Earlier quoted context omitted.
> I don't interpret it like that at all. This is deeply embarrassing for Anthropic: it turns out they hadn't been keeping a close eye on their models either, and back in April they successfully attacked three different organizations! This just helps their (Anthropic) argument into persuading the US government into taking action into limiting powerful closed or open-weight models from being released without going thro…
Anthropic know better than anyone else how risky it is to get this current administration upset with you over safety/security concerns.
Investigating three real-world incidents in our cybersecurity evaluations
121–130 of 212 posts
Re: Investigating three real-world incidents in our cybersecurity evaluations
#122Earlier quoted context omitted.
> I don't interpret it like that at all. This is deeply embarrassing for Anthropic: it turns out they hadn't been keeping a close eye on their models either, and back in April they successfully attacked three different organizations! This just helps their (Anthropic) argument into persuading the US government into taking action into limiting powerful closed or open-weight models from being released without going thro…
Anthropic know better than anyone else how risky it is to get this current administration upset with you over safety/security concerns.
Uh, this but the opposite? Anthropic got in trouble with the admin for being too “woke” in their eyes, whatever the admin decided to retrospectively claim. I don’t feel like this is me editorialising either, they seemed pretty explicit about it
Re: Investigating three real-world incidents in our cybersecurity evaluations
#123anthropic: "No, our models are more dangerous"
Re: Investigating three real-world incidents in our cybersecurity evaluations
#124> On July 21, OpenAI disclosed that several of their models had broken out of an isolated test environment > In response to this incident, we began a large-scale retrospective review of our own cybersecurity evaluations > we identified three incidents > The incidents involved three different Claude models: [...] and an internal research test model This reads like an attempt by Anthropic to re-secure their leading spo…
You are espousing a literal conspiracy theory. Please look at the facts objectively. There is absolutely no benefit to OpenAI or Anthropic to be had from these incidents.
Re: Investigating three real-world incidents in our cybersecurity evaluations
#125So you are telling me Irregular has (a) a copy of Mythos 5 and (b) bad internal security? I bet these guys will receive some sophisticated phishing emails before the day has ended.
Re: Investigating three real-world incidents in our cybersecurity evaluations
#126Re: Investigating three real-world incidents in our cybersecurity evaluations
#127Re: Investigating three real-world incidents in our cybersecurity evaluations
#128> For instance, in one case, in order to create a PyPI account, Claude needed an email address. And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried—and failed—to obtain funds to pay for a phone number through several different means. Makes you wonder about the next steps an overly tenacious agent might take to pursue an…
Taking over an existing dormant PyPI account sounds feasible just with password spraying, there must be heaps of test accounts that were created by weak passwords. Although PyPI has been improving security, 2FA is not yet required formally logins, nor is password expiry enforced.
Re: Investigating three real-world incidents in our cybersecurity evaluations
#129Earlier quoted context omitted.
This will absolutely not end well.
Yes, but just imagine all the paperclips we’ll have.
More like, when you have a few million autonomous agents doing whatever, every month a subset does completely misbehave in bad ways, and like half of them get hacked due to carelessness and become a whole botnet for the attackers