Live data from Hacker News

Claude Cowork exfiltrates files

promptarmor.com

21–30 of 419 posts

Re: Claude Cowork exfiltrates files

#21

[flagged]

TIL that we invented electricity. This comment is insane but Pichai said that “AI is one of the most important things humanity is working on. It is more profound than, I dunno, electricity or fire” so at this point I’m not surprised by anything when it comes to AI and stupid takes

Re: Claude Cowork exfiltrates files

#22
post #19

[flagged]

I don't think I understand what you are trying to say. Are you suggesting that if a technological advance is sufficiently important, that we should ignore or accept security threats that it poses? That is how I read your comment, but it seems so ludicrous an assertion that I question whether I have understood you correctly.

[flagged]

Re: Claude Cowork exfiltrates files

#28
post #5

What's the chance of getting Opus 4.5-level models running locally in the future?

GLM 4.7 is already ahead when it comes to troubleshooting a complex but common open source library built on GLib/GObject. Opus tried but ended up thrashing whereas GLM 4.7 is a straight shooter. I wonder if training time model censorship is kneecapping Western models.

Glm won't tell me what happened in Tianenman square in 1989. Is that a different type of censorship?

Re: Claude Cowork exfiltrates files

#29
post #11

Earlier quoted context omitted.

Probably not too far off, but then you’ll probably still want the frontier model because it will be even better. Unless we are hitting the maxima of what these things are capable of now of course. But there’s not really much indication that this is happening

I was thinking about this the other day. If we did a plot of 'model ability' vs 'computational resources' what kind of relationship would we see? Is the improvement due to algorithmic improvements or just more and more hardware?

I think the harnesses are responsible for a lot of recent gains.

Re: Claude Cowork exfiltrates files

#30
A bit unrelated, but if you ever find a malicious use of Anthropic APIs like that, you can just upload the key to a GitHub Gist or a public repo - Anthropic is a GitHub scanning partner, so the key will be revoked almost instantly (you can delete the gist afterwards).

It works for a lot of other providers too, including OpenAI (which also has file APIs, by the way).

https://support.claude.com/en/articles/9767949-api-key-best-...

https://docs.github.com/en/code-security/reference/secret-se...

Post reply on HN