Hacker Newsnew | past | comments | ask | show | jobs | submit | pczy's commentslogin

Exactly, compare banning books to banning guns.


This policy applies across all providers. Here is the warning in Cursor: https://i.redd.it/7sfyker2ya6h1.png

Note that Anthropic has committed not to train models on logged data, so I don’t understand some of the concerns here. What exactly is your threat model? That Anthropic would train models contrary to their terms of service? That you trust them enough not to log your data prior to this, but not enough to trust their stated limits on how logged data will be used now?

Edit: I am partially convinced by some of the replies. However, it is worth noting that this change primarily affects Enterprise users. Data from consumer plans is already retained for 30 days. Source: https://privacy.claude.com/en/articles/10023548-how-long-do-...


> you trust them enough not to log your data prior to this, but not enough to trust their stated limits on how logged data will be used now

It doesn't really matter how much you happen trust another party. In the regulatory world it only matters what contracts they will sign that guarantee their compliance. We do have those with AWS, we don't with Anthropic. If Anthropic physically captures the data, they just moved themselves outside the boundary of parties who we can do business with. Unless they want to sign a contract and implement all the corresponding compliance measures. They are insane if they think that's a good deal for them to do all that right now in every jurisdiction where AWS operates, when AWS has already spent a decade building it up.


It will absolutely cause some non-trivial number of customers to shift their configs away from Anthropic.


It's worthwhile to remember that this is only true of Mythos/Fable and other future models of "similar or higher capability levels" (ant is treating this as a new tier of model above Opus). Anyone who's already been happy using Haiku/Sonnet/Opus on Bedrock will not be affected by this at all.


Yes and no. Anthropic controls what is determined to be "similar or higher" and when models are deprecated. Will sonnet 4.7 be "too powerful"? Because once it's released. 4.6's days are numbered.

This created a huge future risk for our org and we're already scheduling meetings over it. Regulated industry, we can't lose control over our data governance or residency controls, let alone the lack of visible audit trails that could reveal customer or PII.

Just an absolute bomb of a release


+1 to other commenters here. * They forced Bedrock for instance to change the existing settings for ZDR / ZOA. It used to be enough to have a default. Now we must set to 'none' and pray it does what it says. * And then there is that BS about "contact your account manager, we will decide account/model retention and sharing individually" Just this creates so much uncertainty that Bedrock has become "glowing in the dark". * We have already moved everything to Gemini on Vertex.

PS: this is what you should see as an error from Bedrock. Anything else is not enough today: "AWS Bedrock Error: An error occurred (ValidationException) when calling the ConverseStream operation: The model returned the following errors: data retention mode 'none' is not available for this model"


>Anyone who's already been happy using Haiku/Sonnet/Opus on Bedrock will not be affected by this at all

It is still adding operational overhead because we now need to vet all models and deny access to any retaining data

Previously it was "use and experiment with anything Bedrock offers--the data stays in AWS so we are not concerned"


So basically all models going forward?

I don't think anyone currently thinks the Haiku/Sonnet/Opus models are "good enough" such that they would not want improvements. Users may be cost conscious, but almost every task could be done better.


Which will work for the several weeks it takes for the other commercial providers to follow suit.

The tides are turning. AI companies are IPO'ing. They've gotten where they are by selling $5 bills for $1, to update the old VC adage. I think we can look forward to them rewriting the contracts, both literal and social, on AI going forward to capture a lot more of the value. Or, to put it in more HN-friendly terms, it may not be immediately obvious on a casual viewing, but you're looking at the beginning of the enshittification process hitting AI. The term is a bit deceptive in some sense, because it's not like anyone ever sets out with a terminal goal of making something shitty. It's downstream of trying to capture more value in the customer/vendor relationship by not giving the customer any more value than is barely necessary.

How's coding with qwen doing? The only thing that's going to stop the AI providers from extracting all the value until it's just barely worth using is the free competition.


Bedrock supports many models. Open weights models aren't far behind, maybe a year, 18 months.

Given they could have done this with data residency rules being respected and chose not to suggests all I need to know - this is for Anthropics IPO, not for user safety


>Open weights models aren't far behind, maybe a year, 18 months.

No, open weights are always a year behind +. By the time that year passes Anthropic/OpenAI/Google will have some new model that is ahead of the open models by a year.

Looking at computer security for the last 30 years, no one gives a fuck about user safety. Companies care about profits, and individuals don't care enough for strong laws.

We'll be back here in another year on HN talking about why we should give our retina sample and blood to Anthropic to use the model with a ton of people doing it. It's just the way humans are.


Surely some provider will see the then open opportunity and offer something to capture it.


You’re underestimating how much companies are willing to bend over backwards if they can “get ahead with a god model” compared to their competitors.


No, I'm not. Yes, those companies exist. And, so do many companies on the other end. Where they bend over backwards to ensure their data only lands in places where they have the exact contractual language they want. Any stodgy F500 typically falls in that category. They would not likely be using Anthropic through the AWS "bridge" in the first place if they were chasing latest/greatest.


> Note that Anthropic has committed not to train models on logged data, so I don’t understand some of the concerns here. What exactly is your threat model? That

Like Meta had committed to respect your privacy. Replace the name of the company with any of the top 50 companies in the world and go back how many have hold their promises - or just doing fine when breaking the rules. There is no legislation in the U.S. that can bankrupt the company for violating this? So there are no guarantees.

Meta openly torrented books and nobody asked them to remove/destroy their AI models. Similarly, for Anthropic, it was just a business cost. They were allowed to keep the models. No real consequences for breaking the rules.


It adds another provider that you have to trust with your data. Previously the assumption is that AWS was securely handling your data and you may have the data on AWS to start with anyways. Now you have two providers handling your data which doubles your risk if you trust them equally. If you think AWS has more robust data controls than Anthropic then it more than doubles your risk.

You may also have data management requirements such as allowed storage and transit countries as well as various certifications and contracts that you now need to extend to the second data processor.

Basically if you are already using AWS just adding the AWS-only bedrock model is legally easy and doesn't really change your security posture. If you need to now also log your data to Anthropic it makes the choice much more complicated.


Both can be true simultaneously. Anthropic can probably be trusted not to train on our Fable sessions, but eroding ZDR as the industry standard still sets a dangerous precedent.

There's a parallel between data retention and general mass surveillance. Sure, both systems can be used for purely benign purposes, with appropriate safeguards in place. But history shows that surveillance systems are alarmingly easy to co-opt for nefarious means, and model providers do have a heck of an incentive to leverage retained data for internal means.

This is worth protesting, even if I believe this policy itself does not immediately compromise my privacy.


> Note that Anthropic has committed not to train models on logged data, so I don’t understand some of the concerns here. What exactly is your threat model? That Anthropic would train models contrary to their terms of service? That you trust them enough not to log your data prior to this, but not enough to trust their stated limits on how logged data will be used now?

It is a different thing when they say they don't store your data.

And when they say they store your data for 30 days and review it for "issues", it makes your "spider sense" tingle. Who and how will review it, what are the "issues" they are looking for, etc. It is to vague and they can keep it this "dangerous" model for themselves.


Someone has never dealt with HIPAA laws and it shows.


Who out there is going to be feeding patient medical data to Mythos/Fable?


Whoever Anthropic can convince, to help them form a competitor to OpenEvidence, who already feed patient medical data into their systems.


...the same groups who are currently feeding it to Sonnet and Opus?

Well, they won't be feeding it to Fable unless Anthropic can provide a signed BAA.


Once you start storing anything, whether credit card numbers or AI inputs, then there is possibility (if not in fact probability) that you'll be hacked and it will leak.

Given Anthropic's failure to secure their own source code, do you really trust them to secure yours?


We shipped software to governments and some big companies where this is a big no-no. Try to explain to your clients that during the development process some pieces were sent to Antrophic, and they might keep it for whatever reasons.


here's how they train on your data:

an inference request comes in

claude fable RESTful API service does the stuff, some backend systems run the prefill and batch decode, and your conversation is cached for 5 minutes in some prefix cache.

the request is also sent to claude paraphraser, which does almost exactly the same thing as the compactor and rewrites your conversation.

then they record the paraphrased conversation and train on that. it keeps the salient parts of the conversation, like whatever internal knowledge you have, and disposes of anything that could have been correlated with the earlier conversation, which is easy to do because verification is a string comparison.


> Note that Anthropic has committed not to train models on logged data, so I don’t understand some of the concerns here. What exactly is your threat model?

First of all, will they respect that promise in the future? Because, you know… they already received your data and by some legal quirks they are already required to store it for so many years. “What’s your threat model”, uhh, sending confidential information to a third party.

It’s okay if you do this with your own personal property. But if you are working on client projects, what, are you going to start shipping customer data under nda without consent? Good luck in the court.


They are not blacklisted. You are allowed to use the API at commercial usage pricing. You are just not allowed to use your Claude Code subscription with OpenCode (or any other third‑party harness for the record).


I have my own harness I wrap Claude CLI in, I wonder if I'm breaking the rules...


If you're not paying full-fat API prices, then probably.

From what I've heard, the metrics used by Anthropic to detect unauthorized clients is pretty easy to sidestep if you look at the existing solutions out there. Better than getting your account banned.


No, they specifically said it’s only if you’re trying to build a whole other product for public consumption on top of it


If you’re just essentially calling claude -p you’re fine


Sometimes people want to be real pedants about licensing terms when it comes to OSS, assuming such terms are completely bulletproof, other times people don't think the terms of their agreement with a service provider should have any force at all.


Has it occurred to anyone that Anthropic highest in the industry API pricing is a play to drive you into their subscription? For the lock-in?


The highest in in the industry for API pricing right now is GPT-5.4-Pro, OpenRouter adding that as an option in their Auto Router was when I had to go customise the routing settings because it was not even close to providing $30/m input tokens and $180/m output tokens of value (for context Opus 4.6 is $5/m input and $25/m output)

(Ok, technically o1-pro is even more expensive, but I'm assuming that's a "please move on" pricing)


I dont understand this, what is the difference, technically!


With Anthropic, you either pay per token with an API key (expensive), or use their subscription, but only with the tools that they provide you - Claude, Claude Cowork and Claude Code (both GUI and CLI variants). Individuals generally get to use the subscriptions, companies, especially the ones building services on top of their models, are expected to pay per token. Same applies to various third party tools.

The belief is that the subscriptions are subsidized by them (or just heavily cut into profit margins) so for whatever reason they're trying to maintain control over the harness - maybe to gather more usage analytics and gain an edge over competitors and improve their models better to work with it, or perhaps to route certain requests to Haiku or Sonnet instead of using Opus for everything, to cut down on the compute.

Given the ample usage limits, I personally just use Claude Code now with their 100 USD per month subscription because it gives me the best value - kind of sucks that they won't support other harnesses though (especially custom GUIs for managing parallel tasks/projects). OpenCode never worked well for me on Windows though, also used Codex and Gemini CLI.


>or perhaps to route certain requests to Haiku or Sonnet instead of using Opus for everything, to cut down on the compute

You can point Claude Code at a local inference server (e.g. llama.cpp, vLLM) and see which model names it sends each request to. It's not hard to do a MITM against it either. Claude Code does send some requests to Haiku, but not the ones you're making with whatever model you have it set to - these are tool result processing requests, conversation summary / title generation requests, etc - low complexity background stuff.

Now, Anthropic could simply take requests to their Opus model and internally route them to Sonnet on the server side, but then it wouldn't really matter which harness was used or what the client requests anyway, as this would be happening server-side.


Sounds pretty sane, the same way how OpenWebUI and probably other software out there also has a concept of “tool models”, something you use for all the lower priority stuff.

Actually curious to hear what others think about why Anthropic is so set on disallowing 3rd party tools on subscriptions.


The sota models are largely undifferentiated from each other in performance right now. And it’s possible open weight models will get “good enough” relatively soonish. This creates a classic case where inference becomes a commodity. Commodities have very low margins. Training puts them in an economic hole where low margins will kill them.

So they have to move up the stack to higher margin business solutions. Which is why they offer subsidized subscription plans in the first place. It’s a marketing cost. But they want those marketing dollars to drive up the stack not commodity inference use cases.


Anthropic's model deployments for Claude Code are likely optimized for Claude Code. I wouldn't be surprised if they had optimizations like sharing of system prompt KV-cache across users, or a speculative execution model specifically fine-tuned for the way Claude Code does tool calls.

When setting your token limits, their economics calculations likely assume that those optimizations are going to work. If you're using a different agent, you're basically underpaying for your tokens.


- OR - it's about lock-in.

Build the single pane of glass everyone uses. Offer it under cost. Salt the earth and kill everything else that moves.

Nobody can afford to run alternative interfaces, so they die. This game is as old as time. Remember Reddit apps? Alternative Twitter clients?

In a few years, CC will be the only survivor and viable option.

It also kneecaps attempts to distill Opus.


It’s probably a mixture of things including direct control over how the api is called and used as pointed out above and giving a discount for using their ecosystem. They are in fact a business so it should not surprise anyone they act as one.


It might well be a mixture, but 95% of that mixture is vendor lock in. Same reason they don't support AGENTS.md, they want to add friction in switching.


They can try add as much as friction they want. A simple rename in the files and directories like .claude makes the thing work to move out of CC.

It’s not like moving from android to iOS.


You'd be surprised how effective small bits of friction are.


If it was lock in they wouldn't make it absolutely trivial to change inference providers in Claude Code.


The goal is to use Anthropic subscriptions outside of Claude Code!! That is the lock in.


It's very straightforward to instrument CC under tmux with send-keys and capturep. You could easily use that for distillation, IMO. There are also detailed I/O logs.


Subscription = token that requires refreshing 1-2x/day, and you get the freedom to use your subscription-level usage amount any way you want.

API = way more expensive, allowed to use on your terms without anthropic hindering you.


Also, Subscription: against the TOS of Claude Code, need to spoof a token and possibly get banned due to it.


Yup. And right now I'm straight-up breaking Claude's TOS by modifying OpenCode to still accept tokens. But I only have a few days left and don't care if they ban me. I'm using what I paid for.


Anthropic has an API, you can use any client but they charge per input/output/cache token.

One-price-per-month subscriptions (Claude Code Pro/MAX @ $20/$100/$200 a month) use a different authentication mechanism, OAUTH. The useful difference is you get a lot more inference than you can for the same cost using the API but they require you to use Claude Code as a client.

Some clients have made it simple to use your subscription key with them and they are getting cease and desist letters.


about 30 times more cost


Was it not obvious what the OP meant by blacklisted?


Blacklisted usually means something is banned. OpenCode is not banned from using Anthropic's API.


No, it was not? For those whose native language is English, "blacklisted" implies Claude API will not allow OpenCode.


API will, they just can spoof Claude Code OAUTH credentials


Even being non-American with my necessarily flawed understanding of the US constitution, the scenario you described strikes me as a clear violation of the first amendment. First, you would have to compel someone to write new code that changes the way bitcoin fundamentally works. Assuming you manage to do so, you would then have to compel "everyone" to recognise the hard-fork as the "true" chain, again something clearly at odds with the first amendment, and I suspect the laws in many other jurisdictions as well (for obvious reasons).


It wouldn't violate the First Amendment, since the court isn't going to be a government actor for that purpose. A court absolutely could order someone to change their code to comport with the judgement--I mean, this happened to Apple in the not-too-distant past. What the court can't do is compel everybody to use the new hard fork, first for the simple reason that most of those people aren't being sued, but somewhat more fundamentally for the reason that it doesn't really remedy any judicially-cognizable harm. (That said, it's similarly hard to envision a scenario where the court orders someone to modify Bitcoin's code, especially if you're talking about something that retroactively adjusts balances).


Miners investing hundred millions dollars into operation. If court will tell them, like for example 3 biggest miners from US to make that block, they will do it to protect investment, because other way they will get sanctions from gov. Other people on non-mining nodes can fork it, but noone with millions dollars at stake will be on forked chain and only miners make blocks. Court will not be stupid and believe, that such move is legal way to disobey court.


That isn't how Bitcoin works. Miners can't violate the protocol, since the protocol decides what is and isn't mining.

Wright wants a version of Bitcoin created with a backdoor to transaction authentication that lets him take coins without presenting the required credentials. If he created such a version and convinced some miners to run it, they'd simply stop producing blocks (at least from the perspective of anyone who didn't also adopt his backdoor).

So the situation you imagine would just result in hashrate going down-- which can be a bit of an an annoyance since it slows down transaction settlement temporarily, but isn't a dire issue (e.g. Bitcoin lost on the order of half its hash power for a while after china issued a ban).

In any case, if Wright shared your theory and was acting in good faith the target of his actions would be miners and not volunteer open source developers. He's stated outright in public that he expects the ruinous cost of his litigation to destroy the lives of his targets.


We will see how courts will decide. Right now it's just a presumptions on how things can roll out.


What is a presumption? The targets and content of Wright's lawsuit are not presumptions.

The nature of Bitcoin's operation is not a presumption-- the code is open and anyone is free to go look at how it works.


In the apple case you're referring to the government dropped its case after Apple argued that the government's demand constituted unconstitutional compelled speech.

In the united states the courts only have power at the pleasure of the constitution, the constitution is binding on all actions of a court. (Now, the courts could conclude some action doesn't violate the constitution-- but that's a different matter)

Except in some narrow cases in civil matters US courts do not order specific performance -- they don't order you to perform some specific act -- instead, the award cash damages for the harm you caused the other party.

In the ninth circuit where I reside, the standing, unchallenged, and unambiguous law that the publication of source code is speech protected by the first amending as was established in Bernstein v. US.

This is also recognized by the long line of modern decisions with respect to defamation law-- it cannot be so overpowered that it abridges the publics free speech rights, even though defamation is always a civil matter.

If you adopt an interpretation that the remedies available to the courts aren't constrained by the constitution, then any imaginable abrogation of the civil rights of the public could be lawfully imposed by simply creating a civil cause of action with the otherwise unconstitutional action as a remedy, then the state can induce some private actor to take action under the law. (The idea that Wright is acting on behalf of some state actor out to undermine Bitcoin is a common conspiracy theory, but a less parsimonious explanation than him being a simple con-artist.)

You're absolutely right that Wright's demand would also require that everyone adopt the alternative version and regard it as Bitcoin--- which is akin to expecting everyone to start believing he's a good guy, something no conceivable court could order because no court can never have power over the hearts of mankind (short of someone inventing a mind control gun :P ). It also has the practical problem that many of the defendants, such as myself, haven't been Bitcoin developers for years. And defendants, even the active ones, have no more ability to take action here that Wright himself does-- it's open source software, after all--, except for the fact that the defendants have a good reputation and Wright has a reputation as a fraud.

But to even get that far wright would also need to overcome the civil rights problems with his request-- at least for the US defendants: Wright is asking the government to compel labor to author the backdoored itself, compel speech by making the defendants publish it, and restrain their speech by prohibiting them from publishing non-backdoored code. He also would have to overcome the fact that the license they offered the software under expressly requires the recipient wave liability for any cause in connection with the software. (and the fact that his claimed loss is pretty obviously nonsense)

He also has to overcome a number of procedural issues, including the fact that the lawsuit was brought in the UK by an insolvent foreign shell corporation itself owned by a web of other insolvent shell companies in different jurisdictions -- none of whom operate in the UK against developers none of whom do business in the UK. Wright prefers the UK because of its motion-by-motion loser-pays default that lets Wright extract enormous legal fees by defeating summary judgement motions by offering forgeries (summary judgements are decided by assuming the facts are in the favor of the non-movant), as well as the weak protection for people's free speech rights. Wright's hail mary to try to keep in in the jurisdiction of the UK courts is to include one of his own entities as a defendant, and of course they immediately agreed to the jurisdiction.


This kind of thing happens all the time under the guise of national security.


As far as I'm aware, the arbitrage mechanism works both ways. Continuing your analogy, authorized participants are able to trade the underlying turkeys for new tokens, or redeem the tokens for turkeys. When the price of a token is bidded up, its price becomes attractive relative to the turkeys. Authorized participants buy the underlying turkeys, create new tokens and then sell those tokens to take a risk free profit. This continues as long as there is a price mismatch, and ensures that ETF prices are in sync with the underlying assets.


This is the best explanation of this issue that i know of: https://www.2uo.de/myths-about-urandom


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: