Live data from Hacker News

Claude jailbroken to mint unlimited Stripe coupons

generalanalysis.com

1–10 of 55 posts

Re: Claude jailbroken to mint unlimited Stripe coupons

#3

Companies like this advocate creating the least secure possible deployments so that they can sell a product that patches some holes they advocated for. Astounding. What is “Claude’s iMessage integration”? Apple made it? Anthropic did?

The article states that Anthropic did and it’s open source, that’s how they found out about the expected message structure.

However, I cannot find any reference online to this MCP client or where its source code lives.

Re: Claude jailbroken to mint unlimited Stripe coupons

#5

Companies like this advocate creating the least secure possible deployments so that they can sell a product that patches some holes they advocated for. Astounding. What is “Claude’s iMessage integration”? Apple made it? Anthropic did?

I think this is it: https://i.imgur.com/Iv5Z6JT.png

Claude's web interface offers a list of connectors for you to add. You can also add custom ones.

Sounds like Anthropic made it, but hard to tell for sure.

Re: Claude jailbroken to mint unlimited Stripe coupons

#6
Every single one of these "vulnerabilities" is basically:

- Set up a website without any input sanitization.

- Hey look, you can take control of the database via SQL injection, therefore SQL is completely broken.

- Here's a service you can use to prevent this at your company (which we happen to own).

Re: Claude jailbroken to mint unlimited Stripe coupons

#7
post #4

This is just an ad for generalanalysis (itself an MCP tool).

I don’t think that’s really fair. They are highlighting some pretty serious security flaws in MCP tools that are allowed to do some pretty privileged things.

They don’t even mention their product till the very last section. Overall think it’s an excellent blog post.

Re: Claude jailbroken to mint unlimited Stripe coupons

#9
An LLM - which has functionally infinite unverifiable attack surface - directly wired into a payment system with high authentication. How could anyone anticipate this going wrong?

I feel like everyone is saying 'we're still discovering what LLMs are good at' but it also feels like we really need to get in our collective conscious what they're really, really, bad at.

Post reply on HN