Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

The conclusion of this blog post is a bit hysterical. The intent of this steg is excruciatingly clear (identifying usage by Chinese firms that may be conducting model distillation). It's unclear on how this "punishes normal developers" in any shape or form.


So block people, instead of having false positives be secretly fucked over, and having them pay for the pleasure?

Given the hidden model degradation of fable and now this, what makes you think this is where it stops? That's just what we know about and there's clearly a long-standing and deeply rooted malicious intent here.

I've had Claude fuck over clean well documented code-bases for no reason, and there's a good chance this is due to some faulty trigger. Luckily I don't trust these things one bit, and claude only ever runs in an isolated VM, however, I am pissed I am being made to pay for their errors in detection and waste my time fixing things I apparently paid to have fucked up.

That's unacceptable conduct. It's witch-hunting. Punishment and attacks on you for things without real proof. That isn't right.


> So block people

To be fair to Anthropic, [they're trying very hard to do that.](https://www.anthropic.com/news/detecting-and-preventing-dist...). The attacks are sophisticated and difficult to detect. I don't accept that if this fails, their only option is to just accept Chinese companies stealing IP.


They're not "attacks." Anthropic calling them "attacks" doesn't make them attacks. Companies are collecting transcripts of conversations with Anthropic, and giving users a discount to share them.

As many have pointed out, they're collecting data in ways much less aggressive than Anthropic itself about what Anthropic does.

Anthropic doesn't like it, but I don't see this as "Chinese companies stealing IP," any more than if Google tried to ban competitors from seeing how Google Docs or an Android phone behaves, or Ford trying to ban anyone from Toyota from seeing what their car looks like.

Please stop calling them "attacks." It's distillation training. It's looking at what Anthropic does -- as a block box -- and trying to duplicate or beat it. It's how progress happens.


Stealing IP is an attack. You might feel that Anthropic should just give away hundreds of billions in IP and capex, but that's not the way the world works, and I don't agree with you. They're taking enormous risk to build these models. They should be fairly compensated.


What IP is being stolen?

IP is the code and possibly the weights.

No one is stealing IP.

And I don't think anyone in their right mind would argue the AI industry isn't being fairly compensated.

To go further: most people in the world wouldn't feel bad at all if we found a way to slow what's likely the biggest socio-polical-economic change in human history down a bit.


Them strugglig to prevent others from doing what they themsleves do, is my problem to a degree where I must pay for the pleasure to getting sabotaged? Are you fucked in the head? In what world are we "being fair" by claiming that? It takes a problem anthripic has hallucinated, and makes its consequences mine for no reason. Anthropic chose to create both this problem and it's consequences, why am I wearing it?

If I decide I dislike words starting in S, despite myself being a prolific user of words starting in S, and smack some child who'd never even heard the rules, simply for saying "sorry", simply because some people say "shit" and it makes me mad, despite it being my most used word, are we "being fair" by saying "to be fair, managing curse words is a difficult problem"

no right? Insane take.


I don't think they have been caught distilling OpenAI's models. Do you have a link?


So don’t use it!


Correct, and I've stopped. I've moved to deepseek instead, equally capable and not as morally bankrupt as either OAI or anthropic.


It's like "if you don't like it here just move". Not really good advice, doesn't fix anything at all.


> I've had Claude fuck over clean well documented code-bases for no reason

How exactly do you define "fucking over", and why do you suspect this "fucking" was done as a result of a faulty trigger as opposed to the inability of LLMs to write maintainable, extensible code?

"Never attribute to malice what can adequately be explained by stupidity."


Changing well documented requirememts and functioning code to do subtly incorrect things, over multiple areas, for no reason. When confronted you get the usual, "youre right to push back, there was no reason to touch that and it did make everything worse"

Why do I suspect faulty trigger? The things wrecked weren't wrecked by even much less capable, including local models, while reverting everything to pre fucking up and asking claude again led to similar results. Once on whatever shitlist that was, claude also failed tasks it previously aced when given the exact same prompt and project files. I attributed it to opus 4.6 being a downgrade which people always pushed back on, claiming they thought it was better, but i had empirical proof, it couldnt do tasks 4.5- could do quite well. Now all of this? It's clicking all of a sudden that its quite plausible i got flagged somehow and ended up with an intentionally degraded service.

So, claude is off table for me these days, and deepseek gets very deep git commit read-throughs with every file even being read being carefully monitored. This obviously ruins the "agentic" promise, but the reality is we cannot trust these fucks (being the companies). The irony is deepseek now queries claude on problems its stuck on for input via openrouter, with mild success (the gap really isnt all that big, if its even there), before escalating to me for input on direction on solving a given problem. So now chinese models get more claude training data, not less. In fact, they get training data on frontier ML stacks and problems. Anthropic did that to themselves.


If you want to proxy Claude for a legitimate reason, you’ll have potentially nerfed responses.

edit:

Legitimate reasons include:

- analyzing what Claude Code is sending to Anthropic to verify its not exfiltrating data;

- selecting a model dynamically based on prompt difficulty, or enforcing a particular model;

- switching between multiple Anthropic accounts based on the project;

- filtering out credentials, PII and company secrets.

and many more.


Half of those don't actually require proxying Claude. Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow. If you want to select a model dynamically based on the prompt difficulty, Anthropic wants people to use the API for this. It was the whole issue Claude had with OpenClaw.


This forum is called Hacker News. I would expect most users not to limit themselves to using tools precisely how they were intended to be used.


Irrelevant in terms of what sort of usage Anthropic will enforce.


I mean go do it but don't complain about the company adding countermeasures when they don't want you to do it


> Also, Claude has made it apparent time and time again that it does not want people using Claude Code as a "tool" in a workflow.

Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow)

They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.


> Why would Anthropic get to dictate how someone uses a "tool" (that's literally what Claude Code is... a tool in a workflow)

This is a direct conflict in framing. They clearly do not see Claude Code as a "tool in a workflow" but instead as a service that will eventually replace all programmers.

I think the self-evident quality of the various parts of the Claude Code universe is a pretty obvious indicator of the problems with that approach. It is still important to understand a party's thinking if you want to understand their position.

> They're swimming upstream. Trying to maintain a rapidly shrinking moat and not being very creative about it. Making enemies of your users is often a failing strategy.

Time will tell, but I agree that they are indeed in a tough spot. Probably not for the reasons that they think.


I agree, my wording was a bit off. What I meant was a tool call in a harness. Claude Code should itself be the harness.


Why does the Agent SDK or even claude -p exist then?


I guess I can see why they might nerf detected clients server side, but without evidence I would not assume it. Could also be so that 1) they can identify sus client IPs, 2) do a statistical analysis on distilled models to prove that their system prompts were clearly using unique tokens from Anthropic’s API.


False positives, we've seen them before when they degraded Fable silently based on the prompt/session


Why would a Chinese firm distilling the product use Claude code?


They offer (extremely) discounted Claude prices but you have to go through their gateway. They subsidize part of that, and they get the low price by reselling unused Max capacity, there's been a few posts on that in the past months. People are apparently getting 90% discounts on their claude use this way, tradeoff is that you have two companies learning from your data, instead of just one. So people use the same tools they use normally, but get it for a lot cheaper


I'd assume cost? Claude Code plans give like $5,000 worth of API usage for $200/mo.


[the comment was misinformed, deleted]


> Claude Code can decrypt summarized reasoning traces sent by the API.

Can you cite specifically what in the linked article or discussion leads you to say that?


They have some secret sauce not available through API maybe?


To write distillation code, for one thing.


> hysterical. The intent of this steg is excruciatingly clear

Even good goals do not excuse malicious or reckless execution. The ends do not always justify the means.

Whether or not it harmed you this time, it's a violation of trust and autonomy.

Surely you'd be angry if someone secretly installed a rootkit onto your computer, even if--at least for now--it only had code to try to detect and snitch on Public Enemy #1.


What do you see as malicious or reckless here, exactly?

This seems to be a VERY low resolution, functionally anonymous, bit of info, probably related to protecting their IP from bad actors breaking the TOS.

This looks like it's covered in the second bullet point of the "Personal data we automatically receive", that you consented to:

> Usage Information: We collect information about your use of the Services, such as the dates and times of access, browsing history, search, information about the links you click and about third-party applications, services, and content you integrate or interact with, pages you view, and other information about how you use the Services, and technology on the devices you use to access the Services.

What do you see as malicious or reckless here, exactly?

[1] https://www.anthropic.com/privacy


> probably related to protecting their IP

The same IP that is a highly compressed collection of everyone's else's IP?

That's hilarious.


If some other AI company wants a highly compressed collection of everyone else's IP, they can get it by themselves - not from Anthropic pre-compressed =)


Actually, no, I think I'll rather just take it from them.


I don't want my harness doing sneaky stuff like this. I don't want my harness data mining me. I want my harness to implement the agentic loop and I want it to be transparent.


> I don't want my harness doing sneaky stuff like this.

Since when was it your harness?

Switch to pi if this bothers you.



Your harness isn't doing sneaky things unless you're breaking TOS. HN hysteria is unreal.


You may be ok with the harness doing 100 things that are not what I am using it for. But none everyone is, and it’s hardly hysterical. Perhaps you are simply careless.


Is it completely clear to you what the purpose of this is? It isn't completely clear to me but it's very likely it's an issue with me. I feel that it can be part of some larger counteroffensive against certain actors in China in a way that is more than just the signalling here--like maybe there's much more we haven't seen. In any case, it certainly shows their willingness to use less conventional tactics against those they view as adversaries.


> their IP

it's not IP, and it's certainly not their IP

> the TOS

oh no, the terms of service how dare people break those. you don't get to claim fair use while CFAAing everyone's actual IP then whine about the tos, and then when called out on spying on users point to it as if it being in the tos somehow justifies it

a lot of other malware has a tos too but we still call it for what it is


> it's not IP, and it's certainly not their IP

I'm not a lawyer so maybe that is the wrong legal term for a model/service like this. Would you mind telling me the word I should have used?


"model" or "service" would be the term.

basically the point is that it's not protected because it doesn't fall under any classification of IP (it's not copyright or patent since it's mathematical outputs of a mechanical system, it's not trademark because obvious, and it's not a trade secret because it's not a secret)


Are you honestly surprised that roughly 0 HN users read that, or that they are loudly complaining about this, likely without even reading beyond the headline of this post?


> Surely you'd be angry if someone secretly installed a rootkit onto your computer

I surely would. What does that have to do with this scenario.

Note that the SW running on your machine is not doing anything malicious. The service is the thing that behaves in ways you want like - and that service is not running on your device.

There is no comparison with rootkits here. This is the equivalent of Google giving you a CLI to make searches easier, and that tool decides to just Rickroll you randomly. Annoying, yes. A security concern? No.


The article is really quite reasonable and calmly presented, actually. Your claim re. the intent of the fingerprinting is a guess. Normal developers are the users that aren't taking steps to avoid being flagged by this system.

The software is written in a deliberately obtuse way, presumably in service of some (unknown to us) goal. This is a deceptive and anti-social thing to do, it is by nature an adversarial stance to adopt. An already adversarial actor may be "punished" by this, but in such a relationship, hostility can be expected. A non-adversarial actor -- a normal developer / user -- is being harmed by this because the software is treating them as an adversary.

Further, lets assume your guess is correct and, in addition, that Anthropic elects to alter/downgrade/poison their service[0] for users that fit a particular pattern of markers. It's obvious how this system would "punish normal developers" (i.e. not the intended target/victim) that happen to fit those patterns.

[0] to some extent, the service already has been altered as its behaviour depends on the prompt text


> It's unclear on how this "punishes normal developers" in any shape or form.

There are, of course, no normal Chinese developers


> It's unclear on how this "punishes normal developers" in any shape or form

Tons of normal developers use ANTHROPIC_BASE_URL, the flag which activates the malware.


This is a problem of trust towards a software which runs on the user's machine and secretly conducts malware-like stenographic data exfiltration.


Copying over my comment from elsewhere in this post:

Anthopic choosing to delay their models' invevitable distillation by competitors is their prerogative.

That they choose to implement it by fingerprinting my access patterns without first disclosing is where they shit the bed. It isn't "sneaky" it's straight up sneaky (and dishonest and unscrupulous while we're at it). That this particular instance is harmless doesn't give me much comfort. Who's to say they aren't harvesting PII?

That their actions make sense for their business isn't any reason for people to accept their deceitful, customer-hostile decisions.


Does their user agreement say they won't be harvesting PII?


Are you implying that Anthropic lawyers wrote the user agreement to protect users out of the goodness of their hearts? That's how they receive their big fat paychecks? Very funny.

We all know user agreements exist to strip users of their rights and to absolve companies of wrongdoing. We know that corporate apologists here are also well aware of this fact. When user agreements explicitly grant companies the right to screw over users, apologists are quick to make excuses about how it's all standard operating procedure and accuse people of being uncharitable for doing a plain reading of the text [1]. Yet when people are actually screwed over by companies, those very same people blame users for accepting the user agreement. It's a bad faith system.

User agreements are nothing more than power plays by exploitative companies.

[1]: https://hackertimes.com/item?id=47953501


> by fingerprinting my access patterns

It's based on whether your timezone is in China and your hostname matches a blacklist. Literally 2 bits of information. Not much of a fingerprint.


That's what it's based on right now, anyway. What other bits of info will they add as the Chinese work around this spyware?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: