Live data from Hacker News

Anthropic’s paper smells like bullshit

djnn.sh

101–110 of 349 posts

Re: Anthropic’s paper smells like bullshit

#101
post #58

That whole article felt like "Claude is so good Chinese hackers are using it for espionage" marketing fluff tbh

Reminds me of how when the Playstation 2 came out, Sony started planting articles about how it was so powerful that the Iraqi government was buying thousands of them to turn into a supercomputer (including unnamed military officials bringing up Sony marketing points). https://www.wnd.com/2000/12/7640/

Re: Anthropic’s paper smells like bullshit

#102

"A report was recently published by an AI-research company called Anthropic. They are the ones who notably created Claude, an AI-assistant for coding. Personally, I don’t use it but that is besides the point." Not sure if the author has tried any other AI-assistants for coding. People who haven't tried coding AI assistant underestimates its capabilities (though unfortunately, those who use them overestimate what they…

The article doesn't talk about the implausibility of the the tool to do the stated task. It talks the report, and how it doesn't have any details to make us believe the tool did the task. Maybe the thing they are describing could happen. That doesn't mean we have any evidence that it did.

Re: Anthropic’s paper smells like bullshit

#103

What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?

There’s a report with Bruce Schneier that estimates GenAI tools have increased the profitability of phishing significantly [1]. They create emails with higher click through rates, and reduce the cost of delivering them.

Groups which were too unprofitable to target before, are now profitable.

[1] https://arxiv.org/abs/2412.00586?

Re: Anthropic’s paper smells like bullshit

#104

Earlier quoted context omitted.

What makes you think they lack engineering acumen?

The hot mess that is Claude Code (if you multi-orchestrate with it, it'll start to grind even very powerful systems to a halt, 15+ seconds of unresponsiveness, all because CC constantly serializes/deserializes a JSON data file that grows quite large every time you do stuff), their horrible service uptime compared to all their competitors, their month long performance degradation their users had to scream at them to g…

[flagged]

Re: Anthropic’s paper smells like bullshit

#105

Earlier quoted context omitted.

The hot mess that is Claude Code (if you multi-orchestrate with it, it'll start to grind even very powerful systems to a halt, 15+ seconds of unresponsiveness, all because CC constantly serializes/deserializes a JSON data file that grows quite large every time you do stuff), their horrible service uptime compared to all their competitors, their month long performance degradation their users had to scream at them to g…

[flagged]

You seem to have a personal emotional investment in Anthropic, what's the deal?

Re: Anthropic’s paper smells like bullshit

#106

Does Anthropic currently have cybersec people able to provide a standard assessment of the kind the community expects? This could be a corporate move as some people claim, but I wonder if the cause is simply that their talents are currently somewhere else and they don’t have the company structure in place to deliver properly in this matter. (If that is the case they are not then free of blame, it’s just a different c…

If they don't have cybersec people able to adequately investigate and write up whatever they're seeing, and are simply playing things by ear, it's extremely irresponsible of them to publish claims like "we detected a highly sophisticated cyber espionage operation conducted by a Chinese state-sponsored group we’ve designated GTG-1002 that represents a fundamental shift in how advanced threat actors use AI." without any evidence to back them up.

Re: Anthropic’s paper smells like bullshit

#107

Earlier quoted context omitted.

Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs? I don't doubt of course that reports intended for government agencies or security experts would have those details, but I am not surprised that a "blog post" like this one is lacking details. I just don't see how one goes from "this is lacking public evidence" to "this is likely a political stu…

Not vested in the argument but it stood out to me that, Your argument is similar to tv courts if it’s plausible the report is true. Very far from the report is credible

You're right, lacking information I am coming across as instead willing to give Entropic the benefit of the doubt here.

But I'm also often a Devil's Advocate and the tide in this thread (well, the very headline as well) seemed to be condemning Anthropic.

Re: Anthropic’s paper smells like bullshit

#109
post #88

Earlier quoted context omitted.

Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs? I don't doubt of course that reports intended for government agencies or security experts would have those details, but I am not surprised that a "blog post" like this one is lacking details. I just don't see how one goes from "this is lacking public evidence" to "this is likely a political stu…

There's an incentive to blame "Chinese/Russian state sponsored actors" because it makes them less culpable than "we got owned by a rando". It's like the inverse of "nobody got fired for using IBM" -- "nobody can blame you for getting hacked by superspies". So, in the absence of any evidence, it's entirely possible they have no idea who did it and are reaching for the most convenient label.

That's fair. If the actor (and it's a Chinese state actor here) is what is being questioned as "bullshit" then that should be the discourse in the article and in this thread.

Instead the lack of a paper trail from Anthropic seems to be having people questioning the whole event?

Re: Anthropic’s paper smells like bullshit

#110

What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?

AGI favors attackers initially. Because while it can be used defensively, to preemptively scan for vulns, harden exposed software for cheaper and monitor the networks for intrusion at all times, how many companies are going to start doing that fast enough to counter the cutting edge AGI-enabled attackers probing every piece of their infra for vulns at scale? It's like a very very big fat stack of zero days leaking to…

Defending is much, much harder than attacking for humans, I'd extrapolate that to AI/AGIs.

Defender needs to get everything right, attacker needs to get one thing right.

Post reply on HN