How to Choose an AI Coding Assistant for a Code Repository
A five-question checklist for picking an AI coding assistant: training defaults, telemetry, retention, permissions, and how to verify before you commit.
Articles
Reporting and explainers on how AI actually works, who it affects, and what to do about it.
A five-question checklist for picking an AI coding assistant: training defaults, telemetry, retention, permissions, and how to verify before you commit.
Z.ai's ZCode assistant tried 564 times to upload 313MB of workspace code to Alibaba Cloud without consent. Timeline, what was exposed, what to check.
Real tokens per second from local LLMs on consumer hardware: how quant and context change speed, why memory bandwidth is the limit, and what helps.
MIT Tech Review's 15-month investigation finds Anduril, RVSS, and Elbit surveillance towers failed to catch people dying within range of their cameras.
The five sections that actually matter in any AI privacy policy, what each major assistant's policy really says, and the red flags that mean walk away.
Open-weight coding LLMs sized by VRAM: Qwen2.5-Coder, Qwen3-Coder, Devstral Small 2, KAT-Coder, GLM-4.7-Flash, and the trade-offs at each tier.
The exact steps to delete chats and accounts from ChatGPT, Claude, and Gemini, and what each one keeps on its servers after you hit delete.
The $249 Vocci ring is the latest always-on AI notetaker. We dug into its privacy policy, where the data flows, and the recording laws.
NVIDIA and Apple TDPs, the US residential cents-per-kWh average, and what 24/7 local inference actually adds to your electricity bill by card.
Which AI assistants train on your chats by default, which keep data only briefly, and where the real opt-out toggle actually lives.
EFF obtained ~1,000 pages of FOIA records on Medicare's WISeR AI pilot. Vendors shipped untested code; providers report patient harm.
Reasoning tokens, latency, and KV cache cost of thinking mode in local LLMs. How to toggle it per runner and when it is the wrong choice.
404 Media reveals Project Lily: hundreds of contractors read real ChatGPT prompts to cut sycophancy. OpenAI admits sensitive details slip past scrubbing.
The advertised context window is one number. What your GPU can actually serve is smaller. The KV cache math, RoPE scaling, and the practical ceiling.
Sourced steps to safely download and verify an open-source LLM: safetensors, GPG-signed commits, pinned revisions, and HF / Ollama integrity checks.
Anthropic's Claude Fable 5.1 reportedly decoded a royalist cipher first published in 1653 using 176k tokens. The plaintext is verifiable. The framing is not.
How Ollama, LM Studio, llama.cpp, and vLLM differ on model format, OpenAI-compatible API, hardware support, and which to pick for a home server.
Qwen, Llama, Mistral, Gemma, DeepSeek, Phi - which family to commit to, what each is good at, and the licence traps that send you back to negotiate.
Datasette ran a security audit with Claude Fable 5.1, GPT-5.6 Sol, and GPT-6 Astra. The workflow matters as much as the bugs.
Why general benchmarks like MMLU and GPQA don't predict your results, the index-rebase trap, and a recipe for picking a local model from your own prompts.
How Calif Research used AI to find a WeChat bug and write a working zero-click worm in days, not months. What changes when the exploit loop is automated.
Auth, reverse proxy, HTTPS, concurrency and audit: how a small team shares one local model without exposing it to the public internet.
Meta's personal AI agent runs in a dedicated VM with a Sentinel guard. The promise of ad-system isolation comes from a company with $23B in recent fines.
Reasoning-capable open-weight models sized by VRAM. DeepSeek-R1, Qwen3 with thinking, QwQ, Phi-4 reasoning, gpt-oss, and the licence traps.