HN user

jasondclinton

883 karma

CISO at Anthropic. Former staff software engineer at Google leading the Chrome Infrastructure Security team defending against APTs. Before that: payments security engineer (Android Pay), ChromeOS engineer, beowulf cluster engineer, GNOME Games module maintainer, and author of Ruby Phrasebook.

Signal: @jasondclinton.11

[ my public key: https://keybase.io/jasondclinton; my proof: https://keybase.io/jasondclinton/sigs/DL7kLNV4-17_G3NlqgNDOzGigaqZ72Z8MDwwBybZT9k ]

Posts19
Comments154
View on HN
www.youtube.com 1y ago

Lex: Dario Amodei: Anthropic CEO on Claude, AGI and Future of AI and Humanity [video]

jasondclinton
3pts0
en.wikipedia.org 4y ago

Law of Triviality

jasondclinton
1pts0
en.wikipedia.org 5y ago

Philosophical Zombie

jasondclinton
3pts0
opensource.googleblog.com 5y ago

Google Joins the Rust Foundation

jasondclinton
5pts1
blog.hansenpartnership.com 5y ago

Creating a Home IPv6 Network

jasondclinton
1pts1
www.nytimes.com 6y ago

When 511 Epidemiologists Expect to Fly, Hug and Do 18 Other Everyday Activities

jasondclinton
2pts0
nick.groenen.me 6y ago

Rust Error Handling in 2020

jasondclinton
2pts0
en.wikipedia.org 6y ago

Utility monster

jasondclinton
59pts67
lwn.net 6y ago

Debian Discusses Discourse

jasondclinton
3pts0
phoronix.com 6y ago

Linux 5.7-rc1 stats show that Covid has not affected kernel dev productivity

jasondclinton
3pts0
plato.stanford.edu 6y ago

Pacifism

jasondclinton
2pts0
theanarchistlibrary.org 6y ago

An Anarchist Solution to Global Warming (2010)

jasondclinton
2pts0
blog.yoshuawuyts.com 6y ago

Contributing to Rust: first 9 patches

jasondclinton
2pts0
www.shrm.org 6y ago

Why Are Companies Ending Remote Work? (2019)

jasondclinton
1pts0
en.wikipedia.org 6y ago

Irrational Exuberance

jasondclinton
1pts0
www.vice.com 6y ago

Why the Ashes of People with Aids on the White House Lawn Matter (2016)

jasondclinton
1pts0
www.zdnet.com 6y ago

Chrome cuts 'patch gap' in half, from 33 to 15 days

jasondclinton
1pts0
www.phoronix.com 6y ago

Looking at the Linux Performance Two Years After Spectre / Meltdown Mitigations

jasondclinton
5pts0
lenta.ru 6y ago

Rambler retracts lawsuit against Nginx (Russian)

jasondclinton
5pts3
Claude 4 1 year ago

Thanks for the report! We're addressing it urgently.

Starlink has been deployed on JSX for almost a year now and I've taken quite a few flights on their Bay Area to LA and Vegas routes. Despite 20 people on the planes, no one has ever been on a video conference, though I could see it becoming an issue with a broader consumer base.

Hi, CISO at Anthropic here. Sorry that we didn't respond to your BAA request. I am accountable for our response to BAA requests and I'd like to dig into what happened here. If you are comfortable, would you please reach out to me at j@anthropic.com to let me know how you sent your request in?

Hi, Anthropic is a 3 year old company that, until the release of GPT-4o last week from a company that is almost 10 years old, had the most capable model in the world, Opus, for a period of two months. With regard to availability, we had a huge amount of inbound interest on our 1P API but our model was consistently available on Amazon Bedrock throughout the last year. The 1P API has been available for the last few months to all.

No open weights model is currently within the performance class of the frontier models: GPT-4*, Opus, and Gemini Pro 1.5, though it’s possible that could change.

We are structured as a public benefit corporation formed to ensure that the benefits of AI are shared by everyone; safety is our mission and we have a board structure that puts the Response Scaling Policy and our policy mission at the fore. We have consistently communicated publicly about safety since our inception.

We have shared all of our safety research openly and consistently. Dictionary learning, in particular, is a cornerstone of this sharing.

The ASL-3 benchmark discussed in the blog post is about upcoming harms including bioweapons and cybersecurity offensive capabilities. We agree that information on web searches is not a harm increased by LLMs and state that explicitly in the RSP.

I’d encourage you to read the blog post and the RSP.

Our consistent position has been that testing and evaluations would best govern actual risks. No measured risk: no restrictions. The White House Executive Order put the models of concern at those which have 10^26 FLOPs of training compute. There are no open weights models at this threshold to consider. We support open weights models as we've outlined here: https://www.anthropic.com/news/third-party-testing . We also talk specifically about how to avoid regulatory capture and to have open, third-party evaluators. One thing that we've been advocating for, in particular, is the National Research Cloud and the US has one such effort in National AI Research Resource that needs more investment and fair, open accessibility so that all of society has inputs into the discussion.

Hi, I'm the CISO from Anthropic. Thank you for the criticism, any feedback is a gift.

We have laid out in our RSP what we consider the next milestone of significant harms that we're are testing for (what we call ASL-3): https://anthropic.com/responsible-scaling-policy (PDF); this includes bioweapons assessment and cybersecurity.

As someone thinking night and day about security, I think the next major area of concern is going to be offensive (and defensive!) exploitation. It seems to me that within 6-18 months, LLMs will be able to iteratively walk through most open source code and identify vulnerabilities. It will be computationally expensive, though: that level of reasoning requires a large amount of scratch space and attention heads. But it seems very likely, based on everything that I'm seeing. Maybe 85% odds.

There's already the first sparks of this happening published publicly here: https://security.googleblog.com/2023/08/ai-powered-fuzzing-b... just using traditional LLM-augmented fuzzers. (They've since published an update on this work in December.) I know of a few other groups doing significant amounts of investment in this specific area, to try to run faster on the defensive side than any malign nation state might be.

Please check out the RSP, we are very explicit about what harms we consider ASL-3. Drug making and "stuff on the internet" is not at all in our threat model. ASL-3 seems somewhat likely within the next 6-9 months. Maybe 50% odds, by my guess.

None of the "washlet" toilet attachments need a hot water line. They have built-in heaters and heat the water coming in from the cold water line.

Whole-house battery backup is a modern marvel, too. (We have 80KWH of stored battery capacity and it shifts grid load to non-peak hours to save huge amounts of money.)

Thanks for the vote of confidence. I led the Chrome Infrastructure Security Team hardening for insider risk and generally defending against APTs for the last 3 years at Google. Before that, I was on the Payments Security Team defending PII and SPII data up and down the stack. Indeed, I and the company take this very seriously. We're racing as fast as we can to defend against the run-of-the-mill opportunistic attackers but also APTs. We've ramped the securtiy team over the last year from 4 to 35 people. I'm still hiring, though!

We are tracking LMSys, too. There are strange safety incentives on this benchmark: you can “win” points by never blocking adult content for example.

LLMs are building blocks and I’m excited about folks building with a concert of models working together with subagents.

Hi, CISO of Anthropic here. Thank you for the feedback! If you can share any details about the image, please share in a private message.

No LLM has had an emergent calculator yet.

Claude 2.1 3 years ago

Heya, as with all language models, if you open the conversation with antagonistic questions, the rest of the conversation thread becomes tainted. If you ask most of your questions in a new thread, almost everything you ask here will be answered. See our model card for more prompting guidance.

Claude 2.1 3 years ago

Howdy, CISO of Anthropic here. I'm not sure what happened in your case but please reach out to support@ and mention my name; we'll respond ASAP.