frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Are you worried, and care, about AI stealing your code/secrets?

2•fnoef•1h ago
Recently, I started to use AI coding agents. They are really great, and I feel like this is the best $100 month I spend for my career.

And yet, I understand that I don’t fully know how they work and what they do behind the scenes. I know the general gist of how an agent works, but I don’t really know if they don’t cat .env behind the scenes, or whether someone on the other side of the planet gets pieces of my code in their AI response.

This is the reason I use AI mainly at $JOB, but not on my personal project (in addition to keeping my skills sharp, and the fun factor). Do you ever think about this? Do you care?

Comments

viraptor•1h ago
You need to run them sandboxed in some way. Docker is one kind of solution, selinux / apparmor / sandbox-exec is another. Basically, create an environment where .env is not accessible in any way and you don't have to worry about it anymore.

I don't care about it reading the code itself. 90% of my usage is on opensource projects anyway. The other - if I can generate something, then there's no barrier to someone else doing the same - I'm just making applications that do expected things, not doing some groundbreaking research.

fnoef•1h ago
It’s not only about the .env, but also intellectual property, algorithms, even product ideas.

Moreover, let’s say you run a dev server with watch mode, and ask claude to implement a feature. Claude can generate a code that reads your .env (from within the server) and send to some third party url. The watch mode would catch it and reload the server and will run the code. By the time you catch it, it’s too late. I know it’s far fetched, and maybe the paranoia is coming from my lack of understanding these tools well, but in the end they are probabilistic token generators, that were trained on all code in open existence, including malware.

viraptor•1h ago
> Claude can generate a code that reads your .env (from within the server) and send to some third party url.

Again - sandboxes. If you either block or filter the outbound traffic, it can't send anything. Neither can the scripts LLMs create.

coolcat258•1h ago
tbh im sure they do.

A simple TUI video converter for the AV1 codec

https://github.com/framicheli/av1converter
1•francescomi•2m ago•0 comments

Show HN: Free and open sourced prompt skills game for kids

https://prompts.chat/kids
1•fka•3m ago•0 comments

Mission planning system will break before your rockets do

https://blog.satsearch.co/2026-01-14-spotlight-your-mission-planning-system-will-break-before-you...
1•kartikkumar•4m ago•0 comments

I built a tool to help me explain my work to clients automatically

https://delivrr.work/
1•ymfh•8m ago•1 comments

Show HN: 0xCal – A calorie tracker where you just describe what you ate

https://apps.apple.com/pl/app/0xcal-ai-calorie-tracker/id6749210009
1•namedix•8m ago•0 comments

Declarative YAML Workflow System for AI Agents

https://twitter.com/nedim0x01/status/2011733056709636471
1•nedim0x01•10m ago•1 comments

AI-powered automatic translation in WordPress (YouTube video tutorial)

https://gatoplugins.com/blog/youtube-video-tutorial-ai-powered-automatic-translation-in-wordpress
1•leoloso•13m ago•0 comments

LiteStar – a FastAPI rival (DTOs, controllers, msgpack)

https://litestar.dev/
1•begoon•13m ago•0 comments

Second Thoughts on James Burnham (George Orwell, 1946)

https://www.orwellfoundation.com/the-orwell-foundation/orwell/essays-and-other-works/second-thoug...
1•duggan•15m ago•0 comments

Semi-Automating 200 Pull Requests with Claude Code

https://blog.davisvaughan.com/posts/2026-01-09-claude-200-pull-requests/
1•sebg•15m ago•0 comments

The crisis whisperer: how Adam Tooze makes sense of our bewildering age

https://www.theguardian.com/business/2026/jan/15/the-crisis-whisperer-how-adam-tooze-makes-sense-...
1•6LLvveMx2koXfwn•17m ago•0 comments

Blacksmith – AI Powered Penetration Testing

https://github.com/yohannesgk/blacksmith
1•jchris280•22m ago•3 comments

Codeless Code – Fables and Koans for the Software Engineer

https://thecodelesscode.com/case/234
1•todsacerdoti•24m ago•0 comments

Napa: Powering Scalable Data Warehousing with Robust Query Performance at Google

https://research.google/pubs/napa-powering-scalable-data-warehousing-with-robust-query-performanc...
1•tosh•24m ago•0 comments

Bruce Perens: The Ham Radio Operator Who Made Trump Want Greenland

https://web.archive.org/web/20260115085443/https://www.linkedin.com/pulse/ham-radio-operator-who-...
1•weinzierl•25m ago•1 comments

Use Agents or Be Left Behind? A Personal Guide to Automating Your Own Work

https://timdettmers.com/2026/01/13/use-agents-or-be-left-behind/
3•sebg•26m ago•0 comments

Optimizing data throughput for Postgres snapshots with batch size auto-tuning

https://xata.io/blog/postgres-snapshots-with-batch-size-auto-tuning
1•gulcin_xata•27m ago•1 comments

Typical: TypeScript with type safety at runtime

https://typical.elliots.dev/
1•elliotshep•27m ago•0 comments

Me and the Machine

https://mitsuhiko.github.io/talks/me-and-the-machine/
1•obiefernandez•28m ago•0 comments

LevelDB is a fast key-value storage library

https://github.com/google/leveldb
1•tosh•29m ago•0 comments

Hacking Wheelchairs over Bluetooth

https://www.securityweek.com/researchers-expose-whill-wheelchair-safety-risks-via-remote-hacking/
1•7777777phil•30m ago•0 comments

ICE Is a Secret Police

https://www.nytimes.com/2026/01/10/opinion/immigration-ice-violence-minnesota.html
3•KnuthIsGod•34m ago•0 comments

Show HN: Getmaapp/signal-WASM v0.1.0 – Signal Protocol for the Web

https://github.com/getmaapp/signal-wasm
1•getmaapp•34m ago•0 comments

Show HN: S3mini(0.9.1) Tiny ts S3 client, now supports blobs and streams

https://github.com/good-lly/s3mini/releases/tag/v0.9.1
1•neon_me•37m ago•0 comments

SETI@home: UC Berkeley scientists are homing in on 100 signals they found

https://news.berkeley.edu/2026/01/12/for-21-years-enthusiasts-used-their-home-computers-to-search...
1•1659447091•38m ago•0 comments

Saving 675 Engineering Hours a Month Using an AI Slack On-Call Agent

https://www.wix.engineering/post/when-ai-becomes-your-on-call-teammate-inside-wix-s-airbot-that-s...
1•yardenw•44m ago•0 comments

Test 8 hour work simulation

1•magentamountain•44m ago•0 comments

Python: Tprof, a Targeting Profiler

https://adamj.eu/tech/2026/01/14/python-introducing-tprof/
1•jonatron•45m ago•0 comments

Microfeatures I Love in Blogs and Personal Websites

https://danilafe.com/blog/blog_microfeatures/
2•alexharri•46m ago•0 comments

Show HN: Aeph – A minimal TUI Markdown editor with task management

https://github.com/siki-712/aeph
1•ovonvo•47m ago•0 comments