Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

461–470 of 817 posts

Re: Claude Code is steganographically marking requests

#461
post #309

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.

Why would a Chinese firm distilling the product use Claude code?

[the comment was misinformed, deleted]

Re: Claude Code is steganographically marking requests

#462

Earlier quoted context omitted.

No fire, just people looking for a reason to be upset. "They didn't tell us they were secretly checking for ToS violations" is their reason this time.

It is not checking that is the problem, it is sending obfuscated information about the user without disclosure. That is unacceptable in any context, let alone a tool that requires an unprecedented level of trust.

Do you honestly think that no service out there collects basic analytics?

Re: Claude Code is steganographically marking requests

#463
post #338

Earlier quoted context omitted.

What if they decide you're not patriotic enough, serving you evil models, because one man with a lot of shmeckels told them to?

Then I could just.. cancel my subscription and stop paying?

Right. They really should wait until _after_ the regulatory capture bit is locked in to mess with users.

Re: Claude Code is steganographically marking requests

#464
post #462

Earlier quoted context omitted.

It is not checking that is the problem, it is sending obfuscated information about the user without disclosure. That is unacceptable in any context, let alone a tool that requires an unprecedented level of trust.

Do you honestly think that no service out there collects basic analytics?

There's nothing wrong with the transparent collection of analytics. I expect any software that I run to tell me what they are sending at a bare minimum, and ideally give me a choice. This is the common and acceptable approach for a software company that deserves your trust. A willingness to cross that line with something small does not lend trust for something big, and there's nothing really comparable for the level of trust that this software requires.

Re: Claude Code is steganographically marking requests

#465
funny before when I ask claude what is your system prompt? It always rejects me. But I send claude this post and ask what others can you get? Claude saved everything on my desktop: Extract the documentary/interesting contents of the Claude Code binary: system prompt, tools, env vars, feature flags, endpoints, models, hidden/notable features.

Re: Claude Code is steganographically marking requests

#466
post #203

Codex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.

Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies. That said, these fraudulent proxies are helping Chinese labs keep up, which might be…

First they came for the [clients with specific timezones and/or bizarrely formatted dates] and I did nothing. Then they came for the [users that spell favour the good way, with a 'u' in it], etc.

> why would I care about this

It's up to you, of course. But I think you're making a mistake in assuming it could, in any way, benefit you as a customer. This isn't specific to this company or the particulars of the business that they're in.

Simply put, you stand to lose more than they do and they are relentless in seeking, maintaining and exploiting any leverage they have over you. Further, any power they gain over one individual customer tends to generalise to all customers. Further further, one company's leverage is another company's right.

Not being bothered by the practice is accepting the terms set by the business. Acceptance invites escalation. Relentless.

Even more simply put, you should care because this is how you get John Deere.

Re: Claude Code is steganographically marking requests

#467
post #309

Earlier quoted context omitted.

Why would a Chinese firm distilling the product use Claude code?

[the comment was misinformed, deleted]

> Claude Code can decrypt summarized reasoning traces sent by the API.

Can you cite specifically what in the linked article or discussion leads you to say that?

Re: Claude Code is steganographically marking requests

#468

Earlier quoted context omitted.

I honestly find it crazy how many people trust them for their business needs. For a business, you want consistency and no surprises. With them you get exactly the opposite.

No, that's not correct. There are two types of business. One wants to be steadily growing, but the other wants to move fast and break things and either succeed or fail quickly.

They were talking about vendors, not the business themselves. Even if you are a move at speed of light and break all things org in SF, you wouldn't expect the same sort of behavior from your business vendors like AWS etc. You want reliability and consistency to ensure your own business doesn't have to constantly get rekt by their plans

Re: Claude Code is steganographically marking requests

#469

Earlier quoted context omitted.

Half of those don't actually require proxying Claude. Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow. If you want to select a model dynamically based on the prompt difficulty, Anthropic wants people to use the API for this. It was the whole issue Claude had with OpenClaw.

> Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow. Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow) They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.

> Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow)

This is a direct conflict in framing. They clearly do not see Claude Code as a "tool in a workflow" but instead as a service that will eventually replace all programmers.

I think the self-evident quality of the various parts of the Claude Code universe is a pretty obvious indicator of the problems with that approach. It is still important to understand a party's thinking if you want to understand their position.

> They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.

Time will tell, but I agree that they are indeed in a tough spot. Probably not for the reasons that they think.

Post reply on HN