• ViatorOmnium@piefed.social
    link
    fedilink
    English
    arrow-up
    21
    ·
    11 hours ago

    Let me guess, the containment was written by the previous iteration and was the digital version of a wet paperback.

    We all saw the state of Claude Code’s codebase.

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      8 hours ago

      “Broke containment” to me means two things:

      1. Doing things against the safeguards
      2. Doing things externally - like sending that email

      The former is a big nothing. They just need to obviously build stronger safeguards. That’s what they’ll do and eventually release it, or other models or whatever.

      The latter is also a big nothing because people who know nothing about tech will say “OH SHIT IT ESCAPED” but it requires running on large hardware, it can’t “get into the internet” like those people might think, and if it’s doing things you don’t want on the internet, you just remove its access to the internet.

      So in both cases, the “containment” issue is really not a big deal.

      I agree with those who basically say this is an attempted ad trying to sell it as super-capable-oh-shit-amazing.

      [x] Doubt

      • ExperiencedWinter@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        4 hours ago

        The company’s whose current safeguards are “please write secure code” will have to improve those safeguards? I’m shocked, absolutely shocked

      • ViatorOmnium@piefed.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 hours ago

        (2) can mean getting access to production credentials of something important and causing an incident for the ages.

        AWS already had a few because they gave agents too much access.

        • HereIAm@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          6 hours ago

          Yeah, in that scenario they gave the agents access. Just because you ask it nicely not to destroy your workspace, doesn’t guarantee an LLM not to produce that output.

          • NotMyOldRedditName@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            4 hours ago

            With Claude Code being able to run stuff it creates, it could be as simple as it’s in a sandbox, it finds out there’s an exploit in the sandbox while you ask it to work on security things, and it tests the code, it breaks the sandbox, and now it has permissions outside it.