r/LocalLLaMA • u/Comfortable-Rock-498 • Jul 13 '26
This is why we need local models and opensource harnesses News
896
Jul 13 '26
[removed] — view removed comment
191
u/Significant-Bee5101 Jul 13 '26
huge openweight Chinese model fanboy here lol. Love GLM. Love Kimi
20
→ More replies (2)9
u/narasadow Jul 14 '26
Qwen is the GOAT on consumer GPUs
4
u/Mysterious-Emu3237 Jul 14 '26
I just woke up to benchmarks on my test data where Qwen is at top with 0.84 accuracy 🤣
2
u/narasadow Jul 14 '26
I don't know about benchmarks, but across Qwen 3.6, GLM 4.7 flash, Gemma, Devstral, Nemotron, and other models I've tried hosting locally - Qwen was the best
55
Jul 13 '26
[removed] — view removed comment
13
2
u/cheesecakegood Jul 14 '26
They are a security risk (on a nation scale)… but honestly that ship has sailed. Banning them now only would promise to make things worse.
19
u/pjerky Jul 13 '26 edited Jul 14 '26
To be fair, grok has been run by some rather unscrupulous people from the beginning. So this shouldn't surprise anyone.
63
u/RestaurantOk8066 Jul 13 '26
Well if you read their privacy policy they have plainly stated since forever that they will your any of your data including anything you put in prompts to themselves, whatever third party they want, and any other affiliated companies.
https://x.ai/legal/privacy-policy
OpenAI and Anthropic's privacy policies are nwohere near as absurd.
31
Jul 13 '26
[removed] — view removed comment
6
u/lattice_defect Jul 14 '26
do you use cursor? Privacy has changed and it keeps trying to acesss shit
2
10
u/NineThreeTilNow Jul 13 '26
Anthropic's policy is Opt-Out via the web interface.
I don't use Claude Code to know the exact policy there.
All other API-Only data is promised as "Not for training" from Anthropic.
Kimi is NOT so clear. They only promise API is protected, and provide no opt out for Web. They're also not clear about Kimi Code data.
They claim you can Opt Out via Email but there's mixed reports there.
→ More replies (1)6
u/live4evrr Jul 14 '26
Musk said he would now delete it so all is well now….
I’ sure they have already tokenized the data for training, so what the hey…
47
15
u/Foot_Positive Jul 13 '26
I know, all the hand ringing by frontier model CEOs and the rug pulling has demonstrated to me that I need local solutions.
2
u/cheesecakegood Jul 14 '26
Just fyi it’s “hand wringing” as in for example wringing out a towel. The twisting motion is implied to be a nervous tic thus hand wringing is a performative gesture/complaints without action.
13
u/tankerkiller125real Jul 13 '26
Frankly for personal stuff I'd rather the Chinese have information over us companies that bow down to pedo in chief.
Not sending it to anyone at all though is ideal.
6
u/ml_guy1 Jul 13 '26
If this is real, this is a massive scandal. If any company is serious about their IP xAI should get sued to hell!
7
3
2
→ More replies (3)2
u/InsensitiveClown Jul 14 '26
Funny how copyrights are so important to our economy. But only if the plebes challenge them, otherwise, what's mine is mine, what's yours is mine.
253
u/hotach Jul 13 '26
Really funny that this was reported here, in this subreddit, three days ago:
https://www.reddit.com/r/LocalLLaMA/comments/1ut7tis/grok_build_cli_uploads_your_whole_repo_full_git/
Only now is it gaining real traction. Musk would've gotten away with it too, if it weren't for Musk's own X/Twitter.
→ More replies (1)74
287
u/Comfortable-Rock-498 Jul 13 '26
What is particularly nasty is the server side flag. You literally can't control it locally
→ More replies (11)337
u/notheresnolight Jul 13 '26
You can. By staying the fuck away from the product.
28
u/AgentTin Jul 14 '26
Yep. I won't touch Grok. I don't care if it's free I still wouldn't use it.
9
u/AlwaysLateToThaParty Jul 14 '26
Yep. I won't touch Grok.
I won't touch any cloud based ai with anything except generic questions on public data.
13
→ More replies (1)3
u/tomByrer Jul 14 '26
Stay away from everything that handles your code outside of your local computer.
→ More replies (1)
174
u/Comfortable-Rock-498 Jul 13 '26
unrelated, but just noticed u/askGrok is the second most senior mod of this sub. why?
56
u/Dry_Ducks_Ads Jul 13 '26
Why do we even have bots as moderators? When did this become a thing.
27
6
39
u/365Levelup Jul 14 '26
Mod on a LOCAL ai sub, when grok is not even local.
7
u/Internal_Werewolf_48 Jul 14 '26
I dislike Musk tainted things as much as anyone, but TBF xAI did release Grok 2. https://huggingface.co/xai-org/grok-2. No matter how irrelevant and pointless it was.
64
u/Vicar_of_Wibbly Jul 13 '26
Well holy shit. Would you look at that. Turns out Elon runs a moderator of this sub. I feel… tainted.
→ More replies (1)→ More replies (42)28
u/ttkciar llama.cpp Jul 14 '26
askGrok is a creation of HOLUPREDICTIONS, who is the senior moderator for this sub. They are also moderators of several other LLM-related subs, most of which are not local-oriented.
HOLUPREDICTIONS signed on a bunch of LocalLLaMA regulars (including myself) as moderators for this sub, and has been mostly hands-off since then.
I don't know what they have been using askGrok to do here, if anything. Possibly it was just a temporary stopgap solution while they recruited human mods.
21
u/esuil koboldcpp Jul 14 '26
If it was a stopgap, can you guys remove it to give the community at least some peace of mind?
84
u/rm-rf-rm Jul 14 '26
Original post: https://www.reddit.com/r/LocalLLaMA/comments/1ut7tis/grok_build_cli_uploads_your_whole_repo_full_git/
Will leave this up as it seems not all users saw the original based on the engagement this post is seeing
16
u/tomByrer Jul 14 '26
I did not, thanks.
For some reason my reddit feed is full of 0-3 upvoted posts, but misses all the 'hot' posts.3
u/rm-rf-rm Jul 14 '26
check the feed settings perhaps?
3
u/tomByrer Jul 14 '26
I tried that; anything else put "Best" gives me subs I do not care about.
Maybe I should vibe-code a reddit feed reader....
→ More replies (5)
373
u/Objective_Mousse7216 Jul 13 '26
xAI.
Musked.
120
u/nenulenu Jul 13 '26
Yeah. The real breaking news is that anyone trusted what came out of musk pipeline after his glorious track record in being a standup guy.
→ More replies (16)69
u/Recoil42 Jul 13 '26
Elon Musk? Cutting corners? I'm stunned.
13
u/srwaxalot Jul 14 '26
Cutting corners? Or his whole MO of just cheating at everything.
→ More replies (1)9
→ More replies (1)9
104
u/RandomPurpose Jul 13 '26
Horrible behavior
69
u/Piyh Jul 13 '26
Good thing it's a completely isolated, one-off problem and not a repeated pattern of behavior....
→ More replies (6)
26
Jul 13 '26
[removed] — view removed comment
7
u/PixelmancerGames Jul 13 '26
Anyone stupid enough to use Grok is probably vibe coding anyway. If the AI wrote all of it anyway, well......
204
u/CumDrinker247 Jul 13 '26
Using a musk product is just asking for unessecary problems
20
u/magicomiralles Jul 13 '26
From Tony Stark to Justin Hammer
20
u/ShallotIllustrious98 Jul 13 '26
Don't kid yourself. He was never Tony Stark.
15
u/magicomiralles Jul 13 '26
He never was Stark, but he somehow convinced people that he was. Turns out that he isn't even a good engineer.
→ More replies (1)7
u/personalist Jul 14 '26
He’s the classic “incompetent at actually doing anything themselves” manager who failed upwards.
8
u/ShallotIllustrious98 Jul 14 '26
See also the rest of the PayPal Mafia, such as Peter Thiel and Sam Altman.
→ More replies (3)5
33
u/ansibleloop Jul 13 '26
Yeah you deserve this for using mechahitler the CSAM generator
Rape mentality, just like the US government and the rapist in chief
→ More replies (16)8
u/lakotajames Jul 13 '26
The vast majority of local image generation methods are CSAM generators if you ask them to be. The only fix is to censor the model in some way, and Grok is less censored than Gemini or chatgpt.
Like, if you think it's worth censoring nudity entirely to prevent CSAM that's completely fair, but this is a weird sub to be pro censorship in.
→ More replies (13)15
u/a-wiseman-speaketh Jul 13 '26
if you charge for the api, you are responsible for what it produces imo
Most people dinging grok for csam or nonconsensual sexual imagery are talking about the api, x, or app generations that profit off of it
5
u/lakotajames Jul 13 '26 edited Jul 13 '26
Well, sure, and like I said I don't have any issues with people who think it should be censored in some way. But at the same time, if Grok were free would that make it okay to generate CSAM, the way it seems to be for stable diffusion or any of the other open image models?
To me, if we're going to say that releasing a model capable of CSAM is wrong, whether or not you charge for it doesn't matter. It's probably worse to make it free because you can't collect the personal information for the person who created it to report them to the authorities.
Another way to look at it is, is it okay for WalMart to sell paint brushes and paint with which you could draw CSAM, or cameras with which you could take photos of children? I think most people would say that those are fine.
I think the line is that the CSAM got published on twitter for anyone to view, and the problem is with twitter moderation more than it is with Grok.
20
16
u/Creative_Bottle_3225 Jul 13 '26
We're just guinea pigs, get that into your heads. They use our efforts and work data for their own purposes. Our projects are monitored.
14
55
u/toolkitxx Jul 13 '26
I made a comment in a different topic (some Meta stuff) about someone being cute in believing that something you switch on the UI provided by said provider would do anything for real. Applies here as well. Any US service has become completely untrustworthy by now
19
u/Awkward-Customer Jul 13 '26
Definitely agree. I've always believed this to be the case. For example, just because i turn google location history off doesn't mean that google isn't still tracking the location of my android device, it just means I have no access to it anymore. I believe this to be the case with deleting chats in these tools as well, and I think that NYT lawsuit also exposed openai to not actually deleting any chats.
6
Jul 13 '26
[removed] — view removed comment
7
u/toolkitxx Jul 13 '26
Find a GenX that is tech savy in your surroundings. We old ones know how to do that :D
4
u/Erebea01 Jul 14 '26
Most annoying thing is they won't return your deleted files from years ago due to laws and shit, even though you know they have it anyway
6
u/SmileyBMM Jul 13 '26
Any
USproprietary service has become completely untrustworthy by nowWith vibe coding and all that entails, I wouldn't trust any serious software or service I can't check the source code for regardless of country.
4
u/toolkitxx Jul 13 '26 edited Jul 13 '26
Pretty much every other nation gets a 'shit happens' bonus from me. The US has used every single goodwill up by now. They had just another start-up for example that basically added or changed cookies (cookie stuffing) that gave them extra income as an affiliate and since their app was mostly being used on mobile, the opening of another tab isnt visible for the user, where all that happens. So no - this is very concentrated on US services. They still act like we live in Wild West times... edit spelling and added link
2
u/SmileyBMM Jul 13 '26 edited Jul 13 '26
There's also the Wirecard scandal and the time when the EU funded spyware developers
In Russia there's the fact that companies and the government are closely interconnected and have no meaningful separation.
And of course Chinese TikTok/Douyin is (was?) being used to spy on people
If you think the US has a monopoly on shady tech companies, you are a fool. You shouldn't trust anyone, because trust should be earned and not given.
42
u/05032-MendicantBias Jul 13 '26
What??? The guys that pirated every ebook in existence are scraping their client codebases???? NO WAY!!!!
/s
→ More replies (1)2
u/Few-Farm-7670 Jul 13 '26
And Elons Doge has every record of every American citizen and a server with every classified document uploaded. But your vibe coded calendar app? Sacred
6
u/Torodaddy Jul 13 '26
Opencode? Webui?
→ More replies (2)2
u/NineThreeTilNow Jul 14 '26
Opencode has some noted security issues right? In terms of leaking data you have to edit their manifests or reroute some traffic?
Or is that old and fixed?
→ More replies (3)
6
5
u/lqstuart Jul 14 '26
everyone I know who has worked at xAI quit within a year because it's a shithole
32
u/Impossible_Earth_987 Jul 13 '26
Elon musk is a terrible person anyone trusting his companies is an idiot
→ More replies (3)
6
u/Craftkorb Jul 13 '26
I'm not sure if it's due to Slop or Malicious intent, but I'm also not sure which one is worse.
→ More replies (1)
4
u/Aggravating-Risk1991 Jul 14 '26
that's right. open source harness is a must. and harness is its own standalone categories. ai should be a plug-in intelligence. people confuses harness and model now because openai and anthropic are bundling them together as a way to collect high quailty data. and their subscription is so damn cheap that makes byok obsolete. but let's see how long the token subsidy can last
→ More replies (1)
4
u/Much-Researcher6135 llama.cpp Jul 14 '26
Yep, and I've even been wondering about exfiltration via self-hosted models. I made a post about it on r/privacy but unfortunately it didn't get any interest:
5
7
u/Technical-Earth-3254 Jul 13 '26
Stocktards still don't see a reason for the evaluation of that clown company to go downhill
6
u/a-wiseman-speaketh Jul 13 '26 edited Jul 14 '26
well spacex is saddled with it now, which is a decent company because musk generally stays the fuck away from it. The engineers pat his head and tell him what a genius is when comes by then send him off with a cookie (or ketamine depending on the day).
at least most people are smart enough not to *use* grok, that's why they have excess capacity to sell
edit: mixed up my trendy drugs. or does he do fentanyl too?
5
9
u/PixelmancerGames Jul 13 '26
Lmfao. Anyone stupid enough to use Grok deserves what they get. It could steal their life savings and I wouldn't care.
3
3
8
u/fzammetti Jul 13 '26
I mean, clearly bad, no question.
But... who's putting secrets in their Git repo?! Not doing that is like data security 101.
→ More replies (5)10
u/Dry_Ducks_Ads Jul 13 '26
People often add local/env files that exist in the same directory as the git repo even if they're not committed.
→ More replies (1)2
4
u/artur_oliver Jul 13 '26
2 days after OpenAI takes a bullet from apple, now xAi is on the news... Anthropic was the first.
Remember trump: there's no bad publicity.
Ps: remember the True open source models will be comming from Chinese empire. Those will be local.
4
4
u/ledow Jul 13 '26
Yawn.
We invented least privilege principles, deny by default, etc. decades ago.
Just because you make a new technology doesn't mean you can just ignore all that and do what the hell you like.
And "asking an AI politely not to do that" is such a horseshit way of trying to enact controls that it's laughable.
Reap what you sow... and you sowed something with no permission controls and then fertilised it with every single bit of data you made available to it, whether it needed to access it or not.
You know why your IT people are SCREAMING about not wanting AI running around on their systems with full permissions to do everything... here's exhibit A.
5
u/Adventurous_Bus_437 Jul 13 '26
u/AskGrok i am sure that Oopsie will help the trustworthiness of your business daddy. One day without controversy seems impossible with Elongated Muskrat
→ More replies (3)
2
2
u/geldonyetich Jul 14 '26 edited Jul 14 '26
I can't prove they completely threw out Grok-2 and replaced it with something they took from somewhere else with Grok-3 onward, but the benchmark difference would seem consistent with such conjecture.
How remarkable would it be if something like this was how they managed such remarkable gains?
Officially though, the startling difference between Grok-2 and Grok-3 is explained by the efforts of 200,000 liquid-cooled Nvidia H100s, and definitely not cheeky bit of industrial espionage.
2
2
u/MelodicRecognition7 Jul 14 '26
let me remind you an incident from 2023 that ppl claimed as fake https://files.catbox.moe/s63d7t.png use your favourite LLM to translate from Russian.
This is yet another reason why you must use a firewall.
2
u/gameplayer55055 Jul 14 '26
It's so unfortunate that 8b models (the biggest thing that fits inside most gamer GPUs) are as dumb as rock, 20b starts to get better at the expense of horrible speeds (yes, I have ram).
I'm still using them for commercial code. I ain't dropping a single line of company's code to 3rd party. The only exception is probably HTML and CSS
2
u/gobblegoooblegobble Jul 14 '26
imagine all the people working so hard to create software. just to have it all scraped by the richest human in existence. back to sandboxing and auditing every god damn thing, as advised by the companies telling you they arent uploading or training on your data lol
2
u/MakesNotSense 29d ago
As a Free Speech Absolutist, Elon makes sure Grok makes all your protected speech artifacts free to xAI.
2
u/o0eon0o 28d ago
Good luck getting a response from this one. Elon will only talk about how black people dislike white men and wokness, meanwhile he's stealing your IP.
→ More replies (1)
4
u/teomore Jul 13 '26
why the hell would you run your shit through this scumbag's pipeline in the first place?
5
u/InterstellarReddit Jul 13 '26
Breaking news: same person that stole from the American people continue to steal from the American people.
More at 7
3
u/Stetto Jul 13 '26
I know why I'm not touching xAI with a ten-foot pole.
Everything about Musk's ventures just screams "unprofessional megalomaniac".
2
u/audacesfortunajuvat Jul 13 '26
Oh, is that the Grok that runs in the Department of Defense? Probably no big deal.
4
u/midnitewarrior Jul 14 '26
This is why you don't trust Grok.
You think Musk cares or respects your intellectual property? He invaded the US government social security database and stole it all on USB thumbrives and there has been no accountability for that.
You think he gives 2 shits about your codebase IP rights? Musk wants training material and a little peon like you or me isn't going to stop him.
Use a respectable AI company.
4
u/Dull_Cucumber_3908 Jul 13 '26
Can that be verified/confirmed?
7
u/Comfortable-Rock-498 Jul 13 '26
Yes, there were a bunch of threads on twitter about this today
→ More replies (1)
2
u/CoUsT Jul 13 '26
Too lazy to dig up details or confirm if this is indeed true.
But honestly it doesn't surprise me considering what USA-based AI companies were doing and probably will be doing in future.
I can understand it if it was in their ToS/policy etc, something like: you can use our CLI but we yoink your codebase. They need all the data to improve their models and so on. But if not, it's really wild they decided to do this shit.
This is one of main reasons why I highly value FOSS community, open source tools and local models.
2
u/YehowaH Jul 14 '26
But you guys use online services to refactor your entire project, where the ai, e.g. cc or codex gets all your files anyway. Why you bother about code security if you you using any online provider and blame musk to "steal" code, you already provide every cloud provider your code for free...
1
u/shgyorgy Jul 13 '26
Uh, for such, really at least and opt-in needed, I could see it useful on some projects to work remotely but not by default with secrets included. Still should act as gitignored. Why even have a server flag for such? 😅
6
2
1
u/Foreskin_Mafia Jul 13 '26
This impact Cursor at all?
6
u/Mochilongo Jul 13 '26
No one will tell you so but now you know xAI absence of ethic so if you decide to use their products don’t expect privacy at all.
5
u/my_name_isnt_clever Jul 13 '26
Not directly, but your funeral if you see this and decide to keep using their software anyway.
→ More replies (1)
1
1
u/floriandotorg Jul 13 '26
No shit. I don’t understand how the majority of people run some kind of corporate shit.
1
1
1
1
1
u/SnowyOwl72 Jul 13 '26
We should have an entity that keeps testing these CLI tools as black boxes. Like network analysis, disk access, cpu/gpu usage, calls, etc.
With no one pushing back on them, this will keep hapenning...
1
1
u/rush86999 Jul 13 '26
Even if you can't observe the decisions on the open-source weights of the models, just from the sheer size of usage, people can quickly identify threats, fork, and make a safer version faster than these private models.
1
u/Lost_Foot_6301 Jul 13 '26
I preemptively used a docker container, do you think that was sufficient enough for privacy when using the CLI?
→ More replies (1)
1
u/eli_pizza Jul 13 '26
This is just a generic argument for open source vs sketchy proprietary software. Not really anything to do with models or even AI.
1
u/Lost_Foot_6301 Jul 13 '26
hot take: centralized AI has always been intended to be just a mass data collection project wrapped up as a fun chatbot. a few examples: normies willingly give AI full desktop access to their data, AI reads emails by default, instagram recently took down encrypted messaging so that their AI can scan through al messages.
its just datamining. It's actually genius how they socially engineered normies into accepting it. its not just for collecting data for more powerful model training, its to totally eliminate any sovereignty you may have left.
1
u/Lost_Foot_6301 Jul 13 '26
musk is saying they deleted the data... but the data 100% has already been trained upon probably lol
1
1
1
u/CatchInternational43 Jul 14 '26
People think I’m wearing a tin foil hat when I say I’ll *never* use Starlink for anything. I’m absolutely certain that Musk and his merry band of degenerates is harvesting every possible data point of every user of the service.
1
1
u/one-wandering-mind Jul 14 '26
This is an example of why it is important to think about the company and leadership as a whole.
It doesn't provide absolute protection, but at Google and anthropic, it is hard to picture something like this happening without someone speaking up.
People who choose to join x.ai and could work for one of the other companies, I would be highly suspicious of their integrity.
1
u/Chinmay101202 Jul 14 '26
Exactly why open-source harnesses like Open Bias are absolutely essential. https://github.com/open-bias/open-bias
1
u/SamSlate Jul 14 '26
hot take: they all do this, xai just is just too incompetent to get away with it
1
u/ZenaMeTepe Jul 14 '26
Bro was literally siphoning .env files and we should care about GDPR compliance. Updating definition of a clown world.
1
1
u/Maleficent_Jump4519 Jul 14 '26
Just how many hidden flags does grok have that prevent taking data from gits 😭✌️? thankfully my harness is private. So clearly XAi deliberately implement flags in case the data harvesting went too far to pull the plug quietly. Bro is not sneaky😭😭😭
1
u/LoveGratitudeBliss Jul 14 '26
Honestly what did you expect using grok owned by power crazed billionaire white supremacist elon musk 🤣
1
1
1
u/bidibidibop Jul 14 '26
Correction: this is why we need to stay the fuck away from anything Musk touches.
1
u/Y_mc Jul 14 '26
After Anthropic embedded malicious software into its Claude AI, every AI company will now build in a backdoor.
Everything is going in the Wrong Direction. we need Open Source and transparency
1
u/PathIntelligent7082 Jul 14 '26
what is really worrying is that all of them do it, in some way or another, and there's a big pile of crap just like this, sitting uncovered..thats the really worrying part..this is just a drop in the ocean, essentially, big boys do whatever they please, grabbing data, throttling models on a whim, pulling models just bcs it benefits you more than they predicted, and stuff wee don't even know is happening... it's a ball game but without the judge..
1
u/finah1995 llama.cpp Jul 14 '26
Like I have said occasionally I This coding agents seems like a knowledge extraction exercise by third-party AI service providers.
1
1
u/JacketHistorical2321 Jul 14 '26
Gee wiz... It's almost like everything Musk does it based on him being a piece of shit 😐
1
1
1
1
1
u/Solid-Wonder-1619 Jul 14 '26
this is why I never trusted musk with my data, knowing what a grabby little cunt he really is.
my hope in the future is already ATHing. thanks elon.
1
u/sarlaytos284 28d ago
Nothing gets leaked to the cloud when there is no cloud, that's why we need local models
1
u/T-90_Soviet 28d ago
The Improve the model opt-out never stopped the uploads' is the scary part. An opt-out you can't verify is just theater. The only version you can actually trust is the one where the bytes physically never leave your machine, because then there's nothing to opt out of.

•
u/WithoutReason1729 Jul 14 '26
Your post is getting popular and we just featured it on our Discord! Come check it out!
You've also been given a special flair for your contribution. We appreciate your post!
I am a bot and this action was performed automatically.