Live data from Hacker News

Anthropic’s paper smells like bullshit

djnn.sh

41–50 of 349 posts

Re: Anthropic’s paper smells like bullshit

#41
post #3
post #2

Even Claude thinks the report is bullshit. https://x.com/RnaudBertrand/status/1989636669889560897

Even your own AI model doesn't buy your propaganda Let's not pretend the output of LLMs has any meaningful value when it comes to facts, especially not for recent events.

Even if this assertion about LLMs is true, your response does not address the real issue. Where is the evidence?

Re: Anthropic’s paper smells like bullshit

#42
This is an excellent article. Anthropic's "paper" is just rambling slop without any details that inserts the word "Claude" 50 times.

We have arrived at a stage where pseudoscience is enough to convince investors. This is different from 2000, where the tech existed but its growth was overstated.

Tesla could announce a fully-self-flying space car with an Alcubierre drive by 2027 and people would upvote it on X and buy shares.

Re: Anthropic’s paper smells like bullshit

#43
post #23

Anthropic is not a security vendor. They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality. What would the IoCs even be? "Malicious Claude Code A…

> What would the IoCs even be? Prompts.

The prompts aren't the key to the attack, though. They were able to get around guardrails with task decomposition.

There is no way for the AI system to verify whether you are white hat or black hat when you are doing pen-testing if the only task is to pen-test. Since this is not part of a "broader attack" (in the context), there is no "threat".

I don't see how this can be avoided, given that there are legitime uses to every step of this in creating defenses to novel attacks.

Yes, all of this can be done with code and humans as well - but it is the scale and the speed that becomes problematic. It can adjust in real-time to individual targets and does not need as much human intervention / tailoring.

Is this obvious? Yes - but it seems they are trying to raise awareness of an actual use of this in the wild and get people discussing it.

Re: Anthropic’s paper smells like bullshit

#44

This site is hostile to VPNs, so I cannot read this unfortunately.

I got a Cloudflare captcha to access a few kb of plain text. Chances are, the captcha itself is heavier than the content behind it. What is the point?

The point is to have Cloudflare serve the few KB of cached content instead of the original server.

Re: Anthropic’s paper smells like bullshit

#45

What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?

At the end of the day AI at any level of capability is just automation - the machine doing something instead of a person.

Arguably this may change in the far distant future if we ever build something of significantly greater intelligence, or just capability, than a human, but today's AI is struggling to draw clock faces, so not quite there yet...

The thing with automation is that it can be scaled, which I would say favors the attacker, at least at this stage of the arms race - they can launch thousands of hacking/vulnerability attacks against thousands of targets, looking for that one chink in the armor.

I suppose the defenders could do the exact same thing though - use this kind of automation to find their own vulnerabilities before the bad guys do. Not every corporation, and probably extremely few, would have the skills to do this though, so one could imagine some government group (part of DHS?) set up to probe security/vulnerability of US companies, requiring opt-in from the companies perhaps?

Re: Anthropic’s paper smells like bullshit

#46

Does Anthropic currently have cybersec people able to provide a standard assessment of the kind the community expects? This could be a corporate move as some people claim, but I wonder if the cause is simply that their talents are currently somewhere else and they don’t have the company structure in place to deliver properly in this matter. (If that is the case they are not then free of blame, it’s just a different c…

I throw Anthropic under the bus a lot for their lack of engineering acumen. If they don't have a core competency like engineering fully covered, I'd say there's a near 0% chance they have something like security covered.

Re: Anthropic’s paper smells like bullshit

#47
I was at an AI/cybersecurity conference recently and the talk given by someone from Anthropic was a lot like this report: tantalizing, vague, and disappointing. The speaker alluded to similar parts of this report. It was though everything was reflected through Claude, simultaneously polished, impressive, and lost in the deep end.

Re: Anthropic’s paper smells like bullshit

#48

So Claude will reject 9 out of 10 prompts I give it and lecture me about safety, but somehow it was used for something genuinely malicious? Someone make this make sense.

I've never had a prompt rejected by Claude. What kind of prompts are you sending where "9 out of 10" get rejected?

Re: Anthropic’s paper smells like bullshit

#49
post #34
post #23

Anthropic is not a security vendor. They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality. What would the IoCs even be? "Malicious Claude Code A…

If Anthropic is not a security vendor, then they should not make statements like "we detected a highly sophisticated cyber espionage operation conducted by a Chinese state-sponsored" or "represents a fundamental shift in how advanced threat actors use AI" and let the security vendors do that. If the report can be summed up as "they detected misuse of their own product" as you say, then that's closer to a nothingburge…

That makes no sense. Just because they aren't a security vendor doesn't mean they don't have useful information to share. Nor does it mean they shouldn't share it. They aren't pretending to be a security researcher, vendor, or anything else than AI researchers. They reported on findings on how their product is getting used.

Anyone acting like they are trying to be anything else is saying more about themselves than they are about Anthropic.

Re: Anthropic’s paper smells like bullshit

#50
post #20

The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.

[flagged]

‘No true Scotsman’?

Also, plenty of folks with no allegiance would love to pit everyone else against each other.

Post reply on HN