Live data from Hacker News

Anthropic requires 30 day data retention for Fable and Mythos

support.claude.com

131–140 of 330 posts

Re: Anthropic requires 30 day data retention for Fable and Mythos

#131
post #77

It is actually worse than that. It is at least 30 days. There is an "almost" that is doing a ton of heavy lifting here "deletion after 30 days in almost all cases". My read of that is they can hang onto data for as long as they want, even if they usually won't. And "all traffic" with an agentic harness is basically your entire codebase you work on. > We will require 30-day retention for all traffic on Mythos-class mo…

I cannot help wondering if the 'we won't train on your data' applies across the fence over there in pentagon land, where the classified contracts be. Yeah, of course they are not connected. Or.. Present user-llm activity is a goldmine of intel the agencies literally spent lives and billions on getting hardly close to, yet they elect to just let this one slip by.. Maybe. Really, I don't dispute it. But why? It's what,…

I don't know why you'd read literally the last 25 years of leaks from mass surveillance programs and think for one moment that they've just, gosh, overlooked the opportunities.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#132

It is actually worse than that. It is at least 30 days. There is an "almost" that is doing a ton of heavy lifting here "deletion after 30 days in almost all cases". My read of that is they can hang onto data for as long as they want, even if they usually won't. And "all traffic" with an agentic harness is basically your entire codebase you work on. > We will require 30-day retention for all traffic on Mythos-class mo…

It’s even worse than that. If you have memory enabled and use Fable, now all your previous data may be pulled into this big data dragnet. How can Anthropic possibly think this is okay?

Well, it's okay for them.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#133

Earlier quoted context omitted.

One of the major attack vectors is distillation, where millions of questions are auto-generated and coordinated to produce training data for new LLMs. Anthropic alleges Minimax, Deepseek and Kimi were trained this way. Deepseek 4 compares favorably to Opus, so they're probably trying to prevent Deepseek 5 from being a bootleg Mythos. https://www.anthropic.com/news/detecting-and-preventing-dist...

Distillation is not an "attack", despite Anthropic themselves coining the self-serving phrase "distillation attack". And as others have noted, it is precisely identical to the sort of "attack" on published works which Anthropic themselves used to train their models.

Agreed. Distillation is as much of an attack as scraping is an attack ;)

Re: Anthropic requires 30 day data retention for Fable and Mythos

#134
post #6

So if you are under an NDA, does this violate it? I guess the better question would be if you are under and NDA and using an online model, are you already violating it but does this violate it further?

In the same way that using Gmail and Dropbox and iCloud and Notion violates it. (Which IANAL but for most NDAs would be not at all.)

Google Workspaces and Dropbox have an IL5-compliant offering, which means they attest that they will not do exactly this (and are audited on that). Not sure about iCloud and Notion.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#135
post #95

Earlier quoted context omitted.

Does anyone know about the jailbreaks and attacks they are referring to? These are done through model queries?

Why would you trust anything they say at face value? When they literally just showed you they are being deceptive by sneaking in the weasel word “almost”?

I'm asking for information to understand. What about that says I trust what they say as face value?

Re: Anthropic requires 30 day data retention for Fable and Mythos

#136
post #27

Earlier quoted context omitted.

I never had an NDA permit such usage.

Your NDAs prohibit emailing a colleague about the e.g. project, or discussing it in a Slack DM with the client, or tracking progress on it in JIRA? You have to do NDA’d work exclusively with local tools or end-to-end encryption? Those are some difficult NDAs!

Oh Lord yes. We have very specific communications channels we're allowed to use about any of our sensitive products, and that's only the unclassified stuff (classified is obviously its own, stricter, beast).

Re: Anthropic requires 30 day data retention for Fable and Mythos

#137
post #66

Earlier quoted context omitted.

Half of my customers will drop them right away, and the other half, after I explain to them what this means.

It's only for this model, not the one you're already using. And they're not training on the data. It's supposedly to detect abuse etc (such as someone retrying repeatedly with different variations to get around their protections)

> they're not training on the data

How would you know that? You can only know what they say they will do with the data.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#138
post #47

Earlier quoted context omitted.

We use inhouse on-premises email, issue tracking, and messaging. Depending on the project, external communication does require E2EE email. Development happens on local hardware and software unless required otherwise by the customer.

I’m pretty sure (even just based on the revenue of various SaaS products) that’s not typical, hence “most NDAs”. I’m also sure some require a SCIF, but that’s not most of them.

No this is still the level below needing a SCIF. The USG really tightened this stuff up in the 2010s and highly restricts what you can do with CUI. That's why there's a whole parallel FedRamp-compliant cloud ecosystem.

But in terms of how common it is, pretty much everybody in Fairfax County works in a company with rules like this; it's a big part of why the tech culture is so different than Austin or SFO.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#139

Earlier quoted context omitted.

It takes a lot of audacity to train on all the data you can without any license, attribution, etc and then act like you can own the outputs of the model so that someone else doesn't make a model from your data without a license. I've lost a lot of respect for Anthropic in the last 24 hours.

Everyone knows it's bullshit but because these companies are being valued at a trillion dollars a piece, it's hard to say that if you were in their shoes you'd do any differently.

I absolutely would do differently. Their behavior in public is gross.

Re: Anthropic requires 30 day data retention for Fable and Mythos

#140

It is actually worse than that. It is at least 30 days. There is an "almost" that is doing a ton of heavy lifting here "deletion after 30 days in almost all cases". My read of that is they can hang onto data for as long as they want, even if they usually won't. And "all traffic" with an agentic harness is basically your entire codebase you work on. > We will require 30-day retention for all traffic on Mythos-class mo…

[dead]
Post reply on HN