Live data from Hacker News

Anthropic’s paper smells like bullshit

djnn.sh

251–260 of 349 posts

Re: Anthropic’s paper smells like bullshit

#251
post #76

Earlier quoted context omitted.

There are obvious problems with wasting time and sending people off the wrong path, but if an LLM raises a good point, isn't it still a good point?

A broken analog clock will be accurate twice a day despite being of zero use. If someone were to attempt to sell the broken clock as useful because it "accurately returns the time at least twice every day", would Ultimately be causing harm to the consumer.

Depends on what you need the clock for. For example, if it's to serve as an adjustable sign indicating e.g. the closing time of a store, a broken one does the trick just fine :)

In other words: Use the right tool for the right job.

Re: Anthropic’s paper smells like bullshit

#252

There's a big gap of knowledge between infosec researchers and ML security researchers. Anthropic has a bunch of column B but not enough column A. This was discussed in some detail in the recently published Attacker Moves Second paper*. ML researchers like using Attack Success Rate (ASR) as a metric for model resistance to attack, while for infosec, any successful attack (ASR > 0) is considered significant. ML resear…

ML researchers are not sec researchers. they need to stick to their own game. companies need to use both camps for a good holistic view of the problem. ML is the blue team. sec researchers the red.

Plenty of security researchers are blue team.

Re: Anthropic’s paper smells like bullshit

#254

Earlier quoted context omitted.

The hot mess that is Claude Code (if you multi-orchestrate with it, it'll start to grind even very powerful systems to a halt, 15+ seconds of unresponsiveness, all because CC constantly serializes/deserializes a JSON data file that grows quite large every time you do stuff), their horrible service uptime compared to all their competitors, their month long performance degradation their users had to scream at them to g…

I have the opposite perception: they’re the only company in the space that seems to have a clue what responsible software engineering is. Gemini Code and Cursor both did such a poor job sandboxing their agents that the exploits sound like punchlines, while Microsoft doesn’t even try with Copilot Agentic. Countless Cursor bugs have been fixed with obviously vibe-coded fake solutions (you can see if you poke into code…

Every tool in this space is blatantly unsafe. The sandboxes that people have designed are quite ineffective.

Re: Anthropic’s paper smells like bullshit

#255

Earlier quoted context omitted.

What makes you think they lack engineering acumen?

The hot mess that is Claude Code (if you multi-orchestrate with it, it'll start to grind even very powerful systems to a halt, 15+ seconds of unresponsiveness, all because CC constantly serializes/deserializes a JSON data file that grows quite large every time you do stuff), their horrible service uptime compared to all their competitors, their month long performance degradation their users had to scream at them to g…

You think Anthropic’s engineering talent for infosec is possible to determine because…you’ve used Claude Code? Am I understanding this right?

Re: Anthropic’s paper smells like bullshit

#256
post #58

That whole article felt like "Claude is so good Chinese hackers are using it for espionage" marketing fluff tbh

If we’re sharing vibes, “our product is dangerous” seems like an unusual sales tactic outside the defense industry. I’m doubtful that’s how it works? Meanwhile, another reason to make a press release is that you’ll be criticized for the coverup if you don’t. Also, it puts other companies on notice that maybe they should look for this?

I think it might be a "our product IS dangerous but look we are on top of it!" kind of deal. Still leaves a funny taste either way.

Re: Anthropic’s paper smells like bullshit

#257

Why isn’t Anthropic held liable for crimes committed with their product? I feel totally befuddled as to why that is not the conversation, but rather Anthropic is doing a victory lap like they are the good guys despite their product enabling widespread fraud while they amass outrageous, undeserved, profits. Why is Anthropic not liable?

Because deciding how much culpability they have is not a solved problem.

Re: Anthropic’s paper smells like bullshit

#258
post #20

The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.

Anthropic has also been the biggest anti-China LLM in a long while, so it's possible they're using an opportunistic hack (potentially involving actual Chinese IP addresses) as another way to push their agenda.

Considering ever since the Vault 7 releases, we should be well aware of the fact that at least one government is able to make any attack look like any other nation state actor, any attribution to, especially convenient adversaries, is extremely suspicious on the face of it.

Re: Anthropic’s paper smells like bullshit

#259
post #52

People grossly underestimate APTs. It is more common than an average IT curious person thinks. I happened to be oncall when one of these guys hacked into Gmail from our infra. It took principal security engineers a few days before they could clearly understand what happened. Multiple zero days, stolen credit cards, massive social campaign to get one of the Google admins click on a funny cat video finally. The investi…

Do you mean APT (Advanced persistent threat)?

i seriously thought APT meant advanced persistent teen

Re: Anthropic’s paper smells like bullshit

#260

When I worked at a FAANG with a "world leading" AI lab (now run by a teenage data labeller) as an SRE/sysadmin I was asked to use a modified version of a foundation model which was steered towards infosec stuff. We were asked to try and persuade it to help us hack into a mock printer/dodgy linux box. It helped a little, but it wasn't all that helpful. but in terms of coordination, I can't see how it would be useful.…

> you're API is tied to a bankaccount, There are a lot of middlemen like open router who gladly accept crypto.

Can you show me exactly how to pay for open router with monero? Because it doesn’t seem possible.
Post reply on HN