Codex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.
Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies.
That said, these fraudulent proxies are helping Chinese labs keep up, which might be to my advantage long term in eventually having a high quality private AI I fully control on my own hardware. That's not support, but I do recognize the incentive, for whatever that's worth.
One negative is that Claude Code is pretty buggy, and Anthropic makes frequent changes that cause unexpected regressions [0]. With the harness now doing weird stuff with proxies, I'd be worried of them inadvertently introducing bugs which affect people using the feature legitimately.
First they came for the [clients with specific timezones and/or bizarrely formatted dates] and I did nothing. Then they came for the [users that spell favour the good way, with a 'u' in it], etc.
> why would I care about this
It's up to you, of course.
But I think you're making a mistake in assuming it could, in any way, benefit you as a customer.
This isn't specific to this company or the particulars of the business that they're in.
Simply put, you stand to lose more than they do and they are relentless in seeking, maintaining and exploiting any leverage they have over you.
Further, any power they gain over one individual customer tends to generalise to all customers.
Further further, one company's leverage is another company's right.
Not being bothered by the practice is accepting the terms set by the business. Acceptance invites escalation. Relentless.
Even more simply put, you should care because this is how you get John Deere.
"malicious"? Seems like a great way to filter users breaching the TOS while not impeding on normal users. A FOSS client just means they're doing more analysis hidden on their servers.
It's released and signed by GitHub I believe (although not deterministic builds), but there's at least a little bit of provenance that you're getting the real repository.