Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

331–340 of 817 posts

Re: Claude Code is steganographically marking requests

#331

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

[flagged]

Re: Claude Code is steganographically marking requests

#332

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

So they’re watermarking requests according to your environment variables and maybe changing a string format if you’re in a certain time zone? Am I missing something here? Where’s the five alarm fire?

Re: Claude Code is steganographically marking requests

#333

Earlier quoted context omitted.

From my understanding, distilling the model with another model is not illegal per se. Also, the output of the LLM is public domain by law, too. So, why all this "effort" to protect the model? This is a free market, and moving fast and breaking things is the norm. If they are so adamant on protecting their IP, maybe they can start by respecting others' IP, so we can start talking about ethics, equality and playing fai…

> Also, the output of the LLM is public domain by law Why so? Also there is a lot of code in ironically claude and ChatGPT that’s generated by LLM . Yet I haven’t seen the public domain code

The code is not eligible for copyright. If they do not give you a copy of the source code, that does not matter. And if you don't know which parts were generated by LLM, you can't safely reuse the code.

Re: Claude Code is steganographically marking requests

#334
post #295

Earlier quoted context omitted.

oh no, the company that illegally used every possible media they could get their hands on is crying that some other company is doing something potentially shady but not illegal? And using that excuse to put in place hidden surveillance systems on their customers?

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

You have to admit that "downloading every book ever written for free from a repository of books that is itself illegal to compile and to run, in order to write a text generation tool" being legal is at least unintuitive, to put it mildly.

Re: Claude Code is steganographically marking requests

#335

I used my proxy https://github.com/softcane/cc-blackbox setup to capture this. This is how it looks. # userEmail The user's email address is . # currentDate Today's date is 2026-06-30. IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task. I also do not understand what's the point of this, because if I have a gateway that can…

Yes, a very easy and destructive man-in-the-middle attack seems likely.

But the whole point of this is to prevent the distillation and identify the list of blocked providers. If a provider is capturing the proxy, they can identify and modify that as well, so it only looks legitimate to the model. What am I missing here?

Re: Claude Code is steganographically marking requests

#336
post #328

Earlier quoted context omitted.

I love the asymmetry. When small fish tries to protect itself, big fish hits small fish with "It's not illegal" pole. When small fish points out that what the big fish is crying about is "not illegal", big fish has the right to be above the law to prevent the problem themselves. Having values requires equality. They have lost the right to cry foul when they trained their model with "but it's fair use" card. Life work…

"It's not illegal" is only an argument against lawsuits / law enforcement involvement. Those PoW anti-AI things people put on pages aren't illegal either.

No. From my interactions, I have understood that some people use the same argument to wash their consciences from any guilt. What they do is unethical, but not illegal, and they hide under the same argument to drown the ethical angle.

In other words, being honest to oneself is important.

Anti-scraping measures people utilize are neither unethical nor illegal. That’s the difference.

Re: Claude Code is steganographically marking requests

#337

Earlier quoted context omitted.

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

Right, so it seems that distilling an AI model is legal too then. At least it is somewhat similar.

Legal vs "They aren't going to let you do it with their service" are two different things.

Re: Claude Code is steganographically marking requests

#338
post #203

Earlier quoted context omitted.

Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies. That said, these fraudulent proxies are helping Chinese labs keep up, which might be…

What if they decide you're not patriotic enough, serving you evil models, because one man with a lot of shmeckels told them to?

Then I could just.. cancel my subscription and stop paying?

Re: Claude Code is steganographically marking requests

#340
post #244

Earlier quoted context omitted.

What do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as t…

I don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.

Your harness isn't doing sneaky things unless you're breaking TOS. HN hysteria is unreal.
Post reply on HN