Live data from Hacker News

Claude Code is steganographically marking requests

thereallo.dev

521–530 of 817 posts

Re: Claude Code is steganographically marking requests

#522

Earlier quoted context omitted.

[flagged]

I don’t mean to insult you, but it is probably worth refreshing yourself on when slippery slope is actually a fallacy. It’s not correct to suggest logical extension of an established precedent is a slippery slope.

Putting "I don't mean to insult you" before a mild phrase just makes it sound you actually want to insult but in a passive aggressive way.

Re: Claude Code is steganographically marking requests

#523
post #462

Earlier quoted context omitted.

Do you honestly think that no service out there collects basic analytics?

There's nothing wrong with the transparent collection of analytics. I expect any software that I run to tell me what they are sending at a bare minimum, and ideally give me a choice. This is the common and acceptable approach for a software company that deserves your trust. A willingness to cross that line with something small does not lend trust for something big, and there's nothing really comparable for the level…

This entire thread has lost its collective mind. Tracking time zone has to be up there with IP address and referer in the list of "trivial things every company in the entire world collects about you", and these things are entirely trackable without your consent or even knowledge. You're gonna have to turn off the Internet.

Re: Claude Code is steganographically marking requests

#524

Earlier quoted context omitted.

I honestly find it crazy how many people trust them for their business needs. For a business, you want consistency and no surprises. With them you get exactly the opposite.

No, that's not correct. There are two types of business. One wants to be steadily growing, but the other wants to move fast and break things and either succeed or fail quickly.

altmanaltman is correct, I was talking about vendors. If you rely on a vendors service for your own business, you want it to be consistent. How can you plan around and rely on something that is inconsistent?

Your vendors plans to grow fast and break things shouldn’t affect your ability to provide your service to your customers.

Anthropic has not been a reliable vendor. Previously, when they were compute starved, the quality of their models degraded in the weeks before new releases, without warning to their customers. You just suddenly got a worse service. I wrote a little more a few months ago: https://news.ycombinator.com/item?id=47375818 And then there’s the transparent downgrading they did with Fable.

If your running a business, that’s not what you want to be relying on.

Re: Claude Code is steganographically marking requests

#525

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

I don't see any ethical connection between adding canary tokens to your output to catch people breaking your accepted ToS through ongoing distillation and stealing your PII off of your machine. How are legitimate users in US or China possibly harmed by Anthropic silently changing the apostrophe in Today's or the date separator from - to /?

> I don't see any ethical connection

Trust isn’t about ethics, it is about individual judgement of how much risk some actor poses to your own interests. Trust is context-dependent

There can be unethical actors whom you have good reason to trust, and highly ethical actors whom you have good reason to distrust

Re: Claude Code is steganographically marking requests

#526

Earlier quoted context omitted.

I love the asymmetry. When small fish tries to protect itself, big fish hits small fish with "It's not illegal" pole. When small fish points out that what the big fish is crying about is "not illegal", big fish has the right to be above the law to prevent the problem themselves. Having values requires equality. They have lost the right to cry foul when they trained their model with "but it's fair use" card. Life work…

> I love the asymmetry. Much as I hate to defend companies climbing to success and pulling up the ladder afterwards, this asymmetry you note is kind of the whole point a company would want to grow big . Growing an organization has some super-linear costs and generally sucks for most individuals living through it - including the management - but it's still considered worth it, precisely because big entities can do thi…

> Much as I hate to defend companies climbing to success and pulling up the ladder afterwards

Based on your post, you don't sound like you hate it at all.

Re: Claude Code is steganographically marking requests

#527

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

I don't see any ethical connection between adding canary tokens to your output to catch people breaking your accepted ToS through ongoing distillation and stealing your PII off of your machine. How are legitimate users in US or China possibly harmed by Anthropic silently changing the apostrophe in Today's or the date separator from - to /?

It's clandestine behavior, we all here assume it's trying to signal whether a user is in China, but this breaks an implicit trust.

How do we know this isn't the work of a rogue developer at anthropic and that they are not subtly switching visually identical characters in other contexts to ship your ssh keys or whatever.

We don't. After the trust that the software doesn't do things it doesn't disclose has been broken you can assume it operates like malware.

Re: Claude Code is steganographically marking requests

#528
post #279

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

Whether or not you find Anthropic's behavior bad, theybhave been very loudly stating the foreign labs have been distilling their models for a while now. This seems like an obvious response to me that would be a mechanism to make that obvious.

i think you're being played by their whole ethical high horse PR angle

Re: Claude Code is steganographically marking requests

#530

There are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thou…

First its the "Chinese" then it will be people using "cyber" capabilities, or "jailbreaking" or "going against Dario" or any other thing they find "objectionable".

Their terms of service already effectively attacks people for criticizing Anthropic. It says that if you use Claude to criticize Anthropic, then you've pre-agreed to pay for their lawyers going after you, and pre-agreed to lose the court case.
Post reply on HN