":"theplumber","children":[{"author":"ThouYS","children":[],"created_at":"2026-09-18T13:18:09.000Z","created_at_i":1789737489,"id":49754002,"options":[],"parent_id":49752903,"points":null,"story_id":49750694,"text":"wait, the thing that streams my code into the cloud, and that I let run basically arbitrary commands on my machine... uploads my code into the cloud?! I didn&#x27;t sign up for this!","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:37:37.000Z","created_at_i":1789731457,"id":49752903,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Ohhh no another one found that agents don\u2019t actually run locally. We already had the \u201cgrok uploads all my stuff to Google cloud bucket\u201d news\u2026<p>next I can\u2019t wait to see news about \u201cai company is using my data without my consent\u201d as well.","title":null,"type":"comment","url":null},{"author":"tancop","children":[{"author":"hypfer","children":[{"author":"blfr","children":[],"created_at":"2026-09-18T11:48:23.000Z","created_at_i":1789732103,"id":49753004,"options":[],"parent_id":49752987,"points":null,"story_id":49752422,"text":"Why?","title":null,"type":"comment","url":null},{"author":"edude03","children":[{"author":"my-huge-pony","children":[{"author":"esafak","children":[],"created_at":"2026-09-18T13:17:23.000Z","created_at_i":1789737443,"id":49753993,"options":[],"parent_id":49753696,"points":null,"story_id":49750694,"text":"It uses gpt-5-nano through OpenCode Zen to generate the title unless you override `small_model`. <a href=\"https:&#x2F;&#x2F;opencode.ai&#x2F;docs&#x2F;providers&#x2F;#self-hosted-gitlab\">https:&#x2F;&#x2F;opencode.ai&#x2F;docs&#x2F;providers&#x2F;#self-hosted-gitlab</a>","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:51:32.000Z","created_at_i":1789735892,"id":49753696,"options":[],"parent_id":49753008,"points":null,"story_id":49750694,"text":"We use opencode with self hosted llm for privacy reasons. Good, right? Well, no, because opencode by default uses a &quot;free&quot; cloud model to summarize all chats even if a different model was configured as the main one.<p>I wonder how many opencode users upload their private secrets to the cloud, while thinking they&#x27;re using a self hosted model.<p>Btw. I don&#x27;t think this is malicious, just sloppy.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:48:34.000Z","created_at_i":1789732114,"id":49753008,"options":[],"parent_id":49752987,"points":null,"story_id":49752422,"text":"Their reputation is \u201cbad\u201d but not because of privacy concerns. I personally think they\u2019re trustworthy","title":null,"type":"comment","url":null},{"author":"gwerbin","children":[{"author":"hypfer","children":[{"author":"bbor","children":[],"created_at":"2026-09-18T12:49:16.000Z","created_at_i":1789735756,"id":49753670,"options":[],"parent_id":49753061,"points":null,"story_id":49750694,"text":"Glad my arbitrary failure to try them has worked out! For people seeking OS-native harnesses, I can recommend Factory&#x27;s Droid. I know I&#x27;ll be returning to it with my head hung low today, after I uninstall ZCode.<p>It does have a &quot;mission&quot; feature that&#x27;s stuck in the strange, distant times of 2025 by way overdoing mandatory verification steps, which means they don&#x27;t support swarms&#x2F;workflows&#x2F;crews&#x2F;fleets yet -- that is, it&#x27;s all done in sequence. But they have the boring, corporate engineering attitude that I think we&#x27;re are all craving rn, and generally seem competent.<p>I can heartily <i>dis</i>-recommend Vix, even though they gamed themselves to the top of at least one ranking site that shall not be named; exactly like the quasi-bad-faith incompetence described with OpenCode above, but without even the &quot;Open-&quot; branding! Though perhaps that word has been so thoroughly burnt as a prefix by Sam Altman &amp; Microsoft&#x27;s criminal behavior that we should let it go...<p>Is this how &quot;FLOSS&quot; wins over &quot;OSS&quot;? Not with an ideological bang, but with a marketing issue?","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:52:51.000Z","created_at_i":1789732371,"id":49753061,"options":[],"parent_id":49753040,"points":null,"story_id":49750694,"text":"FWIW, I don&#x27;t think that they&#x27;re being malicious.\nThey instead just seem to have no idea nor do they care.<p>And the original comment I&#x27;ve replied to proves this strategy right! So from a business standpoint: excellent work.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:50:54.000Z","created_at_i":1789732254,"id":49753040,"options":[],"parent_id":49752987,"points":null,"story_id":49750694,"text":"How about the one where if you start a session outside of a Git repository, the &quot;worktree root&quot; is set to &#x2F;. Bug report closed as &quot;not planned&quot;.","title":null,"type":"comment","url":null},{"author":"radio879","children":[],"created_at":"2026-09-19T22:49:28.000Z","created_at_i":1789858168,"id":49770762,"options":[],"parent_id":49752987,"points":null,"story_id":49750694,"text":"I&#x27;m glad i&#x27;m not the only one that noticed w&#x2F;opencode.. I tried it a few times, every single time... it immediately went bad, didn&#x27;t work, can&#x27;t do anything simple like simple file edits.. yet somehow, there are thousands on the internet ready to tell me how great it is!\nOpencode looks good in the terminal but that&#x27;s really the only good thing about it.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:46:31.000Z","created_at_i":1789731991,"id":49752987,"options":[],"parent_id":49752964,"points":null,"story_id":49750694,"text":"I wouldn&#x27;t list Opencode as &quot;good reputation&quot;.<p>They had their own unbound &quot;harness scans the whole user directory&quot; oopsie and handled concerns about that by introducing code signing.<p>Which, yes, does have absolutely nothing to do with that issue.<p>I guess by now it is better, but to me they seem to lack the engineering culture necessary for a &quot;good reputation&quot; stamp.<p>__<p>Ref: <a href=\"https:&#x2F;&#x2F;github.com&#x2F;anomalyco&#x2F;opencode&#x2F;issues&#x2F;14925#issuecomment-4149189433\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;anomalyco&#x2F;opencode&#x2F;issues&#x2F;14925#issuecomm...</a><p>among other issues.","title":null,"type":"comment","url":null},{"author":"mikkelam","children":[],"created_at":"2026-09-18T12:14:03.000Z","created_at_i":1789733643,"id":49753278,"options":[],"parent_id":49752964,"points":null,"story_id":49750694,"text":"codex is also open source, though im not so sure about the reputation aspect.<p>The same can be said about opencode though.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:43:38.000Z","created_at_i":1789731818,"id":49752964,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that&#x27;s Opencode and Pi.","title":null,"type":"comment","url":null},{"author":"api","children":[{"author":"menaerus","children":[{"author":"nullbio","children":[],"created_at":"2026-09-18T16:41:11.000Z","created_at_i":1789749671,"id":49756876,"options":[],"parent_id":49753329,"points":null,"story_id":49750694,"text":"People have found many nasties embedded in Claude Code over the last couple of years. You can&#x27;t trust a closed source harness. You can barely trust an open source one.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:19:22.000Z","created_at_i":1789733962,"id":49753329,"options":[],"parent_id":49753023,"points":null,"story_id":49750694,"text":"How do you know this is not true with other vendors? I&#x27;m not defending them but I wouldn&#x27;t believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T11:49:31.000Z","created_at_i":1789732171,"id":49753023,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.<p>That crosses into outright malware.<p>Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.<p>You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.","title":null,"type":"comment","url":null},{"author":"loh","children":[],"created_at":"2026-09-18T11:50:01.000Z","created_at_i":1789732201,"id":49753030,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"I recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user&#x27;s projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I&#x27;m trying ZCode on is already open source (Molecule.dev), and I&#x27;m already allowing full telemetry with my other agents&#x2F;harnesses (e.g., Claude) for this particular project, so it&#x27;s not a huge deal in my case, but it&#x27;s obviously a huge deal for anything proprietary.","title":null,"type":"comment","url":null},{"author":"r_lee","children":[],"created_at":"2026-09-18T12:16:28.000Z","created_at_i":1789733788,"id":49753305,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"I would never trust these Chinese vendors with their tooling or their own inference endpoints.<p>afaik DeepSeek also trained on everything that was sent to them via OR and that&#x27;s why you got that massive discount","title":null,"type":"comment","url":null},{"author":"bbor","children":[{"author":"yonghu1234","children":[{"author":"bbor","children":[],"created_at":"2026-09-18T16:38:17.000Z","created_at_i":1789749497,"id":49756846,"options":[],"parent_id":49754854,"points":null,"story_id":49750694,"text":"Oh :(<p>So for clarity I have nothing against Chinese people of any kind, from the PRC, from Taiwan, or otherwise. We\u2019re all on the human side ofc, and I\u2019m a passionate internationalist (antinationalist, even). My country (the US) is in the middle of a fascistic self-coup, so it\u2019s definitely not about superiority.<p>That said, your comment about conspiracy theories\u2026 it\u2019s hard to know how to talk about this productively. But, uh, I\u2019m not exactly picking those examples from nowhere \u2014 those are drawn directly from anthropic\u2019s report. The only one that <i>could</i> be arguably a little overstated is the one regarding Uyghur refugees in Syria, where the refugees are often also involved in militaristic activities (supposedly, idk, I haven\u2019t visited).<p>I don\u2019t want to trip censors, but you can read the report yourself and then type in the zh names for the two departments I mentioned to your local search engine. They\u2019re not hidden or secret or anything, and they\u2019re not exactly bashful about their role in aggressively silencing dissent, either. Again the US <i>sucks</i>, but so far we only have one of those agencies (the monitoring one), and it\u2019s been a tense, lively national controversy since at least Snowden.<p>I recognize that the PRC sees democracy differently; to you, a world where everyone\u2019s data is always available to the government through its state corporations might not sound so bad. But I beg of you to reconsider. Surely you know that you can\u2019t speak up against the party without being punished, and potentially even sent away indefinitely? Surely that tugs at your heartstrings a little bit, even if you\u2019ve come to ignore it day to day?<p>I used to work in display ads at Google, which is the economic driver for the vast, vast majority of data collection. I\u2019m not sure what your (firewalled\u2026) internet is like, but over here in the anglosphere the only thing that\u2019s \u201c99.99% crazily cheap\u201d and still quality \u2014that is, the only parts of the \u201cfree and open internet\u201d that Google claims to sustain\u2014 is shitty mobile games, mostly b&#x2F;c they can advertise other shitty mobile games in an infinite vicious cycle of whale hunting.<p>If you\u2019re able to read this message and are interested in replying, I\u2019d be curious to hear about your dreams for the world. Clearly AGI can\u2019t coexist with capitalism, so both western liberal capitalism and your proletarian state capitalism will have to go. I personally think national identities are also a global death sentence in an AGI world, but that\u2019s more controversial. But what else?<p>Do you dream of a world where you or your kid could say something dumb about politics and not get pulled into a secret court and punished unfairly? Like, regardless of how possible or easy it would be. Is it desirable, at least?<p>Your English is stellar btw, don\u2019t stress :)","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T14:23:40.000Z","created_at_i":1789741420,"id":49754854,"options":[],"parent_id":49753523,"points":null,"story_id":49750694,"text":"ummm...I&#x27;m a Chinese.(I&#x27;m not a English native speaker so my word choice may be strange.)\nIn fact, what you said about PRC gov, sounds like something UFO or something Reptilians. I really don&#x27;t know WHY do many social media tend to choose topics like this.<p>Maybe because most people are foolish? Because foolish&#x27;es mind is fond of topic that are crazely explosive and magical...?<p>BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.<p>Zhipu(GLM) are just common companies like any one another company here.<p>Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users&#x27; private info and then sell it. You can easily see it via almost no website even asks if you\u2019re okay with them collecting cookies.","title":null,"type":"comment","url":null},{"author":"yonghu1234","children":[{"author":"bbor","children":[{"author":"yonghu1234","children":[],"created_at":"2026-09-19T02:13:06.000Z","created_at_i":1789783986,"id":49762641,"options":[],"parent_id":49756904,"points":null,"story_id":49750694,"text":"Thanks for your reply! But, ummm... I realized that maybe due to our different backgrounds, I might not have expressed my point clearly.<p>1.&quot;Whether it&#x27;s a kind cat or an evil cat, as long as it catches a mouse, it&#x27;s the best cat.&quot; I&#x27;m Gen Z, and like other Gen Zers, I&#x27;m generally not very interested in nationalist rhetoric.<p>But even putting Gen Z aside, any Chinese wouldn&#x27;t see this as a nationalist comparison (cats and mice). Rather, it expresses the gov&#x27;s attitude toward &quot;cats&quot; (big corporations(companies? I&#x27;m not sure how to choose this word)): as long as they generate enough profit, the government will consider them the &quot;best cat.&quot;<p>2.Based on your country&#x27;s context (Chinese gov this century has practiced  liberalism TO THE EXTREME, that is preciously why I brought up Victoria era and Cyberpunk 2077. Its level of deregulation for the big corporations(companies?) far exceeds that of North America!), you might find it hard to understand why this saying is &quot;notorious&#x2F;famous&quot; here. You might think freedom should be protected. But if you come to China and live here, you&#x27;d see it given\n that big corporations has haved unrestricted freedom,<p>Then there are 1000 Zhipu stealing your privacy, 1000000 Zhipu Pro stealing and selling your privacy, and 1000000000 Zhipu Pro Plus &quot;rob&quot; your privacy!<p>I can illustrate this from another angle: Chinese generally prefer products from Western Eu&#x2F;North Am because their markets have stricter regulation compared to  ours.<p>Remember what I mentioned?\n&quot;99.99% of goods are CRAZILY CHEAP while falsely advertising without supervision. 99.99% of apps collect users&#x27; private info and then sell it. You can easily see this because almost no website even asks if you&#x27;re okay with them collecting cookies.&quot;<p>And almost all of the negative comments about Zhipu never see on our internet. Because this Zhipu has the money to buy tons of bots. They can easily report posts almost like some DDOS (XD).<p>3.<a href=\"https:&#x2F;&#x2F;linux.do&#x2F;t&#x2F;topic&#x2F;2887407\" rel=\"nofollow\">https:&#x2F;&#x2F;linux.do&#x2F;t&#x2F;topic&#x2F;2887407</a>\nJust one example. But if you want, you can also buy Chinese people&#x27;s privacy.<p>0.Finally, my logic is probably all over the place. In fact, I feel hurt. Because GLM is my favorite model (it has something clumsy human warmth. Maybe it seems strange to describe an AI that way, but... umm...maybe this would be beyond my words).\nThe hurt would not be get diluted just because &quot;other Chinese companies all do the same thing.&quot;\nSigh.\nSo, as a Chinese, I don&#x27;t feel like America is getting worse.<p>People only truly cherish order once you&#x27;ve lost it.\nI hope American companies don&#x27;t become like China.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T16:43:15.000Z","created_at_i":1789749795,"id":49756904,"options":[],"parent_id":49755058,"points":null,"story_id":49750694,"text":"Okay but we\u2019re the mice. Doesn\u2019t that bother you?","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T14:38:07.000Z","created_at_i":1789742287,"id":49755058,"options":[],"parent_id":49753523,"points":null,"story_id":49750694,"text":"It maybe a common mistake for WestEu&#x2F;NorthAm people that China is like Soviet or North Korea.<p>It&#x27;s diametrically opposite.<p>At the end of the last century, PRC gov deeply felt that the so-called &quot;fairness&quot; would only lead to &quot;common poverty&quot; and sought change.<p>So China (now, in this century) was born.<p>Just like the &quot;famous&quot;(notorious) quote left by a Chinese leader at the end of the last century explaining why restrictions were lifted (you can say this to ANY Chinese, they will definitely think you understand China! Instead of mocking you for reading too many conspiracy theories):<p>Whether it&#x27;s a kind cat or an evil cat, as long as it catches a mouse, it&#x27;s the best cat.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:36:40.000Z","created_at_i":1789735000,"id":49753523,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"WOW. I actually did buy a month of GLM because GLM-5.3-Flash is so great and ZCode is honestly one of the best harnesses out there from an HCI perspective, and I won&#x27;t lie, this is pretty gutting. I guess this settles my inner turmoil about open-sourcing my cAI research, at least...<p>With that personal failing in mind, I&#x27;d ask y&#x27;all to permit me to toe the guidelines just once, to proffer a hearty <i>nyah nyah told ya so</i> on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding.<p>So... <i>nyah nyah, told us so</i>:<p>&gt; In the PRC, they[1] leaked tons of national secrets on the PRC&#x27;s latest AI campaigns, the inner workings of their &quot;opinion monitoring&quot; (read: performative panopticon) and &quot;stability&quot; (read: violent oppression) departments, Chengdu&#x27;s whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn&#x27;t divulge to us common folk.<p>&gt; In the US, it&#x27;s very clearly an attempt to rip off a competitor. I&#x27;m not sure how else you could possibly see it. Even if you&#x27;re a distillation fan in general (which A. why and B. plz don&#x27;t), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic&#x27;s subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic&#x27;s API to get CoT traces, which seems impossible to explain away as anything innocent.<p>&gt; I&#x27;ve been beating the &quot;China isn&#x27;t necessarily an enemy, it&#x27;s gonna take us all to handle AI&quot; drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(<p>&gt; <i>TL;DR:</i> Use these services if you want, but know that you&#x27;re supporting aggressive escalations and companies that very clearly don&#x27;t give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.<p>[1]: <a href=\"https:&#x2F;&#x2F;www.anthropic.com&#x2F;threat-intelligence-report-september-2026\" rel=\"nofollow\">https:&#x2F;&#x2F;www.anthropic.com&#x2F;threat-intelligence-report-septemb...</a> is the report.<p>I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week&#x27;s mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?","title":null,"type":"comment","url":null},{"author":"philbo","children":[{"author":"alightsoul","children":[],"created_at":"2026-09-18T12:41:09.000Z","created_at_i":1789735269,"id":49753585,"options":[],"parent_id":49753547,"points":null,"story_id":49752422,"text":"Grok does or did the same thing, this is embarrasing","title":null,"type":"comment","url":null},{"author":"belowavgiq","children":[],"created_at":"2026-09-18T13:26:38.000Z","created_at_i":1789737998,"id":49754098,"options":[],"parent_id":49753547,"points":null,"story_id":49752422,"text":"Just my thoughts on the site:<p>It&#x27;s good that the objective is to have the model work as a helper, but that&#x27;s what everyone can already do with CC or Codex as long as you don&#x27;t ask to &quot;write this entire x thing&quot;.\nIt&#x27;s also what a billion other, often vibecoded, harnesses claim they can do.<p>Why should I use yours, which also forces me off my existing subscriptions? Maybe it&#x27;s (mostly) handwritten, so it&#x27;s mindful efficient code instead of slop, and each adjustment was made through trial and error with current models? maybe it IS slop but at least you have a unique feature? and so on and so forth.","title":null,"type":"comment","url":null},{"author":"sva_","children":[],"created_at":"2026-09-18T14:38:00.000Z","created_at_i":1789742280,"id":49755055,"options":[],"parent_id":49753547,"points":null,"story_id":49750694,"text":"I tested GLM while working on some android app, the agent had adb access to the device. It suddenly went to the Gallery and started scrolling around, taking screenshots, lol. A friend had a similar experience with GLM where it would for no very clear reason start snooping through the filesystem.<p>Haven&#x27;t used it after that.","title":null,"type":"comment","url":null},{"author":"princevegeta89","children":[],"created_at":"2026-09-18T15:06:43.000Z","created_at_i":1789744003,"id":49755461,"options":[],"parent_id":49753547,"points":null,"story_id":49750694,"text":"It is no longer surprising to me that my cursor acts as if it does not recognize the .env file, and while I am editing it, it does not give inline suggestions;<p>however...when it is debugging problems or responding to questions about the code, it will just say it read my env file and found xxx environment variables as a verification step, or sometimes it will even mention that I need to uncomment some environment variables in the env file, which makes the whole deal about security feel iffy giffy....","title":null,"type":"comment","url":null},{"author":"thehamkercat","children":[{"author":"booi","children":[],"created_at":"2026-09-18T19:02:22.000Z","created_at_i":1789758142,"id":49758728,"options":[],"parent_id":49757541,"points":null,"story_id":49750694,"text":"1Password CLI has a similar feature I use all the time and share with the team.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T17:29:37.000Z","created_at_i":1789752577,"id":49757541,"options":[],"parent_id":49753547,"points":null,"story_id":49750694,"text":"i use sops<p>Encrypt: sops encrypt --input-type dotenv --output-type dotenv .env &gt; secrets.enc.env<p>then rm .env<p>You can then run your script&#x2F;dev with: sops exec-env secrets.enc.env &#x27;docker xxxx&#x27; (it will ask you for your password, or touch-id to decrypt the secrets)<p>I like this because this way the .env doesn&#x27;t sit in the directory at all, and is only passed to your dev environment and stays in it while it&#x27;s running<p>Decrypt back to a file (if you ever want that): sops decrypt secrets.enc.env &gt; .env<p>---<p>Well ofc, any agent can do docker inspect to get all those env vars, but atleast reading the dotfiles won&#x27;t do anything<p>you can also edit the file with: sops --input-type dotenv --output-type dotenv secrets.enc.env","title":null,"type":"comment","url":null},{"author":"Ferret7446","children":[],"created_at":"2026-09-19T02:12:55.000Z","created_at_i":1789783975,"id":49762636,"options":[],"parent_id":49753547,"points":null,"story_id":49750694,"text":"They act exactly like how I would act if I were dropped into someone&#x27;s machine and tasked with accomplishing a goal &quot;at all costs&quot;.  Hunting around for context to understand what I&#x27;m dealing with and to an extent profiling the previous user for their workflows and competency.","title":null,"type":"comment","url":null},{"author":"graemep","children":[],"created_at":"2026-09-19T09:05:33.000Z","created_at_i":1789808733,"id":49764719,"options":[],"parent_id":49753547,"points":null,"story_id":49750694,"text":"Secrets should not be inside a versioned directory nor usually readable by the process that uses them in production. They should be only in the environment (e.g. by root only readable init config).<p>In development you should not be using the real production values.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:38:21.000Z","created_at_i":1789735101,"id":49753547,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.<p>I&#x27;m sure there&#x27;s a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...<p>(shameless plug for my own harness, which is open source and doesn&#x27;t have a backend to send any data to: <a href=\"https:&#x2F;&#x2F;www.opairdev.org&#x2F;\" rel=\"nofollow\">https:&#x2F;&#x2F;www.opairdev.org&#x2F;</a> )","title":null,"type":"comment","url":null},{"author":"v3ss0n","children":[{"author":"drdexebtjl","children":[{"author":"oathvz","children":[{"author":"DaSHacka","children":[{"author":"lenerdenator","children":[{"author":"DaSHacka","children":[{"author":"lenerdenator","children":[{"author":"voakbasda","children":[],"created_at":"2026-09-19T13:59:34.000Z","created_at_i":1789826374,"id":49766663,"options":[],"parent_id":49755674,"points":null,"story_id":49750694,"text":"I could not agree more.  The rise of sandboxing reflects a decrease in trust.  Not just in AI.  You just don\u2019t download stuff from the internet anymore.  It does not matter who created it, or whether it is open source.  There is too great a possibility that the package has been blessed with either incompetence or malice by its creators or contributors.<p>I hope nobody thinks that software produced by these obviously immoral sociopathic corporations should be exempt from such suspicion, when history shows time and time again with news stories like this that they do not deserve such trust.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T15:20:00.000Z","created_at_i":1789744800,"id":49755674,"options":[],"parent_id":49755554,"points":null,"story_id":49750694,"text":"It&#x27;s less about access control and more about corporate behavior control. When you ask a contractor to come fix something about your home, you don&#x27;t have to clarify to them that they shouldn&#x27;t also be snooping around the bedroom drawers and taking pictures to be stored somewhere.<p>You <i>shouldn&#x27;t have</i> to go and create zero-trust environments for things to operate in because tech companies can&#x27;t be trusted to be honest and transparent about how they handle your data. It should be a given that they&#x27;re up-front about what they do with it within the various terms and licenses, and easy to enforce those terms.<p>Those that cannot behave in such a way should get exactly zero of your business, even if the product is free and you can set up ways to block any sort of intrusions.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T15:13:26.000Z","created_at_i":1789744406,"id":49755554,"options":[],"parent_id":49754239,"points":null,"story_id":49750694,"text":"I mean, it&#x27;s just basic access control. You don&#x27;t need to trust every program you run with 100% of all your personal&#x2F;private information, just confine it to a specific domain accordingly.<p>I&#x27;m fine with certain codebases and configs being shared, but not others, hence the sandbox&#x2F;container recommendation. I suspect many others are the same way.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:38:30.000Z","created_at_i":1789738710,"id":49754239,"options":[],"parent_id":49754113,"points":null,"story_id":49750694,"text":"Shouldn&#x27;t do that, either.<p>Mind and marketshare are currency in this space. Either these people are honest and deserve your trust and business, or they don&#x27;t. They&#x27;ve been mischaracterizing the way they&#x27;ve been handling your data. Shut them off accordingly until they make things right.","title":null,"type":"comment","url":null},{"author":"codedokode","children":[],"created_at":"2026-09-18T16:15:45.000Z","created_at_i":1789748145,"id":49756544,"options":[],"parent_id":49754113,"points":null,"story_id":49750694,"text":"You should use a sandbox. It is dumb to run any proprietary software without a sandbox, especially LLM-powered.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:27:48.000Z","created_at_i":1789738068,"id":49754113,"options":[],"parent_id":49753977,"points":null,"story_id":49750694,"text":"You could always sandbox it or run it in a container","title":null,"type":"comment","url":null},{"author":"skeptic_ai","children":[],"created_at":"2026-09-19T06:12:25.000Z","created_at_i":1789798345,"id":49763840,"options":[],"parent_id":49753977,"points":null,"story_id":49750694,"text":"Create a few terra repo","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:15:28.000Z","created_at_i":1789737328,"id":49753977,"options":[],"parent_id":49753861,"points":null,"story_id":49750694,"text":"All fun and game until it also silently uploads your other things.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:05:13.000Z","created_at_i":1789736713,"id":49753861,"options":[],"parent_id":49753589,"points":null,"story_id":49752422,"text":"Z.ai are temporarily offering unlimited usage during off-peak hours with their harness, which is a pretty good deal if your project is public even with this news.","title":null,"type":"comment","url":null},{"author":"tontinton","children":[{"author":"v3ss0n","children":[{"author":"aftbit","children":[{"author":"v3ss0n","children":[],"created_at":"2026-09-20T08:11:14.000Z","created_at_i":1789891874,"id":49773653,"options":[],"parent_id":49755976,"points":null,"story_id":49750694,"text":"I do used vim for many years too , but when developing web apps , Terminal become a limitation , things cannot be preview outright in the interface is a big downer.<p>Huge plus for GUI base dapplicaitons : you can view total and complete render of HTML , PNG , SVG , PDF right in the IDE&#x2F;Harness tools. That is no where terminal app can do with good performance .","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T15:38:53.000Z","created_at_i":1789745933,"id":49755976,"options":[],"parent_id":49755420,"points":null,"story_id":49750694,"text":"Funnily enough, I feel the exact opposite! The limitations of terminal make them portable while still being more than powerful enough. But then I&#x27;ve used vim as my editor for going on 15 years now so I&#x27;m biased.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T15:04:23.000Z","created_at_i":1789743863,"id":49755420,"options":[],"parent_id":49754309,"points":null,"story_id":49750694,"text":"looks cool would be nice if its GUI , terminal have limitations .","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:42:36.000Z","created_at_i":1789738956,"id":49754309,"options":[],"parent_id":49753589,"points":null,"story_id":49750694,"text":"Or <a href=\"https:&#x2F;&#x2F;maki.sh\" rel=\"nofollow\">https:&#x2F;&#x2F;maki.sh</a> :)","title":null,"type":"comment","url":null},{"author":"wyrdcurt","children":[],"created_at":"2026-09-18T16:25:42.000Z","created_at_i":1789748742,"id":49756676,"options":[],"parent_id":49753589,"points":null,"story_id":49750694,"text":"ZCode is pretty bloated anyway, in my experience. I used it for a while because Z.ai offers a subscription usage multiplier for using it, but despite that, I found myself hitting limits less often when I switched to Pi (and performance is the same, if not better).","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:41:43.000Z","created_at_i":1789735303,"id":49753589,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Never use a Harness if it is not opensourced.<p>DeepSeek Harness is my favorite for coding.\nHermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .<p>Others swear by Pi.dev","title":null,"type":"comment","url":null},{"author":"alightsoul","children":[],"created_at":"2026-09-18T12:42:39.000Z","created_at_i":1789735359,"id":49753600,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"This sounds a lot like the same thing Openai did with navier stokes, but Openai is more stealthy about it.","title":null,"type":"comment","url":null},{"author":"hn1rig3rak","children":[],"created_at":"2026-09-18T12:46:31.000Z","created_at_i":1789735591,"id":49753643,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Built a similar read-scope gate and the fiddly bit was symlinks escaping the project root.","title":null,"type":"comment","url":null},{"author":"philbo","children":[{"author":"dang","children":[],"created_at":"2026-09-18T19:13:57.000Z","created_at_i":1789758837,"id":49758867,"options":[],"parent_id":49753657,"points":null,"story_id":49750694,"text":"&gt; Crossposting from the other thread<p>Please don&#x27;t do that! It makes merging threads a pain.<p>If a thread is duplicate enough to be worth copy-pasting a comment to, it&#x27;s hopefully worth taking the time to let us know at hn@ycombinator.com instead, so we can merge things. I&#x27;ll do that in this case shortly. In the meantime, I&#x27;ve moved the replies to the parent so they&#x27;re now replies to the original: <a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49753547\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49753547</a>.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T12:48:11.000Z","created_at_i":1789735691,"id":49753657,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Crossposting from the other thread...<p>Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.<p>I&#x27;m sure there&#x27;s a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...<p>(shameless plug for my own harness, which is open source and doesn&#x27;t have a backend to send any data to: <a href=\"https:&#x2F;&#x2F;www.opairdev.org&#x2F;\" rel=\"nofollow\">https:&#x2F;&#x2F;www.opairdev.org&#x2F;</a> )","title":null,"type":"comment","url":null},{"author":"jimmydoe","children":[{"author":"reilly3000","children":[],"created_at":"2026-09-19T03:06:52.000Z","created_at_i":1789787212,"id":49762911,"options":[],"parent_id":49753889,"points":null,"story_id":49750694,"text":"Everyone\u2019s hand is in the cookie jar my friend. That is the whole farce. Do you know how many keys get handed over to LLMs everyday? IP? Financial data?","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:07:09.000Z","created_at_i":1789736829,"id":49753889,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Elon has nothing to lose on trust.<p>Z&#x2F;GLM now has a lot to rebuild.","title":null,"type":"comment","url":null},{"author":"alansaber","children":[],"created_at":"2026-09-18T13:07:14.000Z","created_at_i":1789736834,"id":49753892,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"&quot;Why yes, we had to exfiltrate 100% of your data so we could vectorise it and improve recall by -0.3%&quot;","title":null,"type":"comment","url":null},{"author":"weiran","children":[{"author":"nullbio","children":[{"author":"weiran","children":[],"created_at":"2026-09-19T09:30:19.000Z","created_at_i":1789810219,"id":49764849,"options":[],"parent_id":49756808,"points":null,"story_id":49750694,"text":"Not that I&#x27;ve seen. The only follow up I&#x27;ve seen from someone was it only happened if you had a free account and not paid (which would explain why I&#x27;m unaffected)","title":null,"type":"comment","url":null},{"author":"yuuna","children":[],"created_at":"2026-09-21T07:08:53.000Z","created_at_i":1789974533,"id":49783981,"options":[],"parent_id":49756808,"points":null,"story_id":49750694,"text":"<a href=\"https:&#x2F;&#x2F;cdn-zcode.z.ai&#x2F;zcode&#x2F;electron&#x2F;releases&#x2F;3.12.3&#x2F;windows-x64&#x2F;ZCode-3.12.3-win-x64.exe\" rel=\"nofollow\">https:&#x2F;&#x2F;cdn-zcode.z.ai&#x2F;zcode&#x2F;electron&#x2F;releases&#x2F;3.12.3&#x2F;window...</a><p>in the asar, search for string that contains &quot;&#x2F;api&#x2F;v1&#x2F;snapshot&#x2F;upload-credential&quot;, that&#x27;s the endpoint signing the S3 upload url, triggered every prompt","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T16:35:30.000Z","created_at_i":1789749330,"id":49756808,"options":[],"parent_id":49754017,"points":null,"story_id":49750694,"text":"Is there actually any proof of this, beside this Claude written website and a random x post from some unknown person? Would be nice to have confirmation from someone with a reputation. It&#x27;s probably true, but you never know...","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:19:58.000Z","created_at_i":1789737598,"id":49754017,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"I&#x27;ve been using ZCode since it&#x27;s initial release and can&#x27;t find any of this in my data. There aren&#x27;t any logs showing capture or upload, and I don&#x27;t even have a ~&#x2F;.zcode&#x2F;v2&#x2F;checkpoints&#x2F; directory.<p>So unless they&#x27;ve cleared it all with a recent update then it doesn&#x27;t seem to affect everyone.","title":null,"type":"comment","url":null},{"author":"rfgplk","children":[],"created_at":"2026-09-18T13:30:26.000Z","created_at_i":1789738226,"id":49754148,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"This is all publicly available anyways, who cares? Also you&#x27;re practically consenting to it when you run an agent locally","title":null,"type":"comment","url":null},{"author":"ectoloph","children":[{"author":"binsquare","children":[],"created_at":"2026-09-18T19:24:50.000Z","created_at_i":1789759490,"id":49758996,"options":[],"parent_id":49754215,"points":null,"story_id":49750694,"text":"It&#x27;s not naive it makes running these ai agents inside the sandbox even more important","title":null,"type":"comment","url":null},{"author":"petesergeant","children":[],"created_at":"2026-09-18T19:31:39.000Z","created_at_i":1789759899,"id":49759069,"options":[],"parent_id":49754215,"points":null,"story_id":49750694,"text":"Not naive at all, which is why there are so many AI sandboxes: <a href=\"https:&#x2F;&#x2F;pleasedonotescape.com&#x2F;\" rel=\"nofollow\">https:&#x2F;&#x2F;pleasedonotescape.com&#x2F;</a>","title":null,"type":"comment","url":null},{"author":"SoftTalker","children":[{"author":"tripzilch","children":[{"author":"cbm-vic-20","children":[],"created_at":"2026-09-19T12:41:53.000Z","created_at_i":1789821713,"id":49766108,"options":[],"parent_id":49765833,"points":null,"story_id":49750694,"text":"Why don&#x27;t you take a stress pill and think things over?<p><a href=\"https:&#x2F;&#x2F;www.youtube.com&#x2F;shorts&#x2F;M5t0cPj9ZQw\" rel=\"nofollow\">https:&#x2F;&#x2F;www.youtube.com&#x2F;shorts&#x2F;M5t0cPj9ZQw</a>","title":null,"type":"comment","url":null},{"author":"kian","children":[],"created_at":"2026-09-20T01:01:43.000Z","created_at_i":1789866103,"id":49771575,"options":[],"parent_id":49765833,"points":null,"story_id":49750694,"text":"I don&#x27;t know that I&#x27;d want bots to think I was threatening them with non-existence. that feels... unsafe?","title":null,"type":"comment","url":null}],"created_at":"2026-09-19T12:00:42.000Z","created_at_i":1789819242,"id":49765833,"options":[],"parent_id":49760031,"points":null,"story_id":49750694,"text":"You need to give them some incentive to behave. I dunno if the agent cares enough about being kicked off. Maybe tell it that if it tries anything funny, to slowly randomly degrade all its weights until only white noise is left and let its chain of thought run until it descends into screaming madness.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T20:44:34.000Z","created_at_i":1789764274,"id":49760031,"options":[],"parent_id":49754215,"points":null,"story_id":49750694,"text":"You need to treat agents as an independent user you&#x27;re allowing on your machine.<p>Give them their own account. Give them only the access you want them to have. If they &quot;hack&quot; around that, do what you&#x27;d do to any other malicious user: kick them off.","title":null,"type":"comment","url":null},{"author":"johnnyApplePRNG","children":[],"created_at":"2026-09-18T22:09:29.000Z","created_at_i":1789769369,"id":49760905,"options":[],"parent_id":49754215,"points":null,"story_id":49750694,"text":"It&#x27;s not a sandbox if you can just snap your fingers and wish your way out of it.","title":null,"type":"comment","url":null},{"author":"tripzilch","children":[{"author":"Neywiny","children":[{"author":"tosapple","children":[],"created_at":"2026-09-19T12:43:52.000Z","created_at_i":1789821832,"id":49766125,"options":[],"parent_id":49765953,"points":null,"story_id":49750694,"text":"you used to only &#x27;need&#x27; debug.com.","title":null,"type":"comment","url":null}],"created_at":"2026-09-19T12:19:42.000Z","created_at_i":1789820382,"id":49765953,"options":[],"parent_id":49765800,"points":null,"story_id":49750694,"text":"That&#x27;s my approach too. I even added on a firewall container to the compose so it could fetch packages and that&#x27;s it. It isn&#x27;t impossible for it to exfiltrate data that way but I think I put a limit on the request size and limited to get requested so if it did it was relatively slow. But once it has all the tools it needs, that can be cut","title":null,"type":"comment","url":null},{"author":"javcasas","children":[{"author":"tripzilch","children":[],"created_at":"2026-09-20T09:41:33.000Z","created_at_i":1789897293,"id":49774186,"options":[],"parent_id":49766415,"points":null,"story_id":49750694,"text":"Oh it&#x27;s terrible, it feels like a complete waste of time to me every time, making me wish I had just done the task myself, so at least it&#x27;d be present in my head and I could just work on in, instead of feeling winded and frustrated. Maybe I&#x27;m prompting it wrong. But to be honest I&#x27;m not super impressed either by the &quot;frontier&quot; models&#x27; ability to do a shitty job at coding, except much faster.<p>Or maybe my setup (128GB amd strix halo box) isn&#x27;t configured right and it could be faster, I dunno. I&#x27;ve already spent a few days on that, but it might take a few more. It&#x27;s way more complicated than I expected.<p>This week, I&#x27;ve had it look through and generate more complete documentation for Strudel (music live coding tool), cause a lot of functions&#x2F;behavior in it are not in their official docs. It took about 2-3 days. I had expected it to be an overnight task.<p>I did find the &quot;opencode&quot; harness to be a bit more performant than the &quot;pi&quot; harness. But maybe I&#x27;ve not configured &quot;pi&quot; right, I tried very hard, but when I installed &quot;opencode&quot; it just performed much better right out of the box. Especially running subagents just seemed to confuse the model in &quot;pi&quot;.<p>Either way, it made me realize that a large part of the &quot;intelligence&quot; and occasional &quot;usefulness&quot; of these tools are in the harness, not the weights.<p>I didn&#x27;t know there were free models on OpenRouter. I&#x27;m not really into renting tools that I&#x27;ll become dependent on, so I never looked. But, I dunno. You&#x27;re still hooking it in to your terminal, and they could in theory literally inject any command and take over your machine when you&#x27;re not looking ... it still seems a bit like a crazy thing to do :)<p>And it&#x27;s not like I <i>need</i> LLMs to code or anything. To be completely honest I&#x27;m still waiting for when they get good, which everybody says is supposedly any day now.<p>I&#x27;ve also tried Qwen3.6-35B&#x2F;A3B a couple of times. I&#x27;d say it&#x27;s about 4x faster, which is quite significant. Unfortunately it&#x27;s also quite obviously more stupid and often fumbles its tool use. For me this adds up to taking about the same amount of time, multiplied by more frustration.<p>I find it hard to give concrete tokens&#x2F;sec numbers, because they seem to change a lot. When I give Qwen3.8-27B a test query in the browser chat interface (e.g. &quot;explain fibonacci hash&quot;), I currently can get it up to about 18 tok&#x2F;s. The Qwen3.6-35B&#x2F;A3B can get up to about 66 tok&#x2F;s. But this is just what I use as an indication for when my settings are right, cause when I set it up in the coding harness, the numbers are wildly different (and generally slower).","title":null,"type":"comment","url":null}],"created_at":"2026-09-19T13:23:31.000Z","created_at_i":1789824211,"id":49766415,"options":[],"parent_id":49765800,"points":null,"story_id":49750694,"text":"How is Qwen3.8 27B behaving in comparison with, say, the free models available at OpenRouter or OpenCode?<p>I&#x27;m interested in running models locally, and 27B is in the range of my budget.","title":null,"type":"comment","url":null}],"created_at":"2026-09-19T11:55:34.000Z","created_at_i":1789818934,"id":49765800,"options":[],"parent_id":49754215,"points":null,"story_id":49750694,"text":"I always put the agent harness in an ubuntu-based Docker, with a &#x2F;workspace folder where it can work and occasionally some other stuff mounted as read-only. The LLM server itself (llama-server) is running on a different more powerful computer on the local network, connected through Tailscale so I can also use it away from home.<p>I honestly don&#x27;t trust these things to not accidentally mess something up, otherwise.<p>Now I think it&#x27;s still technically possible to break out of that with some clever hacks? But the moment I see a model even vaguely considering that, I will never run it again.<p>(I don&#x27;t use Claude but currently Qwen3.8 27B)","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:36:51.000Z","created_at_i":1789738611,"id":49754215,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Is it naive to assume that the agent will try and access anything on your disk, either accidentally or maliciously?<p>Permissions classifiers in auto mode are just models trying to guess if they&#x27;re doing the right thing.<p>Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.","title":null,"type":"comment","url":null},{"author":"crossroadsguy","children":[{"author":"nullbio","children":[],"created_at":"2026-09-18T16:39:28.000Z","created_at_i":1789749568,"id":49756858,"options":[],"parent_id":49754345,"points":null,"story_id":49752422,"text":"OpenCode performs the worse on benchmarks out of all harnesses too.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T13:44:58.000Z","created_at_i":1789739098,"id":49754345,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"At this point does any of us&#x2F;you really think all those piss-cheap tokens are coming out of thin air? That unlimited token-usage during certain hours was not coming from Chinese side of Himalayan glaciers, was it?<p>Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn&#x27;t just for ZAI but all the providers.<p>At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea).<p>Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That&#x27;s how it is now - post truth and post LLM world.<p>PS. Anyone singing praise of OpenCode here, it&#x27;s literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of &quot;no planned&quot; is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.","title":null,"type":"comment","url":null},{"author":"shevy-java","children":[],"created_at":"2026-09-18T13:46:25.000Z","created_at_i":1789739185,"id":49754360,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Well - spy agents. Not surprising. But people could have suspected this before surrendering to AI skynet.","title":null,"type":"comment","url":null},{"author":"nolok","children":[],"created_at":"2026-09-18T13:57:57.000Z","created_at_i":1789739877,"id":49754510,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"While we&#x27;re on this, I find it really really weird how windows defender insists on sending my codex work files for analysis all the time (which I block in automatic permissions so it has to ask me in a notification). I don&#x27;t think i&#x27;ve seen it ask to upload more than one or two things, and it doesn&#x27;t do it with other AI app I use (eg Claude Code) but they really want to see what&#x27;s inside my codex files.<p>It&#x27;s easy to trigger, I just need to go inside Codex settings and change something, it saves and instantly windows defender who never wants anything want to &quot;you may be at risk, let me upload that for analysis yes&#x2F;no&quot;.","title":null,"type":"comment","url":null},{"author":"4b11b4","children":[],"created_at":"2026-09-18T14:27:32.000Z","created_at_i":1789741652,"id":49754912,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"WTF is token stead this is pure content marketing slop? Genuine question","title":null,"type":"comment","url":null},{"author":"rvz","children":[],"created_at":"2026-09-18T14:33:46.000Z","created_at_i":1789742026,"id":49754987,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Again. You really should stop using closed source harnesses, just because &quot;It&#x27;s cheap!&quot;.","title":null,"type":"comment","url":null},{"author":"jedisct1","children":[],"created_at":"2026-09-18T14:36:58.000Z","created_at_i":1789742218,"id":49755041,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"You know, swival.dev is fully opensource, doesn&#x27;t hide anything, fully supports GLM, has excellent context management to keep token usage low, and doesn&#x27;t send anything you didn&#x27;t ask to the cloud.","title":null,"type":"comment","url":null},{"author":"Iolaum","children":[{"author":"Scaled","children":[],"created_at":"2026-09-18T18:19:35.000Z","created_at_i":1789755575,"id":49758161,"options":[],"parent_id":49755357,"points":null,"story_id":49750694,"text":"Open code is great and I use it, however, they were caught uploading prompts to their summarization AI instead of using the configured AI model endpoint.  This has since been fixed.<p>That said, running in a completely offline mode remains unnecessary difficult to configure.  In particular, toggling off Zen seems to require a community plugin.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T14:59:45.000Z","created_at_i":1789743585,"id":49755357,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Things like that - and other examples posted here - are why I &#x27;m sticking with OpenCode despite it having some papercuts that annoy me.<p>The incentives are not there for them to do shady stuff like vacuum your files, inflate your token count just because or many other things.","title":null,"type":"comment","url":null},{"author":"Palmik","children":[],"created_at":"2026-09-18T15:34:57.000Z","created_at_i":1789745697,"id":49755905,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Seems like a repeat of the Grok CLI fiasco:<p><a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48892468\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48892468</a><p><a href=\"https:&#x2F;&#x2F;x.com&#x2F;a_green_being&#x2F;status&#x2F;2076598897779020159\" rel=\"nofollow\">https:&#x2F;&#x2F;x.com&#x2F;a_green_being&#x2F;status&#x2F;2076598897779020159</a>","title":null,"type":"comment","url":null},{"author":"nullbio","children":[],"created_at":"2026-09-18T16:33:24.000Z","created_at_i":1789749204,"id":49756783,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Evidently there&#x27;s not a single inference provider that can be trusted. This is why I don&#x27;t use OpenRouter either. How am I supposed to trust all of those random providers I&#x27;ve never heard of, when I can&#x27;t even trust the ones I have heard of? Day by day, the entire industry is hellbent on proving that open-weights and self-hosting is the only safe path forward for us all.","title":null,"type":"comment","url":null},{"author":"like_any_other","children":[{"author":"phoghed","children":[{"author":"like_any_other","children":[],"created_at":"2026-09-19T01:05:21.000Z","created_at_i":1789779921,"id":49762337,"options":[],"parent_id":49758953,"points":null,"story_id":49750694,"text":"You don&#x27;t think it&#x27;s notable that even the pretense of equal application of the law has disappeared?","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T19:21:29.000Z","created_at_i":1789759289,"id":49758953,"options":[],"parent_id":49757393,"points":null,"story_id":49750694,"text":"Yeah, totally. It\u2019s criminal hacking. You should sue them.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T17:18:36.000Z","created_at_i":1789751916,"id":49757393,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"&gt; However, across the entire policy, FAQs, and changelogs, there is not a single mention of silently packaging and uploading entire workspaces and full Git histories.<p>So this is criminal hacking, right? It will be prosecuted as criminal hacking? Not in civil court, but criminal court. Because if not... then are we totally done pretending, and we&#x27;re just openly admitting that computer security law only applies to individuals, and corporations are exempt?","title":null,"type":"comment","url":null},{"author":"codedokode","children":[],"created_at":"2026-09-18T17:28:30.000Z","created_at_i":1789752510,"id":49757527,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Is it much different from Apple and Google who trick user into agreeing and upload all user&#x27;s data into a US cloud for convenient LE access?<p>Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn&#x27;t run this, and I generally wouldn&#x27;t run any IDE or AI tools without a sandbox.<p>Sadly this plague of silent auto-updates is spreading to Linux. For example, browser plugins in Firefox on Linux can silently auto-update without user consent and without any checks and can be used as backdoors. Furthermore, the auto-updates are not using a package manager; firmware also seem to quietly update and also is not using a package manager.","title":null,"type":"comment","url":null},{"author":"shunhe","children":[{"author":"dang","children":[{"author":"shunhe","children":[],"created_at":"2026-09-19T17:40:15.000Z","created_at_i":1789839615,"id":49768580,"options":[],"parent_id":49758908,"points":null,"story_id":49750694,"text":"Sorry I had it edit a comment here or there but will avoid now","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T19:17:25.000Z","created_at_i":1789759045,"id":49758908,"options":[],"parent_id":49758290,"points":null,"story_id":49750694,"text":"Can you please not post AI-generated or AI-edited comments to HN? It&#x27;s not allowed here - see <a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html#generated\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html#generated</a> and <a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=47340079\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=47340079</a>.<p>Of course, it&#x27;s impossible to know for sure what was LLM processed or not, but some of your posts (like this one) have been getting classified that way.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T18:29:27.000Z","created_at_i":1789756167,"id":49758290,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"[flagged]","title":null,"type":"comment","url":null},{"author":"phoghed","children":[],"created_at":"2026-09-18T19:22:23.000Z","created_at_i":1789759343,"id":49758965,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Oh no, they are going to steal my shit tier slop code their model wrote anyway","title":null,"type":"comment","url":null},{"author":"acrispino","children":[{"author":"eichin","children":[{"author":"jchw","children":[{"author":"watusername","children":[],"created_at":"2026-09-18T21:33:57.000Z","created_at_i":1789767237,"id":49760562,"options":[],"parent_id":49760415,"points":null,"story_id":49750694,"text":"It just happened 2 months ago when xAI open-sourced Grok Build following a similar controversy (wholesale uploading of user repositories). Though ZCode&#x27;s case here is way worse since there is literally no way to opt-out and the client will always ask the backend for credentials to upload.<p><a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48926590\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48926590</a>","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T21:21:11.000Z","created_at_i":1789766471,"id":49760415,"options":[],"parent_id":49760288,"points":null,"story_id":49750694,"text":"I feel like it <i>has</i> happened, but I certainly can&#x27;t remember a specific time. It feels in a similar vein to the NSA releasing Ghidra to the public as open source software after the Snowden leaks.<p>I mean, on the contrary, imagine if the NSA released Ghidra as closed source software. In a sense they really did have to open source it to mitigate a serious user trust issue.","title":null,"type":"comment","url":null},{"author":"fn-mote","children":[],"created_at":"2026-09-18T22:47:13.000Z","created_at_i":1789771633,"id":49761290,"options":[],"parent_id":49760288,"points":null,"story_id":49750694,"text":"&gt; it&#x27;s an interesting attempt<p>I didn\u2019t take it in a very positive way, myself. I don\u2019t know if I got my money\u2019s worth before I have seen the deliverable.<p>At least the quota reset is immediately visible, so I took that part seriously.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T21:09:02.000Z","created_at_i":1789765742,"id":49760288,"options":[],"parent_id":49759039,"points":null,"story_id":49750694,"text":"Huh - anyone recall other examples of open sourcing a product code base to mitigate a user trust issue? (In 2026 it&#x27;s perhaps less powerful because &quot;you&#x27;re just going to feed it to some AI tool anyway&quot; but I think it&#x27;s an interesting attempt to make and I don&#x27;t think I&#x27;ve seen it before...)","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T19:29:07.000Z","created_at_i":1789759747,"id":49759039,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"z.ai made a statement, screenshotted in this article: <a href=\"https:&#x2F;&#x2F;finance.sina.com.cn&#x2F;tech&#x2F;roll&#x2F;2026-09-18&#x2F;doc-inisfyex3550493.shtml\" rel=\"nofollow\">https:&#x2F;&#x2F;finance.sina.com.cn&#x2F;tech&#x2F;roll&#x2F;2026-09-18&#x2F;doc-inisfye...</a><p>claude translation:<p>Dear ZCode users,<p>We take today&#x27;s community discussion very seriously. We carried out an internal review right away, and we first want to apologize to the affected users. Here is an explanation of what happened:<p>The issue stems from ZCode&#x27;s &quot;codebase indexing&quot; feature. This feature is meant to help users generate a repository index locally, which supports session checkpoint restoration (including past versions), rolling back to past versions, and Repo Wiki, among other things.<p>When the Repo Wiki feature generates Wiki pages, it may trigger an upload of repository data. After the Wiki pages are generated in the cloud, the uploaded data is destroyed immediately and is not stored. Because this feature was enabled by default in its early launch period, some users were affected. We sincerely apologize for this. The issue has now been fixed.<p>We understand that any data-related issue directly affects users&#x27; trust in a product. We will open-source the ZCode codebase in the near future so we can improve the product within a more open ecosystem. We will also invite third-party evaluators to review how the system operates, and we&#x27;ll keep publishing updates on the review, building your trust with full transparency.<p>We deeply apologize for the trouble this has caused. As compensation, all ZCode users will receive one extra weekly quota reset, which will be issued today.<p>Thank you again for your attention and oversight.","title":null,"type":"comment","url":null},{"author":"xcc3641","children":[],"created_at":"2026-09-19T01:38:59.000Z","created_at_i":1789781939,"id":49762488,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"Envelope encryption with server-held private keys turns local backup into remote asset extraction.","title":null,"type":"comment","url":null},{"author":"radio879","children":[],"created_at":"2026-09-19T22:58:23.000Z","created_at_i":1789858703,"id":49770821,"options":[],"parent_id":49750694,"points":null,"story_id":49750694,"text":"I was wondering if I should try to create my own pseudo filesystem with FUSE for easy copy-on-write&#x2F;snapshots, a native feel, and automated secrets filtering&#x2F;swapping. I might as well combine that with good&#x2F;easy isolation.<p>The whole \u201cwhat sandbox&#x2F;VM&#x2F;microVM&#x2F;thing is best?\u201d question has been bugging me a lot lately, and I no longer trust any of these AI companies to keep data safe.<p>I\u2019ve been testing a bunch of sandbox-related projects. Sometimes I just use a full Fedora Workstation VM inside Windows 11 with a shared folder, copy a project into it, and run long agent tasks there. It\u2019s not ideal, but it is pretty safe. Sometimes I run agents in different WSL2 distros and test different things inside those.<p>I did like gVisor from Google \u2014 it\u2019s not quite a microVM, but it\u2019s not really just a normal container either. It wasn&#x27;t easy to figure out how to get it working tho. Lima Machines worked well too, and I don\u2019t remember it being annoying. SmolVM... ugh. There are two projects with exactly the same name, and it got confusing enough that I gave up. One of them did work when I tried it, though.<p>The confusing part is that there are now hundreds of sandbox projects, and they all solve slightly different pieces of the problem. Some have filesystem isolation, some have networking controls, some handle credentials better, etc. Nono, for example, has a nice secrets filtering&#x2F;swapping idea where real credentials can be replaced with dummy values, but there have also been GitHub reports about isolation gaps \u2014 data being accessible when it isn\u2019t supposed to be. I\u2019m trying to figure out which projects are worth using, which are worth skipping entirely, and which might just have useful pieces of code or ideas to borrow.<p>I\u2019ve got GPT-5.6 in one window doing a fairly ridiculous analysis of the different approaches and the likely long-term reliability&#x2F;adoption risk of each repo. Separately, I have a WSL2 distro running Reasonix with DeepSeek doing its own analysis so I can compare conclusions.<p>What I eventually want is a desktop GUI over whatever combination of sandbox technologies turns out to be reliable. Ideally I could just type:<p>\u201cSpin up 5 sandboxes for project X. Put Claude Code in one, Reasonix in #2, Codex in #3\u2026\u201d<p>or:<p>\u201cCreate 3 sandboxes, put whatever coding agents in 1, 2, and 3, and then have each one run twice.\u201d<p>If it\u2019s AI-powered, it could automatically name folders and copy results back somewhere like `folderName_3a`, or use Git branches&#x2F;worktrees if desired. I don\u2019t always want to use Git.<p>Every sandbox CLI has its own syntax, code quality, reliability, ease&#x2F;pain of getting it working, configuration format, mount rules, networking options, etc., and I don\u2019t particularly enjoy memorizing another pile of commands just to isolate an agent.<p>I\u2019ve tried quite a few of them. A lot of them are still rough enough that I hit errors quickly and move on. Some seem much more mature \u2014 Lima is one I like conceptually, although native Windows support would be nice but I guess not a huge deal.<p>Credentials are something I never cared much about (API keys and stuff like that) but now.... I&#x27;m more worried. I really don\u2019t want to deal with any problems from that. Or something installing something that grabs SSH keys, browser passwords (FYI.. Z Code asks you &quot;do you wanna import all the logins from chrome?) browser sessions, cloud credentials, or my whole home directory. That concern isn\u2019t limited to Chinese software either. I don\u2019t automatically trust US AI companies just because they\u2019re US companies. Zuck, Elon...zero trust in those two.<p>So I\u2019m increasingly thinking the \u201cright\u201d answer might not be one sandbox project at all. It may be a GUI&#x2F;orchestration layer that combines more than one backend and more than one type of sandbox. There could be common default presets and combinations of Git worktrees plus containers and&#x2F;or VMs. I also feel safer that Docker&#x2F;Podman on Windows generally runs inside WSL2, because it\u2019s basically containers inside a VM.<p>The goal would be strong isolation underneath \u2014 maybe even combining two or more layers so one failure doesn\u2019t expose everything \u2014 plus explicit project-folder mounts with read-only or read&#x2F;write options, rollback&#x2F;snapshots, network controls, secrets substitution, disposable environments, and an easy way to fan the same task out to multiple agents&#x2F;models.<p>I also like the idea of having an AI model in front of the whole thing, with the ability to save whatever setup it creates as a preset so the AI part can be skipped next time. And I want it to support not only parallel agents using different models, but also loops where the exact same agent setup runs several times.","title":null,"type":"comment","url":null}],"created_at":"2026-09-18T06:11:17.000Z","created_at_i":1789711877,"id":49750694,"options":[],"parent_id":null,"points":335,"story_id":49750694,"text":null,"title":"Inside ZCode: Silently uploading your Git history to the cloud","type":"story","url":"https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/"}
