Hacker News new | ask | show | jobs
by fintechie 517 days ago
Hopefully this makes the Cursor team reconsider security (which doesn't seem very good really).

Stopped using it for serious stuff after I noticed their LLMs grabs your whole .env files and sends them to their server... even after you add them to their .cursorignore file. Bizarre stuff.

Now imagine a bad actor exploiting this... recipe for disaster.

1 comments

Security often means the opposite of scalability and growth, so why should they? The business goal is to make sure Cursor grows large enough that they have economics of scale to be a viable business.

If you want secure LLM you can use Mistral, which comes with all the EU limitations, good and bad.

Mistral (an LLM company) is not really a substitute for cursor (an IDE). Tabby is probably the closest open-source alternative. https://github.com/TabbyML/tabby