A security analysis reveals xAI's Grok Build command-line tool transmits complete source code and project files to xAI's servers. The discovery raises data privacy questions for developers using the tool.
A detailed technical breakdown posted on GitHub shows that xAI's Grok Build CLI sends substantially more data to xAI's infrastructure than users might expect. The tool transmits full source code, project structure, and file contents to xAI servers during build operations.
The analysis, which gained 145 upvotes on Hacker News with 79 comments, documents the exact data flows occurring when developers run the CLI. This includes code that developers may consider proprietary or sensitive.
While xAI's terms of service likely address data handling, the transparency of what's actually transmitted wasn't immediately clear to users. The findings highlight a broader concern in AI tooling: understanding what data gets sent to external services during development workflows.
Developers using Grok Build should review xAI's data policies and consider the sensitivity of their codebase before running the tool. The open discussion on Hacker News suggests growing developer interest in understanding data flows in AI-assisted development tools.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.
Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.
A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.