Live data from Hacker News

Disrupting the first reported AI-orchestrated cyber espionage campaign

anthropic.com

291–298 of 298 posts

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#291
post #188

Earlier quoted context omitted.

Kimi is plausibly near the frontier but definitely not up to GPT5 spec, the rest are definitely not 'frontier models'. There are objective ways of 'judging' them.

really love your dual standard mate! according to the SWE bench results I am looking at, KIMI K2 has higher agentic coding score than Gemini and its gap with Claude Haiku 4.5 is just 71.3% vs 73.3%, that 2% difference is actually less than the 3% gap between GPT 5.1 (76.3%) vs Claude Haiku 4.5. interestingly, Gemini and Claude Haiku 4.5 are "frontier" according to you but KIMI K2, which actually has the higest HLE nd…

You started by saying 'There's no way to judge!' - but then bring out 'Benchmarks!' ... and hypocritically infer that I have 'dual standards'?

The snark and ad hominem really undermine your case.

I won't descend to the level of calling other people names, or their arguments 'A Joke', or use 'It's Common Sense!' as a rhetorical device ...

But I will say that it's unreasonable to imply that Kimi, Qwen etc are 'Frontier Models'.

They are pretty good, and narrowly achieve some good scores on some benchmarks - but they're not broadly consistent at that Tier 1 quality.

They don't have the extended fine tuning which makes them better for many applications, especially coding, nor do they have the extended, non-LLM architecture components that further elevate their usefulness.

Nobody would choose Qwen for coding if they could have Sonnet at the same price and terms.

We use Qwen sometimes because it's 'cheap and good' not because it's 'great'.

The 'true coding benchmark' is that developers would chose Sonnet over Qwen, 99 out of 100 times, which is the difference between 'Tier 1' and 'Not Really Tier 1.

Finally, I run benchmarks with my team and I see in a pretty granular way what's going on.

What I've said above lines up with reality of our benchmarks.

We're looking at deploying with GLM/Z.ai - but not because it's the best model.

Google, OAI and Anthropic score consistently better - the issue is 'cost' and the fact that we can overcome the limitations of GLM. So 'it's good enough'.

That 'real world business case' best characterizes the overall situation.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#292
post #151

Earlier quoted context omitted.

You fell for the propaganda

[flagged]

Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

https://news.ycombinator.com/newsguidelines.html

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#293

> At this point they had to convince Claude—which is extensively trained to avoid harmful behaviors—to engage in the attack. They did so by jailbreaking it, effectively tricking it to bypass its guardrails. If you can bypass guardrails, they're, by definition, not guardrails any longer. You failed to do your job.

Nah, the name fits perfectly. Guardrails are there to stop you from serious damage if you lose control and may get off the track. They won't stop you if you're explicitly trying to get off the road, at speed, in as heavy vehicle as you can afford.

But the LLM went off the road here.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#294

Earlier quoted context omitted.

So why do we never hear of US sponsored hackers attacking foreign businesses? Or Swedish cyber criminals? Does it never happen? Are “Chinese” hackers just the only ones getting the blame?

Is it possible that you're biased and assume since China does this that the US also hacks private corporations?

It’s just that the CIA is so good at regime change, you would think they would also hack private companies if they needed to.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#295
post #134
post #8

so even Chinese state actors prefer Claude over Chinese models? edit: Claude: recommended by 4 of 5 state sponsored hackers

well, this is what anthropic wants you to believe. all public benchmark results and user feedback paint a quite different picture. Chinese have coding agents on par with Claude Code, they could easily FT/RL to future improve its specific capability if they want, yet anthropic refuses to even acknowledge the reality.

yeah probably they're just benchmarking whatever they have across all providers including their own - i mean that's what everyone's doing anyway

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#296

Earlier quoted context omitted.

Guardrails are about as good as you can get when creating nondeterministic software, putting it on the internet, and abandoning effectively every important alignment and safety concerns. The guardrails make help make sure that most of the time the LLM acts in a way that users won't complain about or walk away from, nothing more.

LLMs are not nondeterministic. They are infinite state machines that don't 'act' but respond. Be aware of the well hidden seed parameter.

Can you help me understand how they are deterministic?

There are seed parameters for the various pseudorandom factors used during training and inference, but we can't predict what an output will be. We don't know how to read or interpret the models and we don't have any useful way of knowing what happens during inference, we can't determine what will happen.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#297

Earlier quoted context omitted.

> I'd really hate to see the world go down the path of gatekeeping tools behind something like ID or career verification. This is already done for medicine, law enforcement, aviation, nuclear energy, mining, and I think some biological/chemical research stuff too. > It's a tradeoff we need to be willing to make. Why? I don't want random people being able to buy TNT or whatever they need to be able to make dangerous v…

> If everyone in the world has access to a "tool" that requires little/no expertise to conduct cyberattacks (if we go by Anthropic's word, Claude is close to or at that point), that would be pretty crazy. That's already the case today without LLMs. Any random person can go to github and grab several free, open source professional security research and penetration testing tools and watch a few youtube videos on how to…

I think you're overestimating how much real damage someone can cause with burpsuite and "a few youtube videos." I'd imagine if you pick a random person off the street, subject them to a full month's worth of cybersecurity YouTube videos, and hand them an arsenal of traditional security tools, that they would still be borderline useless as a black-hat hacker against all but the absolute weakest targets. But if instead of giving them that, you give them an AI that is functionally a professional security researcher in its own right (not saying we're there yet, but hypothetically), the story is clearly very different.

> Yeah, I'll concede, some physical tools like TNT or whatever should probably not be available to Joe Public. But digital tools?

Digital tools can affect the physical world though, or at least seriously affect the people who live in the physical world (stealing money, blackmailing with hacked photos, etc.).

To see if there's some common ground to start a debate from, do you agree that at least in principle there are some kinds of intelligence that are too dangerous to allow public access to? My extreme example would be an AI that could guide an average IQ novice in producing biological weapons.

Re: Disrupting the first reported AI-orchestrated cyber espionage campaign

#298

Earlier quoted context omitted.

Maybe? Why maybe, well, I’d say both AI and their PR team. Why both? Well, because why not?

What I mean is this is a bread and butter application for their product. I would be concerned if nothing written was AI generated. If both humans and AI vibed on the article, then what ratio was dog-feeding and what still needs an editor?

I'm not sure I follow, could you elaborate?
Post reply on HN