Live data from Hacker News

The Claude Code Leak

build.ms

201–203 of 203 posts

Re: The Claude Code Leak

#201
post #195

Earlier quoted context omitted.

I don't see how that is relevant? I thought the point under discussion was that code does not matter until PMF, and that this would be an illustrative example because there was no code until PMF. Like, from the users' perspectives they were interacting via text messages both before and after PMF, until later down the line they were migrated to an app. At this point, the change was largely aesthetic, the core idea was…

> Maybe we're using different definitions of terms like "PMF" here? No, maybe different perspectives on what "the code matters" means. In this context, I took it to mean that "code being closed/open does not matter", because the context included leaking the source. I see you're taking it to mean "code being good/bad does not matter", because the context included a startup product. We're talking at cross-purposes. The…

Ah gotcha, that makes complete sense.

On that open/close aspect, however, this case is interesting because the leaked code was for a product that was shipped to users' machines in the wild. I'd say that while Anthropic, to your point, absolutely does not want this code leaked, they'd also know very well that any software released this way cannot be considered a competitive advantage for long.

Like, the ability of LLMs to reverse engineer software is well known by now. In fact this blog describes how, even before the leak, they reversed the CLI to patch bugs that Anthropic wouldn't! https://dev.to/kolkov/we-reverse-engineered-12-versions-of-c...

Which may be why other tools in this space have been open sourced. Yet Claude Code hasn't been, so clearly Anthropic wants to protect some rights there. I am very curious about these labs' decision processes when considering what functionality to put in the CLI versus on the servers. That could be a hint about their IP strategy and how they're thinking of moats.

Re: The Claude Code Leak

#202
The five-layer permission system discussion is interesting from a governance angle. Most small teams deploying Claude Code have no idea those permission layers exist — they approved the tool based on the marketing page, not the actual trust model.

The practical question for any CEO: if your developer's machine is running an agent with filesystem access, do you know what it can touch? The leaked code shows the answer is more nuanced than "it only touches what you tell it to."

Wrote a non-technical breakdown of what this means for AI tool policy (specifically the autonomous permissions mode and memory system that were hidden behind feature flags): https://www.aipolicydesk.com/blog/claude-code-leak-what-ceo-...

Re: The Claude Code Leak

#203
post #201

Earlier quoted context omitted.

> Maybe we're using different definitions of terms like "PMF" here? No, maybe different perspectives on what "the code matters" means. In this context, I took it to mean that "code being closed/open does not matter", because the context included leaking the source. I see you're taking it to mean "code being good/bad does not matter", because the context included a startup product. We're talking at cross-purposes. The…

Ah gotcha, that makes complete sense. On that open/close aspect, however, this case is interesting because the leaked code was for a product that was shipped to users' machines in the wild. I'd say that while Anthropic, to your point, absolutely does not want this code leaked, they'd also know very well that any software released this way cannot be considered a competitive advantage for long. Like, the ability of LLM…

You know, you're a very pleasant person to argue with :-)

Your co-workers must be very pleased, and your parents must be very proud.

(I'm a bit ashamed to say that it took me way too long to realise that what you're saying wasn't conflicting with what I was saying. Sorry!)

Post reply on HN