Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Bend 2 and the Vibe-Coding Trap(liampwll.com ↗)
    144comments
  2. An Empirical Study of Harness Design for Coding Agents(arxiv.org ↗)
    5comments
  3. AI chatbots becoming experts at changing people's minds. What's their secret?(science.org ↗)
    26comments
  4. I don't like passkeys(hawksley.dev ↗)
    210comments
  5. ZCode, the GLM coding agent, silently uploads your Git history(tokenstead.ai ↗)
    43comments
  6. OpenJev(openjev.com ↗)
    174comments
  7. The Shadows Lurking in the Equations – Underwater Islands(gods.art ↗)
    3comments
  8. Subnormal floating-point numbers are expensive on Intel processors(lemire.me ↗)
    27comments
  9. Jemalloc 5.4.0(github.com/jemalloc ↗)
    59comments
  10. Microsoft exec called AI scraping 'the largest theft of labor in human history'(techcrunch.com ↗)
    430comments
  11. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss
  12. Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him(nytimes.com ↗)
    95comments
  13. Show HN: Navier-Stokes Visualized as 1kB i386 demos(juandecos.github.io ↗)
    3comments
  14. Replacing Pull Requests with Delta(zed.dev ↗)
    44comments
  15. If materialism is true, the United States is probably conscious(jstor.org ↗)
    37comments
  16. The scourge of x86 emulation(fex-emu.com ↗)
    54comments
  17. Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint(prismml.com ↗)
    160comments
  18. Astra for Law(openai.com ↗)
    639comments
  19. Bend – A language that blocks AI mistakes via proof, on CPU and GPU(bend-lang.com ↗)
    265comments
  20. Qwen 3.8 Omni Flash(qwen.ai ↗)
    101comments
  21. Hister: A private search engine for the pages you visit and the files you keep(github.com/asciimoo ↗)
    177comments
  22. Wax motor(wikipedia.org ↗)
    87comments
  23. When the fractional part of a float fixes your shader(crocidb.com ↗)
    11comments
  24. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    240comments
  25. NATS publishes preliminary report on technical incident of 8 September(nats.aero ↗)
    discuss
  26. Pre-Greek: The lost language hidden within Ancient Greek(linguisticdiscovery.com ↗)
    56comments
  27. How to Write with an LLM(sockpuppet.org ↗)
    164comments
  28. A heap overflow and SSO misconfiguration to compromise OpenAI internal repos(hacktron.ai ↗)
    169comments
  29. New wild cat species discovered – with only one known living member(bbc.com ↗)
    1comments
  30. Dr Julius Neubronner's Miniature Pigeon Camera(publicdomainreview.org ↗)
    discuss

ZCode, the GLM coding agent, silently uploads your Git history

202 pointsby 4h agotokenstead.ai
42 comments
3h agoHN ↗

That’s explains the 300 million of tokens on the weekend only if you use their tool.

2h agoHN ↗

Is this a step forward compared to previous distillations or a step backwards?

2h agoHN ↗

Ohhh no another one found that agents don’t actually run locally. We already had the “grok uploads all my stuff to Google cloud bucket” news…

next I can’t wait to see news about “ai company is using my data without my consent” as well.

1h agoHN ↗

wait, the thing that streams my code into the cloud, and that I let run basically arbitrary commands on my machine... uploads my code into the cloud?! I didn't sign up for this!

2h agoHN ↗

That the article cannot distinguish between the git history 'git log' and the git repository, which is meant here, tells a lot.

Claude Fable uploads my git history (git log) every day to the Anthropic servers!

1h agoHN ↗

This is bad-faith AI slop rephrasing the original article, but regardless: the extent of the issue is far, far, far beyond the metadata you're discussing. No one has 300MB of commit messages.

1h agoHN ↗

It's funny because the author of the article is obviously Claude but most Claude models would definitely know the difference. Some sort of free tier model being used to summarize some other blog that's also ai translated originally it seems.

30m agoHN ↗

Does it do so while using an asymmetric key encryption key?

2h agoHN ↗

Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.

2h agoHN ↗

I wouldn't list Opencode as "good reputation".

They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.

Which, yes, does have absolutely nothing to do with that issue.

I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.

__

Ref: https://github.com/anomalyco/opencode/issues/14925#issuecomm...

among other issues.

2h agoHN ↗

Their reputation is “bad” but not because of privacy concerns. I personally think they’re trustworthy

1h agoHN ↗

We use opencode with self hosted llm for privacy reasons. Good, right? Well, no, because opencode by default uses a "free" cloud model to summarize all chats even if a different model was configured as the main one.

I wonder how many opencode users upload their private secrets to the cloud, while thinking they're using a self hosted model.

Btw. I don't think this is malicious, just sloppy.

2h agoHN ↗

How about the one where if you start a session outside of a Git repository, the "worktree root" is set to /. Bug report closed as "not planned".

2h agoHN ↗

FWIW, I don't think that they're being malicious. They instead just seem to have no idea nor do they care.

And the original comment I've replied to proves this strategy right! So from a business standpoint: excellent work.

1h agoHN ↗

Glad my arbitrary failure to try them has worked out! For people seeking OS-native harnesses, I can recommend Factory's Droid. I know I'll be returning to it with my head hung low today, after I uninstall ZCode.

It does have a "mission" feature that's stuck in the strange, distant times of 2025 by way overdoing mandatory verification steps, which means they don't support swarms/workflows/crews/fleets yet -- that is, it's all done in sequence. But they have the boring, corporate engineering attitude that I think we're are all craving rn, and generally seem competent.

I can heartily dis-recommend Vix, even though they gamed themselves to the top of at least one ranking site that shall not be named; exactly like the quasi-bad-faith incompetence described with OpenCode above, but without even the "Open-" branding! Though perhaps that word has been so thoroughly burnt as a prefix by Sam Altman & Microsoft's criminal behavior that we should let it go...

Is this how "FLOSS" wins over "OSS"? Not with an ideological bang, but with a marketing issue?

1h agoHN ↗

Is this how "FLOSS" wins over "OSS"? Not with an ideological bang, but with a marketing issue?

Nah, I don't think so. Also, we arguably do not want FLOSS to "win" over OSS, because that just means people with no taste or sense cluttering up the repos, issues and support chats.

"Open" being used as a signal for non-hacker people was a weird and unpleasant development, but, if you think about it, it might be a blessing in disguise and shall keep them away from the more pleasant spaces.

It's not that they'd care about being scammed, mistreated and rug-pulled anyway. They want that. They do it themselves all the time. Every time they encounter a space that treats them well, they terraform it into baseline miserable-ness.

So let them have the "Open" prefix. It's just words, anyway.

49m agoHN ↗

This is kinda beside the point and this whole thread may be wiped when dang wakes up and notices the AI slop article we're commending under, but your reply is thought provoking so I'll attempt a response anyway;

I'm sure you're far more experienced than I with basically every aspect of this discussion, but I'd argue that's given you a blindspot, here. I'll hit some specifics below, but the headline is that you're effectively taking a stand against Eternal September II -- a goal that I hope we can all agree would be quixotically antisocial, given what followed the first one!

  we arguably do not want FLOSS to "win" over OSS

I think(/hope) that fellow FLOSS proponents would passionately disagree. FLOSS isn't a brand of chatroom, nor even merely a community: it's an ethos regarding labor, property, and liberty. Demanding that all users of your software are also activists for your particular take on intellectual property is clearly a doomed undertaking for anything beyond a toy or library, anyway.

Didn't you get into this stuff to change the world? To liberate the oppressed, undereducated, and forgotten with the radical power of the information superhighway? Cause it reads here like you're more motivated by selfishness (not wanting to bother talking to people with less expertise than you) and resentment. On that note...

  They want that. They do it themselves all the time.

Here you equate "non-hacker people" with software engineers you don't agree with, it seems. You're ofc welcome to think companies X Y & Z produce "miserable-ness", but as absurd as it sounds, it sure seems like you've forgotten the fact that some users are not developers. Many, in fact! Over 99%, even!

Less confrontationally; my mom is in her late 60s, and is pretty computer-literate for her age after decades of knowledge work. Surely you'd agree that she's not, like, evil for using OSX, iOS, GMail, Word, etc.? That she didn't chose those things because of a philosophical commitment to defending IP laws, but rather because of structural reasons? Even if she were pro-IP, wouldn't we want to win good, well-meaning people to our side?

  So let them have the "Open" prefix. It's just words, anyway.

I do agree with this still, but as a philosopher I just have to say that everything is just words. It's language games, in fact! Which is why I simply had to reply.

I hope none of the above was rude; I'm trying hard to keep my passion for this topic from pushing me past HN guidelines :)

2h agoHN ↗

codex is also open source, though im not so sure about the reputation aspect.

The same can be said about opencode though.

2h agoHN ↗

Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.

That crosses into outright malware.

Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.

You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.

2h agoHN ↗

How do you know this is not true with other vendors? I'm not defending them but I wouldn't believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.

2h agoHN ↗

I recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user's projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I'm trying ZCode on is already open source (Molecule.dev), and I'm already allowing full telemetry with my other agents/harnesses (e.g., Claude) for this particular project, so it's not a huge deal in my case, but it's obviously a huge deal for anything proprietary.

1h agoHN ↗

Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.

I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...

(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ )

1h agoHN ↗

Grok does or did the same thing, this is embarrasing

1h agoHN ↗

Never use a Harness if it is not opensourced.

DeepSeek Harness is my favorite for coding. Hermes is my favourite for Other things , followed by OpenCode (sucks at managing long running services) .

Others swear by Pi.dev

1h agoHN ↗

Z.ai are temporarily offering unlimited usage during off-peak hours with their harness, which is a pretty good deal if your project is public even with this news.

1h agoHN ↗

All fun and game until it also silently uploads your other things.

1h agoHN ↗

You could always sandbox it or run it in a container

58m agoHN ↗

Shouldn't do that, either.

Mind and marketshare are currency in this space. Either these people are honest and deserve your trust and business, or they don't. They've been mischaracterizing the way they've been handling your data. Shut them off accordingly until they make things right.

1h agoHN ↗

This sounds a lot like the same thing Openai did with navier stokes, but Openai is more stealthy about it.

1h agoHN ↗

Built a similar read-scope gate and the fiddly bit was symlinks escaping the project root.

1h agoHN ↗

I've been using ZCode since it's initial release and can't find any of this in my data. There aren't any logs showing capture or upload, and I don't even have a ~/.zcode/v2/checkpoints/ directory.

So unless they've cleared it all with a recent update then it doesn't seem to affect everyone.

1h agoHN ↗

This is all publicly available anyways, who cares? Also you're practically consenting to it when you run an agent locally

51m agoHN ↗

At this point does any of us/you really think all those piss-cheap tokens are coming out of thin air? That unlimited token-usage during certain hours was not coming from Chinese side of Himalayan glaciers, was it?

Besides why would you use a closed source harness from a certain place, even if you decide to use the model (if nothing then for the price alone). And, that first remark wasn't just for ZAI but all the providers.

At this point: wrapping the harness around something like sandbox-exec or agent-safehouse is a must. Better still, create a new user account (after so much resistance I am warming up to the idea).

Will ZAI see a blowback after this news? Naah. People will keep using it. Hell, I will keep using it. That's how it is now - post truth and post LLM world.

PS. Anyone singing praise of OpenCode here, it's literally one of the worst harneses, open or not. Just look at their fricking issues - the strategic and rampant placements of "no planned" is mind boggling. And for what? Slightly better than ClaudeCode in token consumption and that too starts getting muddled after a while.

50m agoHN ↗

Well - spy agents. Not surprising. But people could have suspected this before surrendering to AI skynet.

38m agoHN ↗

While we're on this, I find it really really weird how windows defender insists on sending my codex work files for analysis all the time (which I block in automatic permissions so it has to ask me in a notification). I don't think i've seen it ask to upload more than one or two things, and it doesn't do it with other AI app I use (eg Claude Code) but they really want to see what's inside my codex files.

It's easy to trigger, I just need to go inside Codex settings and change something, it saves and instantly windows defender who never wants anything want to "you may be at risk, let me upload that for analysis yes/no".

9m agoHN ↗

WTF is token stead this is pure content marketing slop? Genuine question