15 ms·
Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says
- rvz 3mo agoAnother reason to use open source coding agents and local language models. Claude Code is neither and it is literally info stealing malware.
- yanhangyhy 3mo agoi gonna ask: how can they still use claude? i thought all users in china are banned
- xyzsparetimexyz 3mo agohttps://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
- dist-epoch 3mo agoThe same way they buy "banned" and "sanctioned" NVIDIA GPUs.
- josh-wrale 3mo agoCc can be used with non Anthropic models.
- re-thc 3mo ago> how can they still use claude? Workarounds aside, it says Claude Code not Claude. i.e. they are using the CLI running any model. You can for instance run GLM with it.
- playnuu9 3mo agoThere is a reason Singapore tops the rank on Claude usage
- byzantinegene 3mo agothe government also actively promotes AI usage in work environments
- chinathrow 3mo agoSource?
- bravetraveler 3mo agoSame way every ban is evaded, smurfing
- _flux 3mo agoDoes Alibaba only have developers in the China?
- one33seven 3mo agoDid china invent VPNs yet?
- dgellow 3mo agoAlibaba has engineers in Hongkong, Singapore, North America. It’s a global corporation
- itake 3mo agowhen i was in hongkong, chatgpt and gemini were disabled. Maybe this has changed though. When I was in China, the corporate vpn (zscaler) routed traffic through hk
- Paradigm2020 3mo agoBut you just said in hk they were disabled? So through a hk vpn still disabled?
- hnfong 3mo agoThis has changed (in a nit-picky way) - Gemini is now generally available to the public in Hong Kong. ChatGPT and Claude are not available. Generally my impression is that OpenAI isn't that anal about service providers reselling ChatGPT in Hong Kong, but Anthropic seems to really strict about the "no China" thingy.
- TZubiri 3mo agoone possibility: iproyal.com Oxylabs.io https://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-from-ddos-to-residential-proxies/ https://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-fro...
- rvnx 3mo agoCan't say they are wrong, after the latest backdoor, or let's say, undocumented functionality that leaks some data that was pushed in Claude Code few days ago https://news.ycombinator.com/item?id=48759754 https://news.ycombinator.com/item?id=48759754
- dgellow 3mo agoThat’s not what a backdoor is…
- SubiculumCode 3mo agoI think most websites transmit general locationbto the server.
- eunos 3mo agoWhat Claude Code did is absolutely mindboggling tho, if Chinese harness did that probably POTUS would lose sleep.
- youre-wrong3 3mo agoMaybe if they didn’t farm all the data from Claude to train their own trash models. Anthropic wouldn’t feel the need to do it.
- vrganj 3mo agoAnthropic stole the entire internet. Excuse my language, but they can fuck right off.
- breppp 3mo agoThe issue here is not whether Anthropic used Common Crawl, Alibaba also does that. The issue is that by distilling Claude, Alibaba reuses the IP anthropic used to train the model that's more akin to historical Chinese reverse engineering methods and disrespect of IP
- vrganj 3mo agoAnthropic clearly doesn't respect other people's IP, it's real rich that they now insist on theirs being worthy of protection. Fwiw, I think the concept of IP in general is counter to human progress.
- breppp 3mo agoIt's more complicated than that because Google has been legally displaying other people copyrighted material for years. In any case there's still a difference between publicly available copyrighted data and whether you can use it for model training, and the innovation around model training, RLHF, etc which you presumably have some interest as a country to allow companies to invest in with some legal protections (like the diff between patent law vs copyright law)
- feverzsj 3mo agoConsidering their massive distillation, if US companies stop publishing new models to the public, would China still be able to develop new open weight models?
- tristanj 3mo agoYes, 100%. GLM 5.2 is capable of RSI. It's too late to stop.
- bel8 3mo agoI don't think China would strugle to scrape the internet for fresh data. And they constantly publish state of the art LLM research (see DS4 context compaction and cache tech). They have very capable tech giants. So while not being able to distill western models would probably have some impact, it's probably becoming lesser as time passes. We might even see Western LLMs distilling Chinese models soon. If they aren't already to some extent.
- hnfong 3mo agoEveryone distills/copies training data. A couple months ago when Anthropic was complaining about Chinese distillation, people found that Claude self-identified as "DeepSeek" when asked in Chinese: https://x.com/stevibe/status/2026227392076018101 https://x.com/stevibe/status/2026227392076018101 It's really a fiasco of massive hypocrisy at this point.
- margorczynski 3mo agoChina has most probably already achieved "escape velocity" on the software side. Now if they achieve parity, to some degree at least, on the hardware side with Nvidia it is very possible they'll overtake the US.
- surgical_fire 3mo agoProbably yes. More than a year ago, when Anthropic and OpenAI started to hide the reasoning bits from the output, a lot of people here on HN predicted that Chinese models days were numbered. Fast forward to today, and models such as DeepSeek and MiMo are nothing short of excellent. I haven't used GLM or Qwen but heard very good things about them as well. This "massive distillation" sounds a lot like anxiety about how companies from outside the US can develop very good models themselves.
- johnathan101 3mo ago[flagged]
- saidnooneever 3mo agonot to mention they are kind of capable of executing code and susceptible to injections which also amounts to being practically backdoors if youre not super careful about how u use the tooling
- spwa4 3mo agoWasn't one of the big promises the AI labs made "uncopyrighting"? Ie. the ability to reconstruct large works, including source code, without actual access to the source code? Everything from movies to operating systems.
- silon42 3mo agoCleverly compressing and decompressing doesn't de-copyright it. ... and if it's not the same who'd trust it.
- xpct 3mo agoInteresting, I haven't heard this claim before. I suppose that claim made sense if their customers were big corporations, not so much when its the masses generating bootleg software copies.
- mannanj 3mo agoI remember hearing something about this. Reminds me of the many lies that political candidates make to garner interest and approval. Except who's holding them accountable - like there's not even a list anywhere tracking these lies.
- llm_nerd 3mo agoBecoming? We've moved entirely in the opposite direction. When these tools first appeared the overwhelming conversation was about the risk of letting a remote tool siphon your code and intellectual property (where eventually they're going to add that to their training). Now everyone is using them, and that fear seems to have dissolved. Every corporation is sprinkled with Claude Code, Antigravity, Copilot, Codex, and so on. Even the long fear-mongered Chinese providers are being heavily used in many spaces. In this case this is a PR battle between two firms, and it isn't much more. And Alibaba isn't worried about the "proprietary code" (the truth is that there is incredibly little interest in most orgs code), but that the tool is a backdoor, or at least that is the claim.
- HlessClaudesman 3mo ago[flagged]
- exe34 3mo agoAs long as they're paying for the tokens, there's no attack . Otherwise you have to call training on copyrighted material theft.
- feverzsj 3mo agoThey are not paying for most tokens. The actual users in China do. All they need is the logs.
- InsideOutSanta 3mo agoAnthropic still gets paid. Unlike the vast majority of people Anthropic stole from.
- dizhn 3mo agoIn that case it's already bought and paid for by the users, is it not?
- vrganj 3mo agoDid Anthropic perform "distillation attacks" when they hoovered up the entire internet?
- RobotToaster 3mo ago(Mis)anthropic already performed "distillation attacks" on the internet.
- vorticalbox 3mo agoi can see why they want to stop it but 1. you have to pay for the "attack" 2. these AI companies trained on copyrighted content without permission or attribution to anyone who's data was used to train.
- 3mo ago
- p0w3n3d 3mo ago[flagged]
- short_sells_poo 3mo agoThe corollary is that there are no morals once the stakes are in the $ billions, let alone hundreds of billions. This isn't even about a single person or personality. Very few people in such position could stand fast by their moral code. In any case, an environment that favors profit above everything will naturally select for individuals who are unencumbered by such hindrances. There might've been 100s of Altmans and Amodeis who had a strong moral code but we don't know about them because they dropped out of the "race" because of said moral hurdles.
- rlpb 3mo agoCopyright law is an artificial legal construct, not a moral code. I think appropriate attribution is a moral code, but I am not able to attribute every idea I have to all those who helped me develop the general intelligence that I use to develop such ideas.
- raxxorraxor 3mo agoI think this behaviour has shown that there are no morals involved. Pirate if you want to, just don't get caught if you don't have a giant backing.
- spinningslate 3mo ago> an environment that favors profit above everything will naturally select for individuals who are unencumbered by such hindrances. Exactly. Dairy farms optimise for milk production so favour cows that produce the most milk. The market economy optimises for profit so favours those most willing/able to generate it. Zuckerberg, Musk, Thiel, Andreesen and co are products of the system.
- rkachowski 3mo ago> The corollary is that there are no morals once the stakes are in the $ billions, let alone hundreds of billions. terrifying
- jdw64 3mo agoI got curious and asked my Chinese friends, and they gave me a Reddit link[1]. It looks like it's about location data collection, and they suggested that might be the reason for the issue. [1]https://www.reddit.com/r/ClaudeAI/comments/1ujila1/anthropic_embedded_spyware_in_claude_code_and/ https://www.reddit.com/r/ClaudeAI/comments/1ujila1/anthropic...
- swingboy 3mo agoThere was a big thread about it here the other day. https://news.ycombinator.com/item?id=48734373 https://news.ycombinator.com/item?id=48734373
- deleted 3mo ago[deleted]
- SubiculumCode 3mo agoWow and very websote on earth practically, collects locationvdata
- bhouston 3mo agoAll remote AI are a massive security risk for individuals/companies/governments that may be targeted by the US government. It is likely that the US will get a live feed from each AI provider that they are inspecting in real time to identity things of interest, terrorist attacks or foreign government planning or even foreign companies competitive to key US companies. It will give them access to the though process in those companies as well as much of their text-based IP (source code, docs, meeting transcripts, etc) Also if you are using local AI that you didn’t train yourself you can never be sure it doesn’t have purposeful biases in its reasoning that may disadvantage you - such as directing you away from certain plans or ideas or patents etc.
- general1465 3mo agoLeakage of IP and training on your data is something what I am pointing out too, but people will turn around and try to smooth me down that TOS does not allow that if you are an enterprise client. Are you really going to believe that AI companies won't ignore TOS, when they were ignoring literal laws which sent others to jail in the past? Especially when more data = better model?
- londons_explore 3mo agoIt is worth thinking about the fact the total throughput of even a big LLM provider isn't many megabits. If a token compresses to around a byte, worldwide AI input and output is around 1 gigabyte per second. For any intelligence agency, they can afford to keep and store all of that forever, and later do analysis on it.
- bhouston 3mo ago> For any intelligence agency, they can afford to keep and store all of that forever, and later do analysis on it. At the scale the AI companies are operating at, I think it isn't likely that they are sucking it all in right now. More likely I think the intelligence agencies will get a real-time live tap into the raw data feed which they will process onsite for interesting things and then if things are flagged, they will log it in the intelligence agency systems.
- ravenstine 3mo agoEmployers in 2022: > No! Don't install that lodash thing without explicit approval from IT. Oh, you want a license for Charles Proxy? Gee, I dunno... we've got a budget to maintain. Employers in 2023: > No! You can't use ChatGPT at work – it's a security risk. Employers in 2024: > Okay, you can use Github Copilot I guess, but you'll have to endure boring corporate training on what you're allowed to do with it. Employers with dollar signs in their eyes in 2025: > We attended a seminar about vibe coding. Why aren't you dumbasses keeping up with the times? Use Claude Code for everything! Don't write any of your own code anymore. We don't even really care if you use yolo mode. Just review code and push 10x more features! Use unlimited tokens! Money printer go brrrrr. Employers in 2026: > You mean giving one or two companies full autonomous access to our workstations while stupifying our engineers wasn't a sound business plan?
- dan_i 3mo ago2025 taught me that my employer would replace me with a slave if they could get away with it. The confusing part to me is why these companies believed the "AGI" hype, I.E. that OpenAI or Claude's LLM is the ideal white collar slave. I suppose I can understand that the executive class resents labor enough to make irrational business decisions for the purpose of insulting the workers who design and operate their companies. That being said, the 2025 AI binge feels like a murder-suicide done by the executives of many of these companies.
- bushido 3mo agoWhat's very interesting to me is these moves will introduce a good amount of doubt in future claims by Claude etc, that the open source and non-US models are only getting better because they're distilling from frontier labs.
- Jeff9James 3mo agoStory of Z.ai: use claude-code see how good it is send 100k bots to distill fable 5 (GLM 5.2 is the result of this) release Zcode ditch claude-code ban claude-code
- julianlam 3mo ago[citation needed]
- codedokode 3mo agoThe outcome is that we get either free or cheaper model. Good work.
- kgeist 3mo agoFable 5 was released on June 9 and removed on June 12. GLM-5.2 was released on June 13. It would be an amazing feat to make a model SOTA in just 3 days but I highly doubt it. It's more like z.ai released an existing checkpoint earlier than planned to capitalize on the news
- vitorgrs 3mo agoAlibaba is not the owner of GLM5.2/Z.AI.
- khurs 3mo agoSnowden files revealed NSA collect everything they can. Of-course USA is collecting everything, not just from China but everyone. And same with every one else.
- mbmbn 3mo ago[flagged]
- Simulacra 3mo agohttps://archive.is/bmyny https://archive.is/bmyny
- aivisibility96 3mo ago[flagged]
- avd201 3mo agoAnthropic has been doing this sort of stuff for a while already. I mean, who remembers when Claude would just consume all your remaining usage if it read anything indicating that Openclaw had been used on your codebase? Because I remember. Two months ago btw https://news.ycombinator.com/item?id=47963204 https://news.ycombinator.com/item?id=47963204 Then there was the whole debacle of Fable silently downgrading to other models if it detected wrong think, or worse, outright sabotaging your codebase if you were working on language models lol
- nicogentile 3mo agoSeems that we are finally moving to the next stage in LLM's. not only customize based on old searches but also targeted you based on non disclose data. Its basically the same flow we had years ago with ads in social media. Interesting to notice that we can do the same with these models.
- arkhiver 3mo agono ads or captcha: https://nonogra.ph/alibaba-to-ban-employees-from-using-anthropics-coding-tool-source-says-07-03-2026 https://nonogra.ph/alibaba-to-ban-employees-from-using-anthr...
- JPLeRouzic 3mo ago> employees were being told to use the company's own coding platform Qoder That looks a no-nonsense decision, isn't?
- gchamonlive 3mo agoThere was recently this case here in Brazil https://www.mixvale.com.br/2026/06/26/fbi-warns-brazilian-police-about-man-who-confessed-to-chatgpt-plan-to-kill-his-son-for-child-support-en/ https://www.mixvale.com.br/2026/06/26/fbi-warns-brazilian-po... This is a double edge knife. In this specific instance this was absurdely important for that kid's life, but this work both ways. What if the US authorities deemed it necessary to snoop on foreign governments and citizens for political reasons, now leveraging AI to do it at an industrial scale? One thing is certain though is that assuring privacy isn't top priority for any cloud provider. Companies doing cutting edge, sensitive work should be wary.
- bathtub365 3mo agoThe US government deemed it necessary to snoop on foreign governments and citizens decades ago and is doing it on a continuous basis. Also on their own government and citizens.
- rosegroove 3mo ago[dead]
- gchamonlive 3mo agoThanks, I've edited my original comment to address this more clearly
- synapsehire 3mo ago[flagged]
- fcanesin 3mo agoIt is not a risk is a fact - people decompiling Claude Code have found many times that it has code branchs to detect it is being used in Chinese timezone and locale.
- kordlessagain 3mo agoWell, that's a revenue hit for sure for Anthropic.
- somelamer567 3mo agoThe extreme downvoting of certain viewpoints that are less-than-flattering about China's conduct in the AI race is quite telling. They seem to have given themselves license to do what they like, but _God forbid_ they're called out for acting less-than-honourably. Most adults around the world can associate actions and consequences. The incomprehension and entitlement here speaks volumes about the moral and emotional maturity of the Chinese Communist Party and their political system.
- 0xEnsp1re 3mo agoThey don't wanna Anthropic to collect data ))
- impartshadow 3mo ago[flagged]
- gomilesfd 3mo ago[flagged]
- luciana1u 3mo ago[flagged]
- novoreorx 3mo agoAs someone who knows a lot of Alibaba engineers, this is a fairly common thing and nothing special. Their company owned device has the most strict security control I've ever seen, and it's been for many years. Many softwares are not allowed to run. To me I think it's quite reasonable as the company owned device can access most of the internal resources of this huge monoploy, many of them are confidential. This kind of restriction is only for working in the company, employee's own device out of the company is free from surveillance.
- rldjbpin 3mo agobeing true or not is irrelevant for decisions such as this. has been done on both sides, whether at software level or "hardware". from Teslas not allowed parked around sensitive areas in the city, to blocking a (very famous and quite well-made) Russian antivirus, or Huawei communication stack. Anthropic is not doing itself any favours with their recent (?) antics [1], so it is completely well-founded to do this imho. regardless, harness as a moat is not quite as established as the underlying models to the same extent. [1] https://news.ycombinator.com/item?id=48734373 https://news.ycombinator.com/item?id=48734373