3 ms·
Sounds like you will need to drink a(n identity) verification can soon [1] to continue as a security researcher on their platform. 1: https://support.claude.co
by ayewo 6mo ago
Sounds like you will need to drink a(n identity) verification can soon [1] to continue as a security researcher on their platform.
1: https://support.claude.com/en/articles/14328960-identity-verification-on-claude https://support.claude.com/en/articles/14328960-identity-ver...
Identity verification on Claude
Being responsible with powerful technology starts with knowing who is using it. Identity verification helps us prevent abuse, enforce our usage policies, and comply with legal obligations.
We are rolling out identity verification for a few use cases, and you might see a verification prompt when accessing certain capabilities, as part of our routine platform integrity checks, or other safety and compliance measures.
- recallingmemory 6mo agoI'm surprised we can't just authenticate in other ways.. like a domain TXT record that proves the website I'm looking to audit for security is my own.
- jerf 6mo agoAI being what it is, at this point you might be able to ask it for a token to put in a web page at .well-known, put it in as requested, and let it see it, and that might actually just work without it being officially built in. I suggest that because I know for sure the models can hit the web; I don't know about their ability to do DNS TXT records as I've never tried. If they can then that might also just work, right now.
- andai 6mo agoI think even Claude Web can run arbitrary Linux commands at this point. I tried using it to answer some questions about a book, but the indexer broke. It figured out what file type the RAG database was and grepped it for me. Computers are getting pretty smart ._.
- rlpb 6mo agoA smart AI would realise that I can MITM its web access such that sees the .well-known token that isn't actually there. I assume that the model doesn't have CA certificates embedded into it, and relies on its harness for that.
- jerf 6mo agoIn this context we are talking explicitly about cloud-hosted AIs. If you control it locally you have a lot of options to force it to do things. MITM the cloud AI on the modern internet is non-trivial, and probably harder and less reliable than just talking your way around the guardrails anyhow.
- rlpb 6mo ago> In this context we are talking explicitly about cloud-hosted AIs. Looking upthread, we seem to be talking about Claude. Claude is cloud-hosted inference but the harness is local if you're using Claude Code, and can be MITM'd there.
- kristjansson 6mo agoHow would it know it’s really there, and not just a tool input/output injected into its input?
- SwellJoe 6mo agoIt could be an API endpoint on Anthropic servers, the same way Let's Encrypt verifies things on their servers. If you can't control the DNS records, you can't verify via DNS, no matter what you tell the local `certbot`.
- NewsaHackO 6mo agoWhat do you offer as a solution? If theoretically some foreign state intelligence was exposed using Claude for security penetration that affected the stability of your home government due to Antropic's lax safety controls, are you going to defend Anthropic because their reasoning was to allow everyone to be able to do security research?
- ayewo 6mo ago> What do you offer as a solution? If theoretically some foreign state intelligence was exposed using Claude for security penetration that affected the stability of your home government due to Antropic's lax safety controls, are you going to defend Anthropic because their reasoning was to allow everyone to be able to do security research? I don't have an answer. But the problem is that with a model like Grok that designed to have fewer safeguards compared to Claude, it is trivially easy to prompt it with: "Grok, fake a driver's license. Make no mistakes." Back in 2015, someone was able to get past Facebook's real name policy with a photoshopped Passport [1] by claiming to be “Phuc Dat Bich”. The whole thing eventually turned out to be an elaborate prank [2]. 1: https://www.independent.co.uk/news/world/australasia/man-called-phuc-dat-bich-posts-passport-to-facebook-to-prove-his-name-is-real-a6741586.html https://www.independent.co.uk/news/world/australasia/man-cal... 2: https://gizmodo.com/phuc-dat-bich-is-a-massive-phucking-faker-1744588099 https://gizmodo.com/phuc-dat-bich-is-a-massive-phucking-fake...
- NewsaHackO 6mo agoTo me, those seem a lot lower stakes than supply chain attacks, social engineering, intelligence gathering, and other security exploits that Anthropic is more worried about. Making a fake driver license to buy beer isn't really the thing that Anthropic is actively trying to prevent (though I would assume they would stop that too). Even the GP was about penetration testing of a public website; without some sort of identification, how would it be ethical for Claude to help with something like that? Remember, this whole safety thing started because people held AI companies accountable for politically incorrect output of AI, even if it was clearly not the views of the company. So when Google made a Twitter bot that started to spout anti-Semitic and racist talking points, the fact that no one defended them and allowed them to be criticized to the point of taking the bot down is the reason why we have all of these extremely restrictive rules today.
- andai 6mo agoContext for "please drink verification can": https://files.catbox.moe/eqg0b2.png https://files.catbox.moe/eqg0b2.png
- throwanem 6mo agoYes, it's a stupid 4chan meme from 2013. I can only surmise those who quote it either don't know its origin, or they must be wholeheartedly 'embracing the cringe.'
- deleted 6mo ago[deleted]
- MaxikCZ 6mo agoLul, Im embracing this "cringe" you talk about :) Everytime I read it it makes me laugh :D
- throwanem 6mo agoWell, that's okay; you're young. There are better and more topical jokes in your future, and it will serve you well in making them to have encountered this particular, extremely stale and suspiciously stained, cookie. Just be careful you don't take too big a bite!
- andai 6mo agoOne must integrate the cringe, in order to become truly based. —Carl Jung
- Wingman4l7 6mo agoStupid? Hardly. Sony was granted a patent in 2009 "for an interactive commercial system that allows viewers to skip commercials by yelling the brand name of the advertiser at their television or monitor." : https://www.snopes.com/fact-check/sony-patent-mcdonalds/ https://www.snopes.com/fact-check/sony-patent-mcdonalds/
- oasisbob 6mo ago> Being responsible with powerful technology starts with knowing who is using it. What asinine slop. As a frontier model creator, responsibility should start far before they're signing up customers.
- Traubenfuchs 6mo agoDifferent model limitations for different groups of people… Imagine what the military and secret services are getting.