Remix.run Logo
rvz 5 hours ago

> I don't interpret it like that at all. This is deeply embarrassing for Anthropic: it turns out they hadn't been keeping a close eye on their models either, and back in April they successfully attacked three different organizations!

This just helps their (Anthropic) argument into persuading the US government into taking action into limiting powerful closed or open-weight models from being released without going through (yet to be defined) regulatory oversight.

The only "embarrassing" thing for Anthropic was that there was little to no continuous security monitoring of this since April, and they then decided to do a cybersecurity transcript review only AFTER the incident with OpenAI and Huggingface.

simonw 4 hours ago | parent | next [-]

Anthropic know better than anyone else how risky it is to get this current administration upset with you over safety/security concerns.

gck1 4 hours ago | parent | prev [-]

They also gave access to Mythos (the Mythos) to some companies, based on... vibes.

Who knows how these companies are using it. If Anthropic can't effectively contain their own models, can the partners?

While the rest of us get fallbacks and warnings, not even being able to defend against the attacks they themselves are causing.

Do we really have to re-learn all the industry's knowledge the hard way?

htrp 4 hours ago | parent | next [-]

You also got access to mythos based on how much you spent with anthropic. I think sales guys were bragging about getting their enterprises access

jryle70 3 hours ago | parent | prev [-]

> based on... vibes

According to whom?

> Do we really have to re-learn all the industry's knowledge the hard way?

Yes we do. That's why there is the saying "regulations are written in blood". Especially for LLM, which not too long ago a lot of people on HN dismissed as stochastic parrot and next token generator.

gck1 3 hours ago | parent [-]

> According to whom?

It's very easy to answer this without my help by trying to get access to Mythos.

Do you see requirements clearly listed anywhere?Can you even apply?

What you'll find is maintainers of large open source projects and analysts' reports with vague statements like - "should follow strict security requirements":

"Trinidad also noted that the Anthropic announcement pointed out that each of the 150 new participants, in Anthropic’s phrasing, “will need to meet our security requirements before they gain access.”

Trinidad said the security requirement claim doesn’t build confidence, because “nobody knows what those security requirements are.” [1]

It's also some random rich companies like Hitachi or Dragos [2]

Do you trust that Hitachi and hundreds of other random organizations will be able to contain Mythos and not accidentally attack your project or your bank? I don't.

> Yes we do. That's why there is the saying "regulations are written in blood"

We absolutely don't. We have already learned with blood that gating access to security based on the number of zeroes in bank account and authority is a horrible model. We can apply this knowledge to LLMs, we don't have to spill blood again.

[1] https://www.csoonline.com/article/4180265/anthropic-grants-p...

[2] https://www.bankinfosecurity.com/anthropic-limits-on-ot-acce...