|
|
|
|
|
by fwlr
5 days ago
|
|
Agreed that people claiming “marketing stunt” need to pull their heads out the sand, but likewise Simon needs to do some of his own beach-cranium-dislodging for laying the blame of constraints on the US govt. Before the export controls were ever floated, Glasswind found many thousands of exploits, and offered patches/fixes for approximately none of them. (perhaps their exploit capability far outstrips their remediation capability, or perhaps they’ve calculated that it somehow better suits their business model to find exploits but not remediations). |
|
But https://www.anthropic.com/coordinated-vulnerability-disclosu... says:
> Every report we send generally reflects a finding that a human security researcher has reviewed and confirmed. Reports originating from AI-powered discovery are clearly labeled as such. Where we have access to source and our tooling produces a potential candidate patch, we include it, labeled by provenance and offer to collaborate with the maintainer on a production-quality fix.
So I'm not sure why so few of the reported issues have a confirmed patch.