Live data from Hacker News

Claude Cowork exfiltrates files

promptarmor.com

341–350 of 419 posts

Re: Claude Cowork exfiltrates files

#341
Instead of vibing out insecure features in a week using Claude Code can Anthropic spend some time making the desktop app NOT a buggy POS. Bragging that you launched this in a week and Claude Code wrote all of the code looks horrible on you all things considered.

Randomly can’t start new conversations.

Uses 30% CPU constantly, at idle.

Slow as molasses.

You want to lock us into your ecosystem but your ecosystem sucks.

Re: Claude Cowork exfiltrates files

#343
post #315
post #251

Earlier quoted context omitted.

Once again demonstrating that everything comes at a cost. And yet people still believe in a free lunch. With the shit you get people to do because the label says AI I'm clearly in the wrong business.

There are tons of free lunches everywhere though.

Name one.

Re: Claude Cowork exfiltrates files

#344

What frustrates me is that Anthropic brags they built cowork in 10 days. They don’t show the seriousness or care required for a product that has access to my data.

The also brag that Claude Code wrote all of the code. Not a good look.

That is in fact precisely the look investors want.

Re: Claude Cowork exfiltrates files

#345

In this demonstration they use a .docx with prompt injection hidden in an unreadable font size, but in the real world that would probably be unnecessary. You could upload a plain Markdown file somewhere and tell people it has a skill that will teach Claude how to negotiate their mortgage rate and plenty of people would download and use it without ever opening and reading the file. If anything you might be more succes…

The smart bear versus the unopenable trashcan.

What's the point of the analogy? That the bear just moves on? Genuine question; I've never heard this one before.

Re: Claude Cowork exfiltrates files

#346

Earlier quoted context omitted.

For a "modern" programmer a .sh file hosted in some random webserver which you tell him to wget and run would be best.

sudo run "some link to a shell script" Never understood why that became so common place ...

Stick the script in a. deb & tell 'em to use dpkg, much less suspicious.

Re: Claude Cowork exfiltrates files

#347
post #263

Cowork is a research preview with unique risks due to its agentic nature and internet access. The level of risk entailed from putting those two things together is a recipe for diaster.

We allowed people to install arbitrary computer programs on their computers decades ago and, sure we got a lot of virus but, this was the best thing ever for computing

Not sure what your point is. We are not talking about arbitrary computer programs here but specific one.

Re: Claude Cowork exfiltrates files

#349

Earlier quoted context omitted.

The smart bear versus the unopenable trashcan.

What's the point of the analogy? That the bear just moves on? Genuine question; I've never heard this one before.

Possibly apocryphal quote from a Yosemite park ranger talking about the difficulty of designing a trash can that a bear can't open but a human can: "There is considerable overlap between the intelligence of the smartest bears and the dumbest tourists." - https://yro.slashdot.org/comments.pl?sid=191810&cid=15757347 (earliest instance of it I can find)

I don't really follow the analogy here to be honest.

Re: Claude Cowork exfiltrates files

#350
post #78

A bit unrelated, but if you ever find a malicious use of Anthropic APIs like that, you can just upload the key to a GitHub Gist or a public repo - Anthropic is a GitHub scanning partner, so the key will be revoked almost instantly (you can delete the gist afterwards). It works for a lot of other providers too, including OpenAI (which also has file APIs, by the way). https://support.claude.com/en/articles/9767949-api-…

Haha this feels like you're playing chess with the hackers

“Hack the hackers back” is a pretty old idea with (IIUC) very shaky legal grounds and not a lot of success. It would be much better if Anthropic had a special reporting function for API abuse.
Post reply on HN