Hacker News new | ask | show | jobs
by yodon 7 days ago
One of the links in Schneier's article makes a credible sounding case that Anthropic is using open source vulnerabilities as a shakedown operation.

When the model finds a vulnerability, it also finds a fix. Anthropic only shares the vulnerability with the Open Source maintainer, not the fix. Paying customers get fixes, confirming that the model does generate fixes for the vulnerabilities.

Sharing the vulnerabilities but not the fixes does sound like a shakedown operation.