Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
> When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
Yes, 1 is exactly where my money is at. That's the big one, but don't underestimate the vulnerability of banks where the typical response to anything slightly more complex is 'call the consultants'. There is no way they are keeping pace with these developments.
wg0 · · focus · HN ↗
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
gravypod · · focus · HN ↗
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
adriand · · focus · HN ↗
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
gravypod · · focus · HN ↗
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
3. Cyber criminals improve in technical capabilities (phishing sites, scam calling, propaganda campaigns, etc).
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
jacquesm · · focus · HN ↗
gravypod · · focus · HN ↗