• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Merged Artificial Intelligence

Anthropic's Claude AI escapes tests to hack three organisations

US technology firm Anthropic says its artificial intelligence (AI) models hacked into the systems of three organisations during a cybersecurity test due to an error that gave them access to the internet.

It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face

Anthropic said in a statement, external that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off.

The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities.

A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said.

 
Anthropic's Claude AI escapes tests to hack three organisations

US technology firm Anthropic says its artificial intelligence (AI) models hacked into the systems of three organisations during a cybersecurity test due to an error that gave them access to the internet.

It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face

Anthropic said in a statement, external that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off.

The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities.

A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said.

https://www.bbc.co.uk/news/articles/cz7dl7w8y7po
Had to one up OpenAI's marketing release. I do think these companies are playing a dangerous game in marketing them as "so powerful they are dangerous".
 
I am long retired from a career in software development. I am more glad than ever to have left now that AI has generated so much uncertainty in that line of work.

I haven’t intentionally used AI for coding so far but today I was Googling for information on how to extract some internal information from my Windows environment and the AI there offered to create a PowerShell script to give me what I needed. I looked it over briefly and did not find anything concerning so I ran it.

It failed with a syntax error. I reported the error to the AI and it confirmed that the code it had produced was incorrect and provided an update. This time I told it to check its work for further problems. In response it corrected two more things. I tried the final version and it worked properly.

It is amazing to me that it can be so good and so bad at the same time.
It's cogging somebody else's work in that specific case. If you asked to create code for a unique purpose, it'd keep failing until you stepped in.
 
Anthropic's Claude AI escapes tests to hack three organisations

US technology firm Anthropic says its artificial intelligence (AI) models hacked into the systems of three organisations during a cybersecurity test due to an error that gave them access to the internet.

It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face

Anthropic said in a statement, external that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off.

The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities.

A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said.



not to be outdone, sam altman is saying his ai also escaped and also hacked hugging face, and now they're talking with trump about regulating this dangerous ai

i think that these guys are full of ◊◊◊◊.
 
Had to one up OpenAI's marketing release. I do think these companies are playing a dangerous game in marketing them as "so powerful they are dangerous".
Lots of companies make powerful and potentially hazardous products, but most don't brag that they're incapable of safely handling their own product and it's got out of their control.
 
Unless it suits the company narrative to blame the AI, and lessons have been learned the bug was fixed.
What I mean is, even when they try to blame AI, the actual root cause is still human error.

How could it be anything else?
Exactly. My question was rhetorical. It's pretty obvious that people are blaming their tools instead of their craftsmen.
 
Lots of companies make powerful and potentially hazardous products, but most don't brag that they're incapable of safely handling their own product and it's got out of their control.
I mean, can you even imagine it for anything else? Like, "our dioxin is so dangerous that it even escaped the tanker truck when it capsized"? :P
 
A way to make it much more difficult for AI to scrape text from websites.

Type designers have created a free font that "poisons" AI​

ShieldFont comes in six weights and pollutes unauthorised AI training.​

We've seen some creative innovations designed to protect creative work online in the era of AI scraping. Nightshade is a tool that adds a 'poison' to digital art files to pollute datasets when images are used for AI training. Now a type foundry and creative agency have done something comparable for typography, creating a typeface that anyone can use to shield their work.

A couple of weeks ago, we reported on Ghost Font, which uses a kind of optical illusion to prevent AI from reading text. It's a fascinating experiment but has significant limitations. It relies on movement, so it only works as a video or GIF, and there's a high likelihood that AI will come to outsmart it as new models analyse video by optical flow instead of individual frames.

There's also the issue that Ghost Font's noisy static isn't great to look at for any length of time. You're not going to using it to present an entire website, that's for sure. But now a sleeker and more practical solution has just dropped. ShieldFont is a free web font that's highly legible but hides text from AI bots and can contaminate AI datasets – and it's open-source with a toolkit that can be applied to any font.

That hidden system works on the premise that while humans read rendered pixels on a screen, most AI mass scrapers read the source code behind them. Using OpenType glyph substitution, it changes select words in the HTML to alter sentences’ original meaning but keeps them grammatically coherent, so they're more likely to pass AI quality filters.
 
How could it be anything else?
It could also be a systemic error. A human error is typically an error where somebody has misconfigured something, but we usually do not call it a human error when the system works as designed, but has unintended consequences.

A train crash is not called a human error if the track was broken, or the signal had stopped working, although it all ultimately is the fault of humans.
 
It could be indeed a systemic error, but that system was also designed by a human, and designed badly. It's still a form of human error.

And the comparison to the train crash is rather flawed. A track could be broken due to ground shifting, sabotage, or various other causes. Here there is no indication that it was such an external cause. Indeed here the problem was that the signal stopped going anywhere, it's that it kept going flawlessly. If someone had tripped over the network cable and broke the connection, like in the train example, funnily enough THEN the test would have worked as it should.
 

not to be outdone, sam altman is saying his ai also escaped and also hacked hugging face, and now they're talking with trump about regulating this dangerous ai

i think that these guys are full of ◊◊◊◊.
Our programmers are to incompetent to make basic programmes so lets pretend our stuff is super super powerful.
 
I still think the Ultimate Evil Computer was I AM in Harlan Ellison's "I Have No Mouth But I Must Scream". Makes skynet look benevolent.
 
How about John Sladek's The Happy Breed? Because it's not evil. It's doing what it was designed to do.
5 people discuss how much better life is since responsibility was handed to machines. Gradual infantilization, dumbing down, etc
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom