The government is full of stupidity and this is indeed a big moment, but Anthropic has been begging for this outcome in their public messaging. If their fear-mongering was genuine, then great, they got their pause. If not, then what exactly did they want to happen?
I think it's mainly because the difference in models at the frontier isn't "response to prompt X", but rather "coherence with 500K tokens of context and instructions in play"
Somewhere I read that malware is already starting to use nuclear and biological and cybersecurity terms in the code to trick Fable into shutting down. Even if this is just a hypothetical attack vector so far, it seems likely to work.
Some of the latest versions of Shai Hulud do this. Worked a contract recently where they were having AI check packages for obfuscation before admitting them into Artifactory but had vibed up the logic and it failed open.
So in other words this worked because the terms caused the LLM checker to stall out and then the fail open logic resulted in the package being pulled down.
> This header appears designed for AI-mediated analysis, not for Node, Bun, or Python. It attempts to derail scanners or analyst copilots that feed the beginning of a file to a language model without clearly isolating the content as untrusted data. In weak pipelines, this can cause refusal behavior, prompt confusion, context pollution, or premature classification before the scanner reaches the actual malware.
> This is not a magical bypass against static detection. YARA rules, entropy checks, AST parsing, string extraction, deobfuscation, and behavioral rules still work. But it is a practical anti-analysis trick against naive LLM-first triage systems.
Would this affect many systems? You mention someone writing logic that fails open, but can't that be chalked up to just not following good security principles?
We all need to use nuclear, bio and cybersec terms in all our code to make low quality filtering like this untenable. When you can't work on a resume that has cybersecurity or biology terms in it or reply to a job opening that includes them because the "AI" filtering is so bad that it confuses these for threats, that deserves a collective response, particularly to an IPO'ing company that claims they'll make workers obsolete in two years.
I've done this, including the hardcoded refusal strings that already exist in claude code. It won't stop a real attacker, but I still find it really funny when you're trying to use one of the AI tools and it gives you a random refusal and you don't know why, wastes a little bit of time.
Yes, the miasma worm does this since the new Hades campaign.
Note that the 3rd wave now also uses a pth file in pypi packages that _search system wide_ for any index.js or .github/setup.js to find its own payload. It literally splits up the payload on purpose to avoid detection.
Pretty small sample size here, but it's hard to avoid the conclusion that DeepSeek and friends will start to put some serious downward pressure on frontier lab token pricing.
Hopefully this dynamic continues long enough to make local/private inference the leading solution for coding.
It seems frontier, on the balance, would rather lose that segment of he market than lower the API price. They are getting the bag in the enterprise segment, those clients aren't ditching them for DeepSeek.
As for other segments, high API pricing gets people to switch to the subscriptions instead which is stickier than the API.
I've been hearing that Anthropic want all major AI providers to stop developing front tier models for a year for safety reasons. The real reason is they need time to get there models cheaper because of the DeepSeek threat or local llms or other even cheaper providers.
Won't the lockup expiry increase the float on these already-included companies, forcing mechanical buying by all the very large pool pool of folks holding these index funds? Thus creating forced buyers to maintain said share price?
Every single index fund is different. They all have publicly available methodology guides; you can read them to understand how it works and to model various scenarios.
This particular one, the CRSP total market - which Vanguard uses for VTI - has a “modern” methodology that is thought to be very good. Once every three months they re-rank the entire market and assign weights based on the market as of a particular point in time. Then, a randomly-chosen number of days later, the fund (Vanguard) begins a weeklong reconstitution process in which they buy and sell stocks to reflect the new weights. It is intentionally a weeklong process so that the market is setting prices and not Vanguard with the size of their orders.
The lockup expiry happens, the market reacts, the market is re-weighted, the index reconstitutes. In that order. The price of the stock has to survive the increased float to force the index fund to buy lots more shares.
I am not dyslexic, but the roboto example also highlighted a very stark difference in readability for me! Especially after having gotten used to shantell sans reading up to that point, the roboto felt nigh-unreadable.
I also love this font -- it seems very readable and could be a good go-to in many places.
Having said that -- the speciifc image showing difference between this font and Roboto -- uses a lower contrast for Roboto -- which surely has an effect on its readability?
I wish they showed a more direct comparison without changing the contrast to introduce an extra element.
The government is full of stupidity and this is indeed a big moment, but Anthropic has been begging for this outcome in their public messaging. If their fear-mongering was genuine, then great, they got their pause. If not, then what exactly did they want to happen?
reply