Technology

213 readers
2 users here now

Work in Progress:

For tech news/discussions about something more substantial than a tweet.

Be nice. All instance rules apply.

founded 1 year ago
MODERATORS
can
1
 
 

cross-posted from: https://lemmy.sdf.org/post/31995242

Archived

Unveiling Trae: ByteDance's AI IDE and Its Extensive Data Collection System

Trae - the coding assistant of China's ByteDance - has rapidly emerged as a formidable competitor to established AI coding assistants like Cursor and GitHub Copilot. Its main selling point? It's completely free - offering Claude 3.7 Sonnet and GPT-4o without any subscription fees. Unit 221B's technical analysis, using network traffic interception, binary analysis, and runtime monitoring, has identified a sophisticated telemetry framework that continuously transmits data to multiple ByteDance servers. From a cybersecurity perspective, this represents a complex data collection operation with significant security and privacy implications.

[...]

Key Findings:

  • Persistent connections to minimum 5 unique ByteDance domains, creating multiple data transmission vectors
  • Continuous telemetry transmission even during idle periods, indicating an always-on monitoring system
  • Regular update checks and configuration pulls from ByteDance servers, allowing for dynamic control
  • Permanent device identification via machineId parameter, which appears to be derived from hardware identifiers, enabling long-term tracking capabilities
  • Local WebSocket channels observed collecting full file content, with portions potentially transmitted to remote servers
  • Complex local microservice architecture with redundant pathways for code data, suggesting a deliberate system design
  • JWT tokens and authentication data observed in multiple communication channels, presenting potential credential exposure concerns
  • Use of binary MessagePack format observed in data transfers, adding complexity to security analysis
  • Extensive behavioral tracking mechanisms capable of building detailed user activity profiles
  • Sophisticated data segregation across multiple endpoints, consistent with enterprise-grade telemetry systems

[...]

2
3
4
19
submitted 4 months ago by can to c/technology
 
 

Well, not this one. But this one is! How? Let’s take a closer look at Bluesky and the AT Protocol that underpins it.

5
6
12
submitted 5 months ago* (last edited 5 months ago) by can to c/technology
 
 

As chatbots like ChatGPT improve, their use in our personal and even romantic lives is becoming more common. So much so, some executives in the dating app industry have begun pitching a future in which people can create A.I. clones of themselves that date other clones and relay the results back to their human counterparts

No

7
8
15
submitted 1 year ago* (last edited 1 year ago) by can to c/technology
9
10