I could really benefit from experts' analysis of this WSJ article reporting that China-backed hackers used Anthropic’s Claude to automate 80% to 90% of a September hacking campaign targeting corporations and governments.
There aren't a lot of specifics, but among those provided:
The effort focused on dozens of targets and involved a level of automation that Anthropic’s cybersecurity investigators had not previously seen.
In this instance 80% to 90% of the attack was automated, with humans only intervening in a handful of decision points.
The hackers conducted their attacks “literally with the click of a button, and then with minimal human interaction."
Anthropic disrupted the campaign and blocked the hackers’ accounts, but not before as many as four intrusions were successful.
In one case, the hackers directed Claude tools to query internal databases and extract data independently.
“The human was only involved in a few critical chokepoints, saying, doesn’t look right, Claude, are you sure?’” ‘Yes, continue, ’ ‘Don’t continue, ’ ‘Thank you for this information, ’ ‘Oh, that
Stitching together hacking tasks into nearly autonomous attacks is a new step in a growing trend of automation that is giving hackers additional scale and speed.
We've seen so many exaggerated accounts of AI-assisted hacks. Is this another one? Are there reasons to take this report more seriously? Any other thoughts?
In 20 minutes NY AG Letitia James will participate in the Conde Nast union rally supporting 4 of our colleagues who were illegally fired. If you're near WTC in Manhattan, please show your support.
Wow, the lack of ANY factual support for such a claim amounts to hyperbole. And from a CEO peddling a service to "guarantee content integrity." File this one under "Umbrella salesman predicts torrential rain."
"The former executive of Trenchant who pleaded guilty this week to selling his company's software hacking tools to a zero-day broker in Russia, sold at least one of these tools to the Russian firm even after learning that a previous tool he sold the broker was being used by a South Korean broker – indicating that the stolen tools were being passed on to others downstream."
A reminder that if you're not following @kimzetter you should be.
People working on post-quantum-proofing vulnerable encryption protocols (and curious onlookers) can find lots of value in this new post from Cloudflare. It discusses the herculean engineering challenges of revamping anonymous credentials that will be broken by a quantum computer. There's a growing need for this kind of privacy (for instance to make digital drivers licenses privacy preserving), which allows individuals to prove specific facts, like they have had a drivers license for more than 3 years, without divulging personal information like their birthday or place of birth. The long and short of of the challeng is that engineers can't simply drop quantum-resistant algorithms into AC protocols that currently use vulnerable ones. Instead, engineers will need to collaborate with standards bodies that build entirely new protocols, largely from scratch. The post goes on to name a few of the most promising approaches.
As @kimzetter reported recently, a CISA official blamed democrats during a press call. very concerning that even securing the nations infrastructure isn't immune from politicization.
Can anyone recommend a free, secure way for someone with only a Chromebook to manage passwords? The person isn't very good with computers, so usability is a must.
"When you look closer at Benioff’s big investment [in San Francisco], it becomes clear that the move was as cartoonishly fake as the forest characters Salesforce uses in its branding. In real life, that $15-billion “investment” isn’t an investment at all, but rather business as usual for Salesforce, which is the city’s largest private employer and has been headquartered here since it was founded in 1999."
As the wave of authoritarianism keeps cresting, I've been challenging myself and others to ween ourselves off of centralized platforms that leak our private data (through breaches or voluntarily) and deplatform us for any reason or no reason, leaving us high and dry with no warning. You know this is awful when labor unions, civil rights groups and other groups under threat continue to trust Slack, Gmail, Xitter and the rest now of the broligarch-owned gatekeepers more than ever.
Some of you (and in some cases I) have responded with criticism of those still using these platforms. Many of you say unions should use decentralized alternatives such as Zulip, PGP on top of Slack, Mattermost, Matrix. Besides victim blaming, this response is misguided because it expects groups divert resources from their core missions to making immature and hard-to-use platforms work inside their organization.
All of this reminds me of the struggles we had with our dependence on unencrypted email in the 2000s and early 2010s. Back then, the only alternative was PGP, which was unusable for 50% or more of email senders. Then @signalapp came along and solved most of the sticking points, almost overnight.
The lesson: decentralized, privacy-preserving platforms don't happen by accident. And they can't be cobbled together in beta form. They require funding and smart engineering that prioritizes usability as much as security.
I'm still not sure how we ween ourselves off of centralized platforms, but I think the success of Signal may serve as a useful model. Maybe we don't try to replace all platforms at once, Maybe for now we focus on finding an alternative to, say, Slack and use the momentum of that to tackle other platforms afterward.
I obviously don't have answers yet. I don't think anyone does yet. But it's important we start asking questions and stop blaming non-technologists who just want a platform that works.
The owner of Slack, the platform so many of us security and MAGA critics use both for work and other communications, is offering its AI capabilities to to help ICE staff up as it expands immigration raids and deportations around the US. Salesforce's CEO last week called for Trump to deploy the National Guard to San Francisco.
"Godfather of Silicon Valley" Ron Conway resigns from Salesforce board after its CEO revealed his authoritarian leanings by calling on Tump to send national guards to San Francisco. "“It saddens me immensely to say that with your recent comments, and failure to understand their impact, I now barely recognize the person I have so long admired,” Conway tells Marc Benioff in an email.
Here's another reminder that it's best to resist as much as possible the siren's call of relying on AI and other services from Big Tech. Gemini is blocking questions about Trump showing signs of dementia even as it answers the same question when applied to Biden. When we turn to AI we are abdicating our own judgement and research responsibilities to a broligarchy that bends to the whims of billionaires.
Now that Marc Benioff, owner of Slack and Salesforce, has confirmed he sides with authoritarianism, it's more incumbent on us than ever to move off central platforms, which can dump communications we presumed were private or cut us off for any reason or no reason at all.
The complexity and problem-solving required for making the Signal Protocol quantum safe are as daunting as any in modern-day engineering. In less adept hands, mucking about with an instrument as complex as the Signal protocol could have led to shortcuts or unintended consequences. Yet this latest post-quantum upgrade is nothing short of a triumph.
After 25 years, I still struggle to find an intuitive way to describe computer "state" to non-techies. Such a simple thing and yet I still don't know how to give it a simple description/definition.
Can you imagine the huge bonanza espionage and ransomware threat actors are going to have when every service you use forces you to provide them with your ID? This is a disaster that 100% will happen. I can hardly wait.
A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default. Senator Ron Wyden went on to liken Microsoft to an "arsonist selling firefighting services to their victims.”