Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

371–380 of 817 posts

Re: Claude Code is steganographically marking requests

#371

I don't understand the privacy concerns the author is trying to highlight. Granted, doing anything "sneaky" will always raise suspicious once caught, but on the other hand, there would be no point in implementing these "security features" if they were upfront about how they work. And no, IMO stenography isn't security by obscurity, in the same that using RSA and keeping the private key private isn't security by obscu…

Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative. That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't har…

I'm using "sneaky" here to refer to anything that's not very obviously stated but anyway

> That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.

While I agree it's a dangerous precedence to set, I think this is a "vote with your wallet" sort of situation. They shouldn't do it, but from their POV this is what they need to do to offer the product they do at the price they do. If the product wasn't compelling people wouldn't accept that they do this. However they've decided if you want their product you have to use their interface and whatever spyware it comes with, so it comes down to, is the value proposition good enough that people will put up with it? As of today, the answer is unfortunately yes

Re: Claude Code is steganographically marking requests

#372
post #295

Earlier quoted context omitted.

oh no, the company that illegally used every possible media they could get their hands on is crying that some other company is doing something potentially shady but not illegal? And using that excuse to put in place hidden surveillance systems on their customers?

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

Has it? Because as far as I can tell those cases keep getting settled out of court before a legal precedent can be set.

For record breaking amounts too.

Re: Claude Code is steganographically marking requests

#373

I reported a similar system prompt injection mechanism here: https://news.ycombinator.com/item?id=48259288 https://github.com/anthropics/claude-code/issues/62061 Looks like they just keep finding new "creative" uses for such things, as expected. I'll keep patching them out.

Thanks for doing this. I had no idea the system prompt was embedding things like "avoid abstractions; three similar lines of code are better than one helper." Stuff I disagree with.

Is there a way to modify these prompts e.g. by putting instructions in CLAUDE.md to override it? I know it won’t directly modify the system prompt, but it seems like CLAUDE.md should have the final say, shouldn’t it?

Re: Claude Code is steganographically marking requests

#374
post #347

Earlier quoted context omitted.

> foreign labs Apparently not just foreign labs. It looks like xAI distilled Anthropic models to train grok. https://opentools.ai/news/xai-trained-coding-models-claude-o...

That's less of a worry though since xAI is patently incompetent.

Incompetence is not an excuse for amorality

Re: Claude Code is steganographically marking requests

#375
post #295

Earlier quoted context omitted.

oh no, the company that illegally used every possible media they could get their hands on is crying that some other company is doing something potentially shady but not illegal? And using that excuse to put in place hidden surveillance systems on their customers?

People keep throwing this idea around haphazardly, but U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use. You may not like it, but that doesn't make it "illegal".

> U.S. courts have pretty consistently decided that training on copyrighted works falls under fair use.

I don't believe that this has been resolved at all, and there are quite a few pending lawsuits about it at this very moment.

Re: Claude Code is steganographically marking requests

#376

> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes. This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The ste…

Seriously, the author has clearly never had to deal with client abuse. This is a total non issue unless you are Chinese distilling lab.

Old Marv from Cocke County, Tennessee had a distilling lab too. I'm not sure if he'd have issues too. Well, probably many issues but unrelated.

Re: Claude Code is steganographically marking requests

#377

Earlier quoted context omitted.

That's true, I am less familiar with the workings of cloud services than some are (as relevant as that may be in a discussion about a client that users run on their local machines). However, it sounds like you do understand how cloud services work. In interest of educating those less informed than yourself perhaps you could share with us why the reasoned points I've brought up are incorrect by actually addressing the…

[flagged]

Aw buddy, you seem to think I'm trying to hurt you. Furthest, thing from the truth.

I think you might have had enough HN for today. Take a nap and then eat a snack if you still feel cranky. The internet and all your cloud services will still be here when you want to play next.

(Well rested you'll also be able to string together a cogent argument but we're clearly struggling with bigger things here.)

Re: Claude Code is steganographically marking requests

#378
post #189

Earlier quoted context omitted.

Watch out for the press release where Dario denies this was ever intentional, and it’s actually emergent behavior demonstrating that Claude wants to claim authorship of its works

It's crazy that you could actually use the excuse that since it's all vibe-coded, there's no way a human could have written it, so Anthropic bears no responsibility. Meanwhile humans can pop in and leave little morsels like this and blame it on the model.

Something something blame something something management decisions

Re: Claude Code is steganographically marking requests

#379

To summarize what they've already been doing: - filtering out people from the wrong side of "all humanity", years before it was demanded by the government - downgrading their models in arbitrary ways (later saying "sorry but not really") - actively sabotaging the replies, as in covertly modifying them to feed the users incorrect results What's next to expect from Anthropic? Malware to brick your machine if they don't…

HN hysteria is ridiculous. All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence. The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that: - you want to prevent China from getting to superint…

> HN hysteria is ridiculous.

> this is a race that will result in the extinction of humanity if you fail in these goals

Re: Claude Code is steganographically marking requests

#380

Earlier quoted context omitted.

HN hysteria is ridiculous. All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence. The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that: - you want to prevent China from getting to superint…

The purpose of system is what it does. Can you read their previous musings about the glorious future, look at what they actually do, read Amodei's batshit insane nationalistic rants, and say in all seriousness yeah it's the kind of people I want to entrust my entire future life? >you want to prevent China from getting to superintelligence first I don't. Prevent , not even outpace? Why? Seems like you're assuming Chin…

[flagged]
Post reply on HN