Live data from Hacker News

Claude for Chrome

anthropic.com

61–70 of 433 posts

Re: Claude for Chrome

#61
post #37

> When we added safety mitigations to autonomous mode, we reduced the attack success rate of 23.6% to 11.2% Ah, so the attacker will only get full access to my information and control over my accounts ~10% of the time. Comforting!

[deleted]

Re: Claude for Chrome

#62
post #6

> Malicious actors can hide instructions in websites, emails, and documents that trick AI into taking harmful actions without your knowledge, including: > * Accessing your accounts or files > * Sharing your private information > * Making purchases on your behalf > * Taking actions you never intended This should really be at the top of the page and not one full screen below the "Try" button.

[deleted]

Re: Claude for Chrome

#63
post #6

> Malicious actors can hide instructions in websites, emails, and documents that trick AI into taking harmful actions without your knowledge, including: > * Accessing your accounts or files > * Sharing your private information > * Making purchases on your behalf > * Taking actions you never intended This should really be at the top of the page and not one full screen below the "Try" button.

It's insane how we're throwing out decades of security research because it's slightly annoying to have to write your own emails.

With regards to llm injection, we sorta need the cat and mouse games to play out a bit, no? I have my concerns but I'm not ready to throw out the baby with the bathwater. You could never release an OS if "no zero days" was a requirement. Every piece of software we use has and will have its vulnerabilities (see Apple's recent RCE), we play the arms race and things look asymptotically fine.

This seems to be the case in llms too. They're getting better and better (with a lot of research) at avoiding doing the bad things. I don't see why its fundamentally intractable to fence system/user/assistant/tool messages to prevent steering from non-trusted inputs, and building new fences for cases we want the steering.

Why is this piece of software particularly different?

Re: Claude for Chrome

#65
post #53
post #28

Earlier quoted context omitted.

When we felt we were getting close to flight, people were jumping off buildings in wing suits. And then, the Wright Bros. cracked the problem. Rocketry, Apollo... Same thing here. And it's bound to have the same consequences, both good and bad. Let's not forget how dangerous the early web was with all of the random downloadables and popups that installed exe files. Evolution finds a way, but it leaves a mountain of b…

I'm ok with individual pioneers taking high but informed risks in the name of progress. But this sounds like companies putting millions of users in wing suits instead.

Was just coming here to say that. Anyone who's familiar with the Mercury, Gemini and Apollo missions wouldn't characterize it as a technological evolution that left mountains of bodies in its wake. Yes, there were casualties (Apollo 1) but they were relatively minimal.

Re: Claude for Chrome

#66
It seems to me that becoming a malware author is now a viable career path for us devs since elon tries to eliminate all dev jobs with his company macrohard, anthropic tries to make it as easy as possible to steal an identity. What am i missing?

Re: Claude for Chrome

#67
post #58
post #54

Earlier quoted context omitted.

No, it's because big tech has taken control of our data and locked it all down so we don't have control over it. AI browser automation is going to blow open all these militarized containers that use our own data and networks against us with the fig leaf of supposed security. I'm looking forward to the revival of personal data mashups like the old Yahoo Pipes.

> AI browser automation is going to blow open all these militarized containers that use our own data against us. I'm not sure what you mean by this. Do you mean that AI browser automation is going to give us back control over our data? How? Aren't you starting a remote desktop session with Anthropic everytime you open your browser?

> Do you mean that AI browser automation is going to give us back control over our data? How?

Narrator: It won't.

Re: Claude for Chrome

#68
I could see this being very helpful for testing certain functionality during development.

As for using it on a regular basis, I think the security blurb should deter just about anyone who cares at all about security.

Re: Claude for Chrome

#70
post #63

Earlier quoted context omitted.

It's insane how we're throwing out decades of security research because it's slightly annoying to have to write your own emails.

With regards to llm injection, we sorta need the cat and mouse games to play out a bit, no? I have my concerns but I'm not ready to throw out the baby with the bathwater. You could never release an OS if "no zero days" was a requirement. Every piece of software we use has and will have its vulnerabilities (see Apple's recent RCE), we play the arms race and things look asymptotically fine. This seems to be the case in…

Because the flaws are glaring, obvious, and easily avoidable.
Post reply on HN