Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

341–350 of 817 posts

Re: Claude Code is steganographically marking requests

#341
post #191

Earlier quoted context omitted.

The site collection seems pretty random. There's a mix of actual AI labs, extremely questionable resellers (like whatever "claude-opus.top" is), and then random consumer sites like baidu and xiaohongshu.

Baidu has an actual AI lab: https://huggingface.co/baidu So does Xiaohongshu: https://huggingface.co/rednote-hilab Pretty much every Chinese internet company seems to have an AI team nowadays, however small. In addition, many Chinese companies are trying to give their programmers access to Anthropic models even though they're legally prohibited from doing so. And that might involve employees using unmodified Claude C…

Are Chinese programmers really prohibited from accessing American models?

Re: Claude Code is steganographically marking requests

#342

To summarize what they've already been doing: - filtering out people from the wrong side of "all humanity", years before it was demanded by the government - downgrading their models in arbitrary ways (later saying "sorry but not really") - actively sabotaging the replies, as in covertly modifying them to feed the users incorrect results What's next to expect from Anthropic? Malware to brick your machine if they don't…

HN hysteria is ridiculous.

All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence.

The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that:

- you want to prevent China from getting to superintelligence first

- you must gate access of SI to known good actors

- and that this is a race that will result in the extinction of humanity if you fail in these goals

Literally everything these people do is totally understandable if you drop the assumption that they're lying when they say "we think we are building superintelligence."

Re: Claude Code is steganographically marking requests

#343
post #309

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

Why would a Chinese firm distilling the product use Claude code?

They have some secret sauce not available through API maybe?

Re: Claude Code is steganographically marking requests

#344

> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes. This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The ste…

Seriously, the author has clearly never had to deal with client abuse.

This is a total non issue unless you are Chinese distilling lab.

Re: Claude Code is steganographically marking requests

#345

“So the feature mostly punishes the exact people who are easier to fingerprint: normal developers doing weird but legitimate things” What’s the punishment here exactly?

Higher odds of being banned for legitimate usage.

If you are accessing Claude through the listed domains it is not "legitimate use."

Re: Claude Code is steganographically marking requests

#346
post #45

This was already discovered during the source map leak. > This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust. They already tell you they scan for malicious prompts, and they have no ZDR guarantees for consumers. Why do signatures like this matter at all?

There has been an anti anthropic propaganda push by bad actors across social media sites especially Reddit and twitter. This started a few months ago when anthropic started beating openai.

I was browsing Threads and saw a lot of Anthropic hate. Randomly clicked on a profile and looked them up on LinkedIn - literally an OpenAI PR guy.

Re: Claude Code is steganographically marking requests

#347
post #279

Earlier quoted context omitted.

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

> foreign labs Apparently not just foreign labs. It looks like xAI distilled Anthropic models to train grok. https://opentools.ai/news/xai-trained-coding-models-claude-o...

That's less of a worry though since xAI is patently incompetent.

Re: Claude Code is steganographically marking requests

#348
post #279

Earlier quoted context omitted.

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

> foreign labs Apparently not just foreign labs. It looks like xAI distilled Anthropic models to train grok. https://opentools.ai/news/xai-trained-coding-models-claude-o...

I wouldn't be surprised

Re: Claude Code is steganographically marking requests

#349
post #191

Earlier quoted context omitted.

Baidu has an actual AI lab: https://huggingface.co/baidu So does Xiaohongshu: https://huggingface.co/rednote-hilab Pretty much every Chinese internet company seems to have an AI team nowadays, however small. In addition, many Chinese companies are trying to give their programmers access to Anthropic models even though they're legally prohibited from doing so. And that might involve employees using unmodified Claude C…

Are Chinese programmers really prohibited from accessing American models?

By the terms of service: https://www.anthropic.com/supported-countries

Re: Claude Code is steganographically marking requests

#350
post #337

Earlier quoted context omitted.

Right, so it seems that distilling an AI model is legal too then. At least it is somewhat similar.

Legal vs "They aren't going to let you do it with their service" are two different things.

Screw those poor copyright holders without the means to stop frontier AI labs, amirite?
Post reply on HN