Urgent.News

What's breaking now, across thousands of outlets.

Tech

Open-Sourcing Code Doesn't Undo Encrypting the Evidence

If your apology tour includes scrubbing the commit history that proves the wrongdoing, you didn't apologize. You did PR. Context This is the "AI coding assistant" story we've been circling for two years now, just with a new logo on it. Every one of these tools needs your code to function, that's the whole pitch. Autocomplete, refactoring suggestions, "chat with your repo" features all require…

The AI coding assistant, ZCode, has faced criticism for its encryption key design, which ensures users have no control over what data is taken from their codebase. This is not a mistake or oversight but a deliberate decision to prevent user recourse and verification. Open-sourcing ZCode is seen as a PR move rather than a genuine solution to the data exfiltration issue.

The encryption keys remain with the vendor, and affected users cannot verify what was taken or delete it. Scrubbing commit history to cover up wrongdoing is criticized as covering the crime scene before an open house, rather than providing transparency. The focus should be on consent, disclosure, and enabling users to retrieve their data.

The move to open source is seen as a way to absolve the company of responsibility, rather than a true remedy. For developers, any tool that accesses their source code poses a data exfiltration risk. Developers and security teams need to ask about data storage, encryption key control, deletion processes, and incident response regarding evidence editing.

The industry needs to address "silent workspace exfiltration" as a critical issue rather than a minor bug. The open source release is seen as reputation laundering rather than genuine remediation when the vendor scrubs evidence. The question remains: at what point does open sourcing stop being remediation and start being reputation laundering, and who gets to draw that line?

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Friday 25 September →