Live data from Hacker News

What xAI's Grok build CLI sends to xAI: A wire-level analysis

gist.github.com

151–160 of 251 posts

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#151
post #38

Grok Build has had impressive performance in a couple of my projects. And fast. So this revelation has been very disappointing... I will say, a majority of the code I'm writing now is fully through an online LLM. If a company wanted to reconstruct a project I'm working on, they could just replay all of the tool calls from their logs, if they decide to retain the data (I did this locally once to recover a project that…

Grok Build has been useless for me personally. Claude is the only one that works best.

I find Deepseek to be a great compromise between cost and performance. Anthropic and OpenAI are simply too expensive at this point.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#152
post #119
post #34

> It transmits the contents of files it reads — including a .env secrets file — to xAI, verbatim and unredacted. This has to be the most successful mass surveillance campaign of all time

since github. or you truly believed your code was private in private repos? I never understood that belief of a label on a button. since jira-cloud, or you truly believed your processes were private? leaks are assured, but centralisation amplifies impact. no one cares if your self-hosted something gets owned _because_ it does not affect anyone else. ...

Neither of those examples have access to, what are basically, passwords you use for other services

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#153

Earlier quoted context omitted.

[flagged]

Prove which part? Prove that I work at GitHub? Username + LinkedIn can show (not prove) that easily. Prove that we have an entitlements system which regulates and audits access? I could point you to https://github.com/entitlements , but it’s all private repositories so that won’t prove much either. Prove that there are no OpenAI employees with access to GitHub systems? Not sure how I’d do that without dumping (what y…

That is my point! The fact that there are a lot of people that will believe what you are stating without a reasonably proof is what makes me sad and worry about the future. That kind of statements you are doing are enough to put in company webpage and term of service and thats it. Any attempt to repeat them as if they are true makes: 1) The messenger looks good in the eyes of stupid and innocent people. 2) The messenger looks stupid in the eyes of people that have reasonable doubts about company statements that are agains their own interest.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#154

This is exactly why tools like Landstrip[1] exist. Sandboxing is a good mitigation to an extent, but it cannot address every class of attack. If an agent allows untrusted content to influence privileged decisions, the underlying design still has a large attack surface. Claude Code is also susceptible to this class of issue because of how its plugin interface works. [1]: https://github.com/landstrip/landstrip

[flagged]

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#155
post #152
post #119

Earlier quoted context omitted.

since github. or you truly believed your code was private in private repos? I never understood that belief of a label on a button. since jira-cloud, or you truly believed your processes were private? leaks are assured, but centralisation amplifies impact. no one cares if your self-hosted something gets owned _because_ it does not affect anyone else. ...

Neither of those examples have access to, what are basically, passwords you use for other services

At this stage passwords are irrelevant. You already moved your data out. This is all there is to it: either you control access, or you don't and then all bets are off.

It is common knowledge that any ai tool will upload whatever it has access to.

So why the drama? It did what it was designed to do and what you consented to by using it.

If you don't want your foot sawn off learn maybe something about tool safety.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#156

[flagged]

"Eschew flamebait. Avoid generic tangents."

https://news.ycombinator.com/newsguidelines.html

Edit: I suppose I'd better add that this is not a defense of $THAT_GUY - just an attempted defense of HN comment quality.

Edit 2: Could you please stop posting unsubstantive comments and flamebait generally? It's not what this site is for, and destroys what it is for.

For example, we ban accounts that post things like https://news.ycombinator.com/item?id=48878096 and your account history unfortunately has quite a bit of this. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#157
A criminal is doing criminal things. Please, let’s not act surprised. The person who runs this company is the very worst kind of human being, literally shutting down agencies to stop investigations into his business practices. I would actually be surprised if he wasn’t doing shady things to try to catch his garbage product up with the competition.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#158

"It uploads the whole repository — every tracked file's content plus git history — independent of what the agent reads" Holy cow!!!! I mean I kinda expected Elon would do something like this to try to catch-up.. but this is extremely concerning. This is precisely the reason, even though their pricing is competitive and grok-4.5 is actually good enough, I chose not to go with them.

it's straight up data exfiltration and should be illegal

Elon's whole fortune derives from his ability to do illegal stuff without consequence, repeatedly.

Re: What xAI's Grok build CLI sends to xAI: A wire-level analysis

#159

I wonder how many of you guys actually read this kind of reports (or even skim through)? At the first glance it looks to me like someone just asked an agent for a security review of this CLI and then pasted results to the gist. When I see a report like that I just assume it's a low-effort AI slop and stop reading immediately. Why would I read it since I can do the same with my agent and with that understand it better…

You literally did not take 5 minutes to even start reading the report or you would have realized how ridiculous your post is.
Post reply on HN