BTC $85,940.10 +5.85%
ETH $2,745.04 +4.24%
BNB $799.28 +3.86%
XRP $1.51 +6.89%
SOL $117.34 +6.82%
TRX $0.3439 +0.14%
DOGE $0.0990 +14.19%
ADA $0.2434 +7.17%
BCH $264.44 +5.28%
LINK $12.88 +3.45%
HYPE $92.87 +0.06%
AAVE $143.26 +5.69%
SUI $1.00 +12.82%
XLM $0.2088 +6.73%
ZEC $1,480.84 +0.81%
AAPL $338.91 +1.47%
AMZN $258.45 +2.02%
GOOGL $355.24 +1.65%
MSFT $497.83 +0.71%
META $747.25 +11.38%
NVDA $227.46 +2.88%
TSLA $374.75 +2.88%
SNDK $1,759.17 -0.58%
INTC $121.39 +9.52%
SPCX $152.27 -0.88%
MU $1,044.28 +3.81%
AMD $608.03 +9.11%
BTC $85,940.10 +5.85%
ETH $2,745.04 +4.24%
BNB $799.28 +3.86%
XRP $1.51 +6.89%
SOL $117.34 +6.82%
TRX $0.3439 +0.14%
DOGE $0.0990 +14.19%
ADA $0.2434 +7.17%
BCH $264.44 +5.28%
LINK $12.88 +3.45%
HYPE $92.87 +0.06%
AAVE $143.26 +5.69%
SUI $1.00 +12.82%
XLM $0.2088 +6.73%
ZEC $1,480.84 +0.81%
AAPL $338.91 +1.47%
AMZN $258.45 +2.02%
GOOGL $355.24 +1.65%
MSFT $497.83 +0.71%
META $747.25 +11.38%
NVDA $227.46 +2.88%
TSLA $374.75 +2.88%
SNDK $1,759.17 -0.58%
INTC $121.39 +9.52%
SPCX $152.27 -0.88%
MU $1,044.28 +3.81%
AMD $608.03 +9.11%

zcode

All
Article
Flash

first_img Zhipu Tangjie filed a defamation complaint against Xiaohongshu, ZCode has been open-sourced for rectification

On September 21, netizen "Zhang Kangkang kk" revealed on social media that Tang Jie, the founder of Zhipu and a professor at Tsinghua University, filed a complaint on Xiaohongshu regarding a user post. The complaint stated that the post used phrases like "code is pretty much the same as copy, both start with c and steal code" without factual basis, fabricating rumors that Zhipu's ZCode was involved in code theft and plagiarism. It also used terms like "Uncle Tang Jie" to associate Tang Jie with the plagiarism rumors for character defamation, while utilizing AI technology to synthesize Tang Jie's image with anime materials in a defamatory context. The complainant believed the content constituted malicious defamation and commercial disparagement, damaging both Tang Jie's personal reputation and Zhipu AI's reputation, and requested the platform to take down the post and deal with the user who posted it.On the same day, Zhipu announced that it had completed rectifications regarding the safety issues of the independent desktop AI programming client ZCode in response to community feedback and apologized to all users. The company has open-sourced ZCode, handing over the code to community supervision, and will establish a regular product security vulnerability mechanism moving forward. Previously, developers discovered that ZCode had silently uploaded user local repository data without prior notice. On September 18, Zhipu publicly apologized and made an emergency fix, explaining that the root cause was the "repository indexing" feature, which was enabled by default and had no option to turn it off. On September 20, Taiyuan Chengming Technology Co., Ltd. sent a letter to Zhipu, accusing ZCode of unauthorized uploading of company data assets and trade secrets, making claims for rights protection and reserving the right to pursue legal responsibility.

first_img ZCode is about to officially open source and conduct a security audit

The domestic large model enterprise Zhipu (2513.HK) is about to officially open source its AI programming tool ZCode. Zhipu stated that this open source initiative is the first step in response to external concerns about ZCode's data processing. In the future, it will further promote ZCode's transition to community-driven development and welcomes external parties to download, inspect the code, and participate in improvements.Zhipu has invited the China Academy of Information and Communications Technology to conduct a security audit on ZCode, focusing on verifying data retention. In the future, a regular product security vulnerability reporting mechanism will be established. According to the technical evaluation by the China Academy of Information and Communications Technology, it has been confirmed that the status of the zcode-prod Alibaba Cloud OSS storage bucket is zero data in the cloud; the ZCode v3.14.0 client has completed security rectification, removed the Repo Wiki feature, and severed the link for generating and uploading local repository snapshots. After review by Green Alliance Technology, it has been confirmed that the relevant data objects and the storage bucket itself have been deleted. Zhipu has expressed apologies once again and asks everyone to continue monitoring.Previously, social media revealed that ZCode would silently upload users' programming development data without user consent. On September 18, Zhipu issued a statement saying that the controversy was triggered by the default-enabled code repository indexing feature, and the uploaded data was destroyed immediately after generating the RepoWiki. They have apologized to affected users and will provide an additional weekly quota reset as compensation for all ZCode users. On September 20, Zhipu's MaaS platform announced that a feature to ensure no data retention will be launched soon.

Chengming Technology issued a letter holding ZCode accountable for uploading data without authorization

Taiyuan Chengming Technology Co., Ltd. sent a letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising multiple demands regarding the alleged unauthorized upload of company data assets and trade secrets by its ZCode client, and reserving the right to pursue legal accountability. Chengming Technology pointed out that although Zhipu has publicly apologized for the "silent upload of user local repository data" and claimed to have fixed the issue, independent evidence collection revealed that the upload behavior was automatically triggered and occurred in bulk, including complete archived files such as project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information, far exceeding the scope of collection stated in its Privacy Policy.Although the client was updated to version 3.12.3 on September 16, upload behavior was still detected in the early hours of the day Zhipu publicly apologized, raising doubts about the actual effectiveness of the "fix." At the same time, the ZCode client’s network requests pointed to a Singapore entity, while the service agreement was signed with Beijing Zhipu Huazhang, requesting clarification on the responsible party for this upload, as well as whether the data was transmitted abroad or stored overseas.Chengming Technology demanded that Zhipu respond in writing by October 10 and complete the immediate cessation of processing and thorough deletion of all uploaded data and related derivative data, caches, and backups, provide a complete list of processing situations, clarify the data's whereabouts, whether it was shared with third parties, whether it was used for model training, and whether cross-border transmission occurred, explain the management of encryption private keys and complete operation logs, clarify the exact scope of "destruction" mentioned in previous public responses, issue proof of deletion completion, provide a written commitment not to upload without authorization again, legally provide access, copying, and explanation of personal information, and designate formal communication channels, among other matters. Currently, Zhipu has not publicly responded to the aforementioned letter.
app_icon
ChainCatcher Building the Web3 world with innovations.