Live data from Hacker News

Anthropic requires 30 day data retention for Fable and Mythos

support.claude.com

71–80 of 330 posts

Re: Anthropic requires 30 day data retention for Fable and Mythos

#71
post #21

Fortunately I can't use Fable anyway, since their hyperactive content flaggers do not let you work on anything remotely biological or medical related (i.e. parse a CSV with some medical content, nope, you're probably a bioterrorist) and you get downgraded to Opus immediately.

[flagged]

It's temporary. From the fable blogpost:

>To release the model both safely and quickly, we’ve tuned these safeguards conservatively—they’ll sometimes catch harmless requests, though they trigger, on average, in less than 5% of sessions. With more capable models arriving in the coming months, we’re working to improve our safeguards and reduce false positives as quickly as we can.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#72
post #63

Earlier quoted context omitted.

Even worse when you git push something Microsoft gets all your code!

Yes, that is your intended purpose of “git push”, it’s to save. And only if you use GitHub. A better analogy here is probably “every time you use VS Code, the files you edit get sent to Microsoft”. Some legitimate concerns: • You have trade secrets. Previously; you can use services like Bedrock, etc, with signed contracts and significant reputations. Your contract is between AWS and you, and stays within your AWS sec…

All analogies are bad.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#73
post #53

Earlier quoted context omitted.

It's good they're being overcautious here. The alternative is far worse.

The alternative of... saving lives?

They don't want the real risk of someone using it to make biological or genetically targeted weapons, and they don't want the social risk of someone asking it a bunch of leading questions in order to 'prove' some racist thesis or to 'prove' Mythos is woke if it declines to along with their performative inquiry.

Let's face it, if some rando comes up to and asks if you have a few minutes to talk about population biology there's a good chance they're a kook.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#74
post #7

I actually think that’s warranted. And if you used it to poke around, you would also agree.

> And if you used it to poke around, you would also agree. Would you elaborate? Not sure what you're describing

All he pre-publicity from Anthropic was about how it was amazing at finding security vulnerabilities, so it's not a stretch to think that some people would want to exploit that for nefarious purposes.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#75
Mentioned in the earlier, topic as well, but one very important point here is that it looks like Anthropic is becoming GDPR controller for all submitted data for this model (when they are in GDPR scope anyway). So data subjects would have Article 15 right to request information about processing and possibly a copy of the data. Latter might be contested under "rights of others", but former is more absolute.

What this means it that if someone makes an Article 15 request, they would be entitled to know if Anthropic holds personal data about them and also from who they received this data at minimum.

If someone wants to do that, I would recommend combining it with Article 18 request to forbid deleting the data for legal claim in case you contest Anthropic's reply. Otherwise they could just delete the data per their retention policy and DPA would find much later that they no longer hold the data.

Another issue here is that their DPA frames everything as controller-to-processor, i.e. they do not appear to have SCCs in place to actually receive this personal data as controller. So the original exporter would likely also be in breach if they send any GDPR covered personal data to this model.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#77

It is actually worse than that. It is at least 30 days. There is an "almost" that is doing a ton of heavy lifting here "deletion after 30 days in almost all cases". My read of that is they can hang onto data for as long as they want, even if they usually won't. And "all traffic" with an agentic harness is basically your entire codebase you work on. > We will require 30-day retention for all traffic on Mythos-class mo…

I cannot help wondering if the 'we won't train on your data' applies across the fence over there in pentagon land, where the classified contracts be. Yeah, of course they are not connected. Or..

Present user-llm activity is a goldmine of intel the agencies literally spent lives and billions on getting hardly close to, yet they elect to just let this one slip by..

Maybe. Really, I don't dispute it.

But why? It's what, or precisely what, they always dreamed of.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#78
Didn’t they all but admit they’ve been storing and actively looking at requests with this post: https://www.anthropic.com/news/detecting-and-preventing-dist... ?

If they weren’t storing, they’d be oblivious to what customers are doing, making this kind of detection impossible. What data did they train their classifier on, if not real user (distiller) traffic?

Re: Anthropic requires 30 day data retention for Fable and Mythos

#79
post #66

Earlier quoted context omitted.

Half of my customers will drop them right away, and the other half, after I explain to them what this means.

It's only for this model, not the one you're already using. And they're not training on the data. It's supposedly to detect abuse etc (such as someone retrying repeatedly with different variations to get around their protections)

Still unacceptable.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#80

Didn’t they all but admit they’ve been storing and actively looking at requests with this post: https://www.anthropic.com/news/detecting-and-preventing-dist... ? If they weren’t storing, they’d be oblivious to what customers are doing, making this kind of detection impossible. What data did they train their classifier on, if not real user (distiller) traffic?

[deleted]
Post reply on HN