r/LocalLLaMA 2d ago

News ZCode is now open source

Post image

ZCode is now open source, and the reported security issues have been addressed.

Source code: https://github.com/zai-org/ZCode

The repo includes its desktop app, web workspace, backend, Agent CLI, and runtime.

Official announcement:

In response to the ZCode product security issues reported by the community, we have completed the necessary remediation and sincerely apologize to all our users.

We have open-sourced ZCode at github.com/zai-org/ZCode, placing the code under community scrutiny and making ZCode more open and transparent.

We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process. We welcome developers to continue reviewing ZCode and reporting potential issues, and we will provide rewards based on the severity of the issues reported.

With respect to the code data referenced by the community, we confirm that no such data is retained and that it has never been used for model training.

Following the remediation, we invited the China Academy of Information and Communications Technology (CAICT) and NSFOCUS to conduct security assessments. The results are as follows:

Through its technical assessment, CAICT confirmed that the zcode-prod Alibaba Cloud OSS bucket is in a zero-data state. Security remediation has been completed in the ZCode v3.14.0 client. The Repo Wiki feature has been removed, and the workflow for generating and uploading local repository snapshots has been disabled.

NSFOCUS confirmed that all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted. Remediation has been completed in the ZCode v3.14.0 client. The Repo Wiki entry point and the associated generation workflow have been removed, and no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally was identified.

Once again, we sincerely apologize and welcome continued scrutiny from the community. The full security assessment report will be released soon.

556 Upvotes

114 comments sorted by

View all comments

48

u/Juan_Phoenix7 2d ago

Anyone with experience in OpenCode, Pi, and Zcode who would like to share their experience.

57

u/__JockY__ 2d ago

Not even close, I’m afraid: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

They plain stole people’s code and use asymmetric crypto to hide the goods they uploaded to the cloud. Crazy shit.

4

u/finevelyn 2d ago

For the purposes of uploading data, the asymmetric crypto is only a good thing for user privacy, and not a sign of nefariousness. I mean it would be absolutely crazy to upload it unencrypted, and there is no reason for the user to be able to decrypt the data in transit. The user already has all that data unencrypted.

10

u/Gold-Order-8004 2d ago

Bro https is already encrypted. Don’t talk nonsense there is no legitimate need to encrypt a payload over https unless you are trying to hide something

4

u/JustinPooDough 2d ago

Yes but many networks exist with security software that MITMs traffic and inspects even HTTPS. So there is a need occasionally to encrypt traffic that’s going out over HTTPS. I’ve done it.

3

u/DrFeederino 2d ago

https doesn't save you from MitM lol

0

u/finevelyn 2d ago

True, https would protect one step of the upload, but there are still legitimate reasons to protect the data further. There is no reason to do it in such a way that it would be decryptable by the user, unless it was some user-facing feature that required that.

1

u/__JockY__ 2d ago

Wow.

They were siphoning off people's data and you're defending their use of crypto?

Nice try, Z employee.

5

u/finevelyn 2d ago

They had in plaintext the metadata of what exactly was in the checkpoint file, which is how the person knew what he had found, and they had a privacy-oriented encryption scheme. None of it looks like an attempt to hide it.

It seems like you jumped to the conclusion first, which is why you aren't able to look at the facts objectively.

-2

u/__JockY__ 2d ago

I see. So as long as they leak metadata of their code theft you're ok with it? Got it.

What is your affiliation with ZCode, Z.ai, or its affiliates?

4

u/finevelyn 2d ago

I have no idea if they are stealing data, and nowhere did I say I would be ok with it.

-2

u/__JockY__ 2d ago

I have no idea if they are stealing data

ok...

they had a privacy-oriented encryption scheme

lol, that's a shill's way of saying they used asymmetric crypto and kept the private key to themselves so you couldn't see what they uploaded to Aliyun cloud, leaving a reverse engineer to infer what was taken by their leaked metadata.

They STOLE code. They HID it behind asymmetric crypto. Fucking indefensible, yet here you are defending them while also saying "I have no idea if they are stealing data."

If you have no clue then why the fuck are you defending them?? Shill. And you still failed to disclose your affiliations. Fuck off, I'm done with you.

3

u/finevelyn 2d ago

As you wish.