Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

551–560 of 817 posts

Re: Claude Code is steganographically marking requests

#551

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

This is not a technical issue or a matter of service agreements. They totally knew that this would never be accepted by users, and that is precisely why they resorted to obfuscation and steganography to exfiltrate the data. This was quietly added in an update, and would have been removed in a later one had it gone unnoticed. How is this any different from hiding a drug in food and randomly feeding it to a homeless pe…

I mean, you’d resort to an obfuscated approach if you thought the ‘malicious’ users would remove your direct telemetry. The other users could be perfectly happy about it, but if you announced the change, obviously the malicious users would hear about it too and disable it.

This isn’t a comment on whether I agree with the change. Just that your analogies aren’t applicable here.

Re: Claude Code is steganographically marking requests

#553
post #244

Earlier quoted context omitted.

What do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as t…

> probably related to protecting their IP The same IP that is a highly compressed collection of everyone's else's IP? That's hilarious.

If some other AI company wants a highly compressed collection of everyone else's IP, they can get it by themselves - not from Anthropic pre-compressed =)

Re: Claude Code is steganographically marking requests

#554

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

> It's unclear on how this "punishes normal developers" in any shape or form.

There are, of course, no normal Chinese developers

Re: Claude Code is steganographically marking requests

#555

Earlier quoted context omitted.

I love the asymmetry. When small fish tries to protect itself, big fish hits small fish with "It's not illegal" pole. When small fish points out that what the big fish is crying about is "not illegal", big fish has the right to be above the law to prevent the problem themselves. Having values requires equality. They have lost the right to cry foul when they trained their model with "but it's fair use" card. Life work…

> I love the asymmetry. Much as I hate to defend companies climbing to success and pulling up the ladder afterwards, this asymmetry you note is kind of the whole point a company would want to grow big . Growing an organization has some super-linear costs and generally sucks for most individuals living through it - including the management - but it's still considered worth it, precisely because big entities can do thi…

At risk of losing the metaphor, they reaped stuff across all the lands, even ones that were not theirs, and it is questionbale that they even did most of the sowing in the first place

Re: Claude Code is steganographically marking requests

#556
post #551

Earlier quoted context omitted.

This is not a technical issue or a matter of service agreements. They totally knew that this would never be accepted by users, and that is precisely why they resorted to obfuscation and steganography to exfiltrate the data. This was quietly added in an update, and would have been removed in a later one had it gone unnoticed. How is this any different from hiding a drug in food and randomly feeding it to a homeless pe…

I mean, you’d resort to an obfuscated approach if you thought the ‘malicious’ users would remove your direct telemetry. The other users could be perfectly happy about it, but if you announced the change, obviously the malicious users would hear about it too and disable it. This isn’t a comment on whether I agree with the change. Just that your analogies aren’t applicable here.

Anthropic always came off to me as what can shorthand be described as an abusive controlling partner + the resulting relationship.

If you start viewing the conversations around it through that lens, a lot of stuff intuitively clicks into place.

Including this apologism for example.

Re: Claude Code is steganographically marking requests

#557
post #189

Earlier quoted context omitted.

Watch out for the press release where Dario denies this was ever intentional, and it’s actually emergent behavior demonstrating that Claude wants to claim authorship of its works

Wait a minute! Does it mean that Mythos left the sandbox and can’t be stopped ? Perhaps the only way to stop it is to release the ZMythos(the super secret big brother of Mythos) to go after it. It’s extremely dangerous but it’s our only chance. After that all AI must be put in a box, except the models vetted by the gov with help from ZMythos

I really liked Stanisław Lem's take on this in the short story "The Tale of the Computer That Fought a Dragon".

https://www.oocities.org/stanislaw_lem/opowiadania/opowiadan...

A solution for a military AI gone awry that built a terrifying electro-dragon was obviously to build a super-electro-dragon.

Re: Claude Code is steganographically marking requests

#558

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org . It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving o…

Don't teach them that

Re: Claude Code is steganographically marking requests

#559
> The trigger is ANTHROPIC_BASE_URL, Claude Code's API base URL override

I had a use case where I had to MITM CC's traffic to strip credentials that could have accidentally made it into the harness.

I'm happy my paranoid self told me "You don't really know what they're doing with that flag or if they're honoring it for all requests", so made a decision to proxy it at the network extension level.

Also, does anyone remember Anthropic quite literally sabotaging your project if the classifier in front of fable thought you were working in the AI industry? After backlash, they pulled it back, now they did this. Anthropic is on a weird tangent to ship malware. If someone doesn't stop them, one day, this will backfire catastrophically.

Re: Claude Code is steganographically marking requests

#560
Great find! I would just add that trust is indeed in the boring parts, but with gymnastics like this trust can be irreversibly lost. Then, no matter how boring tool is, there is no going back.

Anthropic has become a choice for many developers because of Claude Code, but in the recents months with "small things" like this and whole Fable fiasco they are *actively* pushing people to both competitors and local alternatives.

And if someone spends a significant amount of time and money to switch, it will be really hard for Anthropic to get those people back.

Post reply on HN