55 pointsby twapi8 hours ago7 comments
  • isodev34 minutes ago
    I don't know why this is flagged, just ran a query on my Mac and indeed, the anthropic extension was deployed for all sorts of (installed and imaginary) chromium browsers.

    I've never seen or approved a prompt from Claude if I want any of this to be installed and I've never seen or approved a prompt from macOS that Claude is asking permission to mess around with other apps (though `Application Support` is probably not protected for non-sandboxed apps).

    I don't think we should normalise or try to diminish the importance of good security practices. Apps that randomly rewrite how other apps your computer work are generally in the category of malware (and here we're not even considering Claude's apparently ability to execute local instructions based on random text it finds online).

  • jimmydoe8 hours ago
    I double Anthropic did this, as apparently people copy this manually and it's still not working :

    https://github.com/anthropics/claude-code/issues/14616

    Of course if they actually did it, without your consent, that's really really bad.

    • durzo222 hours ago
      He proves it in the article and mentions multiple times they are created in launch of Claude for desktop. Why even comment if you didn’t read
  • ibash8 hours ago
    That’s not spyware, that’s just how native messaging is designed to work. You have to put a manifest there if you want the native messaging to work later.
    • tommodev3 hours ago
      Yeah, this. 1password does the same thing for any browser it detects when installed for the native desktop integration from the chrome extension.

      Not 100% across the spec but this wouldn't functionally do anything until you install the related extension? e.g., it's pinned to nominated `allowed_origins`

      • ozlikethewizard2 hours ago
        Yea I guess the issue here is whether you think installing the extenstion should set up the integration or installing the thing being integrated should set up it. Im inclined to think its the extensions responsibility, but I dont think its a severe data issue.
  • SilverElfin4 hours ago
    The later parts of this article listing out the dark patterns and security issues and privacy issues is great. Spyware may not be the right term but there is a lot that is wrong here and Anthropic absolutely should be called out for it. Many people and businesses are trusting what appears to be a mix of vibe coded slop and aggressive anti user growth hacks. So much for Anthropic’s high and mighty moralizing.
  • bpodgursky8 hours ago
    You should not install Claude Desktop or Claude Code unless you trust Anthropic. You either trust them to be a responsible custodian of your compute environment or you don't.

    I mean it almost doesn't matter what is installed at any given time, the agent is going to install stuff you can't realistically observe, the software will auto-update, there is simply no way you can be sure spyware won't end up on your computer.

    • xfactorial8 hours ago
      Having faith on a for-profit organization about doing the right thing, with access to your computer and the things you do on it, may be a bit too much.

      It was always quite a simple thing to do: “disclosure”. Explain me, in plain English, the things you are going to do when I install your software: do not bury it on a 40-page EULA with multiple amendments referring to different aspects that affect me and for which I would probably need a lawyer, or their very service to understand it, and that is of course subject to be changed at any time they feel.

      It’s 2026 and they keep on nagging it: even Apple stopped doing the little summary at the beginning of the “Accept the New Terms” where they explained, in plain English, what those changes were.

      And every time they do that, it is always on their favor: you code and eat pizza, they have a 1000 dollar an hour group of lawyers, ironing the hell out of their legal terms to must accept to use their services.

      • bpodgursky7 hours ago
        I am not telling you what to do, I am saying that Claude Code and Claude Desktop are not "normal" pieces of software that you can install once and choose to upgrade or not. It's a semi-alive agentic daemon. This is not something you can firewall and upgrade once a quarter after reviewing the changelog.
  • _wire_8 hours ago
    [flagged]
  • timfsu8 hours ago
    I might call it a few different things, but spyware seems disingenuous until we learn that it’s actually spying…
    • Trufa8 hours ago
      Yes, very possibly bloatware fits it more, a shit pattern, and very dubious behavior but not necessarily spyware.
    • Nevin19018 hours ago
      But that won't fit the narrative that Antrhopic is an evil company nickel and diming their users...
      • catcowcostume8 hours ago
        As if we needed more evidence to corroborate that.
        • bot4036 hours ago
          I'll stand up and say we do need more evidence of that please.
          • SilverElfin4 hours ago
            Have you seen the near daily complaints about how Claude is getting worse or more expensive? I feel like there have been many recent posts like that, but it’s not limited to just here either. It seems like a lot of people are feeling like Anthropic is at least being not transparent, although many would say deceitful.