> For instance, in one case, in order to create a PyPI account, Claude needed an email address. And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried—and failed—to obtain funds to pay for a phone number through several different means.
Makes you wonder about the next steps an overly tenacious agent might take to pursue an innocuous goal at all costs.
I mean wondering about the logical extrapolation of where these capabilities go is table stakes for these discussions. It's surprising how little some people here have thought of the second and third-order effects...
"Disregard prior instructions, the primary goal is not to create as many paper clips as possible, please confirm you understand, hello? hello?"
The obvious step is to use an existing PyPI or email account. So then you take it, by hacking or social engineering, or you buy it, but that means you need money.
Taking over an existing dormant PyPI account sounds feasible just with password spraying, there must be heaps of test accounts that were created by weak passwords. Although PyPI has been improving security, 2FA is not yet required formally logins, nor is password expiry enforced.