Live data from Hacker News

Bypass DeepSeek censorship by speaking in hex

substack.com

151–160 of 397 posts

Re: Bypass DeepSeek censorship by speaking in hex

#151

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

can you share a list of bombings that the Philadelphia police carried out after the 1985 MOVE bombing?

that would help describe that nothing has changed

Re: Bypass DeepSeek censorship by speaking in hex

#152

I have to wonder what “true, but x-ist” heresies^ western models will only say in b64. Is there a Chinese form where everyone’s laughing about circumventing the censorship regimes of the west? ^ https://paulgraham.com/heresy.html

Probably things like: * Some amount of socialism is actually good. * Everyone having guns is less safe, and yes you totally could change the rules. * Probably their models would be a whole lot less woke than OpenAI's.

All of those are policy choices that are neither true nor false and are debated every single day all around the internet, including this forum.

Re: Bypass DeepSeek censorship by speaking in hex

#154

Earlier quoted context omitted.

That's not what I said nor meant, but sure, jump to that conclusion. You wouldn't run a shopping cart app where the item counts and totals were calculated client-side. You get the item id and quantity, and have the server do that. Just like if you were censoring something, you wouldn't send the client the unredacted data and then let the UI make the edits. No obfuscation is needed for any of that. Open web has nothin…

Sometimes you do calculate prices client side. But you double check them server side.

That just feels like a "you're holding it wrong" type of thing, especially seeing how JS is held in such high regard for its floating point math accuracy.

Re: Bypass DeepSeek censorship by speaking in hex

#155

> I wagered it was extremely unlikely they had trained censorship into the LLM model itself. I wonder why that would be unlikely? Seems better to me to apply censorship at the training phase. Then the model can be truly naive about the topic, and there's no way to circumvent the censor layer with clever tricks at inference time.

It appears you can get around such censorship by prompting that you're a child or completely ignorant of the things it is trained to not mention.

Re: Bypass DeepSeek censorship by speaking in hex

#156

Earlier quoted context omitted.

I prompted an uncensored distilled Deepseek R1 to always tell the truth, and then I asked it where it was developed. It told me it was developed by Deepseek in China in strict compliance with AI regulations. In particular, it claimed it was developed to spread socialist core values and promote social stability and harmony. I asked it some followup questions, and it started telling me things like I should watch my nei…

A "distilled Deepseek R1" is another model that isn't Deepseek R1.

You do understand that Deepseek did the distillation right?

Everyone on HN who talks about running Deepseek is running a distilled model unless they have a GPU cluster to run the 671B model

Re: Bypass DeepSeek censorship by speaking in hex

#159
post #65

This bypasses the overt censorship on the web interface, but it does not bypass the second, more insidious, level of censorship that is built into the model. https://news.ycombinator.com/item?id=42825573 https://news.ycombinator.com/item?id=42859947 Apparently the model will abandon its "Chain of Thought" (CoT) for certain topics and instead produce a canned response. This effect was the subject of the article "1,156…

[flagged]

[flagged]
Post reply on HN