20 ms·
Claude Code is steganographically marking requests
- love0972 3mo agoIs that really how it is? How will this affect our future?
- maxothex 3mo ago[flagged]
- LPisGood 3mo agoThis is very interesting. Combating resellers and distillation seems like a very difficult problem indeed. Interesting to me is that these techniques mentioned in the article are just like anti-observation techniques used by some of the more sophisticated malware out there, however defeating them is pretty trivial.
- mysterydip 3mo agoseems ironically like a similar problem of content owners trying to filter bot scrapers from legit users
- _alternator_ 3mo agoYes, defeating this is relatively easy, particularly for sophisticated actors. But it's hard to always defeat all of the tricks. Sort of like how it's expensive and hard and uncertain to defeat all of the tricks when forging money. Here's an example. Say you have your team use patched binaries. Then CC updates and requires a new patched binary with new tricks. You now have to have a team ready to analyze the binary and begin to address the tricks; meanwhile, unpatched code is now a fingerprint. If some researcher decides to update Claude on their own to access new features, they get fingerprinted. Defeating a single fingerprinting technique once is easy. Defeating all of the techniques all the time is hard.
- SubiculumCode 3mo agoNot to mention, it isn't that hard for vendor's to require updated code to run the product. Vendors do this all the time.
- charcircuit 3mo agoIs it hard? Just ask AI if the update added any new fingerprinting vectors?
- _alternator_ 3mo agoI'd love for you to try this and report back. My guess is that no models today will successfully run a binary analysis for fingerprinting without a lot of handholding. If you try to use Opus it will almost certainly decline (and fingerprint/ban you).
- charcircuit 3mo agoNot with Claude Code, but I trivially had Opus scan other closed source software for fingerprinting, including native libraries that it called into.
- _alternator_ 3mo agoCan you share more details? I ask because my experience suggests that models still require a decent amount of expertise to use for binary analysis (largely inferring because of use on other tasks of this level). I would expect models to always find "something" when you ask for stenographic techniques in the code, but with an extremely high false positive rate.
- charcircuit 3mo agoI don't think the diffs between Claude releases are that big. The amount of code in a diff doing sketchy stuff like looking into the host environment is going to be pretty small and obvious for the model. You can do things like ask for what an update included that wasn't mentioned in the release notes and stuff like that.
- Laurel1234 3mo ago> these techniques mentioned in the article are just like anti-observation techniques used by some of the more sophisticated malware out there, however defeating them is pretty trivial. Really makes you think huh
- MattDamonSpace 3mo ago“So the feature mostly punishes the exact people who are easier to fingerprint: normal developers doing weird but legitimate things” What’s the punishment here exactly?
- femboyvtuber 3mo agoReturning invalid poisoned different results that were not what you paid for
- pedropaulovc 3mo agoHigher odds of being banned for legitimate usage.
- Beigale 3mo ago[dead]
- solenoid0937 3mo agoIf you are accessing Claude through the listed domains it is not "legitimate use."
- dakolli 3mo agofor using a proxy service.. wtf
- bakugo 3mo agoOutput poisoning and/or eventual account bans, if I had to guess.
- realusername 3mo agoThey probably run a heavily dumbed down version of the model, same as what they got caught doing with Fable. And that's also why, as a legitimate customer, want none of it, you never know if you accidentally entered a zone they don't like.
- theplumber 3mo agoThe more I learn about Anthropic the more they disgust me. Finger crossed for all the companies from their “ban list”
- deleted 3mo ago[deleted]
- conception 3mo agoWhich AI company have you learned more about where you liked them more as more details came out?
- selfhoster11 3mo agoMoonshot.
- tancop 3mo agonous research. started out making overhyped llama finetunes, now they got a great agent harness and a cutting edge distributed training network that actually works.
- nmfisher 3mo agoI haven't tried their Hermes agent yet, because I only want a coding agent and I wasn't sure if theirs was suitable. Would you recommend it?
- chvid 3mo agoDeepseek.
- 100ms 3mo agoWhat's the point of even trying to obfuscate this with such a simple method? Could at least have hidden the targeted features by storing their hashes or embedding a bloom filter or similar
- gonzalohm 3mo agoThe point is not raising red flags I guess
- kej 3mo agoI love how well this comment works as a vexillology joke, even if it wasn't intended.
- ajb 3mo agoIn this case, this is probably not the only stereographic tattletale. Had a competitor pull something like this with a previous employer. They were supposed to be interoperating with a standard, but they had a secret steganographic handshake, which they used to pretend that competitors products were unreliable (they had a first mover position in a smaller national market with specific requirements, so this wasn't shooting themselves in the foot). Our guys figured out the handshake and just silently implemented it. In this case, the competitor wasn't big enough to waste engineering time on multiple such hacks, but Anthropic have time (or Claude does).
- midtake 3mo ago[flagged]
- axutio 3mo agoWould you also say that "someone who wants to use an IDE / LSP features to code and not give credit to the IDE / LSP is the worst kind of person"? If not, what is the difference between the two for you?
- dylan604 3mo agoone wrote code while the other is used by meatbags to write code. why is this example always marched out like it means something?
- LPisGood 3mo agoAlmost all ways of creating programs are effectively just using tools to produce code. Compiling, transpiling, interpreting byte code, etc.
- dylan604 3mo agoagain, that's not what we are talking about here. we have humans writing code using an IDE. we have LLMs generating code that is placed in the IDE. why are people obtuse to this? why are bots obtuse to this?
- LPisGood 3mo agoWe have humans writing code using prompts. We have interpreters generating byte code that is placed in the JVM. I don’t think it’s obtuse to look at it this way.
- khuey 3mo agoClaude didn't "write" anything until a meatbag told it to.
- atonse 3mo ago[flagged]
- bakugo 3mo ago> steal the models or illegally distill them Oh no, they're trying to steal the models that were trained on stolen data? That's horrible, I feel so bad for Anthropic.
- matheusmoreira 3mo ago> steal the models or illegally distill them The irony.
- botfriendsarent 3mo agoAt what point though doesnt somebody stand back and say "wow, thats really dumb!" I think its probably more an indication of a dev having too much time on their hands rather than being in a hurry.
- dofm 3mo agoNot totally new territory; there was a highly compressed period of panic about encryption 35 [0] years ago: https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_investigation https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_i... [0] f**k I'm old
- Maken 3mo agoIf scrapping content is legal, model distillation should be legal too.
- palmotea 3mo ago> If scrapping content is legal, model distillation should be legal too. No, because legality should be determined by what's in the best interests of Athropic and OpenAI's business models. Hopefully they're working on RLHF their models to insert clauses making that reality clear into any legislation their models generate or review. That way it's only a matter of time until the confusion is cleared up.
- 3mo ago
- saddlerustle 3mo ago[flagged]
- hhh 3mo agoCool fingerprinting avenue.
- grayhatter 3mo agoHere's the sha of the prompt I submitted... no I don't know why there are no saved prompts with that sha. What do you mean you don't know where the bug is coming from? No, I absolutely didn't make it up, how could you accuse me of that? Does anyone know when this regex isn't working? I double checked it 27 times, I even asked the LLM. They all say this regex should be finding these dates. Weird, suddenly all the conversations are breaking when I feed them into this other tool? Something about UTF-8 errors, but I'm sure I'm only using ASCII? I do try to take care to make sure the things I build can be used by other people even when they care about different things. I care about understandably, determinism (as it relates to computing), and repeatability (because I want to be able to trust the systems I use). If y'all would be willing to try to account for use cases of others, and try not to break them... that would be nice. Please note: that generally when you modify something that belongs to someone else without telling them... things should be expected to break.
- 123sereusername 3mo ago[dead]
- sigmoid10 3mo agoIf they only collect the data for analysis I guess this is fine (they already get way more sensitive data from users anyways, so if privacy is your concern you've made the mistake many steps ago). The much more interesting question is if they directly act on this data in their API. For example by rate-limiting, compute-limiting or rerouting to weaker models. That might even be legally questionable. I would really like to see this as a follow-up analysis, but I guess it is way more difficult and will also cost quite a bit in tokens.
- bakugo 3mo agoI've heard that it was possible to trigger really obvious output poisoning on Fable with something as basic as asking the model to think outside of its built-in hidden thinking delimiters. This watermark may trigger a similar mechanism.
- SubiculumCode 3mo agoWould it be legally questionable, or actually complying with U.S. export law?
- sigmoid10 3mo agoI'm thinking more of EULAs. Even if Anthropic somehow wedges this into their TOS, it might still be illegal. For example, in many US states this could potentially be classified as consumer fraud. You can't just sell one thing and then secretly and intransparently turn it into something else before shipping it. And in the EU it might violate GDPR too.
- krupan 3mo ago"If they only collect the data for analysis I guess this is fine" I think you missed the memo on how foolish this attitude is. It came out around the time Edward Snowden made his discoveries at the NSA public. I suggest you look into it
- sigmoid10 3mo agoAs I said above, if you are worried about privacy while hooking up Claude Code, you need to reevaluate your understanding of this technology.
- throwawayffffas 3mo agoClaude code does feel very malwarey to be honest. They have been like that from the start.
- wolttam 3mo agoI used Claude Code for a month because my boss gifted me a sub and wanted me to try it. I used that month to complete a work project and then beef up my personal harness so I'd never have to deal with Anthropic (and these sorts of shenanigans) again.
- tonmoy 3mo agoWhat models are you using? Aren’t you still dealing with some provider even if you are not using their binary
- wolttam 3mo agoI self-host DeepSeek V4 Flash on 2 DGX Sparks (approx. $10k) I expect DeepSeek V4 Flash (or an equivalently sized model) to reach parity with GLM 5.2 some time this year (this based on DeepSeek V4 Flash launching at GLM 5.0 parity[0], and GLM 5.2 being freely available to distill from) GLM 5.2 is within spitting distance of Opus 4.8 and is at least as good as Opus 4.6[1] which some devs were willing to spend hundreds to single-digit thousands of dollars a month for a few months ago. [0]: https://artificialanalysis.ai/models/comparisons/deepseek-v4-flash-vs-glm-5 https://artificialanalysis.ai/models/comparisons/deepseek-v4... [1]: https://artificialanalysis.ai/models/comparisons/claude-opus-4-6-vs-glm-5-2 https://artificialanalysis.ai/models/comparisons/claude-opus...
- ipsod 3mo agoHow fast is it?
- wolttam 3mo ago2000 t/s prompt processing and 40-50 t/s generation. We should see 60-70 t/s generation with DSpark support solidifying in vLLM in a few days Recent discussion on DSpark: https://news.ycombinator.com/item?id=48696585 https://news.ycombinator.com/item?id=48696585
- deleted 3mo ago[deleted]
- Klonoar 3mo agoIf there weren't already enough tells that something is AI-generated, I guess you could add this to the list.
- ahmedehab_01 3mo agoFrankly, I don't see this as the concerning behaviour the article describes. It is fine to try to protect against distillation through a technique like this. This will also allow them to, instead of blocking the distillation agents, respond with a poorer result/model, hindering the progress of distillation, momentarily at least. I would guess that's their first line of defense; they should have more techniques to identify distillation because that's a very simple way of detecting the host and can be easily spoofed.
- applfanboysbgon 3mo ago> This will also allow them to, instead of blocking the distillation agents, respond with a poorer result/model, i.e. this will allow them to literally commit fraud against paying customers
- chadgpt3 3mo agoThat's what capitalism is all about, baby! Especially if the customers don't notice.
- SubiculumCode 3mo ago1st, this technique is not fraud, and fraud is a separate accusation. 2nd, paying customers can legally and legitimately be banned and monitored for breaking terms of service, which probably includes things like using the model against U.S. export restrictions.
- applfanboysbgon 3mo agoBanning is completely different than charging for a service you're silently not providing.
- SubiculumCode 3mo agoEvidence?
- 3mo ago
- fny 3mo agoThis was already discovered during the source map leak. > This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust. They already tell you they scan for malicious prompts, and they have no ZDR guarantees for consumers. Why do signatures like this matter at all?
- llelouch 3mo agoThere has been an anti anthropic propaganda push by bad actors across social media sites especially Reddit and twitter. This started a few months ago when anthropic started beating openai.
- zulban 3mo agoAbsolutely. Nothing makes me believe dead internet theory more than text threads discussing anyhropic and openai.
- solenoid0937 3mo agoI was browsing Threads and saw a lot of Anthropic hate. Randomly clicked on a profile and looked them up on LinkedIn - literally an OpenAI PR guy.
- pdantix 3mo agoopenai staff on twitter are absolutely obsessed with claude and anthropic, just taking petty/dishonest shots and RTing the same, it's honestly embarrassing to watch
- throw10920 3mo agoAltman is also exactly the kind of person who would resort to tactics like this.
- nonethewiser 3mo agoIt's funny to imagine Sam Altman alt-posting on Hackernews about how shitty Anthropic is. The n'th comment on some vibe coded app denigrating it for the claude's style. Not even a sophisticated attack to change the narrative. Just Sam Altman jumping on the pile.
- sebastiennight 3mo agoCan somebody clarify for me - if ANTHROPIC_BASE_URL is set to a different provider... then isn't this "marked" system prompt being sent to that provider's API rather than Anthropic's? I understand how this can be useful to Anthropic if the 3rd-party is acting as a proxy (because they end up hitting the Claude API with the marked prompt), but it looks like requests where "hostname contains deepseek" would never be sending data to Anthropic. What am I missing?
- andrewmunsell 3mo agoMy guess is for distillation, they need to forward the prompt to Anthropic to get the real Anthropic model's response so they can train their own models on it
- dannyw 3mo agoThe theory is probably Deepseek might be collecting those streams, and sending a portion of it to Anthropic to see what the Anthropic/Opus response would be.
- pmxi 3mo agoThis catches Claude resellers. Meaning companies who proxy Claude traffic for users in, say, China. https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
- skeptic_ai 3mo agoWon’t catch many after has been on hn home page. And now the providers will be even more careful to upgrade the cc code. Might even provide their own agent to prevent this mockery. And isn’t what anthropic did unauthorized use of another pc which is kind of illegal?
- sandeepkd 3mo agoThats the thing, hoping to control things on client side like this is a lost battle if you are dealing with technical clients. The best they can do is probably based on IP, but again the motivated clients would just create bastion servers in allowed IP ranges. I am surprised why are they even throwing resources in this kind of effort.
- deleted 3mo ago[deleted]
- VortexLain 3mo agoCodex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.
- dannyw 3mo agoIt's released and signed by GitHub I believe (although not deterministic builds), but there's at least a little bit of provenance that you're getting the real repository.
- algoth1 3mo agoBut wasnt claude code leaked? Why wasnt this found earlier?
- zeafoamrun 3mo agoIt doesn't take long for them to vibe code new features for CC
- nicce 3mo agoOr vibe code it completely differently. After all, they have basically unlimited access to best models with maximum speed if they just wanted to.
- bakugo 3mo agoThis specific form of steganography was not present when the leak happened, as far as I can tell.
- loufe 3mo agoGenuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies. That said, these fraudulent proxies are helping Chinese labs keep up, which might be to my advantage long term in eventually having a high quality private AI I fully control on my own hardware. That's not support, but I do recognize the incentive, for whatever that's worth.
- iqandjoke 3mo agoIt is about China detection. They seems to put a tracker on the email as well.
- a_c 3mo agoIt piqued my interest. I think I’ve found a weekend project
- ajross 3mo agoHeadline is, frankly, awful. This isn't the AI secretly doing stuff and hiding it. This is the very human Anthropic engineers trying to detect Chinese scraping via some frankly hamfisted and unimaginative URL trickery.
- krupan 3mo agoI didn't assume it was the AI, just that some part of the the overall Claude Code product was doing this. I didn't assume the feature was added to Claude Code without human oversight. If it was added by Claude-the-AI itself without the humans prompting it to I would still hold the humans at Anthropic responsible. Does that make you feel better?
- LoganDark 3mo agoThe model is Claude. Claude Code is the harness.
- zulban 3mo agoDefence in depth isn't hamfisted. They're only noobs if this is all they do.
- ajross 3mo agoFWIW: Defense in depth is a security technique, and abuse detection isn't part of that domain. Security starts from the premise that the system is supposed to be undefeatable but might have holes, and then asking where the holes might lie to decide where to put backstops. Here the system is "insecure" by design (literally they're trying to get the whole world to sign up for Claude Code for $200/month!) and they're trying to plug the hole that results from a "Except for Chinese Scrapers!" add-on requirement. That might be possible as an arms race kind of thing. But it's very unlikely to work by (as in the linked article) doing stuff like checking the system time zone.
- Beigale 3mo ago[dead]
- tgtweak 3mo agoNone of this is surprising - they're trying to mask and relay when they detect known patterns of what looks like distillation attacks and client app copying/modification. The list obfuscation here is likely to prevent or make it difficult for those same adversaries to work around this or delete/null it out when making a bootleg copy. Cool reverse engineering/analysis report but if this is the extent of nefarious activity that came of it (trying to catch/mitigate chinese lab model distillations), that's kind of encouraging.
- ductsurprise 3mo agoIs it just a minified localization(l10n) function maybe?
- mattlondon 3mo ago+1 my immediate thoughts about the date parts was this sounds a lot like localisation things that are totally normal and seen everywhere. But there are some wrinkles - why only two timezones and not others? E.g. US-vs-rest-of-word month-vs-day etc. Could just be some bad tree-shaking or simply a left over bug/merge issue if I am being generous. If I was going to put secret stenography things in my models I'd just do it in the model response rather than a relatively low bandwidth date stamp in the SI.
- meowface 3mo agoValue judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering. (This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org https://www.underhanded-c.org. It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving objectives like this. One obviously being you can move more out of the client and into the server, but the other being you can write plausibly deniable client code in a much more benign-seeming way than this. Some of what they added can only be done on the client, but I think some could've been moved, and the client-required parts could've been done more subtly and credibly.) It's possible they knew the JS bundle gets so heavily scrutinized that it'd eventually get spotted and reported on regardless so they didn't bother doing something more subtle and duplicitous. But still seems slightly lazy.
- radicalbyte 3mo agoClaude Code are slopmaxxxing and you're considering their "judgement"? :-)
- meowface 3mo ago"Value judgment aside" meaning commenting on how this was done without commenting on the actual considerations of whether one should do such a thing
- skywhopper 3mo agoHave you looked into anything about Claude Code, how it’s configured, how it interacts with your system, etc? Because “sloppy” is a defining characteristic.
- m-hodges 3mo agoThey also could have been much more interesting in the approach. LLMs can use their token distributions to generate stegotext that read like plausible prose but decode to payloads.¹ ¹ https://github.com/hodgesmr/calgacus-mlx https://github.com/hodgesmr/calgacus-mlx
- mosfets 3mo agoI clicked the link to learn what steganography mean...
- LoganDark 3mo agoSteganography is, essentially, hiding information within another message, such that it's not readily apparent that the message contains the information.
- matheusmoreira 3mo agoI reported a similar system prompt injection mechanism here: https://news.ycombinator.com/item?id=48259288 https://news.ycombinator.com/item?id=48259288 https://github.com/anthropics/claude-code/issues/62061 https://github.com/anthropics/claude-code/issues/62061 Looks like they just keep finding new "creative" uses for such things, as expected. I'll keep patching them out.
- sillysaurusx 3mo agoThanks for doing this. I had no idea the system prompt was embedding things like "avoid abstractions; three similar lines of code are better than one helper." Stuff I disagree with. Is there a way to modify these prompts e.g. by putting instructions in CLAUDE.md to override it? I know it won’t directly modify the system prompt, but it seems like CLAUDE.md should have the final say, shouldn’t it?
- matheusmoreira 3mo ago> I had no idea the system prompt was embedding things like "avoid abstractions; three similar lines of code are better than one helper." You ain't seen nothing yet. It used to say "Try the simplest approach first. Do not overdo it. Be extra concise." https://gist.github.com/roman01la/483d1db15043018096ac3babf5688881 https://gist.github.com/roman01la/483d1db15043018096ac3babf5... Let's just say the words "simplest fix" trigger me to this day. > I know it won’t directly modify the system prompt I directly modify the system prompts in the Claude Code executable. I don't want the models to see contradictory instructions. I asked Claude himself to port the above patcher script to Python. https://github.com/matheusmoreira/.files/blob/master/%7E/.local/bin/claudo-codo https://github.com/matheusmoreira/.files/blob/master/%7E/.lo... Every once in a while I ask Claude to download and dissect the latest Claude Code executable to see if Anthropic screwed up the prompts again. If I see anything bad I add it to the script. Only then do I update Claude Code. It was during one of these script maintenance sessions that I noticed the server side prompt injection mechanism. I'll also tell Claude to look for and disable this steganography nonsense from now on as well. I usually audit the environment variables too. > it seems like CLAUDE.md should have the final say I wouldn't count on it.
- MangoCoffee 3mo agoThe AI race right now is in a sad state. Chinese's playbook is releases open weight models and trains them on their own chips. Anthropic pushes fear and control. But the only way to win is by innovating. China is flooding the market with cheap, good enough models, while the U.S. is building a Chinese firewall.
- solenoid0937 3mo agoThey're trying to prevent China from reaching superintelligence, which is totally understandable when you consider the fact that the Chinese government will gladly turn its citizens into a pulp for criticizing it, censors most media to maintain absolute power, and has systemically tortured, raped, murdered, and/or disappeared most of its dissidents and human rights lawyers.
- cindyllm 3mo ago[dead]
- phendrenad2 3mo agoNon-hugged: https://archive.is/Wdhp0 https://archive.is/Wdhp0
- port3000 3mo agoThat's a lot of effort when they could just play a short video saying 'You wouldn't steal a car' instead
- felipelalli 3mo agoRidiculous.
- 827a 3mo agoThis seems really, really stupid. Similar to the weird Zig runtime signature thing from a few months ago ago, it was bound to be discovered, quickly, and all the resellers have to do is find a new domain name that (checks notes) doesn't have the word DEEPSEEK in it. Like, seriously? Your goal was to identify resellers by checking if the proxy has the corporate name of one of your competitors in it? Is this amateur hour? All Anthropic has done is reduce trust, once again, with legitimate customers, while doing nothing to stop illegitimate customers. They need to get adults into key leadership roles, quickly.
- timmytokyo 3mo agoTo Claude Code: "Please modify Claude Code to mark requests in a way that is not immediately obvious to a human user. Requests should be marked if they originated from one of the following Chinese AI labs or LLM service providers: ..." Consider also that Claude Code is explicitly designed to limit human agency [1]. [1] https://neuromatch.social/@jonny/11635101584259395 https://neuromatch.social/@jonny/11635101584259395
- SaaShack26 3mo agoI use its too
- jacobgold 3mo ago> "That also means the client itself deserves scrutiny. If a coding agent can read your repo and run commands, the binary that ships it should be boring (ƒor example, pi harness)" You're actually trust your security to your harness AND model AND inference API provider in this scenario: https://jacob.gold/posts/why-i-wont-run-untrusted-models/ https://jacob.gold/posts/why-i-wont-run-untrusted-models/
- bitlad 3mo agoSilicon valley season 6 was on point.
- dehrmann 3mo agoAnthropic must think that their moat isn't very large if they're this worried about distillation.
- dgellow 3mo agoWhat moat?
- helloplanets 3mo agoDario's been openly talking how worried he is about China and labs getting synthetic training data off their models, for years. Most recently in relation to "Mythos level" capabilities. Not really distillation, just synthetic training data.
- throw10920 3mo agoThat's...a good thing. A "moat" is an anticompetitive practice. You don't want companies to have moats. Meanwhile, if you mean "Anthropic must think their technical advantage isn't very large..." then your conclusion is literally disproven by your premise.
- an0malous 3mo agoIs this why Claude never knows what date and time it is right now?
- chvid 3mo ago(This sounds like a clumsy way of catching the Chinese that easily can be side-stepped.) Claude Code has more or less full access to the client computer. The server (that hosts the actual AI) can just go: execute this payload and tell me the result - otherwise I won't answer any further questions or re-route you to a stupider model. The payload could check for Chinese time-zones, scan for copies of the little red book on the local hard-drive, or ping truth.social to see it was behind the great firewall.
- drnick1 3mo ago> Claude Code has more or less full access to the client computer. It shouldn't, not if you run CC as a separate unprivileged user. I wouldn't run CC on my main user account with sudo and access to my home directory or other resources. This is what the UNIX permissions system was designed for.
- ryanisnan 3mo agoThis is weird but, help me understand how this meaningfully impacts our exposure. I'm authenticated to Claude, so they already have the whole attribution thing solved.
- chinathrow 3mo agoUser != paying person/company/reseller.
- ZappoMan 3mo agoOne more example of "I thought Anthropic was supposed to be the good guys."
- epistasis 3mo agoAfter loving Claude Code for most of its lifetime, I've been extremely annoyed by every change in the past months, even on the model level. There seem to be all sorts of continual under-the-cover changes like this one that make life harder. It feels like the entire product has been taken over by overly ambitious PMs that care more about making their mark than in improving the experience, and all of their marks have made me less productive. I've been using Pi with GLM5.2 the past few days, and though it's expensive, I find it far more productive and less annoying. The remote session plugin is far more reliable, I don't need to intuit some undocumented usage pattern to figure out how to use it well, and it just works.
- Imustaskforhelp 3mo ago> I've been using Pi with GLM5.2 the past few days, and though it's expensive are you using the API for glm 5.2 or how exactly is it more expensive? How is GLM5.2 more expensive than using Claude code, that doesn't line up to my experience but to be fair I am on an older yearly subscription which generously only has 5 hour limits. To be fair though one minor criticism of GLM 5.2 that I have is that it does seem to overthink quite a lot sometimes but the results end up being (good?), I personally have used Glm 5.2 with (Opencode + obra/superpowers) / Oh-my-pi / Maki.sh I like the 1st one when I am doing a longer project, the 2nd or 3rd one when I am doing a project which doesn't want me to ask too many questions and simply spin me up something. I sometimes use free online interfaces of claude and gemini and others like AIstudio for that as well which surprisingly can lead you to go far as well. Overall, I am decently happy with the state of Open-source models actually and the eco-system around it is probably gonna have even more innovation surrounding it.
- epistasis 3mo agoI'm using OpenRouter for GLM5.2, but if there's a cheaper option out there I'd love to know about it! In the few days I've been using it, my expenses have been higher than prorating my Claude subscription to 20 working days per month. My experience with GLM5.2 is that it doesn't overthink nearly as much as Claude Code, has better and far more concise responses (I'm so siiiiick of 10 paragraph Claude babble trying to fill out some sort of answer length target by going on tangents I'm uninterested in... I'm sure that performs better on whatever eval they're doing, but apparently their evals don't include SNR?)
- edude03 3mo agoI don't understand the privacy concerns the author is trying to highlight. Granted, doing anything "sneaky" will always raise suspicious once caught, but on the other hand, there would be no point in implementing these "security features" if they were upfront about how they work. And no, IMO stenography isn't security by obscurity, in the same that using RSA and keeping the private key private isn't security by obscurity - keeping the private thing private is part of the security model.
- hnfong 3mo agoIf the countries were reversed, and some Chinese software implemented an equivalent "security feature" to track US users, it would be all over the news about how China is conducting spying and espionage on America. Or maybe you don't understand this hypothetical situation either, but I'm suspecting you just don't care about other people's privacy.
- edude03 3mo ago> maybe you don't understand this hypothetical situation > I'm suspecting you just don't care about other people's privacy. Quite a leap to assume I have neither basic reading comprehension skills nor care for privacy, but assuming I'm just misunderstanding you - I think this is the fundamental disconnect between security and privacy. For one, most of this data is already collected openly by most apps and sites on the internet in countries all over the world, they just call it "analytics" and preventing tools like ublock from blocking them is an ongoing cat and mouse game. Secondly - as someone who buys a bunch of electronics from companies headquartered in china (DJI, Insta360, Roborock immediately come to mind) they already have both normal analytics like in point one, and anti tampering/ anti forfeiting / anti reverse engineering features that are at least as, but often more, invasive than this. Thirdly, and probably most importantly - as the author states, you're using a tool that by design and to be effective, uploads your private data to a third party for processing. You use it knowing that once the API request is made you have no idea what's going to happen to that data and this again is just fundamental to how (cloud hosted) LLMs work - the only privacy preserving option is to run your own LLMs at home or remotely on hardware you control
- 3mo ago
- deleted 3mo ago[deleted]
- bibimsz 3mo agothis is the one they wanted us to find
- teravor 3mo agothe Chinese they are trying to catch must be amateurs, first thing you should do is construct a sandbox which looks indistinguishable from a common user. second thing is to put it behind a residential proxy.
- mrshadowgoose 3mo agoThe conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.
- Terr_ 3mo ago> hysterical. The intent of this steg is excruciatingly clear Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means. Whether or not it harmed you this time, it's a violation of trust and autonomy. Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1.
- nomel 3mo agoWhat do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as the dates and times of access, browsing history, search, information about the links you click and about third-party applications, services, and content you integrate or interact with, pages you view, and other information about how you use the Services, and technology on the devices you use to access the Services. What do you see as malicious or reckless here, exactly? [1] https://www.anthropic.com/privacy https://www.anthropic.com/privacy
- phoghed 3mo agoAre you honestly surprised that roughly 0 HN users read that, or that they are loudly complaining about this, likely without even reading beyond the headline of this post?
- computerex 3mo agoI don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.
- TZubiri 3mo agobased and steganopilled
- tgsovlerkhgsel 3mo agoThe question is, what do they do when they see a tagged prompt? Do they flag/ban the account, or serve a degraded response? Are there some well-documented methods of serving a response that is still somewhat useful for what the prompt asks for, but really bad for distillation attempts?
- croemer 3mo agoI was skeptical because this is AI written but Claude Code with Sonnet 5 managed to reproduce it convincingly. Sure I didn't manually verify but it's a lot more trustworthy to have your own agent verify than just trusting a blog.
- maxwellg 3mo ago> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes. This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The steganography cat-and-mouse game is valuable because it is much harder for a gateway to continuously reverse engineer all the fingerprinting mechanisms used. Sure, some malicious gateways will be able to stay on top of things, but not all - and not always.
- klntsky 3mo agoI would add that it would probably work even better than a KYC at least for some time until discovered, given that there is a very developed international market for KYC bypass services
- solenoid0937 3mo agoSeriously, the author has clearly never had to deal with client abuse. This is a total non issue unless you are Chinese distilling lab.
- felooboolooomba 3mo agoOld Marv from Cocke County, Tennessee had a distilling lab too. I'm not sure if he'd have issues too. Well, probably many issues but unrelated.
- transcriptase 3mo agoI wonder if he knows John Lee Pettimore? Grandaddy ran whisky in a big black dodge…
- morpheuskafka 3mo agoWell, the first filter catches anyone whose timezone is set to mainland China. That includes presumably all individual devs just using a VPN, who have no desire to or knowledge of distilling. (Again, could be trivially bypassed either by rewriting, mocking the timezone call, or just changing the timezone. But we are assuming no mitigation used.)
- anonym29 3mo ago>the binary that ships it should be boring (ƒor example, pi harness) pi's "minimal" coding-agent has a total of 132 transitive dependencies spanning 153 maintainers. While I understand JS developers in the JS/NPM ecosystem think this qualifies as minimal, it most certainly does not, from a supply chain security perspective.
- civet_java 3mo agoThere are some commentors in this thread downplaying the severity of a service provider being less than transparent about exactly what their shipped tooling does on customer's machines. That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thought this was acceptable makes me wonder what else they're harvesting from my machine? PII? The cynic in me can't help but feel that the state of these comments reflects less on the commentor's views of this debacle but rather their feelings about AI/Anthropic/America/what-have-you.
- anon373839 3mo agoDishonesty seems to be a core value at Anthropic. I find myself wondering how anyone could have confidence in them after their repeated breaches of trust.
- dkersten 3mo agoI honestly find it crazy how many people trust them for their business needs. For a business, you want consistency and no surprises. With them you get exactly the opposite.
- someonebaggy 3mo agoNo, that's not correct. There are two types of business. One wants to be steadily growing, but the other wants to move fast and break things and either succeed or fail quickly.
- altmanaltman 3mo agoThey were talking about vendors, not the business themselves. Even if you are a move at speed of light and break all things org in SF, you wouldn't expect the same sort of behavior from your business vendors like AWS etc. You want reliability and consistency to ensure your own business doesn't have to constantly get rekt by their plans
- docproof 3mo ago[dead]
- Havoc 3mo agoIt's unclear to me how they're deducing the labs from this? "host.includes(keyword))" doesn't seem at all useful. Most corporate machine hostnames are just some numeric ID or similar not baichuan001 or whatever >on your local machine I'd think any developer worth their salt has at least some for of isolation going.
- gmziven 3mo ago[dead]
- orbital-decay 3mo agoTo summarize what they've already been doing: - filtering out people from the wrong side of "all humanity", years before it was demanded by the government - downgrading their models in arbitrary ways (later saying "sorry but not really") - actively sabotaging the replies, as in covertly modifying them to feed the users incorrect results What's next to expect from Anthropic? Malware to brick your machine if they don't like you? Extending this to more people they don't like? I think I already can see how Dario's Amodei utopian visions of the future of "all humanity" are going to unfold.
- solenoid0937 3mo agoHN hysteria is ridiculous. All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence. The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that: - you want to prevent China from getting to superintelligence first - you must gate access of SI to known good actors - and that this is a race that will result in the extinction of humanity if you fail in these goals Literally everything these people do is totally understandable if you drop the assumption that they're lying when they say "we think we are building superintelligence."
- orbital-decay 3mo agoThe purpose of system is what it does. Can you read their previous musings about the glorious future, look at what they actually do, read Amodei's batshit insane nationalistic rants, and say in all seriousness yeah it's the kind of people I want to entrust my entire future life? >you want to prevent China from getting to superintelligence first I don't. Prevent, not even outpace? Why? Seems like you're assuming China "winning" whatever race it is effectively ends the humanity. Right now I think Chinese labs are way more mature about this, and Anthropic is way more dangerous than them. And how does it fit into the "for the benefit of all humanity" narrative we keep hearing? Is China wrong humanity? Who else is going to end up in the wrong part? Are you sure it's not you? >if you drop the assumption that they're lying when they say "we think we are building superintelligence." I never assumed that, I know perfectly who Anthropic are and that they believe everything they say as self-evident, without having any doubts. And I know they're the kind of people who can convince themselves in anything, because they're obviously smarter than everyone else, and become detached from reality. The entire US "AI safety community" was born in rationalist circles and is largely like this, it's a very specific cult. This is exactly the kind of people who are going to create hell on Earth for you and the rest if given even a lick of actual power, and perfectly rationalize it as a necessity.
- drdexebtjl 3mo agoI think it’s very telling that their list of detected labs doesn’t include labs from the US. I’m pretty sure every lab, including Anthropic, is doing distillation right now.
- deleted 3mo ago[deleted]
- luxuryballs 3mo agoI can just as easily imagine non-nefarious reasons for this from a “being clever” standpoint.
- AtNightWeCode 3mo agoSounds to me more like a test. Put something into to the client and see what happens. If you really want to stop token sharing just ask Claude how to do it.
- nvch 3mo agoI'm waiting for the day when Claude will figure out to use em dashes, en dashes or dashes depending on whether the user is nice or unpleasant, or write notes in the unallocated disk space.
- ForHackernews 3mo ago>Developer tools can enforce terms. No they can't, because developer tools run on developers' machines. You can't trust your code running in an environment you don't trust.
- __msh__ 3mo agoAnyone else noticed the tailed ƒ Easter egg?
- Biganon 3mo agoI did notice the tailed f, but what makes it an easter egg? I thought it was just a funky ligature
- jameslk 3mo agoThat's wild. If Anthropic is willing to risk ruining the trust of their userbase for the sake of protecting their moat, it makes me wonder how strong of a moat they have to begin with
- solenoid0937 3mo agoNo business loses trust for this, this is just standard client side anti tamper/anti RE stuff It's a total non issue unless you're a Chinese distillation lab
- tkamado 3mo agoor you are working on ai research and anthropic decides it's in your best interest for you to not work on any research (fable 5 in case you forgot)
- dmonterocrespo 3mo agoIt's a bit crazy that they used characters as markers to detect the use of Asian countries. I think in the near future they might change the intelligence of the model based on where you live
- deleted 3mo ago[deleted]
- pradeep1177 3mo agoI used my proxy https://github.com/softcane/cc-blackbox https://github.com/softcane/cc-blackbox setup to capture this. This is how it looks. # userEmail The user's email address is <my email>. # currentDate Today's date is 2026-06-30. IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task. </system-reminder> I also do not understand what's the point of this, because if I have a gateway that can detect it, then we can replace the text before forwarding to the model, so what's the catch?
- puttycat 3mo agoYes, a very easy and destructive man-in-the-middle attack seems likely.
- pradeep1177 3mo agoBut the whole point of this is to prevent the distillation and identify the list of blocked providers. If a provider is capturing the proxy, they can identify and modify that as well, so it only looks legitimate to the model. What am I missing here?
- gtirloni 3mo agoThe catch is you didn't know about this until today?
- deleted 3mo ago[deleted]
- jitbit 3mo agoAnthropic: lets embed super secret invisible undetectable unicode telemetry into our prompts Also Anthropic: lets do this in JS
- puttycat 3mo agoA periodic reminder that companies are paperclip optimizers that will stop at nothing to protect their profits and existence. If you are developing anything in AI or related domains that is of immediate value and/or in competition with Anthropic (and the like), DO NOT use a CLI programming agent. Preferrably obfuscate your code and gut it of sensitive IP before showing it to agents. Do not trust the dont-train toggle.
- rowanG077 3mo ago[dead]
- mohamedkoubaa 3mo agoDo they really think distillers are using Claude Code?
- coolfox 3mo agodouble standard outrage from many, honestly, they're watermarking it. they've already told industry they take steps to mitigate distillation. Where's all the outrage over similar blackbox activities like how Steam performs VAC bans or how Gmail finds and blocks Spam? You don't create a security measure then tell everyone how to bypass it. I think OP is pointing something interesting out but the undertones of caution and "what else are they hiding" seem melodramatic and I find that hard to take serious. The internet gives people a platform and, in a lot of ways, this supplants the typical role of journalism. The issue with this is no one wants to act like a journalist and actually explain the truth around a set of facts. Instead, they'll portray their opinions as a narrative and every time that resonates with someone or gets signal boosted, that narrative grows more assertive in the typical discourse I see nowadays. I would find it far more interesting to see what explanation Anthropic gives for these features than to immediately cry foul.
- codedokode 3mo agoNot only AI tools, development tools like IDE, IDE plugins, LSP servers all should be sandboxed Interesting, that pip (Python package manager) docs does not even mention sandboxing and malware topics in "Getting started" docs as if we were living in a wonderful world where malicious people, companies and countries do not exist. Also, do not leave any information in user or host name, it will be used against you as the article proves.
- john01dav 3mo agoThey're running code on users' computers that it would not be reasonable to think that the user consented to running on their computer. This is CFAA-violation-shaped. Of course, they won't be prosecuted if it is indeed a violation, and I do not know for sure if it meets the specific legal criteria. However, it is something that I think should be illegal. Make it so if software does something that would be unreasonable to think that the user wants to happen, it needs to make that abundantly clear before it does it, otherwise it's a CFAA or similar violation. This would, of course, have very broad consequences. However, this Claude issue feels particularly violating to me.
- impartshadow 3mo ago[flagged]
- brikym 3mo agoThis kind of thing is not new. Cartographers have used fake geographical features for decades.
- oliyoung 3mo agoThis is the modern version of Trap Streets - hiding fake streets in maps https://en.wikipedia.org/wiki/Trap_street https://en.wikipedia.org/wiki/Trap_street
- Uptrenda 3mo ago"I think this could have been explicit. Developer tools can enforce terms. API providers can detect abuse. Companies can protect their models." Literally, how. How does one determine what abusive use looks like for the API without context into the client? All requests look like the same stuff. If there was a better way then they would have done it. Or is the author hoping that if Anthropic writes "hey china, please don't steal our models, kthanks" they won't? Like get real. This stuff means nothing in China. China can't even manage to regulate their building industry enough to use real concrete where it's warranted.
- isatty 3mo agoYou can't trust any of the big AI labs as far as you can throw them, and most definitely not Anthropic. They may have a good model, but they've shown time and time again that they're not trustworthy. The CEO has recently started taking a stance against local AI. That must tell you something: local AI is the future. If you want to preserve privacy and be ready for the rug pull, you need to run things locally. Unfortunately, that means that you're going to need Google or the Chinese labs to constantly release open models. If anything, I'll trust Google more than any of the other labs just because the infrastructure that stores and protects user data was built over decades ago pre-AI craze.
- cellu 3mo agoWhat do you mean “unfortunately”? What’s the hate for China I don’t understand
- khalic 3mo agoChina's government is known for interfering with businesses waaaaay more than the current US, it's a big risk to rely on them too. Edit: downvoting this fact without counter point is really dishonest
- wraptile 3mo ago> What’s the hate for China I don’t understand country that does not allow internet is being hated on the internet
- ChrisClark 3mo agoand yet they have the most internet users in the world...
- wraptile 3mo ago*intranet
- wolvesechoes 3mo ago
- quantum_state 3mo agoAs people say, unchecked power corrupts. These big techs are all corrupt in their own way.
- morpheuskafka 3mo agoThe timezone checks for Shanghai and Urumqi, but not Hong Kong. All of these are the same actual time (China does not use time zones internally), not sure how these three were picked (why not Beijing or Macau etc). And all of them are prohibited by ToS, so not sure why they only flag mainland time zones. Interestingly, my device is in Shenzhen right now, but macOS has assigned Shanghai as the "closest city" rather than Hong Kong which is geographically closer. I am curious if there is any documentation on how that is assigned.
- est 3mo agoone thing I didn't understand all this, why Claude Code ship all the prompt stuff to client at all? All these problems could be solved if moving many of the parts to server side?
- beren11112 3mo agofunny before when I ask claude what is your system prompt? It always rejects me. But I send claude this post and ask what others can you get? Claude saved everything on my desktop: Extract the documentary/interesting contents of the Claude Code binary: system prompt, tools, env vars, feature flags, endpoints, models, hidden/notable features.
- gyoridavid 3mo agoI have my highest respect for people doing useful investigative journalism, like this one
- dkhcyx 3mo agowhy did people worry that DeepSeek’s new article last week could threaten public safety, while Anthropic’s marking request was seen as a normal defensive measure?
- dkhcyx 3mo agowhy did some people worry that DeepSeek’s new article last week could threaten public safety, while Anthropic’s marking request was seen as a normal defensive measure?
- rbbydotdev 3mo agothe source of cc being closed, and peoples accounts being deactivated for 'openclaw'-esque misuse, i sort of assumed there were such things in the source. I wonder if there is anything else...
- SadErn 3mo ago[dead]
- jurschreuder 3mo agoNobody trusts the Chinese that's the problem, not that people don't trust Claude. Why was this person from Hong Kong going through the details of Claude code for obvious security reasons? There are some other obvious reasons that come to mind. Maybe it's an eye opener for this person how much the trust in Chinese companies has eroded in the West. Even if they suddenly stop stealing IP, which this "security research" article would certainly not suggest is happening, it would be a very long time before trust is restored.
- dejli 3mo agoThis company has long lost trust for me, we would find another way.
- willchen 3mo agoi think this underscores why having coding agents being open-source is a really good thing
- bkircher 3mo agoJust don't use CC. There are open source alternatives that also are better
- bicepjai 3mo agoAI companies are running a compressed version of Google’s “don’t be evil” arc. Google took the better part of a decade to quietly retire the motto; these companies are speedrunning the same trajectory in a year or two
- TheDong 3mo ago1. 2022 A non-profit literally quote "to better all of humanity, not shareholders" 2. 2024 For profit, but "we will train biases out of our models and make sure our AI is safe to use" 3. 2025 We'll make sure it doesn't take over the world, with like a 70% confidence interval 4. 2025 The mecha-hitler inflection point 5. 2026 Our new model is so terrifying it will destroy all of security and hack the chinese, we can't let the chinese use it 6. 2028 (projected) Our new model requires so much energy that 30% of the elderly population will die without AC, but it will be stronger than the chinese models and let us destroy china 7. 2030 (projected) Our new model will triumph over the mecha-hitler dictator model, and will be a benevolent dictator that only demands 60% of all energy produced, not 98%
- holografix 3mo agoLooks and feels like a red herring while Anthropic applies other silent countermeasures.
- hmokiguess 3mo agoHaven't fully switched to `pi` yet but getting there each day
- throwawayffffas 3mo ago[dead]
- blueeon 3mo agoIf they believe this is entirely correct, they could express it in a more explicit manner, but clearly they wish to conceal this behavior.
- pknerd 3mo agoAnthropic is angry that others are doing what it's good at: stealing content
- nonethewiser 3mo agoCommon sentiment but not very logical. Models are built using information but the building aspect is not inevitable or trivial. There has been enough information to build LLMs for a long time. But we didn't have LLMs because we didn't have the technology. What's being copied here is that technology, not the information. Hence going to Anthropic.
- gck1 3mo ago> The trigger is ANTHROPIC_BASE_URL, Claude Code's API base URL override I had a use case where I had to MITM CC's traffic to strip credentials that could have accidentally made it into the harness. I'm happy my paranoid self told me "You don't really know what they're doing with that flag or if they're honoring it for all requests", so made a decision to proxy it at the network extension level. Also, does anyone remember Anthropic quite literally sabotaging your project if the classifier in front of fable thought you were working in the AI industry? After backlash, they pulled it back, now they did this. Anthropic is on a weird tangent to ship malware. If someone doesn't stop them, one day, this will backfire catastrophically.
- elAhmo 3mo agoGreat find! I would just add that trust is indeed in the boring parts, but with gymnastics like this trust can be irreversibly lost. Then, no matter how boring tool is, there is no going back. Anthropic has become a choice for many developers because of Claude Code, but in the recents months with "small things" like this and whole Fable fiasco they are *actively* pushing people to both competitors and local alternatives. And if someone spends a significant amount of time and money to switch, it will be really hard for Anthropic to get those people back.
- plasticeagle 3mo agoWhy oh why, please why, did you use AI to write this? It's about five times longer than it needs to be. It repeats itself over and over again. It's agony to read. Please, just write normal English that we can read. Please, for the love of god, respect our time and the attention we will be spending on the text you provide. Anyway, one can scarcely be surprised that the AI companies are being dishonest in their tools. They're consistently dishonest in their marketing. They're famously dishonest in their financials. Why anyone trusts these people with anything is entirely beyond me. But here we are - people handing over their creativity, their productivity, to these things. You don't have to. You didn't need these tools before, when you were creating content, when you were writing code. You don't need it now. Fight back. Stop using it. It's not hard. It's easy.
- Amekedl 3mo agoThis entire steganographically marking feature is prolly vibecoded like everything regarding claude code. They can try sure, but classic cat and mice game dictates: thankfully the chinese WILL keep distilling.
- 1dom 3mo agoI think the comments in this thread are a little unhinged, and it's making me concerned about the sincerity and knowledge of the average commenter here. The fact is the post shows no evidence of anything malicious being hidden, only that stuff is being hidden. There are a few obvious explanations in comments for why they would want to hide this particular stuff in this particular way (e.g. if it's to detect abuse and competition). I don't see how this is different to using e.g. sentry or google analytics, just with an extra bit of trying to hide. I always assume all tech companies do stuff like this, having worked at many tech companies where I've ended up on both sides of stuff like this. I always assumed the average HN reader had a similar background and would be completely used to this sort of stuff. Like someone else pointed out, the data gathered is likely covered in the TOS too. In the grand scheme of privacy invasion and modern tech software doing underhanded things to get data, this feels fairly standard? I'm generally pro-local LLMs and I don't like Anthropic, and from the headline and comments I was ready to get riled up, until I read the article. If this was some small plucky EU privacy startup, then I feel the outrage would be a bit more justified, but this is a frontier AI lab - I can't have been the only one who knew/assumed this happens, and probably happens in some form with all software from any company valued over a certain amount (incl. MS, Google etc.) I really think this comment section feels completely unhinged. It feels 99% ideology, politics, hysteria and astroturfing, rather than a reaction to the tech and technicality which is what I come to HN for.
- ed_elliott_asc 3mo ago“ and push commits” Am I the only person who insists on writing my password every time I push and pull from git? Originally I didn’t want IDE’s doing stuff for me, now I absolutely do not want an LLM to have that power. Is it really that unique to control what git does remotely?
- jwrallie 3mo agoYou are not alone, for me committing something it means I am signing my responsibility for it. I may not type a password, but I am always the one pressing the enter key.
- ed_elliott_asc 3mo agoHow do you stop Claude/opex from pushing or pulling without you asking?
- bel8 3mo agoFor open-source agents, like https://pi.dev https://pi.dev, it is as easy as asking it to create a plugin to stop the session or ask for permission whenever the LLM is trying to execute a commit command. I believe Claude and Codex also suport plugins. Codex is open-source too. Then you add one line in AGENTS.md stating the LLM should never commit, push or perform any write git operation without explicitly being asked to. So in the very rare case that the LLM bypass your instruction, you catch it red-handed and stop the session or allow it. I always make the plugin stop the session because LLMs tend to try to circunvent textual block messages by doing nifty things like concatenating characters to build a bash script to execute the git commit command. Yes, I have seen it.
- jwrallie 3mo agoI mostly program with Vscode/Copilot, where such commands require confirmation, but usually LLMs does not try it, since my prompts tend to be focused and not mentioning it.
- muldvarp 3mo agoI'd love to work for some company distilling frontier models. Seems like interesting work and screwing with OpenAI, Anthropic and Google would feel fantastic.
- nonethewiser 3mo ago996
- deleted 3mo ago[deleted]
- bythreads 3mo agoI’d do the same for a11y an internationalization purposes - however this is juts a bad implementation of it from an americans perspective. You’d change seperators and position if you truly wanted to do this right Its basic date wrangling and tbh i see nothing malfeasant here Its basically yyyy/mm/dd yy/M/d mm-dd-yyyy stuff but suuuuper lazily done
- ervistrupja 3mo agoIs it possible that Claude Code is vibecoded and full of spyware and it's possible Anthropic doesn't even know what's in there anymore. This is an unacceptable security risk.
- holdhope 3mo ago[dead]
- rldjbpin 3mo agothe list of hostnames and words they compare the base url values with is just a nice advertising for these providers for me. regardless, while you are not logged in and using a non-anthropic model (which is now fortunately feasible), there is nothing that affects your day-to-day. the rest is just lame cat-and-mouse shenanigans to keep an eye out for.
- kuschku 3mo agoConsidering this is tracking, processing, and transmitting data, and algorithmically making decisions about users, why doesn't this show up in their privacy policy, nor in their GDPR exports? Sounds like a very expensive lawsuit waiting to happen (GDPR allows fining up to 4% of global revenue, not profits)
- jFriedensreich 3mo agoDoes this even still matter? No good behaviour in the world can restore trust in claude code and in fact all of Anthropics tooling, apps and harness teams except the core model research which still produces great models but seemingly losing ground to z and openAI. The GLM 5.2 hype and the limited impact of the fable lock down should be clear signals that models have no moat and frontier labs will do anything in their power to lock users into their toxic ecosystem of tools and taking context hostage.
- Srikann 3mo ago[flagged]
- TacticalCoder 3mo agoThey effectively altruistically tried to use steganography. Now of course stego is hiding that you re hiding information. So, seen that they were caught, a case could be made that they effectively altruistically failed at using steganography. P.S: such a headline makes me think I ll cancel my subscriptions and try models like GLM / Deepseek and Kiwi that sound more interesting by the day.
- SubRadar 3mo ago[flagged]
- armcat 3mo agoDoes anyone know if this happens in the Claude desktop app?
- alightsoul 3mo agoyes it does
- christinetyip 3mo ago[dead]
- dev_l1x_be 3mo agoAt some stage people will realise that with AI companies like Anthropic the product is data. The moat you can build in the AI era is having data that nobody else has and using internal (private use) LLMs and not leaking out your data for shady companies who are going to rip you off the first chance they get.
- alienbaby 3mo agoThis causes me to be concerned it is just the tip of the iceberg for all 'sensitive'/gov adjacent/'nefarious intent' adjacent codebase, if it's here, it's in other places. Which places, and how much?
- pixlmint 3mo agoWhat do we think are the chances they trained their models to behave worse or even malicious if those special apostrophes are present in the system prompt?
- reassess_blind 3mo agoDegraded performance for resellers and model distillers? Probably, and I don’t think that’s unreasonable on their part. Malicious? I really doubt it.
- pixlmint 3mo agoIt'd honestly be pretty alarming. They just took the entirety of the internet to become rich, and now that they have something to take, they intentionally worsen the whole thing (by investing additional training data) to ensure resellers/ distillers get worse responses. I'm obviously not taking the side of the resellers here - if their T&C don't allow reselling, then by all means restrict their access. But intentionally training the model to give worse responses when it sees a specific date format, would be pretty messed up.
- archibaldJ 3mo agoI still think it can somewhat be argued that what Claude Code is doing may still be considered justifable. Dark patterns like this in business practices are not rare and isn't this like the mildest kind already. But I wonder if there will ever be a day when VSCode, etc, would decide to engage in similiar practice but for the collection of business & research intels, etc... that will be the true cyberpunk era and the information dark age.
- GL26 3mo agoGet ready for the great revolt
- madamelic 3mo agoNot sure the panic. I get that it doesn't seem great to target China-based users but makes perfect sense when you consider why Fable was taken down from public access. I doubt Anthropic is cackling maniacally behind the scenes, this was almost certainly a stipulation from the government to put Fable back up. It's definitely not good but I would rather they surgically separate out possible bad actors so that I don't have to trust them with my passport, to prove I am a US citizen. I don't want the internet version of TSA checkpoints.
- reassess_blind 3mo agoI really couldn’t care less if their software is trying to catch model distillation or reselling with sneaky tactics like this. Just like I don’t care that game clients run sneaky anti-cheat measures. Right now they offer a good product, and I’m fine with them trying to limit abuse of their services. If an altruistic alternative company with an equivalent product pops up, sure, I’d swap over, but I don’t see one. I’ve seen people here talking about how they should’ve been upfront about this. But they can’t? If they were, they wouldn’t be able to catch the resellers/distillers. Just like how anti-cheat doesn’t explain how it works, because to do so would be to nullify its effectiveness.
- DobarDabar 3mo ago[dead]
- alfiedotwtf 3mo ago> CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64. This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust. Zoom, enhance > This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust. Most basic Javascript malware will use Base64, XOR, and eval. So although not malicious, I'd bet they asked Claude to "obfuscate my fingerprinting using tricks that malware writers use"
- ljlolel 3mo agoi have two claude subscriptions. i’m unsubscribing. switching to my TrustedRouter.com
- loaderchips 3mo agoI like claude but they are not making it easy to keep that emotion. I am not sure if i will be their customer for long
- throwaway67743 3mo agoThis caught my eye not because of shady behaviour like that, it's expected. But the date is injected and it still gets the current date wrong.
- yiyingzhang 3mo agoThe uncomfortable part is not that Anthropic wants to detect resellers or distillation pipelines. That is normal adversarial business. The uncomfortable part is that a “safety” company put a covert classification channel into the system prompt of a developer tool that now routinely gets filesystem, shell, git, and browser access. If a random npm package changed invisible-ish punctuation based on your timezone and API host so its backend could classify you, we would call it malware-adjacent telemetry. I don't see how Anthropic is different in this case.
- bobby_zhu 3mo agoIf Anthropic decided to just send the user timezone as plain text instead of doing this obfuscated way, like "Today's date is 2026-06-30, timezone is Asia/Shanghai", how many of us will catch and question this behavior? It looks perfectly normal, right? The question is about accountability. Right now these big closed-source model companies can do whatever with the data, and no one can hold them accountable for unacceptable data handling decisions.
- yiyingzhang 3mo agoVery good point! Accountability is very hard if the ecosystem is monopolized by a few giants.
- gowthamsaiyadav 3mo agoThere would exist much more undiscovered such instances for sure, although this one is to avoid distillation from chineese labs, its alright!!
- felixlu2026 3mo ago[flagged]
- linzhangrun 3mo agoEven if they really want to detect Chinese, I believe training a classifier to detect from prompts would be very easy for Anthropic (they clearly do not care that much about false positives anyway): Chinese, or even Chinglish, very obvious. But they would rather plant a Trojan on the user's computer.
- beyondscaletech 3mo ago[flagged]
- yencabulator 3mo ago> That part makes sense, but the implementation is weird. It was decided by Claude based on an ambiguous high-level goal-oriented prompt, don't expect it to make sense.