People grossly underestimate APTs. It is more common than an average IT curious person thinks. I happened to be oncall when one of these guys hacked into Gmail from our infra. It took principal security engineers a few days before they could clearly understand what happened. Multiple zero days, stolen credit cards, massive social campaign to get one of the Google admins click on a funny cat video finally. The investi…
You're telling me you were targeted by Multiple Zero Days in 1 single attack?
Anthropic’s paper smells like bullshit
211–220 of 349 posts
Re: Anthropic’s paper smells like bullshit
#212People grossly underestimate APTs. It is more common than an average IT curious person thinks. I happened to be oncall when one of these guys hacked into Gmail from our infra. It took principal security engineers a few days before they could clearly understand what happened. Multiple zero days, stolen credit cards, massive social campaign to get one of the Google admins click on a funny cat video finally. The investi…
Do you mean APT (Advanced persistent threat)?
Re: Anthropic’s paper smells like bullshit
#213Re: Anthropic’s paper smells like bullshit
#214Earlier quoted context omitted.
Do public reports like this one often go deep enough into the weeds to name names, list specific tools and techniques, URLs? I don't doubt of course that reports intended for government agencies or security experts would have those details, but I am not surprised that a "blog post" like this one is lacking details. I just don't see how one goes from "this is lacking public evidence" to "this is likely a political stu…
There's an incentive to blame "Chinese/Russian state sponsored actors" because it makes them less culpable than "we got owned by a rando". It's like the inverse of "nobody got fired for using IBM" -- "nobody can blame you for getting hacked by superspies". So, in the absence of any evidence, it's entirely possible they have no idea who did it and are reaching for the most convenient label.
But they didn't get hacked by anyone. I don't see how that applies.
Re: Anthropic’s paper smells like bullshit
#215Earlier quoted context omitted.
State sponsorship can include the state looking the other way.
So all attacks anywhere are state sponsored?
> So all attacks anywhere are state sponsored?
There's a difference between a deliberate decision to look away, and unawareness through lack of oversight.
You steal candy from a store. There's a difference between the security guard seeing you and deliberately looking away, compared to just not seeing you at all.
Re: Anthropic’s paper smells like bullshit
#216Sort of like firearm ads that show scary bad guys with scary looking weapons.
Re: Anthropic’s paper smells like bullshit
#217Launching Soon: Claude for Cybersecurity - Automated Defence in Depth Hacker Protection
Re: Anthropic’s paper smells like bullshit
#218The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.
Re: Anthropic’s paper smells like bullshit
#219The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.
The bubble is gonna burst soon and these companies are desperate to convince the government they are either too big to fail or too critical to national defense to fail.
Re: Anthropic’s paper smells like bullshit
#220Earlier quoted context omitted.
AGI favors attackers initially. Because while it can be used defensively, to preemptively scan for vulns, harden exposed software for cheaper and monitor the networks for intrusion at all times, how many companies are going to start doing that fast enough to counter the cutting edge AGI-enabled attackers probing every piece of their infra for vulns at scale? It's like a very very big fat stack of zero days leaking to…
Defending is much, much harder than attacking for humans, I'd extrapolate that to AI/AGIs. Defender needs to get everything right, attacker needs to get one thing right.
The same way we can build "muscle memory" to delegate simple autonomous tasks, a super intelligence might be able to dynamically delegate to human level (or greater) level sub intelligences to vigilantly watch everything it needs to.