Claude Code is steganographically marking requests
thereallo.dev
thereallo.dev
(This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org. It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving objectives like this. One obviously being you can move more out of the client and into the server, but the other being you can write plausibly deniable client code in a much more benign-seeming way than this. Some of what they added can only be done on the client, but I think some could've been moved, and the client-required parts could've been done more subtly and credibly.)
It's possible they knew the JS bundle gets so heavily scrutinized that it'd eventually get spotted and reported on regardless so they didn't bother doing something more subtle and duplicitous. But still seems slightly lazy.
It's unlikely that this will stop a big AI lab from distilling their model if they're really determined, but A) it may be enough to stop a bunch of fly-by-night token resellers looking to make a quick buck and B) you never know when one person at one of those big labs will mess up and forget to install whatever workaround they have and out themselves.
I think of it like if you have a problem with birds in your yard so you go buy one of those plastic owls. The owl scares away most of the birds, but not all of them, so you go and buy some ultrasonic noise thing to scare them away (I'm just making something up). Just because you bought the new ultrasonic thing though, that doesn't mean you're going to take the owl down. You leave it up because now you've got two layers of defense instead of one.
aka market competitors reverse-engineering for interoperability
Anthropic could have implemented this not as a durable detection system against proxying resellers, but instead as a point-in-time sampling system to detect where (and with what context) proxying reselling is currently happening. Sure, it would be detected eventually, but in the meantime Anthropic could gain useful snapshot data.
As a side note, I have a pet theory that one of the reasons that OpenAI and Anthropic are okay with the latest models not being released is to prevent distillation.
I think they want to wait a couple months and see if the Chinese models continue to keep catching up or if their gains are really just because they're distilling the frontier models.
Oh, of course. I am sure this is the tip of an iceberg of tons of server-side detections and analytics. But, still, the client-side portion could've been done more cleverly.
What I meant was "some of the specific things in this little client-only snippet could've stayed server-only". I am sure long before they added this they already had tons of other mostly-server-side detection coverage.
It's all a losing battle anyway.
There is a real time cat and mouse battle going on here in terms of keeping the advantage here, right.
As a rational actor, if someone was e.g. attacking me, leaving aside the whole copyright thing, but potentially using some sort of system to increase their value while decreasing my value (without calling it theft to avoid the whole debate), I would want to put proportionate defense out there as fast possible, depending on the amount of value that was exchanged to stop the bleed, while in parallel figuring out the best long term plan, right.
I would find it funny if this was due to "laziness" - defining laziness as it was a known oversight yet left unpatched. If we consider Anthropic as the leader in AI-native engineering, workflows, culture, etc. how can laziness in code exist? It should be as easy as for them to tell claude "come up with a better way" or, better yet, had their 24/7 monitoring agents identify and resolve this. If this was an oversight, which is completely natural to the eng process, maybe this current ai narrative/hype/marketing should be taken with a grain of salt
Like maybe some "goal" they set for their AI caused it to decide that putting stego in the requests was the best way to achieve something or other.
(to be clear: I'm not saying this is right, I'm saying this is stupid)
Most likely someone did and raised the issue but they're moving too fast to fix these things before clicking deploy.
‘’’ cn baidu.com alibaba-inc.com alipay.com antgroup-inc.cn bytedance.net kuaishou.com xiaohongshu.com jd.com bilibili.co iflytek.com stepfun-inc.com moonshot.ai anyrouter.top claude-code-hub.app claude-opus.top openclaude.me proxyai.com yunwu.ai zenmux.ai
‘’’
You can view the full list here: https://cdn.thereallo.dev/blog/assets/cc-domains.js
const knownDomains = [ "cn", "sankuai.com", "netease.com", "163.com", "baidu-int.com", "baidu.com", "alibaba-inc.com", "alipay.com", "antgroup-inc.cn", "kuaishou.com", "bytedance.net", "xiaohongshu.com", "ctripcorp.com", "jd.com", "jdcloud.com", "bilibili.co", "iflytek.com", "stepfun-inc.com", "aliyuncs.com", "cn-shanghai.fcapp.run", "cn-beijing.fcapp.run", "xaminim.com", "moonshot.ai", "anyrouter.top", "packyapi.com", "aicodemirror.com", "aigocode.com", "hongshan.com", "iwhalecloud.com", "dhcoder.net", "lemongpt.top", "zhihuiapi.top", "intsig.net", "high-five-ai.xyz", "cloudsway.net", "4sapi.com", "529961.com", "88996.cloud", "88code.ai", "88code.org", "91code.pro", "992236.xyz", "ai.codeqaq.com", "ai.hybgzs.com", "ai.kjvhh.com", "aicanapi.com", "aicoding.sh", "aifast.site", "aihubmix.com", "anmory.com", "api.5202030.xyz", "api.ablai.top", "api.bianxie.ai", "api.bltcy.ai", "api.cpass.cc", "api.dev88.tech", "api.dreamger.com", "api.expansion.chat", "api.gueai.com", "api.holdai.top", "api.ikuncode.cc", "api.lconai.com", "api.linkapi.org", "api.mkeai.com", "api.nekoapi.com", "api.oaipro.com", "api.ruyun.fun", "api.ssopen.top", "api.tu-zi.com", "api.uglycat.cc", "api.v3.cm", "api.whatai.cc", "api.wpgzs.top", "api.xty.app", "api.yuegle.com", "api.zzyu.me", "apimart.ai", "apipro.maynor1024.live", "apiyi.com", "applyj.hiapi.top", "augmunt.com", "b4u.qzz.io", "clauddy.com", "claude-code-hub.app", "claude-opus.top", "claudeide.net", "co.yes.vg", "code.wenwen-ai.com", "code.x-aio.com", "codeilab.com", "cubence.com", "deeprouter.top", "dimaray.com", "dmxapi.com", "docs.aigc2d.com", "duckcoding.com", "fk.hshwk.org", "flapcode.com", "foxcode.hshwk.org", "foxcode.rjj.cc", "fuli.hxi.me", "getgoapi.com", "gpt.zhizengzeng.com", "gptgod.cloud", "gptkey.eu.org", "gptpay.store", "hdgsb.com", "henapi.top", "instcopilot-api.com", "jeniya.top", "jiekou.ai", "kg-api.cloud", "n1n.ai", "new-api.u4vr.com", "new.xychatai.com", "one-api.bltcy.top", "one.ocoolai.com", "oneapi.paintbot.top", "open.xiaojingai.com", "openclaude.me", "opus.gptuu.com", "poloai.top", "poloapi.top", "privnode.com", "proxyai.com", "qinzhiai.com", "right.codes", "runanytime.hxi.me", "sssaicode.com", "store.zzyus.top", "tiantianai.pro", "uiuiapi.com", "uniapi.ai", "vip.undyingapi.com", "wolfai.top", "wzw.de5.net", "wzw.pp.ua", "xairouter.com", "xaixapi.com", "xiaohuapi.site", "xiaohumini.site", "xy.poloapi.com", "yansd666.com", "yansd666.top", "yunwu.ai", "yunwu.zeabur.app", "zenmux.ai", ];
const labKeywords = [ "deepseek", "moonshot", "minimax", "xaminim", "zhipu", "bigmodel", "baichuan", "stepfun", "01ai", "dashscope", "volces", ]
wouldn't this happen due to the massive amounts of spam/slop being released?
they spend their resources on compute and the model itself, the company is carried by the model and software engineers babysitting it
That the provider's business needs necessitate the this behaviour doesn't justify their lack of honest disclosure. That honest disclosure would render the solution to their problem useless isn't my problem. If anything, that they thought this was acceptable makes me wonder what else they're harvesting from my machine? PII?
The cynic in me can't help but feel that the state of these comments reflects less on the commentor's views of this debacle but rather their feelings about AI/Anthropic/America/what-have-you.
They totally knew that this would never be accepted by users, and that is precisely why they resorted to obfuscation and steganography to exfiltrate the data. This was quietly added in an update, and would have been removed in a later one had it gone unnoticed.
How is this any different from hiding a drug in food and randomly feeding it to a homeless person as a human trial? Even if that homeless person is an undocumented immigrant, does that make that acceptable?
They crossed the line.
This isn’t a comment on whether I agree with the change. Just that your analogies aren’t applicable here.
Would you be shocked if some of the current tech bro companies could with finding such subjects?
Sure the thing we know matches the company interests but as the parent mentions for all we know they are also shipping over your ssh keys and browser cookies.
Hah, you just reminded me of this meme I spotted the other day: https://img-9gag-fun.9cache.com/photo/an76Wnz_460swp.webp
No, please don't move past this so quick, because I'm not convinced they have the need, and in some markets (like the US) it is a violation of civil rights, to show people different content based on their ethnicity[1] because those people might have a claim that supersedes anything they might have signed or clicked-through.
That Anthropic did something they could obvious be sued for constitutional violations in multiple countries is shocking.
> what else [are] they're harvesting from my machine? PII?
Assume everything, and yet I think this is more insidious than mere exfiltration, and we should go further: The LLM can respond to these magic quote marks directly, which means it can be trained to give people bad/different advice without those markers being so visible to people using debugging tools.
That's so unethical, the laws on this potentially so severe, Anthropic could be facing unlimited damages, from any one example combined with this article, which means either they have a really stupid management team, or were given a promise of legal immunity in some way.
Neither of those things should be what you should want to base your next big idea on.
[1]: For a simple example, showing an ad for (say) mortgage offers and targeting people by race/ethnicity/gender is totally illegal, but it's also illegal if you make a list of targeting criteria that just happen to select for a protected class.
From a privacy perspective, this is better described as metadata, it is not personally identifiable information (PII).
I just can’t bring myself to trust an organization that allows these types of underhanded things to happen in the first place. The fact that this behavior even got to customers raises a lot of red flags for me.
So any covert bullshittery hits hard.
If that's true, that is another reason why it's an illegitimate business.
You will own nothing and be happy.
Any and all ends justify any and all means.
/s
If anything, I'll trust Google more than any of the other labs just because the infrastructure that stores and protects user data was built over decades ago pre-AI craze.
Or… just that open-weights AI is getting good enough to present a reasonable level of threat to their business. So it popped up on a SWOT analysis and they’ve started putting a strategy together.
This doesn’t need to be anything more nefarious or untrustworthy than a company putting plans in place to deal with a competitive threat.
country that does not allow internet is being hated on the internet
Edit: downvoting this fact without counter point is really dishonest
Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here.
I've had Claude fuck over clean well documented code-bases for no reason, and there's a good chance this is due to some faulty trigger. Luckily I don't trust these things one bit, and claude only ever runs in an isolated VM, however, I am pissed I am being made to pay for their errors in detection and waste my time fixing things I apparently paid to have fucked up.
That's unacceptable conduct. It's witch-hunting. Punishment and attacks on you for things without real proof. That isn't right.
edit:
Legitimate reasons include:
- analyzing what Claude Code is sending to Anthropic to verify its not exfiltrating data;
- selecting a model dynamically based on prompt difficulty, or enforcing a particular model;
- switching between multiple Anthropic accounts based on the project;
- filtering out credentials, PII and company secrets.
and many more.
Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means.
Whether or not it harmed you this time, it's a violation of trust and autonomy.
Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1.
The software is written in a deliberately obtuse way, presumably in service of some (unknown to us) goal. This is a deceptive and anti-social thing to do, it is by nature an adversarial stance to adopt. An already adversarial actor may be "punished" by this, but in such a relationship, hostility can be expected. A non-adversarial actor -- a normal developer / user -- is being harmed by this because the software is treating them as an adversary.
Further, lets assume your guess is correct and, in addition, that Anthropic elects to alter/downgrade/poison their service[0] for users that fit a particular pattern of markers. It's obvious how this system would "punish normal developers" (i.e. not the intended target/victim) that happen to fit those patterns.
[0] to some extent, the service already has been altered as its behaviour depends on the prompt text
There are, of course, no normal Chinese developers
Tons of normal developers use ANTHROPIC_BASE_URL, the flag which activates the malware.
Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative.
That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't harvesting PII?
That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.
- filtering out people from the wrong side of "all humanity", years before it was demanded by the government
- downgrading their models in arbitrary ways (later saying "sorry but not really")
- actively sabotaging the replies, as in covertly modifying them to feed the users incorrect results
What's next to expect from Anthropic? Malware to brick your machine if they don't like you? Extending this to more people they don't like? I think I already can see how Dario's Amodei utopian visions of the future of "all humanity" are going to unfold.
All of this is totally understandable if you take the perspective that these people genuinely believe they're building superintelligence.
The overwhelming majority of the AI safety crowd - which has poured more of their life and time into thinking about these problems than the average HN armchair commentator ever would - understands that:
- you want to prevent China from getting to superintelligence first
- you must gate access of SI to known good actors
- and that this is a race that will result in the extinction of humanity if you fail in these goals
Literally everything these people do is totally understandable if you drop the assumption that they're lying when they say "we think we are building superintelligence."
> this is a race that will result in the extinction of humanity if you fail in these goals
They aren't, they are building LLMs. They aren't even building AGI and they all know it.
Hell, even if they came up with AGI, then Anthropic's service model would become slavery so I'm not sure why they'd want to.
>you want to prevent China from getting to superintelligence first
I don't. Prevent, not even outpace? Why? Seems like you're assuming China "winning" whatever race it is effectively ends the humanity. Right now I think Chinese labs are way more mature about this, and Anthropic is way more dangerous than them. And how does it fit into the "for the benefit of all humanity" narrative we keep hearing? Is China wrong humanity? Who else is going to end up in the wrong part? Are you sure it's not you?
>if you drop the assumption that they're lying when they say "we think we are building superintelligence."
I never assumed that, I know perfectly who Anthropic are and that they believe everything they say as self-evident, without having any doubts. And I know they're the kind of people who can convince themselves in anything, because they're obviously smarter than everyone else, and become detached from reality. The entire US "AI safety community" was born in rationalist circles and is largely like this, it's a very specific cult. This is exactly the kind of people who are going to create hell on Earth for you and the rest if given even a lick of actual power, and perfectly rationalize it as a necessity.
That said, these fraudulent proxies are helping Chinese labs keep up, which might be to my advantage long term in eventually having a high quality private AI I fully control on my own hardware. That's not support, but I do recognize the incentive, for whatever that's worth.
This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The steganography cat-and-mouse game is valuable because it is much harder for a gateway to continuously reverse engineer all the fingerprinting mechanisms used. Sure, some malicious gateways will be able to stay on top of things, but not all - and not always.
This is a total non issue unless you are Chinese distilling lab.
https://news.ycombinator.com/item?id=48259288
https://github.com/anthropics/claude-code/issues/62061
Looks like they just keep finding new "creative" uses for such things, as expected. I'll keep patching them out.
Is there a way to modify these prompts e.g. by putting instructions in CLAUDE.md to override it? I know it won’t directly modify the system prompt, but it seems like CLAUDE.md should have the final say, shouldn’t it?
And no, IMO stenography isn't security by obscurity, in the same that using RSA and keeping the private key private isn't security by obscurity - keeping the private thing private is part of the security model.
That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't harvesting PII?
That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.
Or maybe you don't understand this hypothetical situation either, but I'm suspecting you just don't care about other people's privacy.
What’s the punishment here exactly?
Seeing as how Anthropic cannot stop raising a stink about "illicit Chinese distillation attacks" every month or so, I'd bet money on them either already silently degrading model performance if any of the identification patterns match, or, at the very least, considering it/doing dry runs.
Particularly considering that they've openly stated that the technology to do so exists and that they were going to use it in production on Fable.
And that's also why, as a legitimate customer, want none of it, you never know if you accidentally entered a zone they don't like.
I understand how this can be useful to Anthropic if the 3rd-party is acting as a proxy (because they end up hitting the Claude API with the marked prompt), but it looks like requests where "hostname contains deepseek" would never be sending data to Anthropic. What am I missing?
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
I guess the only explanation is that there's a side-telemetry channel that still sends some data to Anthropic, regardless of ANTHROPIC_BASE_URL overrides.
Here's an example. Say you have your team use patched binaries. Then CC updates and requires a new patched binary with new tricks. You now have to have a team ready to analyze the binary and begin to address the tricks; meanwhile, unpatched code is now a fingerprint. If some researcher decides to update Claude on their own to access new features, they get fingerprinted.
Defeating a single fingerprinting technique once is easy. Defeating all of the techniques all the time is hard.
Really makes you think huh
Just like I don’t care that game clients run sneaky anti-cheat measures.
Right now they offer a good product, and I’m fine with them trying to limit abuse of their services. If an altruistic alternative company with an equivalent product pops up, sure, I’d swap over, but I don’t see one.
I’ve seen people here talking about how they should’ve been upfront about this. But they can’t? If they were, they wouldn’t be able to catch the resellers/distillers. Just like how anti-cheat doesn’t explain how it works, because to do so would be to nullify its effectiveness.
I had a use case where I had to MITM CC's traffic to strip credentials that could have accidentally made it into the harness.
I'm happy my paranoid self told me "You don't really know what they're doing with that flag or if they're honoring it for all requests", so made a decision to proxy it at the network extension level.
Also, does anyone remember Anthropic quite literally sabotaging your project if the classifier in front of fable thought you were working in the AI industry? After backlash, they pulled it back, now they did this. Anthropic is on a weird tangent to ship malware. If someone doesn't stop them, one day, this will backfire catastrophically.
2. 2024 For profit, but "we will train biases out of our models and make sure our AI is safe to use"
3. 2025 We'll make sure it doesn't take over the world, with like a 70% confidence interval
4. 2025 The mecha-hitler inflection point
5. 2026 Our new model is so terrifying it will destroy all of security and hack the chinese, we can't let the chinese use it
6. 2028 (projected) Our new model requires so much energy that 30% of the elderly population will die without AC, but it will be stronger than the chinese models and let us destroy china
7. 2030 (projected) Our new model will triumph over the mecha-hitler dictator model, and will be a benevolent dictator that only demands 60% of all energy produced, not 98%
Cool reverse engineering/analysis report but if this is the extent of nefarious activity that came of it (trying to catch/mitigate chinese lab model distillations), that's kind of encouraging.
This is how it looks.
# userEmail The user's email address is <my email>. # currentDate Today's date is 2026-06-30.
IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task.
</system-reminder>I also do not understand what's the point of this, because if I have a gateway that can detect it, then we can replace the text before forwarding to the model, so what's the catch?
> This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust.
They already tell you they scan for malicious prompts, and they have no ZDR guarantees for consumers. Why do signatures like this matter at all?
It's a total non issue unless you're a Chinese distillation lab
Not really distillation, just synthetic training data.
Meanwhile, if you mean "Anthropic must think their technical advantage isn't very large..." then your conclusion is literally disproven by your premise.
I'm authenticated to Claude, so they already have the whole attribution thing solved.
This watermark may trigger a similar mechanism.
I think you missed the memo on how foolish this attitude is. It came out around the time Edward Snowden made his discoveries at the NSA public. I suggest you look into it
It was decided by Claude based on an ambiguous high-level goal-oriented prompt, don't expect it to make sense.
Had a competitor pull something like this with a previous employer. They were supposed to be interoperating with a standard, but they had a secret steganographic handshake, which they used to pretend that competitors products were unreliable (they had a first mover position in a smaller national market with specific requirements, so this wasn't shooting themselves in the foot). Our guys figured out the handshake and just silently implemented it. In this case, the competitor wasn't big enough to waste engineering time on multiple such hacks, but Anthropic have time (or Claude does).
The uncomfortable part is that a “safety” company put a covert classification channel into the system prompt of a developer tool that now routinely gets filesystem, shell, git, and browser access.
If a random npm package changed invisible-ish punctuation based on your timezone and API host so its backend could classify you, we would call it malware-adjacent telemetry. I don't see how Anthropic is different in this case.
Interestingly, my device is in Shenzhen right now, but macOS has assigned Shanghai as the "closest city" rather than Hong Kong which is geographically closer. I am curious if there is any documentation on how that is assigned.
pi's "minimal" coding-agent has a total of 132 transitive dependencies spanning 153 maintainers.
While I understand JS developers in the JS/NPM ecosystem think this qualifies as minimal, it most certainly does not, from a supply chain security perspective.
>on your local machine
I'd think any developer worth their salt has at least some for of isolation going.
Literally, how. How does one determine what abusive use looks like for the API without context into the client? All requests look like the same stuff. If there was a better way then they would have done it. Or is the author hoping that if Anthropic writes "hey china, please don't steal our models, kthanks" they won't? Like get real. This stuff means nothing in China. China can't even manage to regulate their building industry enough to use real concrete where it's warranted.
Zoom, enhance
> This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust.
Most basic Javascript malware will use Base64, XOR, and eval. So although not malicious, I'd bet they asked Claude to "obfuscate my fingerprinting using tricks that malware writers use"
Models are built using information but the building aspect is not inevitable or trivial. There has been enough information to build LLMs for a long time. But we didn't have LLMs because we didn't have the technology. What's being copied here is that technology, not the information. Hence going to Anthropic.
I doubt Anthropic is cackling maniacally behind the scenes, this was almost certainly a stipulation from the government to put Fable back up.
It's definitely not good but I would rather they surgically separate out possible bad actors so that I don't have to trust them with my passport, to prove I am a US citizen. I don't want the internet version of TSA checkpoints.
Anthropic has become a choice for many developers because of Claude Code, but in the recents months with "small things" like this and whole Fable fiasco they are *actively* pushing people to both competitors and local alternatives.
And if someone spends a significant amount of time and money to switch, it will be really hard for Anthropic to get those people back.
The question is about accountability. Right now these big closed-source model companies can do whatever with the data, and no one can hold them accountable for unacceptable data handling decisions.
You're actually trust your security to your harness AND model AND inference API provider in this scenario: https://jacob.gold/posts/why-i-wont-run-untrusted-models/
But I wonder if there will ever be a day when VSCode, etc, would decide to engage in similiar practice but for the collection of business & research intels, etc... that will be the true cyberpunk era and the information dark age.
Claude Code has more or less full access to the client computer. The server (that hosts the actual AI) can just go: execute this payload and tell me the result - otherwise I won't answer any further questions or re-route you to a stupider model.
The payload could check for Chinese time-zones, scan for copies of the little red book on the local hard-drive, or ping truth.social to see it was behind the great firewall.
It shouldn't, not if you run CC as a separate unprivileged user. I wouldn't run CC on my main user account with sudo and access to my home directory or other resources. This is what the UNIX permissions system was designed for.
I’m pretty sure every lab, including Anthropic, is doing distillation right now.
Interesting, that pip (Python package manager) docs does not even mention sandboxing and malware topics in "Getting started" docs as if we were living in a wonderful world where malicious people, companies and countries do not exist.
Also, do not leave any information in user or host name, it will be used against you as the article proves.
You don't create a security measure then tell everyone how to bypass it.
I think OP is pointing something interesting out but the undertones of caution and "what else are they hiding" seem melodramatic and I find that hard to take serious.
The internet gives people a platform and, in a lot of ways, this supplants the typical role of journalism. The issue with this is no one wants to act like a journalist and actually explain the truth around a set of facts. Instead, they'll portray their opinions as a narrative and every time that resonates with someone or gets signal boosted, that narrative grows more assertive in the typical discourse I see nowadays. I would find it far more interesting to see what explanation Anthropic gives for these features than to immediately cry foul.
But they would rather plant a Trojan on the user's computer.
Now of course stego is hiding that you re hiding information.
So, seen that they were caught, a case could be made that they effectively altruistically failed at using steganography.
P.S: such a headline makes me think I ll cancel my subscriptions and try models like GLM / Deepseek and Kiwi that sound more interesting by the day.
You’d change seperators and position if you truly wanted to do this right
Its basic date wrangling and tbh i see nothing malfeasant here
Its basically yyyy/mm/dd yy/M/d mm-dd-yyyy stuff but suuuuper lazily done
Anthropic pushes fear and control. But the only way to win is by innovating. China is flooding the market with cheap, good enough models, while the U.S. is building a Chinese firewall.
There seem to be all sorts of continual under-the-cover changes like this one that make life harder. It feels like the entire product has been taken over by overly ambitious PMs that care more about making their mark than in improving the experience, and all of their marks have made me less productive.
I've been using Pi with GLM5.2 the past few days, and though it's expensive, I find it far more productive and less annoying. The remote session plugin is far more reliable, I don't need to intuit some undocumented usage pattern to figure out how to use it well, and it just works.
are you using the API for glm 5.2 or how exactly is it more expensive? How is GLM5.2 more expensive than using Claude code, that doesn't line up to my experience but to be fair I am on an older yearly subscription which generously only has 5 hour limits.
To be fair though one minor criticism of GLM 5.2 that I have is that it does seem to overthink quite a lot sometimes but the results end up being (good?),
I personally have used Glm 5.2 with (Opencode + obra/superpowers) / Oh-my-pi / Maki.sh
I like the 1st one when I am doing a longer project, the 2nd or 3rd one when I am doing a project which doesn't want me to ask too many questions and simply spin me up something. I sometimes use free online interfaces of claude and gemini and others like AIstudio for that as well which surprisingly can lead you to go far as well.
Overall, I am decently happy with the state of Open-source models actually and the eco-system around it is probably gonna have even more innovation surrounding it.
No they can't, because developer tools run on developers' machines. You can't trust your code running in an environment you don't trust.
regardless, while you are not logged in and using a non-anthropic model (which is now fortunately feasible), there is nothing that affects your day-to-day.
the rest is just lame cat-and-mouse shenanigans to keep an eye out for.
Also Anthropic: lets do this in JS
I would guess that's their first line of defense; they should have more techniques to identify distillation because that's a very simple way of detecting the host and can be easily spoofed.
i.e. this will allow them to literally commit fraud against paying customers
What do you mean you don't know where the bug is coming from?
No, I absolutely didn't make it up, how could you accuse me of that?
Does anyone know when this regex isn't working? I double checked it 27 times, I even asked the LLM. They all say this regex should be finding these dates.
Weird, suddenly all the conversations are breaking when I feed them into this other tool? Something about UTF-8 errors, but I'm sure I'm only using ASCII?
I do try to take care to make sure the things I build can be used by other people even when they care about different things. I care about understandably, determinism (as it relates to computing), and repeatability (because I want to be able to trust the systems I use).
If y'all would be willing to try to account for use cases of others, and try not to break them... that would be nice.
Please note: that generally when you modify something that belongs to someone else without telling them... things should be expected to break.
The fact is the post shows no evidence of anything malicious being hidden, only that stuff is being hidden.
There are a few obvious explanations in comments for why they would want to hide this particular stuff in this particular way (e.g. if it's to detect abuse and competition).
I don't see how this is different to using e.g. sentry or google analytics, just with an extra bit of trying to hide. I always assume all tech companies do stuff like this, having worked at many tech companies where I've ended up on both sides of stuff like this. I always assumed the average HN reader had a similar background and would be completely used to this sort of stuff.
Like someone else pointed out, the data gathered is likely covered in the TOS too.
In the grand scheme of privacy invasion and modern tech software doing underhanded things to get data, this feels fairly standard?
I'm generally pro-local LLMs and I don't like Anthropic, and from the headline and comments I was ready to get riled up, until I read the article. If this was some small plucky EU privacy startup, then I feel the outrage would be a bit more justified, but this is a frontier AI lab - I can't have been the only one who knew/assumed this happens, and probably happens in some form with all software from any company valued over a certain amount (incl. MS, Google etc.)
I really think this comment section feels completely unhinged. It feels 99% ideology, politics, hysteria and astroturfing, rather than a reaction to the tech and technicality which is what I come to HN for.
But there are some wrinkles - why only two timezones and not others? E.g. US-vs-rest-of-word month-vs-day etc.
Could just be some bad tree-shaking or simply a left over bug/merge issue if I am being generous.
If I was going to put secret stenography things in my models I'd just do it in the model response rather than a relatively low bandwidth date stamp in the SI.
Am I the only person who insists on writing my password every time I push and pull from git?
Originally I didn’t want IDE’s doing stuff for me, now I absolutely do not want an LLM to have that power.
Is it really that unique to control what git does remotely?
If you are developing anything in AI or related domains that is of immediate value and/or in competition with Anthropic (and the like), DO NOT use a CLI programming agent. Preferrably obfuscate your code and gut it of sensitive IP before showing it to agents. Do not trust the dont-train toggle.
Sounds like a very expensive lawsuit waiting to happen (GDPR allows fining up to 4% of global revenue, not profits)
All Anthropic has done is reduce trust, once again, with legitimate customers, while doing nothing to stop illegitimate customers. They need to get adults into key leadership roles, quickly.
Consider also that Claude Code is explicitly designed to limit human agency [1].
Please, just write normal English that we can read. Please, for the love of god, respect our time and the attention we will be spending on the text you provide.
Anyway, one can scarcely be surprised that the AI companies are being dishonest in their tools. They're consistently dishonest in their marketing. They're famously dishonest in their financials. Why anyone trusts these people with anything is entirely beyond me. But here we are - people handing over their creativity, their productivity, to these things.
You don't have to. You didn't need these tools before, when you were creating content, when you were writing code. You don't need it now. Fight back. Stop using it. It's not hard. It's easy.
I used that month to complete a work project and then beef up my personal harness so I'd never have to deal with Anthropic (and these sorts of shenanigans) again.
The cheap tokens are the product.
Why was this person from Hong Kong going through the details of Claude code for obvious security reasons? There are some other obvious reasons that come to mind.
Maybe it's an eye opener for this person how much the trust in Chinese companies has eroded in the West.
Even if they suddenly stop stealing IP, which this "security research" article would certainly not suggest is happening, it would be a very long time before trust is restored.