Live data from Hacker News

Anthropic’s paper smells like bullshit

djnn.sh

201–210 of 349 posts

Re: Anthropic’s paper smells like bullshit

#201

Earlier quoted context omitted.

What makes you think they lack engineering acumen?

The hot mess that is Claude Code (if you multi-orchestrate with it, it'll start to grind even very powerful systems to a halt, 15+ seconds of unresponsiveness, all because CC constantly serializes/deserializes a JSON data file that grows quite large every time you do stuff), their horrible service uptime compared to all their competitors, their month long performance degradation their users had to scream at them to g…

I have the opposite perception: they’re the only company in the space that seems to have a clue what responsible software engineering is.

Gemini Code and Cursor both did such a poor job sandboxing their agents that the exploits sound like punchlines, while Microsoft doesn’t even try with Copilot Agentic.

Countless Cursor bugs have been fixed with obviously vibe-coded fake solutions (you can see if you poke into code embedded in their binaries) which don’t address the problems on a fundamental level at all and suggest no human thinking was involved.

Claude has had some vulnerabilities, but many fewer, and they’re the only company that even seemed to treat security like a serious concern, and are now publishing useful related open source projects. (Not that your specific complaint isn’t valid, that’s been a pain point for me to, but in terms of the overall picture that’s small potatoes.)

I’m personally pretty meh on their models, but it’s wild to me to hear these claims about their software when all of the alternatives have been so unsafe that I’d ban them from any systems I was in charge of.

Re: Anthropic’s paper smells like bullshit

#202

People grossly underestimate APTs. It is more common than an average IT curious person thinks. I happened to be oncall when one of these guys hacked into Gmail from our infra. It took principal security engineers a few days before they could clearly understand what happened. Multiple zero days, stolen credit cards, massive social campaign to get one of the Google admins click on a funny cat video finally. The investi…

You're telling me you were targeted by Multiple Zero Days in 1 single attack?

That's generally how actual APT attacks go, yes.

Re: Anthropic’s paper smells like bullshit

#204
Why isn’t Anthropic held liable for crimes committed with their product? I feel totally befuddled as to why that is not the conversation, but rather Anthropic is doing a victory lap like they are the good guys despite their product enabling widespread fraud while they amass outrageous, undeserved, profits. Why is Anthropic not liable?

Re: Anthropic’s paper smells like bullshit

#205
post #58

That whole article felt like "Claude is so good Chinese hackers are using it for espionage" marketing fluff tbh

If we’re sharing vibes, “our product is dangerous” seems like an unusual sales tactic outside the defense industry. I’m doubtful that’s how it works?

Meanwhile, another reason to make a press release is that you’ll be criticized for the coverup if you don’t. Also, it puts other companies on notice that maybe they should look for this?

Re: Anthropic’s paper smells like bullshit

#206
post #20

The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.

Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs? I don't doubt of course that reports intended for government agencies or security experts would have those details, but I am not surprised that a "blog post" like this one is lacking details. I just don't see how one goes from "this is lacking public evidence" to "this is likely a political stu…

> Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs?

This is literally answered in the second subsection of the linked article ("where are the IoCs, Mr.Claude ?").

Re: Anthropic’s paper smells like bullshit

#207
post #20

The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.

Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs? I don't doubt of course that reports intended for government agencies or security experts would have those details, but I am not surprised that a "blog post" like this one is lacking details. I just don't see how one goes from "this is lacking public evidence" to "this is likely a political stu…

The complaint is that there's no actionable information whatsoever. Alarm bells are just noise.

Re: Anthropic’s paper smells like bullshit

#208
post #129

Dario Amodei, the CEO of Anthropic, openly lied to the public back in March that AI would be writing 90% of the code by Sept. It is Nov now. He obviously doesn't even know the stuff he is working on. How would anyone take him seriously for stuff like security which he doesn't know anything about?

> openly lied He made a prediction from a reasonably informed vantage point

> openly lied

Surely he merely hallucinated based on a fine-tuned distribution, and had no ulterior motive for projecting a level of growth in technical sophistication beyond their current capability onto a somewhat lay, highly speculative, very wealthy crowd.

Re: Anthropic’s paper smells like bullshit

#209

Earlier quoted context omitted.

> now run by a teenage data labeller sick burn

Alexandr Wang is 28 years old, the same age as Mark Zuckerberg was when Facebook IPO'ed,

A business where the distinguishing factor was exclusivity not technical excellence so it tracks.

Re: Anthropic’s paper smells like bullshit

#210
post #131

The below amendment from the anthropic blog page is telling. Edited November 14 2025: Added an additional hyperlink to the full report in the initial section Corrected an error about the speed of the attack: not "thousands of requests per second" but "thousands of requests, often multiple per second"

> The operational tempo achieved proves the use of an autonomous model rather than interactive assistance. Peak activity included thousands of requests, representing sustained request rates of multiple operations per second.

The assumption that no human could ever (program a computer to) do multiple things per second, nor have their code do different things depending on the result of the previous request is... interesting.

(observation is not original to me, it was someone on Twitter who pointed it out)

Post reply on HN