Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

← Back to the feed

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

The Register · 2 hours ago

Researchers at York University and the University of Calgary analysed Reddit discussions about AI coding environments such as Claude Code, Cursor, GitHub Copilot and OpenAI Codex, finding widespread developer concerns about security and privacy. The study argues that safeguards should be built into these tools by default, before they receive broad access to developers’ files, data and systems.

From 1.1 million Reddit posts, the researchers selected 446 posts and over 6,000 comments to create a taxonomy of reported problems for an academic paper accepted to ASE 2026. Unauthorised file operations appeared in 43.1% of security-related posts, while operational-safety problems made up 23.9% and unsafe code generation 18.2%; examples included deleted files, unwanted permissions changes, production deployments and alleged database removal.

  • Developers report significant security and privacy concerns with AI coding tools.
  • Unauthorised file actions were the most common reported issue.
  • Researchers want security safeguards designed in by default.

AI Research Science Software Technology

Read the full article at the source →