logoalt Hacker News

slopinthebagtoday at 3:27 AM8 repliesview on HN

how can they even enforce this? can't you just spoof all your network requests to appear like it's coming from claude code?

in any case Codex is a better SOTA anyways and they let you do this. and if you aren't interested in the best models, Mistral lets you use both Vibe and their API through your vibe subscription api key which is incredible.


Replies

Uehrekatoday at 3:54 AM

> how can they even enforce this?

Many ways, and they’re under no obligation to play fair and tell you which way they’re using at any given time. They’ve said what the rules are, they’ve said they’ll ban you if they catch you.

So let’s say they enforce it by adding an extra nonstandard challenge-response handshake at the beginning of the exchange, which generates a token which they’ll expect on all requests going forward. You decompile the minified JS code, figure out the protocol, try it from your own code but accidentally mess up a small detail (you didn’t realize the nonce has a special suffix). Detected. Banned.

You’ll need a new credit card to open a new account and try again. Better get the protocol right on the first try this time, because debugging is going to get expensive.

Let’s say you get frustrated and post on Twitter about what you know so far. If you share info, they’ll probably see it eventually and change their method. They’ll probably change it once a month anyway and see who they catch that way (and presumably add a minimum Claude Code version needed to reach their servers).

They’ve got hundreds of super smart coders and one of the most powerful AI models, they can do this all day.

show 3 replies
paxystoday at 3:56 AM

Pretty easy to enforce it - rather than make raw queries to the LLM Claude Code can proxy through Anthropic's servers. The server can then enforce query patterns, system prompts and other stuff that outside apps cannot override.

cjpartridgetoday at 4:00 AM

And once all the Claude subscribers move over to Codex subscriptions, I'd bet a large sum that OpenAI will make their own ToS update preventing automated/scripted usage.

baconnertoday at 3:45 AM

They can't catch everything but they can make your product you're building on top of it non viable when it gets popular enough to look for, like they did with opencode.

show 1 reply
tbrownawtoday at 3:54 AM

> how can they even enforce this?

I would think that different tools would probably have different templates for their prompts?

charcircuittoday at 3:47 AM

You could tell by the prompt being used.

techpressiontoday at 5:07 AM

We don’t enforce speed limits, but it sucks when you get caught.

OpenAI will adjust, their investors will not allow money to be lost on ”being nice” forever, not until they’re handsomely paid back at least.