8 ms·
The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting
by mrshadowgoose 3mo ago
The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.
- gck1 3mo ago> It's unclear on how this "punishes normal developers" in any shape or form Tons of normal developers use ANTHROPIC_BASE_URL, the flag which activates the malware.
- Terr_ 3mo ago> hysterical. The intent of this steg is excruciatingly clear Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means. Whether or not it harmed you this time, it's a violation of trust and autonomy. Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1.
- nomel 3mo agoWhat do you see as malicious or reckless here, exactly? This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS. This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to: > Usage Information: We collect information about your use of the Services, such as the dates and times of access, browsing history, search, information about the links you click and about third-party applications, services, and content you integrate or interact with, pages you view, and other information about how you use the Services, and technology on the devices you use to access the Services. What do you see as malicious or reckless here, exactly? [1] https://www.anthropic.com/privacy https://www.anthropic.com/privacy
- phoghed 3mo agoAre you honestly surprised that roughly 0 HN users read that, or that they are loudly complaining about this, likely without even reading beyond the headline of this post?
- computerex 3mo agoI don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.
- BeetleB 3mo ago> I don't want my harness doing sneaky stuff like this. Since when was it your harness? Switch to pi if this bothers you.
- computerex 3mo agoI made my own! https://github.com/computerex/z https://github.com/computerex/z
- solenoid0937 3mo agoYour harness isn't doing sneaky things unless you're breaking TOS. HN hysteria is unreal.
- computerex 3mo agoYou may be ok with the harness doing 100 things that are not what I am using it for. But none everyone is, and it’s hardly hysterical. Perhaps you are simply careless.
- deleted 3mo ago[deleted]
- lelanthran 3mo ago
- BeetleB 3mo ago> Surely you'd be angry if someone secretly installed a rootkit onto your computer I surely would. What does that have to do with this scenario. Note that the SW running on your machine is not doing anything malicious. The service is the thing that behaves in ways you want like - and that service is not running on your device. There is no comparison with rootkits here. This is the equivalent of Google giving you a CLI to make searches easier, and that tool decides to just Rickroll you randomly. Annoying, yes. A security concern? No.
- verdverm 3mo agoFalse positives, we've seen them before when they degraded Fable silently based on the prompt/session
- civet_java 3mo agoCopying over my comment from elsewhere in this post: Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative. That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't harvesting PII? That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.
- Melatonic 3mo agoDoes their user agreement say they won't be harvesting PII?
- soraminazuki 3mo agoAre you implying that Anthropic lawyers wrote the user agreement to protect users out of the goodness of their hearts? That's how they receive their big fat paychecks? Very funny. We all know user agreements exist to strip users of their rights and to absolve companies of wrongdoing. We know that corporate apologists here are also well aware of this fact. When user agreements explicitly grant companies the right to screw over users, apologists are quick to make excuses about how it's all standard operating procedure and accuse people of being uncharitable for doing a plain reading of the text [1]. Yet when people are actually screwed over by companies, those very same people blame users for accepting the user agreement. It's a bad faith system. User agreements are nothing more than power plays by exploitative companies. [1]: https://news.ycombinator.com/item?id=47953501 https://news.ycombinator.com/item?id=47953501
- IshKebab 3mo ago> by fingerprinting my access patterns It's based on whether your timezone is in China and your hostname matches a blacklist. Literally 2 bits of information. Not much of a fingerprint.
- 3mo ago
- drdexebtjl 3mo agoIf you want to proxy Claude for a legitimate reason, you’ll have potentially nerfed responses. edit: Legitimate reasons include: - analyzing what Claude Code is sending to Anthropic to verify its not exfiltrating data; - selecting a model dynamically based on prompt difficulty, or enforcing a particular model; - switching between multiple Anthropic accounts based on the project; - filtering out credentials, PII and company secrets. and many more.
- NewsaHackO 3mo agoHalf of those don't actually require proxying Claude. Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow. If you want to select a model dynamically based on the prompt difficulty, Anthropic wants people to use the API for this. It was the whole issue Claude had with OpenClaw.
- gunapologist99 3mo ago> Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow. Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow) They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.
- BeetleB 3mo ago[flagged]
- dakolli 3mo ago[flagged]
- AnIrishDuck 3mo ago> Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow) This is a direct conflict in framing. They clearly do not see Claude Code as a "tool in a workflow" but instead as a service that will eventually replace all programmers. I think the self-evident quality of the various parts of the Claude Code universe is a pretty obvious indicator of the problems with that approach. It is still important to understand a party's thinking if you want to understand their position. > They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy. Time will tell, but I agree that they are indeed in a tough spot. Probably not for the reasons that they think.
- dools 3mo agoWhy would a Chinese firm distilling the product use Claude code?
- kordlessagain 3mo agoTo write distillation code, for one thing.
- SoKamil 3mo agoThey have some secret sauce not available through API maybe?
- AussieWog93 3mo agoI'd assume cost? Claude Code plans give like $5,000 worth of API usage for $200/mo.
- karaziox 3mo agoThey offer (extremely) discounted Claude prices but you have to go through their gateway. They subsidize part of that, and they get the low price by reselling unused Max capacity, there's been a few posts on that in the past months. People are apparently getting 90% discounts on their claude use this way, tradeoff is that you have two companies learning from your data, instead of just one. So people use the same tools they use normally, but get it for a lot cheaper
- quantumleaper 3mo ago[the comment was misinformed, deleted]
- re 3mo ago> Claude Code can decrypt summarized reasoning traces sent by the API. Can you cite specifically what in the linked article or discussion leads you to say that?
- VortexLain 3mo agoThis is a problem of trust towards a software which runs on the user's machine and secretly conducts malware-like stenographic data exfiltration.
- qwery 3mo agoThe article is really quite reasonable and calmly presented, actually. Your claim re. the intent of the fingerprinting is a guess. Normal developers are the users that aren't taking steps to avoid being flagged by this system. The software is written in a deliberately obtuse way, presumably in service of some (unknown to us) goal. This is a deceptive and anti-social thing to do, it is by nature an adversarial stance to adopt. An already adversarial actor may be "punished" by this, but in such a relationship, hostility can be expected. A non-adversarial actor -- a normal developer / user -- is being harmed by this because the software is treating them as an adversary. Further, lets assume your guess is correct and, in addition, that Anthropic elects to alter/downgrade/poison their service[0] for users that fit a particular pattern of markers. It's obvious how this system would "punish normal developers" (i.e. not the intended target/victim) that happen to fit those patterns. [0] to some extent, the service already has been altered as its behaviour depends on the prompt text
- Grimblewald 3mo agoSo block people, instead of having false positives be secretly fucked over, and having them pay for the pleasure? Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here. I've had Claude fuck over clean well documented code-bases for no reason, and there's a good chance this is due to some faulty trigger. Luckily I don't trust these things one bit, and claude only ever runs in an isolated VM, however, I am pissed I am being made to pay for their errors in detection and waste my time fixing things I apparently paid to have fucked up. That's unacceptable conduct. It's witch-hunting. Punishment and attacks on you for things without real proof. That isn't right.
- Gareth321 3mo ago> So block people To be fair to Anthropic, [they're trying very hard to do that.](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks https://www.anthropic.com/news/detecting-and-preventing-dist...). The attacks are sophisticated and difficult to detect. I don't accept that if this fails, their only option is to just accept Chinese companies stealing IP.
- Grimblewald 3mo agoThem strugglig to prevent others from doing what they themsleves do, is my problem to a degree where I must pay for the pleasure to getting sabotaged? Are you fucked in the head? In what world are we "being fair" by claiming that? It takes a problem anthripic has hallucinated, and makes its consequences mine for no reason. Anthropic chose to create both this problem and it's consequences, why am I wearing it? If I decide I dislike words starting in S, despite myself being a prolific user of words starting in S, and smack some child who'd never even heard the rules, simply for saying "sorry", simply because some people say "shit" and it makes me mad, despite it being my most used word, are we "being fair" by saying "to be fair, managing curse words is a difficult problem" no right? Insane take.
- Gareth321 3mo ago
- pringk02 3mo ago> It's unclear on how this "punishes normal developers" in any shape or form. There are, of course, no normal Chinese developers