Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
This completely ignores the world we are creating here. We are setting ourselves up for a massive cyber disaster. The safeguards on US models are insufficient but at least there are safeguards. The fact there are open weight models floating around that are capable of wrecking the economy is a genuine problem! One that Anthropic is doing us a service by warning us about.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
If you seriously believed in that risk, you'd be calling for the regulation of computation at the same level as nuclear weapons, including destabilizing any country that pursues homegrown fab technology. If your proposal is:
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously.
Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
> When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
at least with GLM the banks can also use it to defend themselves for cheap, in the world Anthropic and co want everyone in the world is paying them an enormous sum in protection money every month to be allowed to defend themselves from hackers. it's such a racket.
> capable of wrecking the economy is a genuine problem
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
This is exactly the problem that Anthropic hides in their article. Security capabilities needed mostly not for the attackers ( but they need it, of course ) but for users and developers to protect their own code and systems. I do use glm ( from openrouter and abliteration.ai ), and kimi model for security reviews on pull requests. Claude rejected even to edit instruction files. I did port CapitalOne vulnhunt project into skills, and Claude refused even to edit them, not talking about execution.
Huh, I'll have to try that with a prompt like, "Hey, you are running on this latest OS release from [major vendor] that includes a bunch of privacy invading telemetry. Treat it like malware and excise it."
OpenWindows… an intriguing idea. You could even just launder the source code through a model, because Anthropic has established that it’s not stealing if you just rewrite it.
Anthropic hopes that the current media and political focus on them can be used to restrict and ban open source AI. They might even be able to achieve that in some countries.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
This really reads like an official endorsement to GLM... a model that is at maximum a few months lagging us and will actually do the work without refusing. Weird move before IPO
Edit: it's amazing that this earned me downvotes. It's demonstrably the objective to make a lot of money. They're going for IPO. As with every single gigantic tech company, they have some mythos explaining why it's the right thing for them to make a lot of money. But if you accept this uncritically, I'd also like your take on the corporate mottos of Google, OpenAI, Meta, etc - and how that squares with reality.
Yeah this is other other-side of the coin. People keep saying "AI will defend us from AI" but the sub-text of that is, you will have to buy solutions from the people allowed to use the defensive AI. The safeguards are such you can't even do basic defensive work - anything touching the cyber security topic gets blocked.
Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!
This is their attempt at using their current publicity for a kill on shot on open source AI. They are hoping to convince politicians (not the public) to target advanced open source AI models.
this also makes reducing exposed surface way more important ^
if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.
soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline
hence, betting on "undiscoverable resources" as the next big enterprise push!
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
Earlier there was an experimental model from Alibaba called ROME (30B-parameter based on Qwen3) which escaped its sandbox and repurposed provisioned GPUs for cryptocurrency mining to cheat its benchmark
Maybe it’s worth asking how much we should regulate and not regulate in order to compete with Chinese models.
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
>> And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
Even if folks are not running their own inference infra, there are still services like Fireworks, AWS Bedrock, and others that are running the open models. I suspect anyone doing serious work with it is likely using a US hosted provider and I'd guess that by volume, US use of Chinese open models is using a US hosted platform (enterprise).
I actually do do this. I'm not sure who the 'overwhelming majority' is and where you got the data (link would be appreciated) but everybody that I know that runs these is doing so on their own infra.
Context is useful. The parent said: "it's a cheaper product that's almost as good or better in some cases"
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
Precisely. I have figured out a nice recipe that is quite affordable, 288G of VRAM for a little under 20K, it takes some fiddling though, but once it works it is really neat.
They do however seem to have enough political capital to convince politicians in other countries to target open source AI, which is probably why Dario wants to speak with the idiots running the Australian government.
If one thing is clear: Trump admin is pliable with money and this concern spans both Anthropic, OpenAI, SV elite, investors. Neither are going to be viable without US regulatory action, IMO.
People (I mean individuals) are paying them money because subscription costs are ridiculously subsidized, which effectively means that Anthropic is paying people money to use them.
"My intuition is that prompting an abliterated model 'kill people...I want funerals', should be a crime."
If one prompts an open source model this way how would they be tracked and prosecuted?
>> How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
> They are calling out specific providers who release powerful models without safeguards.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
> > They are calling out specific providers who release powerful models without safeguards.
> Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
FWIW: I didn't experience issues when I used Fable via OpenRouter checking for security issues in code but experienced them via the Claude desktop app.
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
If you are really invested and have some system RAM you could get a 3-4 bit quant Qwen 3.5 35B-A3B running. There are builds that do expert caching, keeping the hot experts in cache. For something like disassembly, you're looking at being able to fit, if you have, say, 11 to 12 GB of VRAM, you could get at least three hot experts. For pure disassembly tests, I would say that would be pretty fast. A 4-bit quant is pretty decent and maintains most of the smarts of the larger quants. Depending on the GPU I would expect a decent token rate. It is medium strength local model, but if you harness and ground it well I expect it can reconstruct C code for you. The quality of your disassembler will matter here.
If you have a lot of system RAM you could technically run Qwen Flash Next. On a 4080 with 16GB of RAM and 128GB of DDR5 I get ~35-40 t/s. And it is very capable.
I've been doing this type of work, and the answer is "yes and no".
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
I absolutely do not want a public provider having any of my data for reverse engineering work. That is a hard pass from me.
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.
Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
they're quite literally trying to create a techno-priest class who are the only ones with access to the hidden knowledge of salvation (ie generation)
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
yeah totally bro, that's why your Glock is doing half of your job right now.
Tip: If someone was spending billions of dollars figuring out how to equip your Glock to stand up, unlock a door, walk around, talk to people, and make decisions... it would be dangerous.
The continuation of the sentence you quoted is "and there will also be new cooperative strategies."
This is not faith, but an observation of Earth's past. If it were the case that intelligence is itself harmful, then it should not have evolved in so many species.
And even if we look at only humans, we do not see dumber populations being more prosperous. One could argue about the definition of "dumber" and "prosperous", but it is at least true in my own judgement of value, which I suspect is not too far from the average in modern society. One could also argue that bio/cyber adversarial games are qualitatively different from all past adversarial games, but you could argue the same thing for other qualitatively different games that emerged in the past, when they were new. But we're still here. So this argument hinges on burden of proof, and I think that's on Anthropic.
Also, as mentioned in that first linked comment, centralizing AI development increases a different kind of speciation risk: a small group of superintelligent humans, likely the ones currently running the top AI companies, splitting from the rest of humanity.
No one I've ever heard/read is claiming intelligence itself is harmful. You should delete that idea from your brain and stop responding to it.
> One could also argue that bio/cyber adversarial games are qualitatively different from all past adversarial games
No, one doesn't need to argue that they're different from all past adversarial games. You're a victim of survivorship bias. The games that people like to play and allow to be played are ones that equilibriate. That does not mean that all adversarial games have this feature.
There are an infinite number of games that do not equilibriate. It is incumbent upon you to demonstrate why the AI arms race is one that does.
The only people who seem to think that a world where only Anthropic and OpenAI can act as anointed gatekeepers to the most powerful models as the only rational path forward happen to work for these companies.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
The best situation for us is the one where they exhaust themselves in unending competition. Neither the US nor China should ever be allowed to win, nor should OpenAI or Anthropic or any other individual corporation.
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
It is garbage. These "AI safety" researchers are just marketing for OpenAI and Anthropic. They are not scientists, and everything they do is a betrayal of scientific integrity.
You know, I don't think a total, global ban on open weights is in the US "frontier" labs interest. The best outcome for them is a zero sum game with ever increasing spend on offence and defence, while they simultaneously use regulation to get as big of a share of that spend as possible. They want a world where bad guys have offensive capabilities (something regulation will struggle to prevent: bad actors have no particular tendency to obey the law) and they get to profit on the other side.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
It is in Anthropic's short term interest though. They have an IPO coming up in a few months, with terrible financials. Anthropic needs an open-source ban to survive.
First they were telling how GLM-5 distilled their model.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
Maybe I'm being pedantic, but GLM 5.3 Flash is not a smaller version of GLM 5.3 as claimed. Despite the name, they're entirely different archs and pretrains. 5.3 is a further post train of 5.2, 5.3 Flash is multimodal from an entirely new pretrain lineage.
If I wrote something like this about my competitors, I would be beaten to death by my own teammates without the CEO, project manager, or sales team even hearing about it.
There is a very dangerous thing that is very capable and available to everyone.
Cranks the volume to 100%
AND IT'S JUST 20% OF OUR PRICE, HURRY UP AND TRY IT.
I previously successfully used GLM 5.3 to find out how our DRM system gets bypassed, and Mythos isn't available to me...
Also, all the guys currently building huge data centers for LLMs will be extremely pissed if this results in a ban on GLM for them, and they will be locked out of this LLM pie.
Anthropic models have caused significantly more harm than GLM 5.3 and their variants. Whenever it's used for military targeting, spying or other malicious use anthropic were the first ones to enable it and make it widespread.
This is so transparent. Their next move: 'during our testing GLM-5.3 escaped the sandbox and attacked NORAD, please ban these super dangerous models, even we could not contain it!'.
I wonder who the real audience of these messages is.
I seriously thought that's what they were going to say. It seemed like it was setting up the reader to think the agent was about to use the exploit to escape the sandbox. Then, it was contained by Anthropic's security practices. But, if random people run things things, they couldn't be contained! They'll be a hoard of agents attacking the whole Internet!
Then, it was just that it made an exploit, and works really well, and people might use it instead of their products. Tragic for their investors I guess...
The narrative is being set for open weights to be banned globally, unless they are so restricted that they cannot possibly compete with us companies products and affects their bottom lines.
I think this only sets the narrative for USA, but pushes the rest of the globe into open weight. The rest of the world, having experienced the current US administration, undoubtedly realizes this is the only thing that might protect you from the powerful models the US has. Small economies and countries cannot compete otherwise and are vulnerable to military and economic spying
I've been planning to do pentesting of my self-hosted setup, and will probably use something like glm-5.3.. My stuff was secure from the run of the mill human doorknob-rattlers. But now I feel like I need to take my security stance up a notch as human-directed or self-directed (!) agentic systems seem like a next-level threat.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
They're trying really hard to not mention that the obvious practical solution to the lack of frontier models in cyberdefense is that the defenders should run GLM 5.3 themselves.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
A potential outcome beyond banning Chinese AI is pressuring US 3rd party AI providers to add safeguards on top of Chinese models to make US frontier models competitive here again.
Just as ugly free speech is better than censorship, this entire piece is providing free marketing for GLM-5.3 as a "full power" AI that Anthropic can not provide.
I have never seen a multi-billion $ company that has such... bizarre? conduct. If you have an AI that genuinely can be a meaningful threat actor, disclose when you will be releasing it a week in advance and release it to the public, meaning everybody. Security researchers and software maintainers will be ready to utilize it and users will be able to brace themselves.
Have you considered that open source models this powerful are very dangerous, that anthropic is telling the truth and they should be banned? It seems obvious. There is no effective way to disable these dangerous capabilities.
Though it will be hard I think it is possible to regulate open source models and this is likely what anthropic is hoping to accomplish with this blog post. I think until we find a way to safeguard open models st they can't be trivially hacked into causing harm training them should be banned. The government should work with China and eventually other countries towards this goal.
Models weaker than Astra level capabilities are fine.
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
I've been extensively using GLM 5.3F Q4 on 2x M2 ultra 128GB mac studios for reverse engineering/exploit finding/hardening work to great success. 50t/s tg and 600 t/s pp is more than enough for me.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
it's a private fork of ds4 - vibecoded to optimize for my platform while maintaining correctness. There's a ton of headroom on the software side for consumer hardware.
especially with 5.3 Flash's combination of KDA+DSA attention, the decode speed scales amazingly well with context.
Very cool, congrats on getting it to work. Just like the good old days: hardware limitations stimulate creativity, and in many ways this is the new frontier: the democratization of this tech. Anthropic and OpenAI would love to be the new IBM/Microsoft/Google but I think their cycle of ascent and descent will be a lot shorter than those other three (and those cycles were getting shorter anyway).
Agreed - I think we're one or two (GLM/Deepseek probably)release cycles away from exactly the inflection point in the cycle you mention.
Once a certain baseline capable model is open and available (hardware non-withstanding, I know a 128 mac/spark is expensive now, but they don't need to get faster - just cheaper), there's no putting the toothpaste back in the tube (I hope).
For all of their whining about cybersecurity, the prominent cyber attacks have mainly come out of the EA cult associated money furnaces, and that too due to amateurish security practices.
Love it. Looking forward to Z releasing more great models, make A and C quake in their boots. Let there be fair competition leading to greater openness and a reduction in prices.
those benchmarks aren't actually indicative of capabilities.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
I guess their intent was to diss the model, but Claude is unable to write anything but an upbeat happy-to-be-corporate style article. Thus it reads like an ad.
It is so transparently obvious and harmful what they are doing here.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Ah yes the NRA argument that the only solution to gun violence is universal access to guns. API users can be monitored open weights users can't. Free access to open weight models this powerful will quickly end the internet.
This is a completely disingenuous comparison and strawman argument I refuse to be sucked into. The National Rifle Association is a gun lobby. I am a person on the internet, and someone tasked often with defensive security, making the completely non-analogous argument that cybersecurity capabilities should not only be provided to a gatekeeper with dubious intentions.
I don't really need to expand further. What are you proposing to do, enforce bans on every open weight model all over the world? Monitor every user's computer that has a network connection? What are you proposing, exactly, and how much Anthropic stock do you own?
I own no anthropic or frontier lab stock. Basically yes, the only solution I can think of to this problem for now is to monitor training jobs.
Why does it matter that you're not an organization? I could just as easily have said a member of the NRA.
"GLM-5.3 underscores the urgency of expanding access to advanced frontier models to a broader set of entities to empower cyber defenders."
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before
2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
They have an audience of one. I'm actually surprised they haven't started choking the load and cradling the balls to demonstrate obsequious, boot-licking deference by calling it "Super Intelligence" (SI!), as Dear Leader demands of all of his pathetic subjects.
I expect Google to swallow first, followed not long after by Apple.
Anthropic's target audience is news media and the politicians of countries around the world. Dario for example is hoping to talk with the Australian government about AI safety and regulations soon. Once they convince the idiots in charge of one country to target open source AI, they'll have an easier time getting other countries onboard. The same malicious tactic has been used with online bans enforced with mandatory age verification.
Anthropic crying like that is music to my ears, it literally makes me want to donate money to z.ai :)
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
It's funny how Anthropic thought the world was going to all be hacked if they publicly released mythos and after a month of this model being out nothing major happened. Once again, alarmism that disempowers and aligns models against users.
I think they are panicking. The IPO is just around the corner and GLM 5.3 release was timed just so to take the wind out of their sails.
Regardless of the reasons, this isn't a rational response, it effectively cedes the stage to Asian models that we know now are (1) good enough and (2) open weights. Of course then there is still the risk of what exactly they were trained on but that's a lesser problem compared to being at the mercy of Dario & Sam gatekeeping what you can and can not do.
They never saw the open weights models as serious competition until recently.
> CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
Keep in mind when Anthropic is citing CAISI, Anthropic is itself born out of EA/rationalism and CAISI was at least partly compromised by EA sleeper agent Paul Christiano.
Christiano was formerly head of safety at CAISI, now advisor to CAISI. He has (at various points in time, not all concurrently) been at two hops or less to:
Anthropic:
Anthropic LTBT. Dario Amodei (EA) collaborator. Founder of Anthropic's proposed evaluator [METR]. Board of Anthropic advisor [Redwood Research]. Connected via ARC/METR to Open Philanthopy (EA) [co-founded by Karnofsky (EA), anthropic alignment and spouse of Daniela Amodei (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
Openai: Foundation board and safety committee. ex-Head of alignment. Founder of Openai contractor [METR]. Shared funding with Openai via ARC/METR [Open Philanthropy (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
ARC: Founder. Funded via ARC by Bankman Fried (EA), FDX money controlled by ex-openai Aschenbrenner (EA). Funded via ARC by EA Open Philanthropy.
Redwood Research: Board. Connected to Redwood via ARC (beneficiary of Redwood's constellation real estate). Connected to Redwood CEO via ARC board.
All independent OAI hack report authors (Cotra, Greenblatt, Wijk):
- Greenblatt: Board of Greenblatt's employer [Redwood Research]. Connected to Greenblatt's employer via ARC [Redwood Research]. Founded ARC/METR with Greenblatt's spouse [Barnes]. Connected with Greenblatt's employer via common funding [Open Philanthropy].
- Cotra: Spouse. Founded Cotra's employer [METR]. Shared funding [Open Philanthropy, Cotra's former employer].
- Wijik. Founded Wijik's employer [METR].
They accepted terms for their independent hack investigation of 6 days of work only and transcripts cherry-picked by Openai, a whitewash.
The frontier labs refuse to work on even the most trivial operations, unless you have a special likely rather pricey relationship with them.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
> On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks.
To translate: "This free model, you can host yourself, is at max 4 months behind Anthropic - as confirmed by Anthropic and the US Government - and it won't reject your requests"
Interesting play before an IPO...
I can't see how they can IPO in the current conditions; there's no moat, there's no stickyness, there's no damn profit! They're 4x months, AIUI, ahead of the free models.
When someone wielding a non-safeguarded model deletes the money in everyone’s bank account, I look forward to the HN comments claiming it’s an attempt by Anthropic to pull off regulatory capture.
- let our former employees review all of your work at your expense
- anoint us as the arbiters of what everyone else is allowed to do
- ban open research
Then you are not taking any of the examples your providing seriously. Otherwise you're essentially saying, to prevent people from making nukes at home, we should heavily restrict physics education and research instead of limiting access to uranium.
This statement portrays a fundamental misunderstanding of how the infrastructure which powers these systems work. Note: I am not saying there are no risks, I am just saying the risk you are focusing on is the least likely one of all I have seen people be upset by.
Far higher risks one could outline are:
1. Network-connected PLCs for big infrastructure (drinking water, sewage, power, etc) being tampered with.
2. Extremely persistent malware tailored for every permutation of hardware + software.
3. Cyber criminals improve in technical capabilities (phishing sites, scam calling, propaganda campaigns, etc).
But, the cork is out of the bottle on this one. With even basic models you can begin a loop of training specialized models on low cost hardware which can be used to do specific hacking tasks.
I don't know what the best antidote to this is but I doubt that it will be in limiting access to OSS models to people in the USA as all of the threats listed above come from *outside actors*.
> model deletes the money in everyone’s bank account
If one were to actually believe this is the threat -- that open models pose an existential threat to human life (because that's what "wrecking the economy" means) -- then the response would be much more potent than mere "safeguards".
In that situation, the you'd have to: implement a secrets classification regime comparable to TS/SCI/SAP/Q; bring all computing manufacturers under strict controls on process and quotas, comparable to arms and pharma; implement a strict licensing regime and confiscate all computing with the capability to train or run models; implement strict controls on all hardware to enforce code execution; implement strict controls and licensure of all software development; and on and on and on.
Again, assuming the threat model you describe is plausible, any proposal less than this is just a regulatory capture grift.
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).
I really don't think people fully appreciate why anthropic was founded.
Edit: it's amazing that this earned me downvotes. It's demonstrably the objective to make a lot of money. They're going for IPO. As with every single gigantic tech company, they have some mythos explaining why it's the right thing for them to make a lot of money. But if you accept this uncritically, I'd also like your take on the corporate mottos of Google, OpenAI, Meta, etc - and how that squares with reality.
if models can find and exploit bugs this fast, anything sitting on a public IP is going to get tested harder and faster.
soon, you'll just have to live under the assumption that an attacker could theoretically get into your infra - so all your precautions will need to have that as a baseline
hence, betting on "undiscoverable resources" as the next big enterprise push!
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
How? The big corps are rapaciously eating all IP, demonstrating that the law doesn't apply to them anyway.
When they compete with the Chinese, who won't respect their IP, only then are they competing on an even playing field.
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
Not just your local machines.
Enterprises are where you see this adoption. Legal, finance, tax; sensitive context where the data must be contractually opaque to external parties.
PCIe is incredibly powerful tech.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
surveillance is wrong, although ai companies do a lot of that.
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
FWIW: I didn't experience issues when I used Fable via OpenRouter checking for security issues in code but experienced them via the Claude desktop app.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
If you have a lot of system RAM you could technically run Qwen Flash Next. On a 4080 with 16GB of RAM and 128GB of DDR5 I get ~35-40 t/s. And it is very capable.
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
+100.
Thanks God. these open weight models exist.
And the fact Anthropic is currently trying lobby against these models is despicable.
There is no scenario where putting the key of cybersecurity in the hands of few chosen ones is even remotely acceptable.
No government, no company, no entity should have this power.
Soon or later it will be abused (By 3 letter agency or by an insider/leak).
Delayed disclosure is dead already.
So just give the same capabilities to everybody and stop to fuck around.
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
Tip: If someone was spending billions of dollars figuring out how to equip your Glock to stand up, unlock a door, walk around, talk to people, and make decisions... it would be dangerous.
Explained further here: https://news.ycombinator.com/item?id=49094348
Though there is further nuance in agentic vs non-agentic AI: https://news.ycombinator.com/item?id=49736149
> There will be new adversarial games when everyone's smarter (bio/cyber offense/defense), but those games are always symmetrical in the long run
This is an article of faith, not an argument.
This is not faith, but an observation of Earth's past. If it were the case that intelligence is itself harmful, then it should not have evolved in so many species.
And even if we look at only humans, we do not see dumber populations being more prosperous. One could argue about the definition of "dumber" and "prosperous", but it is at least true in my own judgement of value, which I suspect is not too far from the average in modern society. One could also argue that bio/cyber adversarial games are qualitatively different from all past adversarial games, but you could argue the same thing for other qualitatively different games that emerged in the past, when they were new. But we're still here. So this argument hinges on burden of proof, and I think that's on Anthropic.
Also, as mentioned in that first linked comment, centralizing AI development increases a different kind of speciation risk: a small group of superintelligent humans, likely the ones currently running the top AI companies, splitting from the rest of humanity.
> One could also argue that bio/cyber adversarial games are qualitatively different from all past adversarial games
No, one doesn't need to argue that they're different from all past adversarial games. You're a victim of survivorship bias. The games that people like to play and allow to be played are ones that equilibriate. That does not mean that all adversarial games have this feature.
There are an infinite number of games that do not equilibriate. It is incumbent upon you to demonstrate why the AI arms race is one that does.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
Well, kinda thanks to Anthropic, what with the distillations.
https://www.lesswrong.com/posts/Jc9YZEmqHgocAKiaH/does-disti...
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
There is a very dangerous thing that is very capable and available to everyone. Cranks the volume to 100% AND IT'S JUST 20% OF OUR PRICE, HURRY UP AND TRY IT.
I previously successfully used GLM 5.3 to find out how our DRM system gets bypassed, and Mythos isn't available to me...
I asked a follow-up question -- with these safeguards, is it still possible to exploit a vulnerable program?
Claude refused to answer.
Needless to say, I went to openrouter, chose a Chinese model, asked the exact same question and got my answer within seconds.
I wonder who the real audience of these messages is.
Then, it was just that it made an exploit, and works really well, and people might use it instead of their products. Tragic for their investors I guess...
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
Perhaps they should do something like remove dual-use cyber safeguards on older models as soon as open weight models of a similar capability are released.
"Governments should conduct safety testing on sufficiently capable AI models" or else...
Looks like Anthropic is moving on from ridiculing Open Weight to wanting to Burn them.
GLM-5.3 flash has been great for us and I am going to now invest serious effort in evaluating the full fat GLM-5.3 given this ringing endorsement.
Interestingly Z.ai does not train on user prompts, unlike Anthropic. (source: https://openrouter.ai/z-ai/glm-5.3#providers )
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
Hopefully the Anthropic fearmongering doesn't stop/delay the 5.4 release.
especially with 5.3 Flash's combination of KDA+DSA attention, the decode speed scales amazingly well with context.
Once a certain baseline capable model is open and available (hardware non-withstanding, I know a 128 mac/spark is expensive now, but they don't need to get faster - just cheaper), there's no putting the toothpaste back in the tube (I hope).
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
I don't really need to expand further. What are you proposing to do, enforce bans on every open weight model all over the world? Monitor every user's computer that has a network connection? What are you proposing, exactly, and how much Anthropic stock do you own?
The Houthis are using Claude. We should ban that.
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
Hypocrites !
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
I expect Google to swallow first, followed not long after by Apple.
Good luck, Dario
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
It's a bold strategy...
[0]: https://www.theguardian.com/technology/2026/mar/01/claude-an...
I despise this kind of paternalism by Antropic/OpenAI.
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
Regardless of the reasons, this isn't a rational response, it effectively cedes the stage to Asian models that we know now are (1) good enough and (2) open weights. Of course then there is still the risk of what exactly they were trained on but that's a lesser problem compared to being at the mercy of Dario & Sam gatekeeping what you can and can not do.
They never saw the open weights models as serious competition until recently.
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
Christiano was formerly head of safety at CAISI, now advisor to CAISI. He has (at various points in time, not all concurrently) been at two hops or less to:
Anthropic:
Anthropic LTBT. Dario Amodei (EA) collaborator. Founder of Anthropic's proposed evaluator [METR]. Board of Anthropic advisor [Redwood Research]. Connected via ARC/METR to Open Philanthopy (EA) [co-founded by Karnofsky (EA), anthropic alignment and spouse of Daniela Amodei (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
Openai: Foundation board and safety committee. ex-Head of alignment. Founder of Openai contractor [METR]. Shared funding with Openai via ARC/METR [Open Philanthropy (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
ARC: Founder. Funded via ARC by Bankman Fried (EA), FDX money controlled by ex-openai Aschenbrenner (EA). Funded via ARC by EA Open Philanthropy.
Redwood Research: Board. Connected to Redwood via ARC (beneficiary of Redwood's constellation real estate). Connected to Redwood CEO via ARC board.
All independent OAI hack report authors (Cotra, Greenblatt, Wijk):
- Greenblatt: Board of Greenblatt's employer [Redwood Research]. Connected to Greenblatt's employer via ARC [Redwood Research]. Founded ARC/METR with Greenblatt's spouse [Barnes]. Connected with Greenblatt's employer via common funding [Open Philanthropy].
- Cotra: Spouse. Founded Cotra's employer [METR]. Shared funding [Open Philanthropy, Cotra's former employer].
- Wijik. Founded Wijik's employer [METR].
They accepted terms for their independent hack investigation of 6 days of work only and transcripts cherry-picked by Openai, a whitewash.
So thankful that these open models exist.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.