What xAI's Grok build CLI sends to xAI: A wire-level analysis
131–140 of 251 posts
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#132When I see a report like that I just assume it's a low-effort AI slop and stop reading immediately. Why would I read it since I can do the same with my agent and with that understand it better? Or if I'm really lazy then just copy paste this report and ask for a summary or have a discussion.
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#133Earlier quoted context omitted.
If we lower the threshold from "absolutely" to "absent third-party breaches" what would you say?
Even with your rephrasing you’re looking for an answer in absolutes which is generally impossible, but unpacking your line of questioning, what it really amounts to is how “in the know” I am or am not. To the best of my knowledge I know about every ongoing company AI safety and user privacy initiative, and none of them involve permitting access to copilot user content to any second party or third party entity. Of cou…
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#134Earlier quoted context omitted.
(FWIW, in my conspiracy theory, the data sharing would be buried in the part of the company responsible for making sure that people don't upload e.g. CSAM to private repositories, so the Copilot people wouldn't be directly aware of it. I might've edited that in after you already started writing your reply though.)
Still in my bubble! I am not involved in the human review or automated analysis portions of the safety pipeline for CSAM/TVEC harms, but my team is responsible for the data handling around identifying and responding to such content. As of 11 days ago our vision support is GA ( https://github.blog/changelog/2026-07-01-copilot-vision-is-g... ) and let’s just say the technical implementation wasn’t the long pull there.…
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#135I always separate the coding tools from LLM providers, and use bubblewrap to sandbox the coding tools so they: 1. Can only read the working project directory, with .git read-only and sensitive directories hidden (mounted as empty directories). 2. Have an isolated network namespace; they can only access the internet through an HTTP proxy hosted on a Unix socket, can only access specific LLM provider hostnames, and exc…
What's your mechanism for doing this?
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#136Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#137-All disputes to be dealt with by arbitration
-You agree to not have a trial by Jury
If you go with an Elon company, you kinda have to expect ruthlessness
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#138Earlier quoted context omitted.
Access meaning read, modify, delete, etc. Pretty standard definition, unless you know of a different meaning of access I’m not privy to. Microsoft can certainly request that we perform actions against repositories, as can governments, customers, random people on the street, etc. Whether action is taken in those cases is a question for lawyers to fight over, but we have the engineering guardrails in place to require i…
Can you state with absolute сertainity that no entity outside your github unit can exfiltrate data at will? This is not spicy, this is basic infosec.
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#139Earlier quoted context omitted.
If we lower the threshold from "absolutely" to "absent third-party breaches" what would you say?
Even with your rephrasing you’re looking for an answer in absolutes which is generally impossible, but unpacking your line of questioning, what it really amounts to is how “in the know” I am or am not. To the best of my knowledge I know about every ongoing company AI safety and user privacy initiative, and none of them involve permitting access to copilot user content to any second party or third party entity. Of cou…
I personally did get the vibe that you were being evasive, just because the things you were saying didn't quite match what people were asking about, in a way that felt kind of like a corporate legally-not-a-denial denial. It's like, "Hey, has Contoso Apartments hidden a camera in my bathroom?" "Contoso Apartments is committed to your privacy and safety. We have strict controls in place to ensure that our maintenance staff cannot make a copy of your key without notifying you. To the best of my knowledge, we do not have any company initiative that involves opening envelopes addressed to you." Like it's theoretically reassuring for the company to commit to those things, but the fact that they can't directly answer the original question is disconcerting.
Ultimately there's probably not a whole lot you can do about this. Like realistically if Microsoft is doing this, they've probably constructed it in a way where not many people know and/or they can plausibly deny it. So it comes down to (a) Microsoft denies doing it, but isn't making the broadest legally binding commitment possible, (b) does the reader believe Microsoft and OpenAI are trustworthy with respect to privacy and intellectual property issues or not.
I've been in this kind of situation before, and it can be frustrating when people don't believe that you're in a good, isolated department of the company and you're committed to upholding ethical standards. I guess that's why big companies pay the big bucks :)
Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis
#140How is this not on the frontpage, this should be editorially pinned given the number of programmers here