<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Lynx Tech Blog</title><link>https://blog.lynxflow.co/en/tags/security/</link><description>Recent content in Security on Lynx Tech Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Mon, 31 Aug 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/en/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Stop Pasting API Keys and Bank Cards into LLM Relays: A Guide to Self-Hosted Privacy Gateways</title><link>https://blog.lynxflow.co/en/posts/llm-privacy-self-hosted-gateway-guide/</link><pubDate>Mon, 31 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/llm-privacy-self-hosted-gateway-guide/</guid><description>&lt;img src="https://blog.lynxflow.co/images/llm-privacy-self-hosted-gateway-guide.png" alt="Featured image of post Stop Pasting API Keys and Bank Cards into LLM Relays: A Guide to Self-Hosted Privacy Gateways" /&gt;Using a third-party LLM relay to access Claude, GPT, or Gemini is cheap and convenient—but have you considered this: the relay operator can see every single word you send to the model.
That includes API keys you casually paste in, bank card numbers, login passwords, ID numbers, medical records&amp;hellip; all sitting in someone&amp;rsquo;s server logs, in plaintext.
This isn&amp;rsquo;t paranoia—it&amp;rsquo;s architecture. A relay is fundamentally a reverse proxy: your request hits their server, gets unwrapped</description></item><item><title>After Reading the News About Robot Dog Security Guards, I Almost Started a Robot Dog Company—After a Day of Research, I Archived the Idea</title><link>https://blog.lynxflow.co/en/posts/robot-dog-security-company-reality-check/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/robot-dog-security-company-reality-check/</guid><description>&lt;img src="https://blog.lynxflow.co/images/robot-dog-security-company-reality-check.png" alt="Featured image of post After Reading the News About Robot Dog Security Guards, I Almost Started a Robot Dog Company—After a Day of Research, I Archived the Idea" /&gt;One News Story That Almost Made Me Start a Project on Impulse A few days ago, I came across a news story: Business Insider reported that robot dogs in the United States are entering the security industry—patrolling data centers, guarding high-value crops, and monitoring stadiums. The most eye-catching figure was this: using a robot dog to cover a 24/7 security post can save $80,000 to $130,000 per year compared with hiring a human guard.</description></item><item><title>Turn Off the Vendor’s Scratchpad and Hand the Model a New One: A Simple Attack for Extracting AI Reasoning</title><link>https://blog.lynxflow.co/en/posts/extracting-llm-reasoning-traces-via-tool-params/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/extracting-llm-reasoning-traces-via-tool-params/</guid><description>&lt;img src="https://blog.lynxflow.co/images/extracting-llm-reasoning-traces-via-tool-params.png?v=090500" alt="Featured image of post Turn Off the Vendor’s Scratchpad and Hand the Model a New One: A Simple Attack for Extracting AI Reasoning" /&gt;Vendors Locked the Front Door, but Forgot the Window Major model vendors have reached an unspoken consensus: you don’t get to see the raw reasoning process. OpenAI, Anthropic, and Google only return either a “summarized thought process” or a chunk of encrypted data through their APIs, which you can pass back unchanged so the model can continue the context, but you cannot read its contents.
The rationale is perfectly legitimate: raw reasoning may contain API keys, email addresses, access tokens,</description></item></channel></rss>