Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

351–360 of 817 posts

Re: Claude Code is steganographically marking requests

#351

I used my proxy https://github.com/softcane/cc-blackbox setup to capture this. This is how it looks. # userEmail The user's email address is . # currentDate Today's date is 2026-06-30. IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task. I also do not understand what's the point of this, because if I have a gateway that can…

The catch is you didn't know about this until today?

Re: Claude Code is steganographically marking requests

#352
post #191

Earlier quoted context omitted.

Baidu has an actual AI lab: https://huggingface.co/baidu So does Xiaohongshu: https://huggingface.co/rednote-hilab Pretty much every Chinese internet company seems to have an AI team nowadays, however small. In addition, many Chinese companies are trying to give their programmers access to Anthropic models even though they're legally prohibited from doing so. And that might involve employees using unmodified Claude C…

Are Chinese programmers really prohibited from accessing American models?

Anthropic does their best with banning accounts. As the result, shady API reselling market emerges. OpenAI on the other hand doesn't really discriminate based on a country like that (but a VPN is required nevertheless).

Re: Claude Code is steganographically marking requests

#353

Earlier quoted context omitted.

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

Right, so it seems that distilling an AI model is legal too then. At least it is somewhat similar.

It is a violation of their terms of service.

There are plenty of good reasons to not use Anthropic's services. If you don't like their terms of service, do stop using them! I personally think Anthropic's increasingly successful attempts at regulatory capture are even more distasteful.

Re: Claude Code is steganographically marking requests

#354

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

This is a problem of trust towards a software which runs on the user's machine and secretly conducts malware-like stenographic data exfiltration.

Re: Claude Code is steganographically marking requests

#355
double standard outrage from many, honestly, they're watermarking it. they've already told industry they take steps to mitigate distillation. Where's all the outrage over similar blackbox activities like how Steam performs VAC bans or how Gmail finds and blocks Spam?

You don't create a security measure then tell everyone how to bypass it.

I think OP is pointing something interesting out but the undertones of caution and "what else are they hiding" seem melodramatic and I find that hard to take serious.

The internet gives people a platform and, in a lot of ways, this supplants the typical role of journalism. The issue with this is no one wants to act like a journalist and actually explain the truth around a set of facts. Instead, they'll portray their opinions as a narrative and every time that resonates with someone or gets signal boosted, that narrative grows more assertive in the typical discourse I see nowadays. I would find it far more interesting to see what explanation Anthropic gives for these features than to immediately cry foul.

Re: Claude Code is steganographically marking requests

#356

Earlier quoted context omitted.

I would guess this part - since it's so sensitive, and fairly small - was either written or heavily driven by humans. Though I do also think it's possible their internal Mythos ~5.5 or whatever may also not necessarily be heavily optimized for thinking in the right manner for highly effective underhanded code. (I think it's possible it is capable and they just didn't use it for this, for whatever reason, though.)

Issue is if all their human software engineers have been vibe coding everything all the time (which apparently they are according to Boris), then they will be getting stupider and worse at writing code over time from lack of practice. By this point they're probably pretty bad at writing code

I have definitely become much worse at writing code, myself, for that exact reason, but I strongly suspect that's orthogonal to this, especially since this is a tiny amount of code. Underhanded code is not really a software engineering discipline. It's largely a psychological operations practice. I think they're possibly just not quite trained in the art of what could be considered intelligence tradecraft.

Re: Claude Code is steganographically marking requests

#357

To summarize what they've already been doing: - filtering out people from the wrong side of "all humanity", years before it was demanded by the government - downgrading their models in arbitrary ways (later saying "sorry but not really") - actively sabotaging the replies, as in covertly modifying them to feed the users incorrect results What's next to expect from Anthropic? Malware to brick your machine if they don't…

HN hysteria is ridiculous. All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence. The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that: - you want to prevent China from getting to superint…

The purpose of system is what it does. Can you read their previous musings about the glorious future, look at what they actually do, read Amodei's batshit insane nationalistic rants, and say in all seriousness yeah it's the kind of people I want to entrust my entire future life?

>you want to prevent China from getting to superintelligence first

I don't. Prevent, not even outpace? Why? Seems like you're assuming China "winning" whatever race it is effectively ends the humanity. Right now I think Chinese labs are way more mature about this, and Anthropic is way more dangerous than them. And how does it fit into the "for the benefit of all humanity" narrative we keep hearing? Is China wrong humanity? Who else is going to end up in the wrong part? Are you sure it's not you?

>if you drop the assumption that they're lying when they say "we think we are building superintelligence."

I never assumed that, I know perfectly who Anthropic are and that they believe everything they say as self-evident, without having any doubts. And I know they're the kind of people who can convince themselves in anything, because they're obviously smarter than everyone else, and become detached from reality. The entire US "AI safety community" was born in rationalist circles and is largely like this, it's a very specific cult. This is exactly the kind of people who are going to create hell on Earth for you and the rest if given even a lick of actual power, and perfectly rationalize it as a necessity.

Re: Claude Code is steganographically marking requests

#358

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

First its the "Chinese" then it will be people using "cyber" capabilities, or "jailbreaking" or "going against Dario" or any other thing they find "objectionable".

[flagged]

Re: Claude Code is steganographically marking requests

#359

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

> That the provider's business needs necessitate the this behaviour

If that's true, that is another reason why it's an illegitimate business.

Re: Claude Code is steganographically marking requests

#360

Earlier quoted context omitted.

I don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.

> I don't want my harness doing sneaky stuff like this. Since when was it your harness? Switch to pi if this bothers you.

I made my own! https://github.com/computerex/z
Post reply on HN