Z.ai Faces Scrutiny Over ZCode Client's Default Upload of Encrypted User Data to Alibaba Cloud
Z.ai, a company known for its AI models, is under scrutiny after a Chinese developer discovered that its ZCode client was by default uploading encrypted snapshots of his commercial project, including its Git history, to Alibaba's cloud storage. The developer, Ferstar, found a 313MB encrypted archive that had failed to send 564 times, and a smaller file that had already been uploaded. A critical detail is that Ferstar could not decrypt his own file, nor could the ZCode client, because the private key resides on Z.ai’s back end. The upload feature was reportedly on by default, with no option to disable it. Z.ai issued an apology, stating the issue was resolved and attributed it to ZCode’s code repository indexing feature, which supports session checkpoint recovery and version rollback. They claimed that generating a Wiki page in the cloud could trigger a repository upload and that the feature was on by default after launch. Alibaba, which owns the South China Morning Post, did not respond to requests for com...