Isn't that totally expected of a coding agent? Otherwise it's like complaining dropbox "has unfettered access to your files".
“How does Kimi Work protect my privacy when accessing local files?”
It doesn’t protect your privacy. It’s like asking, “how do I know you’re not spying on me?” And getting the reply “we cannot physically enter your house.”
In light of the recent grok build snafu, "Nothing happens without your consent" seems like an upgrade. Moreover what are they supposed to do here? By that logic should any sort of non e2e email/storage provider not be able to put "How does [product] protect my privacy" in their faq?
Looking through their privacy policy, it looks like the bigger issue is that they are (or refuse to refute) training on your data/prompts. That's probably what people should be complaining about rather than complaining about how it "has unfettered access to your files", when that describes all coding harnesses.
> Looking through their privacy policy, it looks like the bigger issue is that they are (or refuse to refute) training on your data/prompts.
You’re making my entire point. They’ve designed an ingestion engine that is not private by design. Any sort of privacy posturing is wrong.
I personally wouldn't use any agentic harness from any company, American, Chinese, or otherwise, that is closed source. The Grok fiasco shows why.
Yes, any tool, including any coding agent, has access to all files $USER has access to.
Sandbox it explicitly to give access to only the current directory - https://github.com/ashishb/amazing-sandbox
Historically, everything you ran was trustworthy.
Android and iOS were invented in an era that does not allow this because the risks became evident by then.
https://drive.google.com/file/d/1JFfgfMO0nO7HR0WHwEqEEjXIIQj...
You have almost no control with Kimi either, they can also say one thing and do another. You will not be able to sue a Chinese company if it breaks the law.
I can think of no faster way to hand over your trade secrets or intellectual property than to run something like this.
I think success and dominance for agent providers will eventually come to which ever is able to best guarantee that they don't damage their customers businesses not the cheapest to run.
It's fair to say whatever software you run from any country of origin is hoovering up as much data about you that it can get away with.
If you haven't compiled open source, audited code and are running on that, all bets are already off.
Isn´t codex (edited) Apache 2.0 (thanks @Shank)
OpenAI's pigeons come home to roost
so ????
LLMs by definition are copyright infringers. so this is nothing compared to that.
Opensource and local are seeming like the only way.
"You're trying to kidnap what I've rightfully stolen!"
In fact, it would be pretty hard to come up with non-infringing software. Did ChatGPT infringe on MSN Messenger? Or Arc Browser?
No, this kind of trivial UI element is not an acceptable use of intellectual property protection. As much as I believe China’s dominance is a threat to the present world order I cannot imagine that attempting this style of IP regime will make us more competitive.
Yes China has companies that compete with existing companies, to the point they are copying. Our companies do the same thing (you're gonna tell me no American AI company has stolen the interface of another? or "borrowed" code?). Yes some of China's companies break laws. Our companies also break laws. YCombinator's funded companies have repeatedly bent and broken laws for over 15 years, to the point it's surprising when they don't break a law to gain unfair advantage.
The anti-Chinese rhetoric needs to be reigned in a bit. Yes the Chinese government is culpable in crimes against humanity and abuses of power - but so is the US government and US corporations. People in glass houses shouldn't throw stones. You wanna call out Chinese companies/government? Fine, but don't pretend it's just China.