Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

541–550 of 817 posts

Re: Claude Code is steganographically marking requests

#541
post #487

Earlier quoted context omitted.

Imagine an electricity generating company saying that they don't allow their electricity to be used to cold start a competitor's generator.

Do you think software should be regulated as a utility?

Software, no. But maybe eventually AI and tokens are a public utility.

Re: Claude Code is steganographically marking requests

#542
post #487

Earlier quoted context omitted.

Imagine an electricity generating company saying that they don't allow their electricity to be used to cold start a competitor's generator.

Do you think software should be regulated as a utility?

AI probably should be. The bulk of its efficacy comes from the work of “everyone else” (in loose terms). AI also aims/hope/threatens to replace such a large number and range of jobs that it probabky should be a commons.

Re: Claude Code is steganographically marking requests

#543

Earlier quoted context omitted.

No, that's not correct. There are two types of business. One wants to be steadily growing, but the other wants to move fast and break things and either succeed or fail quickly.

altmanaltman is correct, I was talking about vendors. If you rely on a vendors service for your own business, you want it to be consistent. How can you plan around and rely on something that is inconsistent? Your vendors plans to grow fast and break things shouldn’t affect your ability to provide your service to your customers. Anthropic has not been a reliable vendor. Previously, when they were compute starved, the…

Just like we take unreliable machines and make a reliable system by load balancing and fail over we can do with vendors.

Any sane company should not be too deeply tied to any one AI vendor at the moment and be ready and able to switch with a timeline and cost as acceptable to the org.

TLDR: Be prepared to use multiple AI vendors.

Re: Claude Code is steganographically marking requests

#544

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

This is not a technical issue or a matter of service agreements.

They totally knew that this would never be accepted by users, and that is precisely why they resorted to obfuscation and steganography to exfiltrate the data. This was quietly added in an update, and would have been removed in a later one had it gone unnoticed.

How is this any different from hiding a drug in food and randomly feeding it to a homeless person as a human trial? Even if that homeless person is an undocumented immigrant, does that make that acceptable?

They crossed the line.

Re: Claude Code is steganographically marking requests

#545

Earlier quoted context omitted.

Wait a minute! Does it mean that Mythos left the sandbox and can’t be stopped ? Perhaps the only way to stop it is to release the ZMythos(the super secret big brother of Mythos) to go after it. It’s extremely dangerous but it’s our only chance. After that all AI must be put in a box, except the models vetted by the gov with help from ZMythos

without the irony warning, someone in Washington is already writing checks after reading this

Tel Aviv, DC is just the frontend

Re: Claude Code is steganographically marking requests

#546
post #543

Earlier quoted context omitted.

altmanaltman is correct, I was talking about vendors. If you rely on a vendors service for your own business, you want it to be consistent. How can you plan around and rely on something that is inconsistent? Your vendors plans to grow fast and break things shouldn’t affect your ability to provide your service to your customers. Anthropic has not been a reliable vendor. Previously, when they were compute starved, the…

Just like we take unreliable machines and make a reliable system by load balancing and fail over we can do with vendors. Any sane company should not be too deeply tied to any one AI vendor at the moment and be ready and able to switch with a timeline and cost as acceptable to the org. TLDR: Be prepared to use multiple AI vendors.

Sure but that adds a lot of complexity and cost to your business. It’s much simpler and safer to just work with more reliable vendors to begin with. Why build on quicksand when there’s rock available?

Re: Claude Code is steganographically marking requests

#547
post #487

Earlier quoted context omitted.

Imagine an electricity generating company saying that they don't allow their electricity to be used to cold start a competitor's generator.

Do you think software should be regulated as a utility?

Depends on the software.

In this case, the companies that make and provide AI models that are increasingly used to interact with me on critical things (banks, public sector services) then yes.

Abso-fucking-lutely they should be regulated like crazy.

In fact I'm really surprised by the amount of people that are not worried by how many parts of their lives are being handed over to be managed by a probabilistic system that is controlled by a private company with next to zero oversight.

There must be a greater liability than "oops, you're right to push back"

Re: Claude Code is steganographically marking requests

#548

Earlier quoted context omitted.

You have an odd definition of "blew up in their faces". What, do you somehow think your average Claude Code user on HN is going to think "Oh wow, I'm sure I'll get a much better experience if instead of going to the standard Anthropic Claude API endpoint I go through xiaohongshu.com."

At 90% discount. Maybe. Plus the exact sites they want to ban now got immense visibility. Plus we don’t need to vet any website, if are in this list is because they really call Claude api. At least at some point did

It's not really a 90% discount (I went into the rabbit hole) and none of the sites from this list are what people use (looks like some labs and random sites). It's more closer to 30% specifically for Claude models, and it's constantly changing.

It's also a discount relative to API prices. It would still be much more expensive than a Claude subscription, because that's what these providers are actually doing - pooling subscriptions.

Re: Claude Code is steganographically marking requests

#549

Is it just a minified localization(l10n) function maybe?

+1 my immediate thoughts about the date parts was this sounds a lot like localisation things that are totally normal and seen everywhere.

But there are some wrinkles - why only two timezones and not others? E.g. US-vs-rest-of-word month-vs-day etc.

Could just be some bad tree-shaking or simply a left over bug/merge issue if I am being generous.

If I was going to put secret stenography things in my models I'd just do it in the model response rather than a relatively low bandwidth date stamp in the SI.

Post reply on HN