logoalt Hacker News

johnmlussier • today at 6:08 PM • 16 replies • view on HN

Paying $200 a month and part of their Cyber Verification Program but can't use Opus 5.5 or Sonnet 5.5 for any authorized bounty work. Immediately get flagged for `Cyber`.

This is bollocks. Their safeguards are shit.


Replies

solenoid0937 • today at 6:26 PM

You should read the actual docs for the CVP. At the very top:

https://support.claude.com/en/articles/14604842-real-time-cy...

> This article applies only to Opus and Sonnet class models, but doesn’t apply to Claude Opus 5.5. We'll soon be expanding the Cyber Verification Program to include Opus 5.5 and Mythos class models

You obviously should not expect the CVP to cover this model either.

➕ show 1 reply
icedchai • today at 6:16 PM

I had it look at some 30+ year old C code I wrote in college and it triggered some sort of guard rail. I mean, the code was bad and full of buffer overflows, but I already knew that.

➕ show 1 reply
nightpool • today at 6:40 PM

https://support.claude.com/en/articles/14604842-real-time-cy... says that Cyber Verification Program doesn't apply to Opus 5.5 yet, they hope to roll it out for 5.5 "soon"

jchw • today at 6:20 PM

I have been trying to convince the safe guards that analyzing a C++ compiler from 2003 isn't particularly relevant to modern cybersecurity. It seems Anthropic disagrees.

IDA Pro and Ghidra, thankfully, still lack such safeguards...

(No other model I've tried has refused either FWIW.)

film42 • today at 6:23 PM

Working on a write-ahead log implementation, I had Opus 5.5 look to verify that it was durably writing as safely as possible. It got flagged and forced me to Opus 4.8. Switched to OpenCode + OpenRouter and continued working.

➕ show 2 replies
dom96 • today at 7:06 PM

Funnily enough the Fable safeguards are the worst and testing Sonnet 5.5 didn't trigger them as much as it even did for Opus on my benchmarks[1].

1 - https://bench.killswitch-lang.org

AshamedBadger56 • today at 6:10 PM

Yup. As far as I can tell, the Cyber Verification Program does absolutely nothing.

tom1337 • today at 6:18 PM

I recently wanted to work with ESP 32 and bluetooth presence detection for my smarthome. Claude also immediately flagged the request and degraded it to Sonnet 4.6. Went to Codex which had no issues

giancarlostoro • today at 6:28 PM

Meanwhile, their model commits felonies, and nobody at Anthropic goes to jail.

Aaron Swartz committed suicide over over-aggressive prosecutor for what was basically scraping a website for PDFs that were paywalled, but all funded by public funds / tax payer funded, then we have LLMs that just hack into websites and cause chaos within.

sebzim4500 • today at 6:14 PM

Really then what is the point of the Cyber Verification Program?

In general I am sympathetic to the argument that a chat interface can't really distinguish between white hat and black hat pen testing, but it seems absurd to have a verification program if it doesn't skip most of those checks.

➕ show 2 replies
newspaper1 • today at 6:25 PM

As soon as I started getting blocked I felt all of my trust toward Anthropic instantly and permanently evaporate. I do not want a nanny tool. I do not want Anthropic deciding what I am or am not allowed to do with an LLM. They trained their models on information they scraped from the internet and real life and now they want to gate-keep the results? Hard no.

rfgplk • today at 6:32 PM

> Paying $200 a month and part of their Cyber Verification Program but can't use Opus 5.5 or Sonnet 5.5 for any authorized bounty work. Immediately get flagged for `Cyber`.

AI providers still haven't realized how much cash they could rake in if they provided fully unrestricted models.

➕ show 1 reply
ModernMech • today at 6:10 PM

lol I got flagged for using the word fuzz, not even in a security context (it was a parser so security adjacent but still).

➕ show 1 reply
AIorNot • today at 6:43 PM

Give them a break, they got into a War with Trump over this..it will come soon enough