Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

301–310 of 817 posts

Re: Claude Code is steganographically marking requests

#301

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org . It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving o…

These countermeasures aren't going to matter for much longer anyway. China has been able to hoover up plenty of training data through their proxies, and now DeepSeek V4 due to their incredibly cheap pricing.

Re: Claude Code is steganographically marking requests

#302
post #295
post #279

Earlier quoted context omitted.

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

oh no, the company that illegally used every possible media they could get their hands on is crying that some other company is doing something potentially shady but not illegal? And using that excuse to put in place hidden surveillance systems on their customers?

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

Re: Claude Code is steganographically marking requests

#304
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

Sounds suspiciously similar to the "album title", "Steal this album" by system of a down.

Im not sure why we are dithering on the boundaries of honesty when the entire content LLMs are trained on is stolen.

Are we debating "honor among thieves"?

Of course we are not, or maybe we are!

Does the behavior of a thief even matter to me? only after they do their time. And they will.

I can see the investors perched on the balconies of their condos in a couple years if that.

its a long way down.

Re: Claude Code is steganographically marking requests

#305

Earlier quoted context omitted.

Copying over my comment from elsewhere in this post: Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative. That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn…

> by fingerprinting my access patterns It's based on whether your timezone is in China and your hostname matches a blacklist. Literally 2 bits of information. Not much of a fingerprint.

That's what it's based on right now, anyway. What other bits of info will they add as the Chinese work around this spyware?

Re: Claude Code is steganographically marking requests

#306
I used my proxy https://github.com/softcane/cc-blackbox setup to capture this.

This is how it looks.

# userEmail The user's email address is . # currentDate Today's date is 2026-06-30.

      IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task.

I also do not understand what's the point of this, because if I have a gateway that can detect it, then we can replace the text before forwarding to the model, so what's the catch?

Re: Claude Code is steganographically marking requests

#307
post #244

Earlier quoted context omitted.

What do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as t…

I don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.

> I don't want my harness doing sneaky stuff like this.

Since when was it your harness?

Switch to pi if this bothers you.

Re: Claude Code is steganographically marking requests

#308
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

> loudly stating the foreign labs have been distilling their models for a while now.

They would be stating this even if it weren't true, because it fits their marketing.

While I don't disbelieve the claim outright, I highly suspect Anthropic is misleading everyone about the severity.

Re: Claude Code is steganographically marking requests

#309

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

Why would a Chinese firm distilling the product use Claude code?

Re: Claude Code is steganographically marking requests

#310
post #290

Earlier quoted context omitted.

First its the "Chinese" then it will be people using "cyber" capabilities, or "jailbreaking" or "going against Dario" or any other thing they find "objectionable".

You forgot "Think about the children"

Won't somebody please think of the Chinese cyber children!
Post reply on HN