Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here.
I've had Claude fuck over clean well documented code-bases for no reason, and there's a good chance this is due to some faulty trigger. Luckily I don't trust these things one bit, and claude only ever runs in an isolated VM, however, I am pissed I am being made to pay for their errors in detection and waste my time fixing things I apparently paid to have fucked up.
That's unacceptable conduct. It's witch-hunting. Punishment and attacks on you for things without real proof. That isn't right.
To be fair to Anthropic, [they're trying very hard to do that.](https://www.anthropic.com/news/detecting-and-preventing-dist...). The attacks are sophisticated and difficult to detect. I don't accept that if this fails, their only option is to just accept Chinese companies stealing IP.
If I decide I dislike words starting in S, despite myself being a prolific user of words starting in S, and smack some child who'd never even heard the rules, simply for saying "sorry", simply because some people say "shit" and it makes me mad, despite it being my most used word, are we "being fair" by saying "to be fair, managing curse words is a difficult problem"
no right? Insane take.
As many have pointed out, they're collecting data in ways much less aggressive than Anthropic itself about what Anthropic does.
Anthropic doesn't like it, but I don't see this as "Chinese companies stealing IP," any more than if Google tried to ban competitors from seeing how Google Docs or an Android phone behaves, or Ford trying to ban anyone from Toyota from seeing what their car looks like.
Please stop calling them "attacks." It's distillation training. It's looking at what Anthropic does -- as a block box -- and trying to duplicate or beat it. It's how progress happens.
IP is the code and possibly the weights.
No one is stealing IP.
And I don't think anyone in their right mind would argue the AI industry isn't being fairly compensated.
To go further: most people in the world wouldn't feel bad at all if we found a way to slow what's likely the biggest socio-polical-economic change in human history down a bit.
How exactly do you define "fucking over", and why do you suspect this "fucking" was done as a result of a faulty trigger as opposed to the inability of LLMs to write maintainable, extensible code?
"Never attribute to malice what can adequately be explained by stupidity."
Why do I suspect faulty trigger? The things wrecked weren't wrecked by even much less capable, including local models, while reverting everything to pre fucking up and asking claude again led to similar results. Once on whatever shitlist that was, claude also failed tasks it previously aced when given the exact same prompt and project files. I attributed it to opus 4.6 being a downgrade which people always pushed back on, claiming they thought it was better, but i had empirical proof, it couldnt do tasks 4.5- could do quite well. Now all of this? It's clicking all of a sudden that its quite plausible i got flagged somehow and ended up with an intentionally degraded service.
So, claude is off table for me these days, and deepseek gets very deep git commit read-throughs with every file even being read being carefully monitored. This obviously ruins the "agentic" promise, but the reality is we cannot trust these fucks (being the companies). The irony is deepseek now queries claude on problems its stuck on for input via openrouter, with mild success (the gap really isnt all that big, if its even there), before escalating to me for input on direction on solving a given problem. So now chinese models get more claude training data, not less. In fact, they get training data on frontier ML stacks and problems. Anthropic did that to themselves.
edit:
Legitimate reasons include:
- analyzing what Claude Code is sending to Anthropic to verify its not exfiltrating data;
- selecting a model dynamically based on prompt difficulty, or enforcing a particular model;
- switching between multiple Anthropic accounts based on the project;
- filtering out credentials, PII and company secrets.
and many more.
Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow)
They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.
This is a direct conflict in framing. They clearly do not see Claude Code as a "tool in a workflow" but instead as a service that will eventually replace all programmers.
I think the self-evident quality of the various parts of the Claude Code universe is a pretty obvious indicator of the problems with that approach. It is still important to understand a party's thinking if you want to understand their position.
> They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.
Time will tell, but I agree that they are indeed in a tough spot. Probably not for the reasons that they think.
Can you cite specifically what in the linked article or discussion leads you to say that?
Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means.
Whether or not it harmed you this time, it's a violation of trust and autonomy.
Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1.
This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS.
This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to:
> Usage Information: We collect information about your use of the Services, such as the dates and times of access, browsing history, search, information about the links you click and about third-party applications, services, and content you integrate or interact with, pages you view, and other information about how you use the Services, and technology on the devices you use to access the Services.
What do you see as malicious or reckless here, exactly?
Since when was it your harness?
Switch to pi if this bothers you.
The same IP that is a highly compressed collection of everyone's else's IP?
That's hilarious.
it's not IP, and it's certainly not their IP
> the TOS
oh no, the terms of service how dare people break those. you don't get to claim fair use while CFAAing everyone's actual IP then whine about the tos, and then when called out on spying on users point to it as if it being in the tos somehow justifies it
a lot of other malware has a tos too but we still call it for what it is
I'm not a lawyer so maybe that is the wrong legal term for a model/service like this. Would you mind telling me the word I should have used?
basically the point is that it's not protected because it doesn't fall under any classification of IP (it's not copyright or patent since it's mathematical outputs of a mechanical system, it's not trademark because obvious, and it's not a trade secret because it's not a secret)
I surely would. What does that have to do with this scenario.
Note that the SW running on your machine is not doing anything malicious. The service is the thing that behaves in ways you want like - and that service is not running on your device.
There is no comparison with rootkits here. This is the equivalent of Google giving you a CLI to make searches easier, and that tool decides to just Rickroll you randomly. Annoying, yes. A security concern? No.
The software is written in a deliberately obtuse way, presumably in service of some (unknown to us) goal. This is a deceptive and anti-social thing to do, it is by nature an adversarial stance to adopt. An already adversarial actor may be "punished" by this, but in such a relationship, hostility can be expected. A non-adversarial actor -- a normal developer / user -- is being harmed by this because the software is treating them as an adversary.
Further, lets assume your guess is correct and, in addition, that Anthropic elects to alter/downgrade/poison their service[0] for users that fit a particular pattern of markers. It's obvious how this system would "punish normal developers" (i.e. not the intended target/victim) that happen to fit those patterns.
[0] to some extent, the service already has been altered as its behaviour depends on the prompt text
There are, of course, no normal Chinese developers
Tons of normal developers use ANTHROPIC_BASE_URL, the flag which activates the malware.
Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative.
That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't harvesting PII?
That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.
We all know user agreements exist to strip users of their rights and to absolve companies of wrongdoing. We know that corporate apologists here are also well aware of this fact. When user agreements explicitly grant companies the right to screw over users, apologists are quick to make excuses about how it's all standard operating procedure and accuse people of being uncharitable for doing a plain reading of the text [1]. Yet when people are actually screwed over by companies, those very same people blame users for accepting the user agreement. It's a bad faith system.
User agreements are nothing more than power plays by exploitative companies.
It's based on whether your timezone is in China and your hostname matches a blacklist. Literally 2 bits of information. Not much of a fingerprint.