This is why all of the claims that “Claude broke containment” are pure hype. They know how to truly design a secure box. They just don’t want to and put out headlines to boast its hacking skills.
You want it secure for experimental model security testing?
No VMs
Physical hardware
Physically disconnected from the internet
For the rest of us who ain’t doing that shit, a properly segregated dev network with firewalled access will suffice.
Doesn’t even need to be completely air gapped, they can still allow it to talk to one specific endpoint to e.g. actually drive the model. As long as all commands are executed on a machine that can’t reach the Internet, all is safe.
I don’t actually doubt anything in the big post they sent out. I just doubt that running a LLM without the possibility of alignment drift is possible. It just doesn’t seem like they work that way.
This is why all of the claims that “Claude broke containment” are pure hype. They know how to truly design a secure box. They just don’t want to and put out headlines to boast its hacking skills.
You want it secure for experimental model security testing?
For the rest of us who ain’t doing that shit, a properly segregated dev network with firewalled access will suffice.
Doesn’t even need to be completely air gapped, they can still allow it to talk to one specific endpoint to e.g. actually drive the model. As long as all commands are executed on a machine that can’t reach the Internet, all is safe.
I don’t actually doubt anything in the big post they sent out. I just doubt that running a LLM without the possibility of alignment drift is possible. It just doesn’t seem like they work that way.