TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Privacy concerns when using AI assistants for coding?

6 pointsby Kholin6 days ago
I&#x27;ve recently seen some teams claim to use third-party AI assistants like Claude or ChatGPT for coding. Don&#x27;t they consider it a problem to feed their proprietary commercial code into the services of these third-party companies?<p>If you feed the most critical parts of your project to an AI, wouldn&#x27;t that introduce security vulnerabilities? The AI would then have an in-depth understanding of your project&#x27;s core architecture. Consequently, couldn&#x27;t other AI users potentially gain easy access to these underlying details and breach your security defenses?<p>Furthermore, couldn&#x27;t other users then easily copy your code without any attribution, making it seem no different from open-source software?

6 comments

apothegm6 days ago
In theory, these companies all claim they don’t use data from API calls for training. Whether or not they adhere to that is… TBD, I guess.<p>So far I’ve decided to trust Anthropic and OpenAI with my code, but not Deepseek, for instance.
jonplackett4 days ago
If your code is written properly then it would be secure even if someone can see the source code (unless there’s environment keys in there that shouldn’t be exposed).<p>If the only security you have it that your code &#x2F; site structure is secret that’s not good.
baobun6 days ago
Especially under current US administration and geopolitical climate?<p>Yeah, we&#x27;re not doing that.<p>Also moved our private git repos and CIs to self-managed.
bhaney6 days ago
&gt; The AI would then have an in-depth understanding of your project&#x27;s core architecture<p>God how I wish this were true
ATechGuy5 days ago
I believe enterprises that care about privacy are using private AI from big tech (say Github copilot), others may not care so much about it.
rvz6 days ago
Don&#x27;t forget that your env API keys are getting read and sent to Cursor, Anthropic, OpenAI and Gemini as well.