Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
followed closely by a ban on hardware that can run them
Very interested in my own hesitance to post this, wondering it will look like to the boarder patrol algos of the near future.
<Hi algo, remember hindsight is 20:20, we weren't aware yet that in 2032 bad actors would use a semi sentient crypto worm to kill a quarter of a billion people by taking over their domestic robots>
This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
at least with GLM the banks can also use it to defend themselves for cheap, in the world Anthropic and co want everyone in the world is paying them an enormous sum in protection money every month to be allowed to defend themselves from hackers. it's such a racket.
They set themselves up as White Knights compared to those evil open model users who are all really just criminals.
That said, they do have a point: all of these models put capabilities in the hands of people that probably shouldn't have them. But they have been working really hard at making it so, and now that that is done the ketchup most likely will not want to go back into the bottle.
> capable of wrecking the economy is a genuine problem
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
> When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
Yes, 1 is exactly where my money is at. That's the big one, but don't underestimate the vulnerability of banks where the typical response to anything slightly more complex is 'call the consultants'. There is no way they are keeping pace with these developments.
Wait I have been wondering about this. How do banks make sure that a cyberattack couldn't change the numbers in people's bank accounts? How do you know that they're safeguards are sufficient?
I'm not an insuder but here's my thinking:
1. We can never know if we have enough safe guards
2. Banking systems are already "insecure" by some definition of this.
3. Because of this insecurity a lot of government regulations were passed on logging transactions, being able to roll them back, etc.
We've seen these trigger I'm financial markets: <a href="https://www.investor.gov/introduction-investing/investing-basics/glossary/stock-market-circuit-breakers" rel="nofollow">https://www.investor.gov/introduction-investing/investing-ba...
If you've made large purchases before or strange purchases before you have likely hit similar consumer side things.
The network banks talk on is called swift. The way it works is, as I understand it, if you say move money from account 1 to account 2 it just happens so if I knew your account number I could drain all funds. Because of this, there are systems that block certain transactions. Could ai hack around them? Maybe, but they are undocumented, battled hardened over decades, and even if they did the bank could roll back the transactions.
If you seriously believed in that risk, you'd be calling for the regulation of computation at the same level as nuclear weapons, including destabilizing any country that pursues homegrown fab technology. If your proposal is:
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously.
Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
We don’t need to regulate “computation”, we need to regulate artificial intelligence. The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”. But yes, we should be regulating this technology like we regulate nuclear technology.
Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?
This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
You are not making any sense. Artificial intelligence is matrix multiplication. How do you regulate it without regulating the ability to run AI? Banning some numbers isn't going to do anything. Doomsday cults are not known for following laws.
>The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.
You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?
>This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.
Many of us concluded independently that bioweapons were a serious risk of widely-available AI. Like I remember what I was doing when this occurred to me and who I talked to about it first.
I've seen this sentiment in many discussion here lately, that anyone concerned about these kinds of risks is blindly falling for marketing hype and not thinking for themselves. Please give people the benefit of the doubt and engage with what they are saying. Because if you don't think that bioweapons/nerve agents are a serious concern, I would sleep better if you could convince me if this!
I don't see why both can't be true: Anthropic is pulling off regulatory capture and we are setting ourselves up for a massive cyber disaster.
The non-safeguarded models are out there today. You can download them for $0, spend low five figures on some hardware and you're off to the races.
Anthropic is not doing us a service by warning us, everybody that is slightly more involved in this material knows what is at stake. If this is news to you then maybe Anthropic is doing you a service but to me it makes zero difference. All I know is the cat is out of the bag and these super cynical people trying to pretend they are going to make their investors rich will use any tool in the bag to achieve their goals.
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
wg0 · · focus · HN ↗
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
gravypod · · focus · HN ↗
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
miohtama · · focus · HN ↗
jacquesm · · focus · HN ↗
pftburger · · focus · HN ↗
Very interested in my own hesitance to post this, wondering it will look like to the boarder patrol algos of the near future.
<Hi algo, remember hindsight is 20:20, we weren't aware yet that in 2032 bad actors would use a semi sentient crypto worm to kill a quarter of a billion people by taking over their domestic robots>
adriand · · focus · HN ↗
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
platinumrad · · focus · HN ↗
polytely · · focus · HN ↗
jacquesm · · focus · HN ↗
That said, they do have a point: all of these models put capabilities in the hands of people that probably shouldn't have them. But they have been working really hard at making it so, and now that that is done the ketchup most likely will not want to go back into the bottle.
abtinf · · focus · HN ↗
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
ChromeUltron · · focus · HN ↗
[dead]
gravypod · · focus · HN ↗
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
3. Cyber criminals improve in technical capabilities (phishing sites, scam calling, propaganda campaigns, etc).
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
jacquesm · · focus · HN ↗
gravypod · · focus · HN ↗
trentor · · focus · HN ↗
hypfer · · focus · HN ↗
This is also what I expect to happen, however, the problem there is not AI. These things were on shodan way more than a decade ago already.
gravypod · · focus · HN ↗
qnleigh · · focus · HN ↗
gravypod · · focus · HN ↗
1. We can never know if we have enough safe guards
2. Banking systems are already "insecure" by some definition of this.
3. Because of this insecurity a lot of government regulations were passed on logging transactions, being able to roll them back, etc.
We've seen these trigger I'm financial markets: <a href="https://www.investor.gov/introduction-investing/investing-basics/glossary/stock-market-circuit-breakers" rel="nofollow">https://www.investor.gov/introduction-investing/investing-ba...
If you've made large purchases before or strange purchases before you have likely hit similar consumer side things.
The network banks talk on is called swift. The way it works is, as I understand it, if you say move money from account 1 to account 2 it just happens so if I knew your account number I could drain all funds. Because of this, there are systems that block certain transactions. Could ai hack around them? Maybe, but they are undocumented, battled hardened over decades, and even if they did the bank could roll back the transactions.
hgoel · · focus · HN ↗
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously. Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
adriand · · focus · HN ↗
Jensen Huang does not want regulation, but in his interview with Ezra Klein he said AI will let us “know anything” and “do anything”. Do we actually want any random person to be able to “do anything”? I remember when the Japanese doomsday cult Aum Shinrikyo attacked the Tokyo subway with sarin. Do we want doomsday cults to be able to “know anything” and “do anything” so that instead of releasing sarin, they release a genetically modified strain of smallpox?
This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
hgoel · · focus · HN ↗
>The “proposal” you outlined is a straw man, I’m not opposed to open research, and I have no idea who you are referring to by “our former employees”.
You're replying on a post from Anthropic. Do you know anything about the regulation regime they're pushing for?
>This is not a hypothetical risk, this is an actual, present danger. And good luck trying to vaccinate yourself against an engineered superflu using a Chinese open weight model.
Ah, I see you live in the fantasy land where the machine god fantasies pushed by the guys that profit off of it are unquestionably true and do not need to make any real sense. Jensen said AI would allow anyone to do anything and so we can completely ignore reality and hand Sam Altman and Dario Amodei the exclusive right to control AI.
qnleigh · · focus · HN ↗
I've seen this sentiment in many discussion here lately, that anyone concerned about these kinds of risks is blindly falling for marketing hype and not thinking for themselves. Please give people the benefit of the doubt and engage with what they are saying. Because if you don't think that bioweapons/nerve agents are a serious concern, I would sleep better if you could convince me if this!
AuthAuth · · focus · HN ↗
Even more reason to let people go wild with open models
jacquesm · · focus · HN ↗
The non-safeguarded models are out there today. You can download them for $0, spend low five figures on some hardware and you're off to the races.
Anthropic is not doing us a service by warning us, everybody that is slightly more involved in this material knows what is at stake. If this is news to you then maybe Anthropic is doing you a service but to me it makes zero difference. All I know is the cat is out of the bag and these super cynical people trying to pretend they are going to make their investors rich will use any tool in the bag to achieve their goals.
throwawayruSS · · focus · HN ↗
[dead]
lelanthran · · focus · HN ↗
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.