Skip to content

Comment on Anthropic's Project Glasswing Update

Comments

One of the links in Schneier's article makes a credible sounding case that Anthropic is using open source vulnerabilities as a shakedown operation.

When the model finds a vulnerability, it also finds a fix. Anthropic only shares the vulnerability with the Open Source maintainer, not the fix. Paying customers get fixes, confirming that the model does generate fixes for the vulnerabilities.

Sharing the vulnerabilities but not the fixes does sound like a shakedown operation.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.