Earlier quoted context omitted.
> What would the IoCs even be? Prompts.
The prompts aren't the key to the attack, though. They were able to get around guardrails with task decomposition. There is no way for the AI system to verify whether you are white hat or black hat when you are doing pen-testing if the only task is to pen-test. Since this is not part of a "broader attack" (in the context), there is no "threat". I don't see how this can be avoided, given that there are legitime uses t…
Anthropic’s paper smells like bullshit
51–60 of 349 posts
Re: Anthropic’s paper smells like bullshit
#52People grossly underestimate APTs. It is more common than an average IT curious person thinks. I happened to be oncall when one of these guys hacked into Gmail from our infra. It took principal security engineers a few days before they could clearly understand what happened. Multiple zero days, stolen credit cards, massive social campaign to get one of the Google admins click on a funny cat video finally. The investi…
Re: Anthropic’s paper smells like bullshit
#53Instead of accusing of China in espionage perhaps they have to think about why they force their users to use phone numbers to register.
Re: Anthropic’s paper smells like bullshit
#54"Look, is it very likely that Threat Actors are using these Agents with bad intentions, no one is disputing that. But this report does not meet the standard of publishing for serious companies."
Title should have been, "I need more info from Anthropic."
Re: Anthropic’s paper smells like bullshit
#55When I worked at a FAANG with a "world leading" AI lab (now run by a teenage data labeller) as an SRE/sysadmin I was asked to use a modified version of a foundation model which was steered towards infosec stuff. We were asked to try and persuade it to help us hack into a mock printer/dodgy linux box. It helped a little, but it wasn't all that helpful. but in terms of coordination, I can't see how it would be useful.…
Re: Anthropic’s paper smells like bullshit
#56What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?
Re: Anthropic’s paper smells like bullshit
#57Even Claude thinks the report is bullshit. https://x.com/RnaudBertrand/status/1989636669889560897
Even your own AI model doesn't buy your propaganda Let's not pretend the output of LLMs has any meaningful value when it comes to facts, especially not for recent events.