Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

281–290 of 817 posts

Re: Claude Code is steganographically marking requests

#281

Earlier quoted context omitted.

> This will also allow them to, instead of blocking the distillation agents, respond with a poorer result/model, i.e. this will allow them to literally commit fraud against paying customers

1st, this technique is not fraud, and fraud is a separate accusation. 2nd, paying customers can legally and legitimately be banned and monitored for breaking terms of service, which probably includes things like using the model against U.S. export restrictions.

> 2nd, paying customers can legally and legitimately be banned and monitored for breaking terms of service

Yes, I said that. If a user is breaking your terms of service, ban them. Continuing to charge them while not providing the service they're paying for is, in fact, literal textbook fraud.

Re: Claude Code is steganographically marking requests

#282

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

Copying over my comment from elsewhere in this post: Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative. That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn…

Does their user agreement say they won't be harvesting PII?

Re: Claude Code is steganographically marking requests

#283

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

[flagged]

Re: Claude Code is steganographically marking requests

#284

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

First its the "Chinese" then it will be people using "cyber" capabilities, or "jailbreaking" or "going against Dario" or any other thing they find "objectionable".

Re: Claude Code is steganographically marking requests

#285

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

Copying over my comment from elsewhere in this post: Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative. That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn…

> by fingerprinting my access patterns

It's based on whether your timezone is in China and your hostname matches a blacklist. Literally 2 bits of information. Not much of a fingerprint.

Re: Claude Code is steganographically marking requests

#286
post #136

Earlier quoted context omitted.

Here is a video I made explaining it from absolute basics: https://m.youtube.com/watch?v=_AgKuFGvJfI And the repo: https://github.com/abtinf/homunctor

I hope you've already invalidated that bearer token :-P

Of course.

Re: Claude Code is steganographically marking requests

#287
post #278

Earlier quoted context omitted.

https://www.anthropic.com/news/claude-fable-5-mythos-5 This is not hundreds of pages and it gets its own bold headline section.

Wrong. That page is after they walked back because of the outrage. The original was on the PDF as reported in this article: > If Claude Fable stops helping you, you'll never know https://jonready.com/blog/posts/claude-fable5-is-allowed-to-... HN post with 1k+ comments: https://news.ycombinator.com/item?id=48467896

The original announcement page mentioned this. It was very obvious. That's why so many people noticed it immediately, because it was announced.

Re: Claude Code is steganographically marking requests

#289
post #203

Codex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.

Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies. That said, these fraudulent proxies are helping Chinese labs keep up, which might be…

What if they decide you're not patriotic enough, serving you evil models, because one man with a lot of shmeckels told them to?

Re: Claude Code is steganographically marking requests

#290

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

First its the "Chinese" then it will be people using "cyber" capabilities, or "jailbreaking" or "going against Dario" or any other thing they find "objectionable".

You forgot "Think about the children"
Post reply on HN