Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

761–770 of 817 posts

Re: Claude Code is steganographically marking requests

#761
post #244

Earlier quoted context omitted.

What do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as t…

> their IP it's not IP, and it's certainly not their IP > the TOS oh no, the terms of service how dare people break those. you don't get to claim fair use while CFAAing everyone's actual IP then whine about the tos, and then when called out on spying on users point to it as if it being in the tos somehow justifies it a lot of other malware has a tos too but we still call it for what it is

> it's not IP, and it's certainly not their IP

I'm not a lawyer so maybe that is the wrong legal term for a model/service like this. Would you mind telling me the word I should have used?

Re: Claude Code is steganographically marking requests

#762

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org . It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving o…

Reminds me of "Could God create a stone so heavy that even he could not lift it"

I would find it funny if this was due to "laziness" - defining laziness as it was a known oversight yet left unpatched. If we consider Anthropic as the leader in AI-native engineering, workflows, culture, etc. how can laziness in code exist? It should be as easy as for them to tell claude "come up with a better way" or, better yet, had their 24/7 monitoring agents identify and resolve this. If this was an oversight, which is completely natural to the eng process, maybe this current ai narrative/hype/marketing should be taken with a grain of salt

Re: Claude Code is steganographically marking requests

#763
If Anthropic decided to just send the user timezone as plain text instead of doing this obfuscated way, like "Today's date is 2026-06-30, timezone is Asia/Shanghai", how many of us will catch and question this behavior? It looks perfectly normal, right?

The question is about accountability. Right now these big closed-source model companies can do whatever with the data, and no one can hold them accountable for unacceptable data handling decisions.

Re: Claude Code is steganographically marking requests

#764

If Anthropic decided to just send the user timezone as plain text instead of doing this obfuscated way, like "Today's date is 2026-06-30, timezone is Asia/Shanghai", how many of us will catch and question this behavior? It looks perfectly normal, right? The question is about accountability. Right now these big closed-source model companies can do whatever with the data, and no one can hold them accountable for unacce…

Very good point! Accountability is very hard if the ecosystem is monopolized by a few giants.

Re: Claude Code is steganographically marking requests

#765
post #754

Earlier quoted context omitted.

Just like Nestlé had strategies to deal with the "competitive threat" of women breastfeeding their children instead of buying formula products. How could it be evil if it's just a corporation moving to neutralize a threat? https://en.wikipedia.org/wiki/Controversies_of_Nestl%C3%A9#B...

I agree that Nestle's actions are evil, based on an assessment of their actual actions and not just the fact that they have a strategy to deal with competition. Let's go back a step. You said Anthropic are "not trustworthy" and appeared to support this by saying "The CEO has recently started taking a stance against local AI". You then said they are doing "evil things". I'm totally prepared to accept that any company…

No, I didn't say those things. I'm not the person you were replying to.

But I do think that trying to create fear and uncertainty around open source in order to neutralize the competitive threat is potentially an evil (or at least not-morally-sound) strategy. I think it was pretty evil when Microsoft tried to do it against Linux.

Re: Claude Code is steganographically marking requests

#766

Earlier quoted context omitted.

So block people, instead of having false positives be secretly fucked over, and having them pay for the pleasure? Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here. I've had Claude fuck over clean well documented code-bases for no reason, and there's a good ch…

> I've had Claude fuck over clean well documented code-bases for no reason How exactly do you define "fucking over", and why do you suspect this "fucking" was done as a result of a faulty trigger as opposed to the inability of LLMs to write maintainable, extensible code? "Never attribute to malice what can adequately be explained by stupidity."

Changing well documented requirememts and functioning code to do subtly incorrect things, over multiple areas, for no reason. When confronted you get the usual, "youre right to push back, there was no reason to touch that and it did make everything worse"

Why do I suspect faulty trigger? The things wrecked weren't wrecked by even much less capable, including local models, while reverting everything to pre fucking up and asking claude again led to similar results. Once on whatever shitlist that was, claude also failed tasks it previously aced when given the exact same prompt and project files. I attributed it to opus 4.6 being a downgrade which people always pushed back on, claiming they thought it was better, but i had empirical proof, it couldnt do tasks 4.5- could do quite well. Now all of this? It's clicking all of a sudden that its quite plausible i got flagged somehow and ended up with an intentionally degraded service.

So, claude is off table for me these days, and deepseek gets very deep git commit read-throughs with every file even being read being carefully monitored. This obviously ruins the "agentic" promise, but the reality is we cannot trust these fucks (being the companies). The irony is deepseek now queries claude on problems its stuck on for input via openrouter, with mild success (the gap really isnt all that big, if its even there), before escalating to me for input on direction on solving a given problem. So now chinese models get more claude training data, not less. In fact, they get training data on frontier ML stacks and problems. Anthropic did that to themselves.

Re: Claude Code is steganographically marking requests

#767

Earlier quoted context omitted.

So block people, instead of having false positives be secretly fucked over, and having them pay for the pleasure? Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here. I've had Claude fuck over clean well documented code-bases for no reason, and there's a good ch…

> So block people To be fair to Anthropic, [they're trying very hard to do that.]( https://www.anthropic.com/news/detecting-and-preventing-dist... ). The attacks are sophisticated and difficult to detect. I don't accept that if this fails, their only option is to just accept Chinese companies stealing IP.

Them strugglig to prevent others from doing what they themsleves do, is my problem to a degree where I must pay for the pleasure to getting sabotaged? Are you fucked in the head? In what world are we "being fair" by claiming that? It takes a problem anthripic has hallucinated, and makes its consequences mine for no reason. Anthropic chose to create both this problem and it's consequences, why am I wearing it?

If I decide I dislike words starting in S, despite myself being a prolific user of words starting in S, and smack some child who'd never even heard the rules, simply for saying "sorry", simply because some people say "shit" and it makes me mad, despite it being my most used word, are we "being fair" by saying "to be fair, managing curse words is a difficult problem"

no right? Insane take.

Re: Claude Code is steganographically marking requests

#768

Earlier quoted context omitted.

So block people, instead of having false positives be secretly fucked over, and having them pay for the pleasure? Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here. I've had Claude fuck over clean well documented code-bases for no reason, and there's a good ch…

So don’t use it!

Correct, and I've stopped. I've moved to deepseek instead, equally capable and not as morally bankrupt as either OAI or anthropic.

Re: Claude Code is steganographically marking requests

#769
post #120

Earlier quoted context omitted.

"If they only collect the data for analysis I guess this is fine" I think you missed the memo on how foolish this attitude is. It came out around the time Edward Snowden made his discoveries at the NSA public. I suggest you look into it

As I said above, if you are worried about privacy while hooking up Claude Code, you need to reevaluate your understanding of this technology.

True. A lot of us missed the memo, or forgot it because of our amazement of LLMs

Re: Claude Code is steganographically marking requests

#770
post #523

Earlier quoted context omitted.

There's nothing wrong with the transparent collection of analytics. I expect any software that I run to tell me what they are sending at a bare minimum, and ideally give me a choice. This is the common and acceptable approach for a software company that deserves your trust. A willingness to cross that line with something small does not lend trust for something big, and there's nothing really comparable for the level…

This entire thread has lost its collective mind. Tracking time zone has to be up there with IP address and referer in the list of "trivial things every company in the entire world collects about you", and these things are entirely trackable without your consent or even knowledge. You're gonna have to turn off the Internet.

It seems like the confusion is about whether it is common practice to collect analytics vs whether it is common/acceptable practice to do so without disclosure and to cover your tracks. I recognize that virtually every cloud service collects info. Even something as trivial as IP address and region are not too trivial to include in the EULA.

What is the harm of that disclosure? If you are a company that wants to establish a firm basis of trust because you deliver a sensitive service, it is a necessity. I can't say with certainty that Anthropic doesn't disclose that they collect this info, but in any case, the way they've chosen to implement it does not lend credibility.

Post reply on HN