Live data from Hacker News

Anthropic’s paper smells like bullshit

djnn.sh

21–30 of 349 posts

Re: Anthropic’s paper smells like bullshit

#22
post #14

This site is hostile to VPNs, so I cannot read this unfortunately.

I’m not even on a vpn and I’m getting an error saying the website is blocked.

One can't be a real infosec influencer unless one blocks every IP range of every hostile nation-state looking to steal valuable research and fill the website with malware

Re: Anthropic’s paper smells like bullshit

#23
Anthropic is not a security vendor.

They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality.

What would the IoCs even be? "Malicious Claude Code API keys"?

The intended audience is more like - AI safety researchers, policy makers, other AI companies, the broader security community understanding capability shifts, etc.

It seems the author pattern-matched "threat intelligence report" and was bothered that it didn't fit their narrow template.

Re: Anthropic’s paper smells like bullshit

#24
Dario has been a reds scare jukebox for a while.Dario has for a year been trying to convince us how open source cCp AI bad and closed source American AI good. Dario driven by the democratic ideals he holds dear has our best interests at heart. Let us all support the banning of cCp's open source AI and welcome Dario's angelic firewall.

Re: Anthropic’s paper smells like bullshit

#25

So Claude will reject 9 out of 10 prompts I give it and lecture me about safety, but somehow it was used for something genuinely malicious? Someone make this make sense.

I've rarely had Claude reject a prompt of mine. What are you prompting for to get a 90% refusal rate?

Re: Anthropic’s paper smells like bullshit

#26
> PoC || GTFO

I agree so much with this. And am so sick of AI labs, who genuinely do have access to some really great engineers, putting stuff out that just doesn't pass the smell test. GPT-5's system card was pathetic. Big-talk of Microsoft doing red-teaming in ill-specified ways, entirely unreproducable. All the labs are "pro-research" but they again-and-again release whitepapers and pump headlines without producing the code and data alongside their claims. This just feeds into the shill-cycle of journalists doing 'research' and finding 'shocking thing AI told me today' and somehow being immune to the normal expectations of burden-of-proof.

Re: Anthropic’s paper smells like bullshit

#27
post #16
post #2

Even Claude thinks the report is bullshit. https://x.com/RnaudBertrand/status/1989636669889560897

The author of the tweet you linked prompted Claude with this: > Read this attached paper from Anthropic on a "AI-orchestrated cyber espionage campaign" they claimed was "conducted by a Chinese state-sponsored group." > Is there any evidence or proof whatsoever in the paper that it was indeed conducted by a Chinese state-sponsored group? Answer by yes or no and then elaborate which has inherent bias indicated to Claud…

> then Claude mostly indulges my perceived bias

I dunno, Claude still seem the same amount of dubious in this instance.

Re: Anthropic’s paper smells like bullshit

#28
When I worked at a FAANG with a "world leading" AI lab (now run by a teenage data labeller) as an SRE/sysadmin I was asked to use a modified version of a foundation model which was steered towards infosec stuff.

We were asked to try and persuade it to help us hack into a mock printer/dodgy linux box.

It helped a little, but it wasn't all that helpful.

but in terms of coordination, I can't see how it would be useful.

the same for claude, you're API is tied to a bankaccount, and vibe coding a command and control system on a very public system seems like a bad choice.

Re: Anthropic’s paper smells like bullshit

#30
post #23

Anthropic is not a security vendor. They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality. What would the IoCs even be? "Malicious Claude Code A…

> What would the IoCs even be?

Prompts.

Post reply on HN