Live data from Hacker News

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

81–90 of 298 posts

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#81

Earlier quoted context omitted.

I'd touch off my nuke to make the world a better place, and I bet you would too, right?

What does it mean to ‘touch off’?

to start a fight or violent activity, or to cause a fire or explosion [1]

1. https://dictionary.cambridge.org/dictionary/english/touch-of...

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#82

I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…

It’s not that this is a crazy reach; it’s actually quite a dumb one.

Too little pay off, way too much risk. That’s your framework for assessing conspiracies.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#84
post #42

It sounds like they directly used Anthropic-hosted compute to do this, and knew that their actions and methods would be exposed to Anthropic? Why not just self-host competitive-enough LLM models, and do their experiments/attacks themselves, without leaking actions and methods so much?

The fact that the cops will show up to a jewelry heist after the diamonds are stolen isn’t a deterrent.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#86
post #53
post #52

I have the feeling that we are still in the early stages of AI adoption, where regulation hasnt fully caught up yet. I can imagine a future where LLMs sit behind KYC identification and automatically report any suspicious user activity to the authorities... I just hope we won’t someday look back on this period with nostalgia :)

Being colored and/or poor is about to get (even) worse

“Colored”?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#87

I might be crazy, but this just feels like a marketing tactic from Anthropic to try and show that their AI can be used in the cybersecurity domain. My question is, how on earth does does Claude Code even "infiltrate" databases or code from one account, based on prompts from a different account? What's more, it's doing this to what are likely enterprise customers ("large tech companies, financial institutions, ... and…

It’s not that this is a crazy reach; it’s actually quite a dumb one. Too little pay off, way too much risk. That’s your framework for assessing conspiracies.

Hyping up Chinese espionage threats? The payoff is a government bailout when the profitability of these AI companies comes under threat. The payoff is huge.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#88
post #77
post #69

This is exactly why I make a huge exception for AI models, when it comes to open source software. I've been a big advocate of open source, spending over $1M to build massive code bases with my team, and giving them away to the public. But this is different. AI agents in the wrong hands are dangerous. The reason these guys were even able to detect this activity, analyze it, ban accounts, etc., is because the models ar…

We should assume sophisticated attackers, AI-enabled or otherwise, as our time with computers goes on, and no longer give leeway to organizations who are unable to secure their systems properly or keep customers safe in the event that they are breached. Decades of warnings from the infosec community have fallen upon the deaf ears of "it doesn't hurt so I'm not going to fix it" of those whose opinions have mattered in…

Would you say the same about all people being responsible for safeguarding their own reputations against reputational attacks at scale, all communities have to protect against advanced persistent threats infiltrating them 24/7, and all people’s immune systems have to protect against designer pathogens by AI-assisted terrorists?

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#89
post #69

This is exactly why I make a huge exception for AI models, when it comes to open source software. I've been a big advocate of open source, spending over $1M to build massive code bases with my team, and giving them away to the public. But this is different. AI agents in the wrong hands are dangerous. The reason these guys were even able to detect this activity, analyze it, ban accounts, etc., is because the models ar…

I don’t think these agents are doing anything a dedicated human couldn’t do, only enabling it at scale. Relying on “not being one of few they focus on” as security is just security as obscurity. You were living on borrowed time anyway.

An, there it is. The stock reply that comes no matter what the criticism of AI is.

I am talking about the international community coming together put COMPETITION aside and start COOPERATING on controlling proliferation of models for malicious AI agents the way the international community SUCCESSFULLY did with chemical weapons and CFCs.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#90
post #45

Earlier quoted context omitted.

"it's not our fault if you misuse the product to commit a crime that's on you" I feel like if guns can get by with this line then Claude certainly can. Where gun manufacturers can be held liable is if they break the law then that can carry forward. So if Claude broke a law then there might be some additional liability associated with this. But providing a tool seems unlikely to be sufficient to be liable in this case…

if anthropic were selling the product and then had no further control your analogy with guns would be accurate here they are the ones loading the gun and pulling the trigger simply because someone asked them to do it nicely

You...do realize Claude is not just a guy sitting in Anthropic's office doing what people on the internet tell him to, right?
Post reply on HN