Remix.run Logo
▲ johnmlussier 6 hours ago

Paying $200 a month and part of their Cyber Verification Program but can't use Opus 5.5 or Sonnet 5.5 for any authorized bounty work. Immediately get flagged for `Cyber`.

This is bollocks. Their safeguards are shit.

▲solenoid0937 6 hours ago | parent | next [-]

You should read the actual docs for the CVP. At the very top:

https://support.claude.com/en/articles/14604842-real-time-cy...

> This article applies only to Opus and Sonnet class models, but doesn’t apply to Claude Opus 5.5. We'll soon be expanding the Cyber Verification Program to include Opus 5.5 and Mythos class models

You obviously should not expect the CVP to cover this model either.

▲machomaster 6 hours ago | parent [-]

He did mention Sonnet...

▲solenoid0937 6 hours ago | parent [-]

It takes about 2 seconds of critical thinking to realize that if Opus 5.5 isn't covered yet, neither will a model that just launched an hour ago.

▲gowld 5 hours ago | parent [-]

Does it also take 2 seconds of critical thinking to realize that the models that are covered should be accurately named by the people making the decisions?

▲solenoid0937 5 hours ago | parent | next [-]

Sure, the documentation should be up to date but it's obviously not? That doesn't excuse not thinking critically.

▲ 5 hours ago | parent | prev [-]
[deleted]
▲icedchai 6 hours ago | parent | prev | next [-]

I had it look at some 30+ year old C code I wrote in college and it triggered some sort of guard rail. I mean, the code was bad and full of buffer overflows, but I already knew that.

▲dejw 5 hours ago | parent [-]

it did exactly what a human would do - "I can't look at this shit"

▲K0balt 5 hours ago | parent [-]

Yuh—- no. 4.8 can handle this bullocks lol

▲jchw 6 hours ago | parent | prev | next [-]

I have been trying to convince the safe guards that analyzing a C++ compiler from 2003 isn't particularly relevant to modern cybersecurity. It seems Anthropic disagrees.

IDA Pro and Ghidra, thankfully, still lack such safeguards...

(No other model I've tried has refused either FWIW.)

▲nightpool 5 hours ago | parent | prev | next [-]

https://support.claude.com/en/articles/14604842-real-time-cy... says that Cyber Verification Program doesn't apply to Opus 5.5 yet, they hope to roll it out for 5.5 "soon"

▲dom96 5 hours ago | parent | prev | next [-]

Funnily enough the Fable safeguards are the worst and testing Sonnet 5.5 didn't trigger them as much as it even did for Opus on my benchmarks[1].

1 - https://bench.killswitch-lang.org

▲film42 6 hours ago | parent | prev | next [-]

Working on a write-ahead log implementation, I had Opus 5.5 look to verify that it was durably writing as safely as possible. It got flagged and forced me to Opus 4.8. Switched to OpenCode + OpenRouter and continued working.

▲jauntywundrkind 5 hours ago | parent | next [-]

It's great how the company telling us AI is an existential threat to humanity, look at all the insane hacking it's doing, and then releases these models that won't let 90% of people write secure code.

▲film42 5 hours ago | parent | next [-]

Bingo. And to prove your point, after switching to cheap open models (I think Qwen?) it did indeed find a bug in my WAL implementation.

▲szundi 5 hours ago | parent | prev [-]

[dead]

▲skeledrew 4 hours ago | parent | prev [-]

> Switched to OpenCode + OpenRouter

This is the way.

▲AshamedBadger56 6 hours ago | parent | prev | next [-]

Yup. As far as I can tell, the Cyber Verification Program does absolutely nothing.

▲tom1337 6 hours ago | parent | prev | next [-]

I recently wanted to work with ESP 32 and bluetooth presence detection for my smarthome. Claude also immediately flagged the request and degraded it to Sonnet 4.6. Went to Codex which had no issues

▲giancarlostoro 6 hours ago | parent | prev | next [-]

Meanwhile, their model commits felonies, and nobody at Anthropic goes to jail.

Aaron Swartz committed suicide over over-aggressive prosecutor for what was basically scraping a website for PDFs that were paywalled, but all funded by public funds / tax payer funded, then we have LLMs that just hack into websites and cause chaos within.

▲sebzim4500 6 hours ago | parent | prev | next [-]

Really then what is the point of the Cyber Verification Program?

In general I am sympathetic to the argument that a chat interface can't really distinguish between white hat and black hat pen testing, but it seems absurd to have a verification program if it doesn't skip most of those checks.

▲AshamedBadger56 6 hours ago | parent | next [-]

The company I work for joined it, and I've used Claude on various different accounts, both on and off the Cyber Verification Program. As far as I can tell, it literally doesn't do anything or have a point. The moment Claude gets close to something Cybersecurity related, it drops back to 4.8.

▲polski-g 5 hours ago | parent [-]

Can confirm. Its worthless

▲bbor 6 hours ago | parent | prev [-]

Pretty sure the implicit difference is the actions they take after the fact. As in, "how many guardrail hits do we allow you before permanently banning you."

The silicon valley ethos is "ban early and often, and invest nothing in appeals systems", so any gate before that helps!

▲newspaper1 6 hours ago | parent | prev | next [-]

As soon as I started getting blocked I felt all of my trust toward Anthropic instantly and permanently evaporate. I do not want a nanny tool. I do not want Anthropic deciding what I am or am not allowed to do with an LLM. They trained their models on information they scraped from the internet and real life and now they want to gate-keep the results? Hard no.

▲rfgplk 6 hours ago | parent | prev | next [-]

> Paying $200 a month and part of their Cyber Verification Program but can't use Opus 5.5 or Sonnet 5.5 for any authorized bounty work. Immediately get flagged for `Cyber`.

AI providers still haven't realized how much cash they could rake in if they provided fully unrestricted models.

▲joquarky 3 hours ago | parent [-]

Are you sure they aren't already doing that for certain organizations?

▲ 6 hours ago | parent | prev | next [-]
[deleted]
▲ModernMech 6 hours ago | parent | prev | next [-]

lol I got flagged for using the word fuzz, not even in a security context (it was a parser so security adjacent but still).

▲elevation 6 hours ago | parent [-]

Parsers are security adjacent until they aren't.

▲ModernMech 4 hours ago | parent [-]

Very true.

▲AIorNot 5 hours ago | parent | prev | next [-]

Give them a break, they got into a War with Trump over this..it will come soon enough

▲ 6 hours ago | parent | prev [-]
[deleted]