Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

621–630 of 817 posts

Re: Claude Code is steganographically marking requests

#621
post #3

This is very interesting. Combating resellers and distillation seems like a very difficult problem indeed. Interesting to me is that these techniques mentioned in the article are just like anti-observation techniques used by some of the more sophisticated malware out there, however defeating them is pretty trivial.

> these techniques mentioned in the article are just like anti-observation techniques used by some of the more sophisticated malware out there, however defeating them is pretty trivial.

Really makes you think huh

Re: Claude Code is steganographically marking requests

#622
I’d do the same for a11y an internationalization purposes - however this is juts a bad implementation of it from an americans perspective.

You’d change seperators and position if you truly wanted to do this right

Its basic date wrangling and tbh i see nothing malfeasant here

Its basically yyyy/mm/dd yy/M/d mm-dd-yyyy stuff but suuuuper lazily done

Re: Claude Code is steganographically marking requests

#623

Earlier quoted context omitted.

You are not alone, for me committing something it means I am signing my responsibility for it. I may not type a password, but I am always the one pressing the enter key.

How do you stop Claude/opex from pushing or pulling without you asking?

For open-source agents, like https://pi.dev, it is as easy as asking it to create a plugin to stop the session or ask for permission whenever the LLM is trying to execute a commit command. I believe Claude and Codex also suport plugins. Codex is open-source too.

Then you add one line in AGENTS.md stating the LLM should never commit, push or perform any write git operation without explicitly being asked to.

So in the very rare case that the LLM bypass your instruction, you catch it red-handed and stop the session or allow it.

I always make the plugin stop the session because LLMs tend to try to circunvent textual block messages by doing nifty things like concatenating characters to build a bash script to execute the git commit command. Yes, I have seen it.

Re: Claude Code is steganographically marking requests

#624

Earlier quoted context omitted.

Just like these distillers can learn from Claude’s output. Fair use is fair use.

I don't think Anthropic argues that distillation violates copyright. AFAIK, their position is that it violates their terms and conditions for interacting with their servers.

[dead]

Re: Claude Code is steganographically marking requests

#625

Earlier quoted context omitted.

The purpose of system is what it does. Can you read their previous musings about the glorious future, look at what they actually do, read Amodei's batshit insane nationalistic rants, and say in all seriousness yeah it's the kind of people I want to entrust my entire future life? >you want to prevent China from getting to superintelligence first I don't. Prevent , not even outpace? Why? Seems like you're assuming Chin…

[flagged]

> Do you know how their human rights violations compare to, say, western nations?

Yes, I could even say that the violations on the U.S. side have been more numerous and worse.

Re: Claude Code is steganographically marking requests

#626
post #600

Earlier quoted context omitted.

> The usage of the output is probably considered legal. The usage of the service for that purpose may not be, and using it at scale in a dishonest way is not This is literally what the "training AI on copyrighted works is just like a human learning/getting inspired" crowd has been arguing though. Literally. People have been literally saying that it was wrong because they did this "learning" at scale in a dishonest wa…

In some ways it's an offshoot of the honest benefit of search engines already crawling all this content. That has its own conflicts, like just how much of a page's content should you reproduce in the results before it's basically considered stealing their content without benefiting the site itself. There is a balance to strike, both in search engine fair use cases and AI fair use cases. The major cloud LLMs do double…

Well it was also problematic when the search engines started quoting the websites in such a way to disincentivize people from visiting the actual website.

> At least within the US, I think there are nuances around fair use and contract law.

The concept of "fair use" as it exists in the US-law system is completely dysfunctional (see e.g. nearly every educational music channel on YouTube), so utterly biased to favour large corporations, that there's very little room for whatever "nuances" you believe exist.

> Similar to old paintings digitized and hosted on some museum website. It's 300 years old, right? It should be public domain, yet the people who digitized it or provided a service to give you access have some say in how their reproduction can be used.

Yes 300 year old paintings are public domain. Indeed there are certain rules for the people/institutions who digitize them. It's not "they have some say", there's actually nothing mysterious about it and it is not similar to Anthropic's copyright heist at all because nearly all of the books they copied were not more than 100 years old.

> there are laws that can govern how you are allowed to use a service if that service has laid out acceptable usage

well where I live, there are laws about what a "service" can claim to "lay out as acceptable usage" instead of the other way around ...

> I also admit that a lot of the usage was probably quite legal

Let's disagree on that. I think it wasn't a lot and the vast majority was not legal. How do you think the LLMs "learned" to speak all these non-English languages? Unless your point is that it's probably quite legal to treat foreign IP like that. Which it may very well be in the US, especially if the corporation is large enough, but imvho it's still wrong.

> With any luck, artforms and skills impacted by technology will adapt and continue to be valuable instead of complete displacement or the dilution of opportunity.

And with any bad luck, these AI corporations will hold frontier models hostage for the rest of time.

I honestly don't want to put that up to "luck".

Re: Claude Code is steganographically marking requests

#628
post #522

Earlier quoted context omitted.

I don’t mean to insult you, but it is probably worth refreshing yourself on when slippery slope is actually a fallacy. It’s not correct to suggest logical extension of an established precedent is a slippery slope.

Putting "I don't mean to insult you" before a mild phrase just makes it sound you actually want to insult but in a passive aggressive way.

I saw it more as “if you are insulted by this reasonable advice, then you are an immature idiot” rather than a more direct insult. Still passive-aggressive, but no insult intended if the reader isn't triggered.

Source: I use similar phrases this way.

Re: Claude Code is steganographically marking requests

#629

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org . It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving o…

What if ... it was sloppy because it wasn't the people at Anthropic, but the AI that is writing a large percentage of their code?

Like maybe some "goal" they set for their AI caused it to decide that putting stego in the requests was the best way to achieve something or other.

(to be clear: I'm not saying this is right, I'm saying this is stupid)

Re: Claude Code is steganographically marking requests

#630
post #504

Earlier quoted context omitted.

Were the copyright owners contacted prior to this lawful obtaining that you speak of? Or after?

I miss the days when tech people were copyright skeptics. Remember when everyone was upset with Disney for our perpetual copyright regime and the destruction of public domain? Now many tech people are copyright maximalists and 100% converted to the church of Disney. It’s depressing.

its not copyright maximalism. people just see the obvious hypocrisy. a lot of people are also fine with some copyright
Post reply on HN