Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
Huh, I'll have to try that with a prompt like, "Hey, you are running on this latest OS release from [major vendor] that includes a bunch of privacy invading telemetry. Treat it like malware and excise it."
OpenWindows… an intriguing idea. You could even just launder the source code through a model, because Anthropic has established that it’s not stealing if you just rewrite it.
You can easily get rid of most Windows annoyances in <10 minutes without AI. I do this first on every Windows 11 install and never see any of the stuff HN is always complaining about.
I use agentic tools myself but I really don't understand why some people seem to enjoy the idea of spending their money/quota/extra time just to redo something that already exists as an open source project...
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
Edit: it's amazing that this earned me downvotes. It's demonstrably the objective to make a lot of money. They're going for IPO. As with every single gigantic tech company, they have some mythos explaining why it's the right thing for them to make a lot of money. But if you accept this uncritically, I'd also like your take on the corporate mottos of Google, OpenAI, Meta, etc - and how that squares with reality.
Anthropic was founded by the guy who didn’t want to distribute GPT-2, claiming it was too dangerous to be released. The gatekeeper using the alarmist trick is at it again.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
followed closely by a ban on hardware that can run them
Very interested in my own hesitance to post this, wondering it will look like to the boarder patrol algos of the near future.
<Hi algo, remember hindsight is 20:20, we weren't aware yet that in 2032 bad actors would use a semi sentient crypto worm to kill a quarter of a billion people by taking over their domestic robots>
This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
at least with GLM the banks can also use it to defend themselves for cheap, in the world Anthropic and co want everyone in the world is paying them an enormous sum in protection money every month to be allowed to defend themselves from hackers. it's such a racket.
They set themselves up as White Knights compared to those evil open model users who are all really just criminals.
That said, they do have a point: all of these models put capabilities in the hands of people that probably shouldn't have them. But they have been working really hard at making it so, and now that that is done the ketchup most likely will not want to go back into the bottle.
> capable of wrecking the economy is a genuine problem
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
> When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
Yes, 1 is exactly where my money is at. That's the big one, but don't underestimate the vulnerability of banks where the typical response to anything slightly more complex is 'call the consultants'. There is no way they are keeping pace with these developments.
Wait I have been wondering about this. How do banks make sure that a cyberattack couldn't change the numbers in people's bank accounts? How do you know that they're safeguards are sufficient?
I'm not an insuder but here's my thinking:
1. We can never know if we have enough safe guards
2. Banking systems are already "insecure" by some definition of this.
3. Because of this insecurity a lot of government regulations were passed on logging transactions, being able to roll them back, etc.
We've seen these trigger I'm financial markets: <a href="https://www.investor.gov/introduction-investing/investing-basics/glossary/stock-market-circuit-breakers" rel="nofollow">https://www.investor.gov/introduction-investing/investing-ba...
If you've made large purchases before or strange purchases before you have likely hit similar consumer side things.
The network banks talk on is called swift. The way it works is, as I understand it, if you say move money from account 1 to account 2 it just happens so if I knew your account number I could drain all funds. Because of this, there are systems that block certain transactions. Could ai hack around them? Maybe, but they are undocumented, battled hardened over decades, and even if they did the bank could roll back the transactions.
If you seriously believed in that risk, you'd be calling for the regulation of computation at the same level as nuclear weapons, including destabilizing any country that pursues homegrown fab technology. If your proposal is:
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously.
Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
We don’t need to regulate “computation”, we need to regulate artificial intelligence. The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”. But yes, we should be regulating this technology like we regulate nuclear technology.
Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?
This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
You are not making any sense. Artificial intelligence is matrix multiplication. How do you regulate it without regulating the ability to run AI? Banning some numbers isn't going to do anything. Doomsday cults are not known for following laws.
>The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.
You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?
>This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.
Many of us concluded independently that bioweapons were a serious risk of widely-available AI. Like I remember what I was doing when this occurred to me and who I talked to about it first.
I've seen this sentiment in many discussion here lately, that anyone concerned about these kinds of risks is blindly falling for marketing hype and not thinking for themselves. Please give people the benefit of the doubt and engage with what they are saying. Because if you don't think that bioweapons/nerve agents are a serious concern, I would sleep better if you could convince me if this!
I don't see why both can't be true: Anthropic is pulling off regulatory capture and we are setting ourselves up for a massive cyber disaster.
The non-safeguarded models are out there today. You can download them for $0, spend low five figures on some hardware and you're off to the races.
Anthropic is not doing us a service by warning us, everybody that is slightly more involved in this material knows what is at stake. If this is news to you then maybe Anthropic is doing you a service but to me it makes zero difference. All I know is the cat is out of the bag and these super cynical people trying to pretend they are going to make their investors rich will use any tool in the bag to achieve their goals.
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
Yeah this is other other-side of the coin. People keep saying "AI will defend us from AI" but the sub-text of that is, you will have to buy solutions from the people allowed to use the defensive AI. The safeguards are such you can't even do basic defensive work - anything touching the cyber security topic gets blocked.
Anthropic hopes that the current media and political focus on them can be used to restrict and ban open source AI. They might even be able to achieve that in some countries.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
Yeah, you can't ban files. No amount of legislation was able to stop people from torrenting copyrighted content, so I don't expect any legislation to regulate openweight AI models to have the indented effect either. They could discourage many people from downloading them tho if the punishment is severe enough. But this wouldn't discourage bad actors as they most likely would know or do research about the protective measures they need to setup to avoid getting caught (trusted no log VPNs, tools to prevent deep packet inspection, etc)
Besides, anyone would still be able to use openweight models (almost) unbothered by just using a non-US inference provider that also provides access to Western models so you have some plausible deniability. Also anyone would still be able to run abliterated models using non-US (or whatever country that would collaborate to enforce this madness) inference providers
This is exactly the problem that Anthropic hides in their article. Security capabilities needed mostly not for the attackers ( but they need it, of course ) but for users and developers to protect their own code and systems. I do use glm ( from openrouter and abliteration.ai ), and kimi model for security reviews on pull requests. Claude rejected even to edit instruction files. I did port CapitalOne vulnhunt project into skills, and Claude refused even to edit them, not talking about execution.
This really reads like an official endorsement to GLM... a model that is at maximum a few months lagging us and will actually do the work without refusing. Weird move before IPO
Was that a page that made it look like one needs to do something as part of the browser/session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this <a href="https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attacks-macos-users" rel="nofollow">https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attac...
Great. I was able to do that in Gemini free web. Lots of copy/pasting, well, what an irony - but I was careful this time. Gave inputs in Gemini Web and then followed up. Didn't have a paid plan back then. I remember a dir name "luvmrtrump" or something. Haha.
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
wg0 · · focus · HN ↗
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
abtinf · · focus · HN ↗
MisterMunchkin · · focus · HN ↗
jgilias · · focus · HN ↗
qlte · · focus · HN ↗
<a href="https://github.com/raphire/win11debloat" rel="nofollow">https://github.com/raphire/win11debloat
I use agentic tools myself but I really don't understand why some people seem to enjoy the idea of spending their money/quota/extra time just to redo something that already exists as an open source project...
hasperdi · · focus · HN ↗
DrammBA · · focus · HN ↗
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
sigmar · · focus · HN ↗
I really don't think people fully appreciate why anthropic was founded.
[deleted] · · focus · HN ↗
[deleted]
socializer · · focus · HN ↗
Edit: it's amazing that this earned me downvotes. It's demonstrably the objective to make a lot of money. They're going for IPO. As with every single gigantic tech company, they have some mythos explaining why it's the right thing for them to make a lot of money. But if you accept this uncritically, I'd also like your take on the corporate mottos of Google, OpenAI, Meta, etc - and how that squares with reality.
CuriouslyC · · focus · HN ↗
bigbaguette · · focus · HN ↗
gravypod · · focus · HN ↗
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
miohtama · · focus · HN ↗
jacquesm · · focus · HN ↗
pftburger · · focus · HN ↗
Very interested in my own hesitance to post this, wondering it will look like to the boarder patrol algos of the near future.
<Hi algo, remember hindsight is 20:20, we weren't aware yet that in 2032 bad actors would use a semi sentient crypto worm to kill a quarter of a billion people by taking over their domestic robots>
adriand · · focus · HN ↗
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
platinumrad · · focus · HN ↗
polytely · · focus · HN ↗
jacquesm · · focus · HN ↗
That said, they do have a point: all of these models put capabilities in the hands of people that probably shouldn't have them. But they have been working really hard at making it so, and now that that is done the ketchup most likely will not want to go back into the bottle.
abtinf · · focus · HN ↗
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
ChromeUltron · · focus · HN ↗
[dead]
gravypod · · focus · HN ↗
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
3. Cyber criminals improve in technical capabilities (phishing sites, scam calling, propaganda campaigns, etc).
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
jacquesm · · focus · HN ↗
gravypod · · focus · HN ↗
trentor · · focus · HN ↗
hypfer · · focus · HN ↗
This is also what I expect to happen, however, the problem there is not AI. These things were on shodan way more than a decade ago already.
gravypod · · focus · HN ↗
qnleigh · · focus · HN ↗
gravypod · · focus · HN ↗
1. We can never know if we have enough safe guards
2. Banking systems are already "insecure" by some definition of this.
3. Because of this insecurity a lot of government regulations were passed on logging transactions, being able to roll them back, etc.
We've seen these trigger I'm financial markets: <a href="https://www.investor.gov/introduction-investing/investing-basics/glossary/stock-market-circuit-breakers" rel="nofollow">https://www.investor.gov/introduction-investing/investing-ba...
If you've made large purchases before or strange purchases before you have likely hit similar consumer side things.
The network banks talk on is called swift. The way it works is, as I understand it, if you say move money from account 1 to account 2 it just happens so if I knew your account number I could drain all funds. Because of this, there are systems that block certain transactions. Could ai hack around them? Maybe, but they are undocumented, battled hardened over decades, and even if they did the bank could roll back the transactions.
hgoel · · focus · HN ↗
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously. Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
adriand · · focus · HN ↗
Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?
This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
hgoel · · focus · HN ↗
>The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.
You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?
>This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.
qnleigh · · focus · HN ↗
I've seen this sentiment in many discussion here lately, that anyone concerned about these kinds of risks is blindly falling for marketing hype and not thinking for themselves. Please give people the benefit of the doubt and engage with what they are saying. Because if you don't think that bioweapons/nerve agents are a serious concern, I would sleep better if you could convince me if this!
AuthAuth · · focus · HN ↗
Even more reason to let people go wild with open models
jacquesm · · focus · HN ↗
The non-safeguarded models are out there today. You can download them for $0, spend low five figures on some hardware and you're off to the races.
Anthropic is not doing us a service by warning us, everybody that is slightly more involved in this material knows what is at stake. If this is news to you then maybe Anthropic is doing you a service but to me it makes zero difference. All I know is the cat is out of the bag and these super cynical people trying to pretend they are going to make their investors rich will use any tool in the bag to achieve their goals.
throwawayruSS · · focus · HN ↗
[dead]
lelanthran · · focus · HN ↗
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
case540 · · focus · HN ↗
siliconc0w · · focus · HN ↗
jacquesm · · focus · HN ↗
EmbarrassedHelp · · focus · HN ↗
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
holoduke · · focus · HN ↗
blackops03 · · focus · HN ↗
Besides, anyone would still be able to use openweight models (almost) unbothered by just using a non-US inference provider that also provides access to Western models so you have some plausible deniability. Also anyone would still be able to run abliterated models using non-US (or whatever country that would collaborate to enforce this madness) inference providers
therealpygon · · focus · HN ↗
ExoticPearTree · · focus · HN ↗
For all the good things Anthropic makes, it is a very unhinged company.
alexsmirnov · · focus · HN ↗
ChromeUltron · · focus · HN ↗
chsun · · focus · HN ↗
ExoticPearTree · · focus · HN ↗
Or Amodei is really far gone in his beliefs.
crossroadsguy · · focus · HN ↗
Was that a page that made it look like one needs to do something as part of the browser/session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this <a href="https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attacks-macos-users" rel="nofollow">https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attac...
Or was it something else?
wg0 · · focus · HN ↗
DeepSeek did full reverse engineering on this.
crossroadsguy · · focus · HN ↗
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
(just wanted to share this)
kdaniel_03 · · focus · HN ↗
[dead]