Even Claude thinks the report is bullshit. https://x.com/RnaudBertrand/status/1989636669889560897
Even your own AI model doesn't buy your propaganda Let's not pretend the output of LLMs has any meaningful value when it comes to facts, especially not for recent events.
Anthropic’s paper smells like bullshit
41–50 of 349 posts
Re: Anthropic’s paper smells like bullshit
#42We have arrived at a stage where pseudoscience is enough to convince investors. This is different from 2000, where the tech existed but its growth was overstated.
Tesla could announce a fully-self-flying space car with an Alcubierre drive by 2027 and people would upvote it on X and buy shares.
Re: Anthropic’s paper smells like bullshit
#43Anthropic is not a security vendor. They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality. What would the IoCs even be? "Malicious Claude Code A…
> What would the IoCs even be? Prompts.
There is no way for the AI system to verify whether you are white hat or black hat when you are doing pen-testing if the only task is to pen-test. Since this is not part of a "broader attack" (in the context), there is no "threat".
I don't see how this can be avoided, given that there are legitime uses to every step of this in creating defenses to novel attacks.
Yes, all of this can be done with code and humans as well - but it is the scale and the speed that becomes problematic. It can adjust in real-time to individual targets and does not need as much human intervention / tailoring.
Is this obvious? Yes - but it seems they are trying to raise awareness of an actual use of this in the wild and get people discussing it.
Re: Anthropic’s paper smells like bullshit
#44This site is hostile to VPNs, so I cannot read this unfortunately.
I got a Cloudflare captcha to access a few kb of plain text. Chances are, the captcha itself is heavier than the content behind it. What is the point?
Re: Anthropic’s paper smells like bullshit
#45What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?
Arguably this may change in the far distant future if we ever build something of significantly greater intelligence, or just capability, than a human, but today's AI is struggling to draw clock faces, so not quite there yet...
The thing with automation is that it can be scaled, which I would say favors the attacker, at least at this stage of the arms race - they can launch thousands of hacking/vulnerability attacks against thousands of targets, looking for that one chink in the armor.
I suppose the defenders could do the exact same thing though - use this kind of automation to find their own vulnerabilities before the bad guys do. Not every corporation, and probably extremely few, would have the skills to do this though, so one could imagine some government group (part of DHS?) set up to probe security/vulnerability of US companies, requiring opt-in from the companies perhaps?
Re: Anthropic’s paper smells like bullshit
#46Does Anthropic currently have cybersec people able to provide a standard assessment of the kind the community expects? This could be a corporate move as some people claim, but I wonder if the cause is simply that their talents are currently somewhere else and they don’t have the company structure in place to deliver properly in this matter. (If that is the case they are not then free of blame, it’s just a different c…
Re: Anthropic’s paper smells like bullshit
#47Re: Anthropic’s paper smells like bullshit
#48So Claude will reject 9 out of 10 prompts I give it and lecture me about safety, but somehow it was used for something genuinely malicious? Someone make this make sense.
Re: Anthropic’s paper smells like bullshit
#49Anthropic is not a security vendor. They're an AI research company that detected misuse of their own product. This is like "Microsoft detected people using Excel macros for malware delivery" not "Mandiant publishes APT28 threat intelligence". They aren't trying to help SOCs detect this specific campaign. It's warning an entire industry about a new attack modality. What would the IoCs even be? "Malicious Claude Code A…
If Anthropic is not a security vendor, then they should not make statements like "we detected a highly sophisticated cyber espionage operation conducted by a Chinese state-sponsored" or "represents a fundamental shift in how advanced threat actors use AI" and let the security vendors do that. If the report can be summed up as "they detected misuse of their own product" as you say, then that's closer to a nothingburge…
Anyone acting like they are trying to be anything else is saying more about themselves than they are about Anthropic.
Re: Anthropic’s paper smells like bullshit
#50The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.
[flagged]
Also, plenty of folks with no allegiance would love to pit everyone else against each other.