logoalt Hacker News

wmfyesterday at 4:58 AM1 replyview on HN

I don't know; "Claude was able to exfiltrate the company’s credentials" sounds bad. Maybe those credentials were just canaries though.


Replies

frabcusyesterday at 7:27 AM

It seems completely unsurprising to me that there is one security company whose software is sufficiently badly written that it executes the code in every package published to PyPI.

It's very very easy to make that kind of mistake. Most coding is rushed, we have no engineering qualifications or industry wide practices.

People are imperfect, companies are imperfect. The strategy to stop AI causing severe harms can't rely on humans or the AI being perfect.