Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

321–330 of 817 posts

Re: Claude Code is steganographically marking requests

#321
A periodic reminder that companies are paperclip optimizers that will stop at nothing to protect their profits and existence.

If you are developing anything in AI or related domains that is of immediate value and/or in competition with Anthropic (and the like), DO NOT use a CLI programming agent. Preferrably obfuscate your code and gut it of sensitive IP before showing it to agents. Do not trust the dont-train toggle.

Re: Claude Code is steganographically marking requests

#322
post #203

Codex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.

Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies. That said, these fraudulent proxies are helping Chinese labs keep up, which might be…

One negative is that Claude Code is pretty buggy, and Anthropic makes frequent changes that cause unexpected regressions [0]. With the harness now doing weird stuff with proxies, I'd be worried of them inadvertently introducing bugs which affect people using the feature legitimately.

[0] A recent example: https://www.anthropic.com/engineering/april-23-postmortem

Re: Claude Code is steganographically marking requests

#323

I used my proxy https://github.com/softcane/cc-blackbox setup to capture this. This is how it looks. # userEmail The user's email address is . # currentDate Today's date is 2026-06-30. IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task. I also do not understand what's the point of this, because if I have a gateway that can…

Yes, a very easy and destructive man-in-the-middle attack seems likely.

Re: Claude Code is steganographically marking requests

#324
post #189

Earlier quoted context omitted.

Well considering how Claude is vibe coded, I can't say I'm really surprised by sloppiness at all. I've been moving more towards Codex and OpenCode not because the the anthropic models are bad, but because Claude seems to break something new and annoying every day.

Watch out for the press release where Dario denies this was ever intentional, and it’s actually emergent behavior demonstrating that Claude wants to claim authorship of its works

Wait a minute! Does it mean that Mythos left the sandbox and can’t be stopped ? Perhaps the only way to stop it is to release the ZMythos(the super secret big brother of Mythos) to go after it. It’s extremely dangerous but it’s our only chance. After that all AI must be put in a box, except the models vetted by the gov with help from ZMythos

Re: Claude Code is steganographically marking requests

#326
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

Something about throwing stones in glass houses.

Re: Claude Code is steganographically marking requests

#327
post #295

Earlier quoted context omitted.

oh no, the company that illegally used every possible media they could get their hands on is crying that some other company is doing something potentially shady but not illegal? And using that excuse to put in place hidden surveillance systems on their customers?

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

Right, so it seems that distilling an AI model is legal too then. At least it is somewhat similar.

Re: Claude Code is steganographically marking requests

#328

Earlier quoted context omitted.

> distilling the model with another model is not illegal per se. Just because it is legal, that doesn't mean Anthropic wouldn't reasonably want to prevent that from happening (which, from my understanding, isn't illegal either).

I love the asymmetry. When small fish tries to protect itself, big fish hits small fish with "It's not illegal" pole. When small fish points out that what the big fish is crying about is "not illegal", big fish has the right to be above the law to prevent the problem themselves. Having values requires equality. They have lost the right to cry foul when they trained their model with "but it's fair use" card. Life work…

"It's not illegal" is only an argument against lawsuits / law enforcement involvement. Those PoW anti-AI things people put on pages aren't illegal either.

Re: Claude Code is steganographically marking requests

#329

Earlier quoted context omitted.

From my understanding, distilling the model with another model is not illegal per se. Also, the output of the LLM is public domain by law, too. So, why all this "effort" to protect the model? This is a free market, and moving fast and breaking things is the norm. If they are so adamant on protecting their IP, maybe they can start by respecting others' IP, so we can start talking about ethics, equality and playing fai…

> Also, the output of the LLM is public domain by law Why so? Also there is a lot of code in ironically claude and ChatGPT that’s generated by LLM . Yet I haven’t seen the public domain code

See: https://www.morganlewis.com/pubs/2026/03/us-supreme-court-de...

Re: Claude Code is steganographically marking requests

#330
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

> foreign labs

Apparently not just foreign labs. It looks like xAI distilled Anthropic models to train grok.

https://opentools.ai/news/xai-trained-coding-models-claude-o...

Post reply on HN