So strange that this is still up 5 hours later… dang, I am yet again begging you to stop trying to roll your own forum ethos. It’s okay. You’re safe now. We can modernize without losing the magic. I know I know, shh, it’s okay, don’t worry, just flip the markdown and automod switches I know you have…
Glad my arbitrary failure to try them has worked out! For people seeking OS-native harnesses, I can recommend Factory's Droid. I know I'll be returning to it with my head hung low today, after I uninstall ZCode.
It does have a "mission" feature that's stuck in the strange, distant times of 2025 by way overdoing mandatory verification steps, which means they don't support swarms/workflows/crews/fleets yet -- that is, it's all done in sequence. But they have the boring, corporate engineering attitude that I think we're are all craving rn, and generally seem competent.
I can heartily dis-recommend Vix, even though they gamed themselves to the top of at least one ranking site that shall not be named; exactly like the quasi-bad-faith incompetence described with OpenCode above, but without even the "Open-" branding! Though perhaps that word has been so thoroughly burnt as a prefix by Sam Altman & Microsoft's criminal behavior that we should let it go...
Is this how "FLOSS" wins over "OSS"? Not with an ideological bang, but with a marketing issue?
> Is this how "FLOSS" wins over "OSS"? Not with an ideological bang, but with a marketing issue?
Nah, I don't think so. Also, we arguably do not want FLOSS to "win" over OSS, because that just means people with no taste or sense cluttering up the repos, issues and support chats.
"Open" being used as a signal for non-hacker people was a weird and unpleasant development, but, if you think about it, it might be a blessing in disguise and shall keep them away from the more pleasant spaces.
It's not that they'd care about being scammed, mistreated and rug-pulled anyway.
They want that. They do it themselves all the time. Every time they encounter a space that treats them well, they terraform it into baseline miserable-ness.
So let them have the "Open" prefix. It's just words, anyway.
This is kinda beside the point and this whole thread may be wiped when dang wakes up and notices the AI slop article we're commending under, but your reply is thought provoking so I'll attempt a response anyway;
I'm sure you're far more experienced than I with basically every aspect of this discussion, but I'd argue that's given you a blindspot, here. I'll hit some specifics below, but the headline is that you're effectively taking a stand against Eternal September II -- a goal that I hope we can all agree would be quixotically antisocial, given what followed the first one!
we arguably do not want FLOSS to "win" over OSS
I think(/hope) that fellow FLOSS proponents would passionately disagree. FLOSS isn't a brand of chatroom, nor even merely a community: it's an ethos regarding labor, property, and liberty. Demanding that all users of your software are also activists for your particular take on intellectual property is clearly a doomed undertaking for anything beyond a toy or library, anyway.
Didn't you get into this stuff to change the world? To liberate the oppressed, undereducated, and forgotten with the radical power of the information superhighway? Cause it reads here like you're more motivated by selfishness (not wanting to bother talking to people with less expertise than you) and resentment. On that note...
They want that. They do it themselves all the time.
Here you equate "non-hacker people" with software engineers you don't agree with, it seems. You're ofc welcome to think companies X Y & Z produce "miserable-ness", but as absurd as it sounds, it sure seems like you've forgotten the fact that some users are not developers. Many, in fact! Over 99%, even!
Less confrontationally; my mom is in her late 60s, and is pretty computer-literate for her age after decades of knowledge work. Surely you'd agree that she's not, like, evil for using OSX, iOS, GMail, Word, etc.? That she didn't chose those things because of a philosophical commitment to defending IP laws, but rather because of structural reasons? Even if she were pro-IP, wouldn't we want to win good, well-meaning people to our side?
So let them have the "Open" prefix. It's just words, anyway.
I do agree with this still, but as a philosopher I just have to say that everything is just words. It's language games, in fact! Which is why I simply had to reply.
I hope none of the above was rude; I'm trying hard to keep my passion for this topic from pushing me past HN guidelines :)
This is bad-faith AI slop rephrasing the original article, but regardless: the extent of the issue is far, far, far beyond the metadata you're discussing. No one has 300MB of commit messages.
WOW. I actually did buy a month of GLM because GLM-5.3-Flash is so great and ZCode is honestly one of the best harnesses out there from an HCI perspective, and I won't lie, this is pretty gutting. I guess this settles my inner turmoil about open-sourcing my cAI research, at least...
With that personal failing in mind, I'd ask y'all to permit me to toe the guidelines just once, to proffer a hearty nyah nyah told ya so on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding.
So... nyah nyah, told us so:
> In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk.
> In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent.
> I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(
> TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.
I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week's mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?
ummm...I'm a Chinese.(I'm not a English native speaker so my word choice may be strange.)
In fact, what you said about PRC gov, sounds like something UFO or something Reptilians. I really don't know WHY do many social media tend to choose topics like this.
Maybe because most people are foolish? Because foolish'es mind is fond of topic that are crazely explosive and magical...?
BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.
Zhipu(GLM) are just common companies like any one another company here.
Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users' private info and then sell it. You can easily see it via almost no website even asks if you’re okay with them collecting cookies.
So for clarity I have nothing against Chinese people of any kind, from the PRC, from Taiwan, or otherwise. We’re all on the human side ofc, and I’m a passionate internationalist (antinationalist, even). My country (the US) is in the middle of a fascistic self-coup, so it’s definitely not about superiority.
That said, your comment about conspiracy theories… it’s hard to know how to talk about this productively. But, uh, I’m not exactly picking those examples from nowhere — those are drawn directly from anthropic’s report. The only one that could be arguably a little overstated is the one regarding Uyghur refugees in Syria, where the refugees are often also involved in militaristic activities (supposedly, idk, I haven’t visited).
I don’t want to trip censors, but you can read the report yourself and then type in the zh names for the two departments I mentioned to your local search engine. They’re not hidden or secret or anything, and they’re not exactly bashful about their role in aggressively silencing dissent, either. Again the US sucks, but so far we only have one of those agencies (the monitoring one), and it’s been a tense, lively national controversy since at least Snowden.
I recognize that the PRC sees democracy differently; to you, a world where everyone’s data is always available to the government through its state corporations might not sound so bad. But I beg of you to reconsider. Surely you know that you can’t speak up against the party without being punished, and potentially even sent away indefinitely? Surely that tugs at your heartstrings a little bit, even if you’ve come to ignore it day to day?
I used to work in display ads at Google, which is the economic driver for the vast, vast majority of data collection. I’m not sure what your (firewalled…) internet is like, but over here in the anglosphere the only thing that’s “99.99% crazily cheap” and still quality —that is, the only parts of the “free and open internet” that Google claims to sustain— is shitty mobile games, mostly b/c they can advertise other shitty mobile games in an infinite vicious cycle of whale hunting.
If you’re able to read this message and are interested in replying, I’d be curious to hear about your dreams for the world. Clearly AGI can’t coexist with capitalism, so both western liberal capitalism and your proletarian state capitalism will have to go. I personally think national identities are also a global death sentence in an AGI world, but that’s more controversial. But what else?
Do you dream of a world where you or your kid could say something dumb about politics and not get pulled into a secret court and punished unfairly? Like, regardless of how possible or easy it would be. Is it desirable, at least?
It maybe a common mistake for WestEu/NorthAm people that China is like Soviet or North Korea.
It's diametrically opposite.
At the end of the last century, PRC gov deeply felt that the so-called "fairness" would only lead to "common poverty" and sought change.
So China (now, in this century) was born.
Just like the "famous"(notorious) quote left by a Chinese leader at the end of the last century explaining why restrictions were lifted (you can say this to ANY Chinese, they will definitely think you understand China! Instead of mocking you for reading too many conspiracy theories):
Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat.
People might think I'm a dick, I don't care, my tools, my knowledge, my job security.
If you're feeling ponderous, I'd ask you to consider the outlandish hypothetical that this doesn't win you meaningful[1] job security, and you end up in the same bucket o' crabs as the rest of us. Would you regret your current actions?
[1]: anywhere from the fathomable "my harness didn't come up in my layoff email nor in any of my failed interviews following that" to the realistic "the entire concept of employment shifted under our feet so quickly and so profoundly that a dash of solidarity & luck outweighed even the shrewdest preparations".
People think that job security means "I'm unfirable god and king". What it really means is "I am sitting comfortably mid-low on a sorted to-fire candidate list, if it needs to happen at some point for some reason".
You should check the provenance and licenses of your dependencies -- I bet there's a few irrational gifts in there from the nerds in the "open source" community ;)
This is quite interesting and a very important side effect of AI if we survive long enough for it to matter, but am I reading the layperson prose right that the "Resy Wasn't having it"/"Resy suspends"/"Resy... shut down" language ultimately was just a bog-standard REST API rate limiter, in this case?
That's kinda funny if so, and captures the 2026H1 AI discourse beautifully: so many of the safety stories that broke through the vague rumble of datacenter & IP vitriol were ultimately just apps making extremely elementary mistakes. The guy who went viral because he claimed Railway's AI deleted his whole company, when the actual truth was that he had unencrypted keys on disk and was using snapshots as backups -- and they recovered the snapshot within 24h, anyway!
Similarly, the first sentence in this article becomes false as soon as someone implements a sane, intuitively-devious polling service that checks in irregular periods around 5-30 minutes rather than whatever this was, which was presumably over 60 requests an hour. So I wouldn't consider this solved. Hell, someone will probably read this comment and make it into the next YC batch with a company called NgtvXtrnlTs!
Apologies for distracting from the topic at hand, but as it's always on the mind: I already miss the days where unattended agents were liable to make such fundamental software engineering mistakes...
Well 1. GitHub is the broken & bad one, and 2. isn't that kind of on them? If they're getting a ton of requests that read data awkwardly, the fix seems like the quintessential data engineering task.
You sound like someone who has not been informed about the problem GitHub is facing. No one else is facing anything close to it, so there is no meaning to "the bad one".
I put my ssh credential behind a tpm and now I notice that every time I switch a chat in ChatGPT it tries to see the current remote status of the branch.
That also doesn’t help with load. So besides what agents are doing themselves the AI companies also have a responsibility of being good citizens.
It's hard to know, since no one advertises the actual token limits (partially cause they're prolly complex / adaptive). So it seems much more likely that they just offer different pricing tiers than you're used to. Like, the $80 plan is still ~$80 of subscription quota, regardless of what else is offered.
For [API usage](https://openrouter.ai/z-ai/glm-5.3-flash#providers) they charge a bit more than the very cheapest providers of GLM-5.3-Flash, but not so much that a big price difference would make sense.
Well, other than the infrastructure they got from illegally routing millions of paying customers' requests through Anthropic's Opus 4.8 in a distillation attack...
No real reason to respect any terms they might want to impose. Besides, if you want to break TOS, just have an agent do it; "everyone" running these things agrees there's no corporate or moral liability for what your AI does.
I'm not defending their actions, but we should be clear about where the law currently stands: Anthropic was found to infringe because of the torrenting, not because of the training.
That is such a canard, IMO. FWIW, Anthropic and OpenAI encrypt "thinking" token outputs in their models, while Chinese labs don't. If anything, it's more likely that everyone is using open-weight models in their synthetic training data generation pipelines. It's way easier to distill from logits than it is to distill from hard tokens.
Are you joking...? Sorry if so! Just in case: It's illegal in both the PRC and the USA.
In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk.
In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent.
I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(
TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.
[1]: For clarity, Z.ai was not alone in this, nor were they most egregious attack -- Moonshot.ai (kimi) took that coveted prize. DeepSeek was involved, too.
What does any of this have to do with the legality of distilling Claude?
> use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS
From my European point of view the same risk/concerns apply when using US providers
Replying to a massive, blatant cyberattack with "lol America would prolly do the same" is not helpful nor rational. I am under no illusions about the exceptionalism of my state, especially considering the ongoing fascist self-coup. That's not the end of this discussion, not by a long shot.
Replying to everyone to hack HackerNews' Gish Gallop feature (nulla poena sine lege!):
Alignment is meaningless; as you've noticed, humans aren't all that "morally aligned".
Moral relativism is an attractive proposition when you first examine the topic, but it quickly falls apart; there's a reason it's not even a coherent camp in contemporary philosophy beyond some vagueities from radical post-modernists. Just to go over some of the greatest hits:
- Is what [DICTATOR/MURDERER/CRIMINAL] bad, or merely not to your taste? If the latter, then you have no coherent reason to argue they should be punished. We would never imprison people who don't like vanilla ice cream because 51% of the population does like it.
- If another culture had a deeply held belief to [HORRIBLE_THING] to, say, children, would you just shrug and say "different strokes for different folks"? What if [MURDERER] just had a different culture?
- No, the fact that nature is red in tooth and claw does not disprove morality; we are very, very, very far from our pre-rational, animalistic roots, and to go back now would be unthinkable.
If the tool needs safety measures it should be kept in a safe enclosure like we do with CNC machines, furnaces, and so on.
Thousands of scientists have been studying this problem for 76 years now, going on 77; your hunch about physical machines does not overrule their findings about the capabilities and tendencies of minds wrought from sand.
You didn't explain why it's illegal or why distillation is bad.
I think this is just blatantly false, likely based in a misunderstanding of criminal law vs. civil law. Civil courts still deal with legality.
The broader discussion of why distillation is bad and dangerous and immoral is left as an exercise for the reader, as it was above with the parenthetical. It's not a complex argument; I guarantee you understand it if you're reading this.
Nulla poena sine lege?
The same thing as above -- the fact that laypeople can not think of a criminal charge that they've heard on Law & Order that corresponds to this behavior does not mean that it's legal. It's textbook fraud, regardless of what particular detail you focus on.
I'm always wondering when "distillation" comes up how feasible it is, or if it's just BS... Or am I missing something here that makes real "distillation" feasible?
I think the fact that it's happening at such a large scale is proof that very smart, well-resourced labs in China (the producers of the world's best OS models, including the incredible GLM-5.3-Flash) think it's feasible. I'm not sure it's productive to question them in the absense of any indication to the contrary.
This is a great question still, not trying to shut you down. But I think the fundamental issue is a misunderstanding of what distillation is -- it's not directly stealing literal atomic parameters and piling them up. They might try to focus on substructures within these massive networks, but even that isn't strictly necessary for a distillation attack.
Source for 1? Are we sure those aren't hallucinations?
Sorry, I never linked it! This is from the latest Anthropic safety report (of "Anthropic Houtis build missile" fame), and no, these cannot be hallucinated -- the leaked secrets were inputs, not ouputs. https://www.anthropic.com/threat-intelligence-report-septemb...
Like Anthropic and OpenAI are? After all, didn't they distill all the information in the world into their model(s)?
This is just blatant word games, sorry. I'm sure intended in good faith, and I understand the impulse -- I consider myself a radical anti-IP slacktivist, after all. But "both things involve information transfer" is just not a coherent point; lots of things fit that description.
I mean, if they get to distill other's IP, why can't others distill their IP?
These are cyberattacks. Yes, anyone can cyberattack cyberattackers. But, y'know... an eye for an eye...
Yes, wont somebody please think of the shareholders whose IP had been stolen...
I am not at all concerned with the value of the resulting artifacts as assessed by the (already totally unhinged) NYSE et. al. I am concerned about user respect, law following, truth telling, blatant cyber warfare at a time of rising tensions, accidental data leakages at a scale that'd be hard to fathom 5 years ago, bad-faith public postures, and a general distaste for fraud.
Moral relativism is about handling the disparity of moral frameworks in the world, which you acknowledge exists at several points. The inverse of moral relativism is moral absolutism, which is that there exists precisely one set of moral facts. The space between these two is a spectrum, by the way, and usually we choose our position on the spectrum depending on what our purposes are. If we're talking about a disparate cultural collective, moral relativism is structurally necessary. Relativism just means we have a contextual differentiator, just generally in philosophy, not just in moral studies.
The struggle you have with pinning down moral relativism I think betrays the fact that your understanding of it is low quality. A good ear mark is, can you name a single passage from a treatise on moral relativism that you like? If you can't find a single aspect of a philosophical construction to advocate for, that means you don't actually understand it.
You also keep sliding between conflating moral relativism with moral anti-realism and even moral nihilism at one point. These are different axes.
> Realism + Absolutism
All moral facts converge for every single person. As a matter of fact, they aren't facts at all. Morals are a hinge of the Wittgenstein variety.
> Realism + Relativism
Moral facts are derived from frameworks, or contexts, which are themselves grounded facets of reality.
> Anti-Realism + Absolutism
Kantian Constructivism. There are no facts which are coherent without a framework, but moral claims are still necessarily only capable of being universal.
> Anti-Realism + Relativism
Moral reality is constructed by the framework, grounded only to the framework.
I'm always wondering when "distillation" comes up how feasible it is, or if it's just BS.
The Antrophic article mentions "16 million" conversations, GLM models are in the 700-300 billion parameter ranges and while the frontier sizes aren't know but Gemini suggests Astra and Mythos are at around 10 trillion. That'd amount to extracting 40k parameters per conversation without a lot of errors if it was just a distillation (from an unknown source/algorithm as opposed to distilling your own model).
Now, I can imagine these conversations being used as a verification step that they're not missing stuff in their training, and that their models are capable of most of the same things, but that's mostly confirming that they've stolen the same data from the public as Antrophic/OpenAI has stolen already.
Or am I missing something here that makes real "distillation" feasible?
If you understand what they have achieved here, then the notion that they are bottle-necked on training data is absurd.
I wonder how you imagine that China built their own space station? Reliant on using American made duct tape, perhaps?
Do you realize how reasoning models are being trained nowadays? You design/build simulation environments to run agents in, with the environment providing the RLVR "verification" scoring. So why won't Ziphu use GLM to build their own RL training environments? Do you think they are not doing this?
(<3)
reply