Hacker Newsnew | past | comments | ask | show | jobs | submit | more gitgud's commentslogin

This is one of the reasons why native proprietary coding agent runners like claude-code, codex, grok-build etc are so dangerous for privacy… you just don’t know what “secret sauce” they’ll add in the next update…

It’s much safer to use something like opencode and use models via their API… however, the tradeoff is that it will never perform as well as it does in their native agent runners…


Give enough usage, you can reconstruct an entire codebase via tool calls alone, and it'll be entirely undetectable because it's all done server side. Whatever grok's doing is just more blatant, but using opencode or whatever doesn't create a meaningful security boundary. It's like the meme of using cheetos as a lock.


> however, the tradeoff is that it will never perform as well as it does in their native agent runners

There's no reason to assume that. The recent Databricks benchmark in fact showed the exact opposite - that using Pi vs native agent both outperformed native agents in terms of task success, and did so cheaper due to using less tokens.


> the next update

That's a major problem in its own right. Yes, not updating an XP SP1 RCE immediately is dangerous, but in the last couple decades I've seen far more damage inflicted from automatic updates than what I think the lack of them would have caused.


I agree with you, but Codex is open source.


Is the server side open-source too, as gruez brought up in the sibling comment?

Technically they can still do potentially any- and everything undetected there; and for what it’s worth, even with a closed-source client bad behavior would get detected eventually through network inspection.


Yeah. Not the Desktop App though.


its an electron app you an inspect it


I'm using my own agent, but i can't risk blocking the company account with it.....


last time I checked, codex is still open source w Apache-2.0 license


Not allowing full screen is the most insane thing for a “chat app ported from the web”… the browser probably has a better experience now…


The best way to access ChatGPT "chat" was always on ChatGPT.com via a web browser, not even the iOS app seems to have all the little things you can do on the web version.

The Mac desktop ChatGPT app had weird issues like not being able to see the model being used by a chat inside a project etc. I just ended up installing ChatGPT Atlas and using that as an AI-only browser for all LLMs including Claude and Grok lol


Always was better IMO. I just pinned the browser app as a desktop app and have been using it that way for many months. Works great.


> Kirsten: All of this, to me, illustrates how quickly things are moving. I mean, when you really think about it, the whole tokenmaxxxing thing has become a thing, peaked, and now is seen disfavorably, within six months

Pretty sure from inception the phrase “tokenmaxxing” was never seen in a positive light…


Article and this post seems to be AI generated… but this is a good quote

> AI coding assistants hallucinate package names. They confidently suggest npm install some-plausible-sounding-package for packages that do not exist. Attackers monitor those hallucinations and register the names - a technique now called slopsquatting

Slopsquatting is a hilarious name for this


> I realize I don’t have much knowledge about the best way to architect applications

There is no “best way”, it always depends on what you are building.

The main advice I would give is to always remember that there’s trade-off’s in every architectural choice…

I guess some general tenants might be… “great architectural solutions…”

- Allow new features to be added, without much complexity

- Have reliable and clear abstraction layers

- Allow tests and typing to validate it’s correctness

- Manage clearly understood limitations, rather than implicit surprise limitations


> we need to stop filming people, and we need a societal norm that treats a violation of this ban on par with spitting someone in the face.

Agreed. Filming strangers in public is making everyone scared to have fun trying anything new, as they’re afraid of online mockery…


I started believing at 4 years old when going to a christian school, then stopped believing a few years later when I realised I couldn’t see any proof of any god watching, planning or influencing the world in any way at all…


Finding bugs in PR’s are exactly what GitHub copilot, GitHub cursor bot and tonnes of other PR bots already do…


What does the AS stand for?

A polite fyi, when skim reading this, it looked like it said AssNotes…


The company is named App Software Ltd, so presumably that.


You can write your ass notes with it too if you like ;)


Well damn, start the countdown till the inevitable exploit of this.

I’m thinking maybe 1 or 2 weeks from now…


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: