Forum Topics Claude Code Security
jcmleng
Added 4 weeks ago

Here we go again, this time on Cyber Security.

Mayhem in cybersecurity companies after Claude released Claude Code Security:

Claude Code Security is designed to autonomously scan software codebases for vulnerabilities and recommend precise fixes—functions traditionally performed by a combination of human security engineers and specialized enterprise software.

The market has taken a shoot-everything-first-ask-questions-later approach, which again, makes zero sense.

https://securityinstitute.com/blog/claude-code-security-announcement.html is currently the best read in the brief scan that I have done to make sense of this. It comes from a deeply experienced cyber security practitioner who is actually advocating an act-now deployment of Claude Code Security.

21

mikebrisy
Added 4 weeks ago

@jcmleng I find it stagging that firms like Crowdstrike and Cloudflare, which are focused on security, are down 38% and 37% from their November peaks.

In all the hullabaloo about Agentic AI and the "SaaSsacre", the topics not getting enough attention in my view are trust and security (addressed in depth by Ed Chung at $TNE last week).

What enterprise Board, Exec, or CIO, or SMB owner for that matter, is going to open up their enterprise for some AgentAI Bots to run amok with their processes, IP, data, customer relationships?

How will the new AI-Native firms build the trust and confidence required? How do they demonstrate that controls are in plac, are effective and are robust?

I for one, would not trust my business to Sam Altman. And although Antropic is founded on principles of safety, is that really enough? Where is the proof that there are effective safeguards and controls? (So, I'm surprised to hear that @Strawman is monkeying around with OpenClaw. How can we even know if the AI Bot hasn't kidnap @Strawman and continues to run the platform for its own nefarious ends? Surely there is enough data on this platform, including all the SM Meetings, that could train a pretty convincing AIStrawman.)

There is a lot of talk about AI making things frictionless. But isn't trust one of the greatest sources of friction of all through all human history?

28

Strawman
Added 4 weeks ago

That's a great observation @mikebrisy. Would you like me to help you brainstorm some possible scenarios?

(joke!!)

I should emphasise that my instance of OpenCLAW is sandboxed, on a separate machine (a VPS) and kept a mile away from anything important. It only has access to what I give it. So it shouldnt be able to cause too much trouble. It's mainly just to get a feel for what's possible and see if reality lives up to the hype (it doesnt, yet, as far as I can see).

But, yeah, be super careful out there!

8ee13a155741c912ba5fdf0f1b3840d776600e.png

https://x.com/ns123abc/status/2025975943529931240?s=20

21

JohnnyM
Added 4 weeks ago

Hmm second time adding this post because I hit Add Reply before but can't see it come up on the feed..

A good way to get me to shorten the post... write it out twice..

Have a listen to this, set to play from the 6min mark where Chamath wrestles with the idea that companies will need to IT Infrastructure back "On Prem" to be in control of their data. He references a legal ruling where if a company (most likely junior employee looking for an edge) has put data and information into a public LLM then the company losses rights over it.

Cheers

JM

16

Raseekingalpha
Added 4 weeks ago

Hi @Strawman @mikebrisy

Today was my first day at Salesforce conference. We had Energy & Utility Summit, where they were showcasing what Salesforce is coming up with. One of the main discussion topic was how to put guard rails on AI.

7

Scott
Added 4 weeks ago

As I understand it (quick read), Claude Code Security looks for vulnerabilities on your own code - so that's a good thing. It seems at odds though for the market to whack companies that protect you against adversaries at the front, side and back doors (firewalls, etc). I hold FTNT IRL - firewalls and network appliances that include hardware hooked up to a global security operations centre that actively looks for threats - and guess what - they use AI to help them do it!

I'd like to see Anthropic release 'Claude Code Equity Analyst' and see all the analysts give themselves a massive pay cut.

17

jcmleng
Added 4 weeks ago

@Scott, thats how I read it too.

Presumably you would deploy Claude Code Security in your environment (heaven forbid) (1) let it run loose on ALL the code that is in your environment (2) flag the vulnerabilities (3) flag the remediation (4) let a human say OK, then presumably (5) you let Claude fix the vulnerabilities.

Operationally, I would have followed Bill Alderson's advice (the dude who wrote the blog I posted) and deploy it into my environment for it to do ONLY (1), (2) and (3), in parallel with whatever vulnerability scan capabilities we already have deployed. Given how the Claude Code is suppose to work, it will be a different way of flagging vulnerabilities and any new vulnerability it does flag can only be a really good thing. So this capability, in itself, is absolutely a positive thing for everyone - companies, internal IT, cyber security companies and the world at large. And

But cybersecurity is not simply scan, flag and fix, so I cannot understand the negative reaction. By spraying anything and everything that smells cyber security, the market has completely lost its collective head ...

16

SayWhatAgain
Added 4 weeks ago

I’ve got openclaw running on a raspberry pi 5 - cost me about 300$ and using open LLMs from Ollama (I am too cheap to pay for them :))- totally isolated from everything and only sees what i put in the pi. TBH its not bad for automating certain things like scraping data from reports etc. but beyond that I have not yet found more use… a better computer will allow running better models locally but for now this has been quite fun!

14

tomsmithidg
Added 4 weeks ago

a378075f4c5d63bbb6d90a8301fdff98138cc6.png

Sounds exactly like what and AI trying to convince us it wasn't an AI would say ;D

11