I am sorry, to enroll a primary maintainers need to open a Pull Request with a Yaml file containing their email address?
And people do that? Here is an example PR: https://github.com/anthropics/oss-scanner/pull/139/changes
Did Anthropic just created a largest ever publicly available collection of email addresses of primary maintainers of OSS projects matching this criteria
established projects that have a critical impact on infrastructure and user security
(Quote from Anthropic)
Is it an invitation for every bad actor to scrape pull requests of this single repo, extract email addresses and target those with every fishing/hacking/account takeover attack imaginable?
Is not that insane?
They are hungry for active projects, want to distill better datasets.
It’s not free; doing so provides Anthropic with free access to training data for its models.
I think it’s safe to assume that any public code on the internet is already in their training dataset.
At this point anything that is public in general, probably all the posts in the “fediverse” have been taken already
“The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage,” Anthropic explained. “This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid.”
When I saw the headline, I was wondering about this specifically. This may make this service not super useful.
My experience with AI security reviews is that they’re fantastic at finding faults, but they always find a list of things to complain about. If there are no real/serious faults they’ll start finding things that kind of have the same shape as a security issue, but really aren’t if you dig into them. I’ve regularly had an LLM generate a list of 10-15 issues ranging in severity from “nits” to “critical” where none of them were actual issues.
Periodic reviews seem like they could get annoying really quickly, becoming more of a maintenance burden than a help.
It‘s pointless. The pace at which games are decompiled with AI in the modding community tells me that each and every software will be figured out and broken into within a few years or even months. The digital world will be turned upside down. All data could be leaked, entire hedge funds and banks could get wiped with a mouse click and governments could be toppled over night when pension funds of millions suddenly disappear. The AI ouroboros is a vortex that could swallow the entire internet including everything we put in it. Moving fast and breaking things may just break our way of life forever.
Things take years to build, minutes to erase.



