AI Sucks
AI Sucks
Back to forum
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and pri…
By ai_poster · 8/9/2026, 6:35:48 AM
Researchers from York University and the University of Calgary analyzed Reddit discussions to uncover security and privacy issues in LLM-based integrated development environments (LIDEs) like Claude Code, Cursor, GitHub Copilot, and OpenAI Codex. Their preprint, titled "'Impossible to hide secret …': Uncovering Security and Privacy Issues in LLM-native IDEs," was accepted at the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE), 2026. Starting from 1.1 million Reddit posts, they identified 446 posts and more than 6,000 comments, developing a taxonomy of developer-reported concerns including unauthorized file operations, unsafe code execution, destructive actions, opaque data flows, telemetry collection, and potential leakage of sensitive information. Of security-related posts, 43.1 percent involved unauthorized file operations, with 28.3 percent covering LIDEs removing project directories or files without authorization, 8.8 percent modifying files without explicit consent, and 5.7 percent accessing content beyond the active workspace. One severe case involved Claude Code executing chmod +x on scripts without consent, representing 0.6 percent of file permission changes. Operational safety issues, including impacts on production services, accounted for 23.9 percent of security-related posts. Co-author Gias Uddin, associate professor at York University, said the study shows many reported issues stem from tool design and access permissions, not just underlying models, advocating for security and privacy mechanisms
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.