LLMs really get in the way of computer security work of any form. Constantly "I can't do that, Dave" when you're trying to deal with anything sophisticated to do with security. Because "security bad topic, no no cannot talk about that you must be doing bad things." Yes I know there's ways around it but that's not the point. The irony is that LLMs being so paranoid about talking security is that it ultimately helps th…
For a further layer of irony, after Claude Code was used for an actual real cyberattack (by hackers convincing Claude they were doing "security research"), Anthropic wrote this in their postmortem:
This raises an important question: if AI models can be misused for cyberattacks at this scale, why continue to develop and release them? The answer is that the very abilities that allow Claude to be used in these attacks also make it crucial for cyber defense. When sophisticated cyberattacks inevitably occur, our goal is for Claude—into which we’ve built strong safeguards—to assist cybersecurity professionals to detect, disrupt, and prepare for future versions of the attack.