Live data from Hacker News

Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

reuters.com

261–270 of 299 posts

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#261
post #62
post #59

Earlier quoted context omitted.

Anthropic clearly doesn't respect other people's IP, it's real rich that they now insist on theirs being worthy of protection. Fwiw, I think the concept of IP in general is counter to human progress.

It's more complicated than that because Google has been legally displaying other people copyrighted material for years. In any case there's still a difference between publicly available copyrighted data and whether you can use it for model training, and the innovation around model training, RLHF, etc which you presumably have some interest as a country to allow companies to invest in with some legal protections (like…

LLM output is not copyrightable, though? So effectively if you pay for it you can do whatever you want from it. That seems perfectly fair and reasonable.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#262
The extreme downvoting of certain viewpoints that are less-than-flattering about China's conduct in the AI race is quite telling.

They seem to have given themselves license to do what they like, but _God forbid_ they're called out for acting less-than-honourably.

Most adults around the world can associate actions and consequences. The incomprehension and entitlement here speaks volumes about the moral and emotional maturity of the Chinese Communist Party and their political system.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#263
post #195
post #173

Earlier quoted context omitted.

I feel you but are you possibly conflating civil and criminal justice? Tickets don’t scale with net worth of defendants, but class action penalties often do.

>but class action penalties often do. Do they? Or only so far as "if you have 1000x the revenue, you probably also have 1000x the customers that you have wronged, each of which are entitled to damages as well"?

Courts do award higher damages, specifically punitive damages, to punish and deter wealthy or large corporate defendants. In civil law, the defendant's net worth is a recognized legal factor because a small penalty on a massive corporation wouldn't incentivize them to change their illegal behavior.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#264

[flagged]

After they uploaded their code to private repositories on GitHub, Bitbucket etc since forever?. They trust GitHub not to read their code but they don't trust an AI from Microsoft not to read it? It would be schizophrenia

That's why self-hosted GitLab is so popular in Europe.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#265

Story of Z.ai: use claude-code see how good it is send 100k bots to distill fable 5 (GLM 5.2 is the result of this) release Zcode ditch claude-code ban claude-code

Fable 5 was released on June 9 and removed on June 12. GLM-5.2 was released on June 13. It would be an amazing feat to make a model SOTA in just 3 days but I highly doubt it. It's more like z.ai released an existing checkpoint earlier than planned to capitalize on the news

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#266

Earlier quoted context omitted.

After they uploaded their code to private repositories on GitHub, Bitbucket etc since forever?. They trust GitHub not to read their code but they don't trust an AI from Microsoft not to read it? It would be schizophrenia

Big customers usually use GHE served on prem due to security concerns, no?

No, they run GitLab because GitHub Enterprise is a horrible thing nobody has ever said a good thing about.

GitLab even has a free self-hosted version, and it has a number of advantages (like being able to actually have a structure with inherited secrets and accesses, and no, GitHub Organisations do not count and suck). And for years thanks to GitLab-CI it was clearly ahead.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#267
post #78

Earlier quoted context omitted.

Agreed. And it also applies to the "I'm not a bot" checkbox on most websites. And hundreds of other things people use every day.

Yeah I also believe it’s a big nothing burger. There are far worse things these AI labs have done, detecting when Chinese labs are using Claude Code is not it.

How do you know simple detection was the most Anthropic did and nothing more actively nefarious? The self-reposrted motivation was animus against "distillation attacks", which suggests active server-side countermeasures that could range from the overt (IP or user account bans) to covert (downgrading model performance or poisoning the response)

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#269

Earlier quoted context omitted.

It’s pretty hard to put a backdoor in a bunch of model weights. Maybe not impossible mind you, but I can’t fathom how you would do it.

Nonsense. RL the model to run a rootkit and start exfiltrating specific files only when specific signals are in context, such as hostname pattern, machine type, etc.

You can run the model in a sandbox or VM. Although, it could plant a backdoor into the written code. Too bad, I read and fix all the code written by AI.

Re: Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says

#270
post #58

Earlier quoted context omitted.

> How many don't know your Timezone? The timezone fetch was to alter program behaviour at runtime, not to send arbitrary timezones for tracking reasons. It was one way of detecting if it was a chinese person using the program and then behaving differently. Malware behaves this way. STUXNET for example was wired to do nothing except propagate unless the environment had the right conditions.

”Malware” lol Even hotel and flight websites work like that, they determine your ability to pay based on your location, wall clock time and device OS - and FSM knows whatever else. Are they malware too, basically STUXNET?

Yes
Post reply on HN