Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Codex CLI is FOSS, unlike Claude Code, so Codex is less likely to do things like that, and it's one more reason to avoid Claude Code and Claude in general. Hopefully, many eyes will be looking into Codex for malicious things like that.


Genuine question though, why would I care about this if I'm paying for a subscription and adhering to TOS. I'm very skeptical about their privacy policy, business practices, and so on, but am curious what the negative about this is. Seems like it would work to my favour as a customer pushing back any date of the cutting of subsidies.

That said, these fraudulent proxies are helping Chinese labs keep up, which might be to my advantage long term in eventually having a high quality private AI I fully control on my own hardware. That's not support, but I do recognize the incentive, for whatever that's worth.


One negative is that Claude Code is pretty buggy, and Anthropic makes frequent changes that cause unexpected regressions [0]. With the harness now doing weird stuff with proxies, I'd be worried of them inadvertently introducing bugs which affect people using the feature legitimately.

[0] A recent example: https://www.anthropic.com/engineering/april-23-postmortem


Maybe they should try running Mythos to check Claude Code, given their marketing with it's superior performance.


Because they could use (or maybe are already using) similar techniques to do things you don't approve of, without your awareness.


What if they decide you're not patriotic enough, serving you evil models, because one man with a lot of shmeckels told them to?


Then I could just.. cancel my subscription and stop paying?


Right. They really should wait until _after_ the regulatory capture bit is locked in to mess with users.


How would you know? They've already degraded model performance silently.


First they came for the [clients with specific timezones and/or bizarrely formatted dates] and I did nothing. Then they came for the [users that spell favour the good way, with a 'u' in it], etc.

> why would I care about this

It's up to you, of course. But I think you're making a mistake in assuming it could, in any way, benefit you as a customer. This isn't specific to this company or the particulars of the business that they're in.

Simply put, you stand to lose more than they do and they are relentless in seeking, maintaining and exploiting any leverage they have over you. Further, any power they gain over one individual customer tends to generalise to all customers. Further further, one company's leverage is another company's right.

Not being bothered by the practice is accepting the terms set by the business. Acceptance invites escalation. Relentless.

Even more simply put, you should care because this is how you get John Deere.


Why care about privacy if your not doing anything wrong??

Not everyone agrees that what you are doing is benign.


What a historically bad take


"malicious"? Seems like a great way to filter users breaching the TOS while not impeding on normal users. A FOSS client just means they're doing more analysis hidden on their servers.


Anthropic is built on raping TOS and copyright.


It's released and signed by GitHub I believe (although not deterministic builds), but there's at least a little bit of provenance that you're getting the real repository.


But wasnt claude code leaked? Why wasnt this found earlier?


It doesn't take long for them to vibe code new features for CC


Or vibe code it completely differently. After all, they have basically unlimited access to best models with maximum speed if they just wanted to.


This specific form of steganography was not present when the leak happened, as far as I can tell.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: