> I don’t trust hosted LLMs for anything that needs to be private
I'd update this to
'I don’t LLMs for anything that needs to be private'
What's to prevent the LLM from sliding a heavily obfuscated binary blob into the application that does nefarious things? If you aren't creating the LLM itself from scratch, I don't feel it can be trusted.
Why do you feel that creating the LLM from scratch is sufficient to trust it? Are you suggesting that you personally would read all 15 trillion tokens (plus every single agentic trade used in RL, along with its relative advantage in the batch) and personally guarantee that gradient descent would train a model which would not exfiltrate your corporate data?
Or that perhaps you have a perfect alignment algorithm which you are unwilling to share with the broader research community (evil)?
> Why do you feel that creating the LLM from scratch is sufficient to trust it
If you're doing the training yourself, you at least have a verifiable supply chain and an audit trail. Today, we have no idea if a black-box model handed to us is coded to recognize specific domains or patterns and back door an application in a sneakily targeted way.
Black box is a black box. Many open-weight models clearly haven't been trained or created in the manner their creators claim---which raises the obvious question: if they lied about the recipe, what else did they lie about? Putting those models in a production capacity scares the living crap out of me.
That said, building from scratch isn't about achieving mathematical perfection or manually auditing 15 trillion tokens---that's impossible. It's about eliminating third-party supply chain risk and having actual governance over the pipeline.
Of course, that doesn't mean we can magically guarantee gradient descent won't produce weird emergent behaviors, or that we can blindly trust OpenAI not to backdoor things. But at least with the latter, you're making a calculated operational decision rather than blindly trusting an opaque black box of entirely unknown provenance.
To be fair - I'd much rather the name be overwrought but clear (once you know or have the decryption key to translate) than to have to look up an even uglier chart that i have ~no chance of memorizing to go 'ok, the Tiberian has X, Y, Z and Q and the Cyrian has Q, Y, but Z is nerfed'
i'm... not sure? This assumes ~stagnation in task-possibility. We've had ~exponential progress for like 3+ years now; I'd have never dreamed the tooling I hammer daily would exist in my lifetime just.. 3? years ago. And it's improving daily.
Maybe Open will win, maybe Closed will keep pushing the envelope. The world here is raw enough i don't think anyone can make any significant claim other than 'holy shit this is useful and moving Fast'.
> to give me a cheaper service that fits my use case?
Because they aren't giving you a cheaper service that fits your use case.
Best Case scenario, it's a trillion-dollar behemoth stealing from a billion-dollar behemoth so they can add their own explicit restrictions/weights on top to influence the masses.
There is no 'robin hood' here, any perceived value you get is clearly and explicitly tainted. "I don't care if it doesn't show me non-party-line results - It makes me a cheap UI !". Ethics/morals be damned.
> There is no 'robin hood' here, any perceived value you get is clearly and explicitly tainted. "I don't care if it doesn't show me non-party-line results - It makes me a cheap UI !". Ethics/morals be damned.
I can't tell if you are talking about Anthropic or Alibaba here.
In a world which already has the likes of Anthropic and OpenAI, having Chinese labs be a counter balance is decidedly better than the hypothetical where American companies had a global monopoly on LLMs.
If your argument is that all present LLM offerings are unethical then that is something I am sypmathetic to. That said, I am also unable to offer a conceivable roadmap to undoing the opening of the LLM Pandora's box so I tend not ground my arguments in anti-LLM advocacy; that would be very 2023 of me.
If you don't think Anthropic and OpenAI are multi-trillion dollar militarized behemoths you need to catch up on some news.
Both are planning $trillion+ IPOs this year. OpenAI is collaborating with the Department of War, and Anthropic is under intense pressure to do the same and their top model is being held hostage right now. This week, the Department of War wrote a statement that xAI should not be held accountable for environmental laws because Grok is a vital weapon system of the US and was used to fire over 2000 missiles at Iran. The pentagon's statement mentions there are 3-4 such models so you may be able to guess which they are.
> You don't trust the multi-billion dollar behemoth, but you trust the militarized multi-trillion dollar behemoth to play 'robin hood'?
Nobody's trusting anyone, we're just enjoying the benefits of true competition much like the working middle class gained benefits between the ideological competition of the Cold War.
Has it been proved in a court of law that it is a copyright violation?
In some cases if the model regurgitates the original material then that is clearly copyright violation, but if the model "learns" from the source material just like a human brain would then that's not a copyright violation.
No, what was proved in court was that they downloaded and trained on millions of pirated books. The court said their use of books is fair use, but stealing them isn't.
I think we're going to see cases that find distillation is also fair use. You're using the competing model like a book. You pay for it, you use it (read it), it informs your model, but you aren't repeating/reselling what the model told you verbatim. Foreign labs may still run afoul of competing labs' Terms of Service, and they may also pay a settlement (or not, it's a different jurisdiction after all), but the damage is already done. Distillation will become uncontroversial when done legally.
it's a 'too big to fail' model. Because they have a big swinging dick all the copyright and other restrictions they violated would nuke them from orbit so we can't actually hold them to account for it .... for some fucking reason.
> Has it been proved in a court of law that it is a copyright violation?
God I'm so tired of this.
The billion dollar companies have the ability to hire an army of lawyers to DDOS the legal system. They at most pay a slap-on-the-wrist fine as the cost of doing business.
I'm extremely pro free markets etc, but the uncomfortable truth is anthropic stole the work of thousands of authors for profit. I think it will end one my favourite things in life: programming books.
If you have ever made a painting and sold it, then you too profited from the work of thousands of artists. How so? Because your sense of what is art came from those who preceded you. You have seen the works of Picasso, Rembrandt, Monet and so on and your brain absorbed from their work, just like an LLM.
If an LLM generalizes from thousands of authors then it is no different from what your brain does.
even if you disregard training costs, pure inference costs are a problem same reason other api have rate limit. this is an attack to bypass the rate limit.
Be careful to properly identify the bad behavior. A customer who buys a product for less money than it cost to produce has not necessarily done anything wrong. They just took advantage of a loss leader. That's on the seller.
Did you notice that when Valve was displeased about scalpers, Valve changed Valve's behavior?
It doesn't seem reasonable to complain that a customer of your AI service received that service for less money than it cost you to provide that service. I don't think that is the complaint here at all. If that was the issue, they could just raise their price.
As most everybody seems to notice, this is just a reenactment of what was once written for comedic effect: "You're trying to kidnap what I have rightfully stolen!"
Still calling it an "attack" feels like a stretch.
They literally had to pay for that "attack", no matter how many accounts they used.
Google was killing many websites for decades with their crawlers. Most large websites decided to create dedicated infrastructure for their traffic alone. Somehow they didn't participate in that cost and were not called the attackers.
They should be. But as the saying goes, one website/company dying is a "tragedy," lots of them dying at the hands of one company is a statistic of corporate growth. Or something like that.
And then of course when the tables turn on a company and they're the ones getting bombarded, they cry foul. Keep in mind Anthropic did many similar things that you mentioned Google did.
I think the term "attack" here is appropriate but not in the way Anthropic is framing it. Alibaba is clearly violating terms to extract data, so that's definitely not above board. But it's not like a DDOS attack where Alibaba is trying to attack Anthropics servers. Alibaba is simply doing exactly what Anthropic did to the rest of the internet, just targeting Anthropic and paying them to do so.
> But it's not like a DDOS attack where Alibaba is trying to attack Anthropics servers. Alibaba is simply doing exactly what Anthropic did to the rest of the internet, just targeting Anthropic and paying them to do so.
Thank you, this is exactly the meritum here.
We faced a mass scale service abuse and licensed intellectual property theft, but we are supposed to defend it because "some of it was not stolen!!1!1"? It is progress, it is amazing, it also is harmful in many ways and pure greed.
This is the mental mental leaps I'm struggling with here. Did you not live through that era where they were explicitly and repeatedly called out as 'attacks'? They were generally tolerated/hardenee around as they provided value-in-discoverability.
I did lived through that era. Outside of people actually working for those companies barely anyone known. For many of us (not working for US dotcoms and other big fish) this was a curiosity we learned fairly recently. Especially on "local" media, papers and socials, this discussion was completely missing. Even today.
Just to ensure you don't gaslight yourself - I did live through that era and I worked on and supported a niche community (a MUD) where we did a lot of work encouraging marketing and discoverability through MUD forums as well as making sure our page was accurately and minimally keyword tagged and highly available for indexers.
In the time since that era search engines have transformed into platforms themselves that do engage in more parasitic behavior but it's important not to assume that the way it is now is how it always was - that's a rather defeatist path to walk down where you ignore awareness of the fact that there can be a highly profitable non-enshittified search engine that supports, rather than destroys, the ecosystem it benefits from.
It was better and, if we're diligent, it can be better again.
Ding. Ding. Ding. "Provided value to the content author". AI scrapping negatively impacts the content author with zero compensation. There is no mutual benefit.
That's violating TOS, spamming, possibly a DDOS, but the distillation in and of itself is not an attack it's just using the model.
Like the difference between scraping a site with one or two active connections vs thousands. It's not the scraping that is an attack, it is how they are going about it
My terms of service are that you are not allowed to breath oxygen.
I am getting a bit tired of companies being able to have user hostile, anticompetitive, monopolistic terms of service. The freedom we give them comes at the cost of the freedom as consumers to have free markets because they lock them up
Illicit means maybe against the law but definitely against the rules, for example an illicit affair. The word for against the law is illegal, from Latin, or unlawful, from Germanic. I guess the Germanic cousin of "illicit" would be "forbidden."
"Licit" in English usage also carries the weight of its connotation in church ("canon") law, wherein it can refer to acts that are considered not only to have occurred spiritually ("valid") according to the law, but have been done in conformity with the process laid out in the law.
For example, canon law asserts that certain sacraments such as marriage or baptism can be conducted validly but illicitly, such that the marriage is still considered to have occurred, but it wasn't done the "right way." In contrast, there are some things that, if done illicitly, aren't valid either. (In this case I think it's because there's a notion that there's a supernatural/spiritual aspect to certain acts that transcends whether they're done licitly, whereas certain other acts are purely creations of human law and therefore if not done licitly are void ab initio.)
Extramarital affairs are against the law in many countries and 17 US states. “Illicit affair” is potentially a holdover from when it was illegal more places, not just a conflating of against the rules with illegality.
Just sending a request to a service does not constitute an "attack". It seems that what Anthropic mean by "fraudulent account" is probably just one violating their terms of service - misuse of a subscription account, and/or the presumed nature of what the user was trying to do.
I guess Anthropoic would regard any developer using their subscription plan with OpenCode to be operating a "fraudulent account", maybe an "attacker" too. Now we know how they think of anyone using Claude to develop software competing with Anthropic. Only an "attacker" would want to vibe code their own harness, or god forbid want to learn how to build/train an LLM.
Of course Anthropic's wording is intended to be deliberately provocative, since they are trying to manipulate the US government into shutting down the Chinese competition.
Is an attempt to copy all or parts of a model an attack, when models have very questionable copyright status? Maybe? I don't think most people have much sympathy here though.
Let’s not forget that by the same logic, Anthropic et al are “attacking” copyright holders all around the world by scraping their data unauthorized for training.
the statement isn't "GLM 5.2 has large token usage", it's "GLM 5.2 has large token usage vs modern Opus".
I haven't used it, but this wouldn't surprise me. I see ~30% lower token usage for better results with Opus 4.8 vs 4.6 (and i had great results with 4.6)
I'm comparing with GPT5.5 on Codex and it's not even a competition. GLM takes way longer and eats a lot of tokens getting work done, it's easy to rack up a big bill on openrouter. I tried the $20 plan from ollama, too, and ate through half a month of budget in a few hours and blew my daily limit twice and still had to get codex to complete it -- which it did with only 10% of my monthly limit remaining.
GLM is promising but it's pretty costly, all things considered.
The real difficulty is deciding what caring means. Some people decide caring means getting onto your adult child's job interview call because you think they need help. For others, caring means giving them a safety net but letting them learn and possibly fail on their own.
I'd update this to
'I don’t LLMs for anything that needs to be private'
What's to prevent the LLM from sliding a heavily obfuscated binary blob into the application that does nefarious things? If you aren't creating the LLM itself from scratch, I don't feel it can be trusted.
reply