Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

421–430 of 817 posts

Re: Claude Code is steganographically marking requests

#421

Earlier quoted context omitted.

They just show their true face. You’ve been lied all this time. They were never “good”.

I used to interact with the LW crowd… and they were mostly not outright swindlers or scoundrels. (from what I could sense) I think it’s fair to say most had decent respectability. Anthropic hired heavily from that pool so it’s astonishing how it turned out.

Everything they do is understandable if you think they are being honest when they say they're building superintelligence.

In this case they want to prevent a nation that censors its citizenry, puts/disappears dissidents into concentration camps for decades, and makes its own human rights lawyers literally eat their own shit, before raping and/or murdering them, from reaching superintelligence.

In this light, some client side code to potentially identify and ban the Chinese labs to slow them down by even a few days, is totally reasonable.

Re: Claude Code is steganographically marking requests

#422

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org . It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving o…

There is laziness, but there's also the conditions in which you have to react fast to an adversial in various conditions. Ultimately it's hard to take any stance here without knowing specifics. But it absolutely could be a matter of time, to do your best effort to stop efforts from the attacker if there's known attack going on.

There is a real time cat and mouse battle going on here in terms of keeping the advantage here, right.

As a rational actor, if someone was e.g. attacking me, leaving aside the whole copyright thing, but potentially using some sort of system to increase their value while decreasing my value (without calling it theft to avoid the whole debate), I would want to put proportionate defense out there as fast possible, depending on the amount of value that was exchanged to stop the bleed, while in parallel figuring out the best long term plan, right.

Re: Claude Code is steganographically marking requests

#423
post #328

Earlier quoted context omitted.

"It's not illegal" is only an argument against lawsuits / law enforcement involvement. Those PoW anti-AI things people put on pages aren't illegal either.

No. From my interactions, I have understood that some people use the same argument to wash their consciences from any guilt. What they do is unethical, but not illegal, and they hide under the same argument to drown the ethical angle. In other words, being honest to oneself is important. Anti-scraping measures people utilize are neither unethical nor illegal. That’s the difference.

I’m still frequently shocked by the entitlement people feel to other people’s work/ideas/data/bandwidth/server load, to feed a multi-trillion dollar industry. I find the totally cynical “well when you’re making an omelet…” types to be a bit pathetic, but I understand their motivation— they’re simply greedy. But I just can’t understand the genuine indignation about people attempting to limit or stop ingestion of their own work, even if it’s just for the bandwidth costs. Go ingest your own shit.

Re: Claude Code is steganographically marking requests

#424
post #222

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

> hysterical. The intent of this steg is excruciatingly clear Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means. Whether or not it harmed you this time , it's a violation of trust and autonomy. Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1…

> Surely you'd be angry if someone secretly installed a rootkit onto your computer

I surely would. What does that have to do with this scenario.

Note that the SW running on your machine is not doing anything malicious. The service is the thing that behaves in ways you want like - and that service is not running on your device.

There is no comparison with rootkits here. This is the equivalent of Google giving you a CLI to make searches easier, and that tool decides to just Rickroll you randomly. Annoying, yes. A security concern? No.

Re: Claude Code is steganographically marking requests

#425

Earlier quoted context omitted.

>Please actually do a modicum of research into AI safety. Your comment is the equivalent of a patient with zero context, arguing against the position of established medical science. What makes you think I didn't? You're talking like it's self-evident and adopt the condescending tone from the start, without giving any actual arguments why. (I'm not really interested in them as all these discussions are pointless and w…

> Rationalists and subsequently AI safety branch invented a religion in a roundabout way If you are arguing in good faith you can very clearly reason about any given AI safety take. Case in point, you refused to engage with most of the questions because you know the conclusions they lead to. > Medicine is largely based on evidence and real-life observations, unlike AI safety "AI safety doesn't exist" is certainly a t…

I believe I clearly marked my position without necessarily addressing those questions one by one, because it leads to an endless chain similar to ones we used to have a decade or more ago. The problem is that you don't seem to even acknowledge that viewpoints other than yours could exist in principle. I don't know how to reason with people talking about abstract matters like game theory as some ultimate source of truth without even mentioning axioms/grounding, applicability, experimentation, and actual real life complexities.

Re: Claude Code is steganographically marking requests

#426
post #115

Earlier quoted context omitted.

Which AI company have you learned more about where you liked them more as more details came out?

nous research. started out making overhyped llama finetunes, now they got a great agent harness and a cutting edge distributed training network that actually works.

I haven't tried their Hermes agent yet, because I only want a coding agent and I wasn't sure if theirs was suitable. Would you recommend it?

Re: Claude Code is steganographically marking requests

#427

Earlier quoted context omitted.

The purpose of system is what it does. Can you read their previous musings about the glorious future, look at what they actually do, read Amodei's batshit insane nationalistic rants, and say in all seriousness yeah it's the kind of people I want to entrust my entire future life? >you want to prevent China from getting to superintelligence first I don't. Prevent , not even outpace? Why? Seems like you're assuming Chin…

[flagged]

> Do you know how their human rights violations compare to, say, western nations?

You have to be joking

Re: Claude Code is steganographically marking requests

#428

Earlier quoted context omitted.

> Rationalists and subsequently AI safety branch invented a religion in a roundabout way If you are arguing in good faith you can very clearly reason about any given AI safety take. Case in point, you refused to engage with most of the questions because you know the conclusions they lead to. > Medicine is largely based on evidence and real-life observations, unlike AI safety "AI safety doesn't exist" is certainly a t…

I believe I clearly marked my position without necessarily addressing those questions one by one, because it leads to an endless chain similar to ones we used to have a decade or more ago. The problem is that you don't seem to even acknowledge that viewpoints other than yours could exist in principle. I don't know how to reason with people talking about abstract matters like game theory as some ultimate source of tru…

No, the problem is that you can't address why a nation that censors its citizenry, puts/disappears dissidents into concentration camps for decades, and makes its own human rights lawyers literally eat their own shit, before raping and/or murdering them - is better suited to reach superintelligence before the US (given that these are the only two left in the race for the superintelligence - I'd prefer the EU.)

You haven't provided a consistent counterpoint to any rationalist/safety viewpoint. I could acknowledge one if you actually provided a counterpoint, but you just say "it's a cult and it's wrong" without addressing the underlying argument.

Re: Claude Code is steganographically marking requests

#429

Earlier quoted context omitted.

At first I was agreeing with you, that this seemed like a sloppy way to implement this that was sure to be pretty quickly detected, but there is another possibility. Anthropic could have implemented this not as a durable detection system against proxying resellers, but instead as a point-in-time sampling system to detect where (and with what context) proxying reselling is currently happening. Sure, it would be detect…

I see your point, but in any case the more data / the less detectable, the better. But, yes, regardless of the exact motivation, I do think it's fairly plausible that they knew this would likely get detected fairly quickly no matter what and made a deliberate decision to not try to make it a super subtle, super clever insertion.

But even if this gets detected, they could have other less detectable processes going on as well, right.

It is going to be this cat and mouse game right, so at some point you want to throw as much out as quickly as possible when you are under attack, while building up the long term more scalable defense mechanisms.

Rationally I would assume that a lot of what you would quickly throw out would seem sloppy whether it is AI or not.

Re: Claude Code is steganographically marking requests

#430
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

What does that have to do with CC? I'm not commenting on that being good/bad/legal/illegal, but CC is separate from the models. If they really are doing this maliciously it is because they are trying to ignore my 'CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1' flag (if that still means anything).
Post reply on HN