upvote
You should read the actual docs for the CVP. At the very top:

https://support.claude.com/en/articles/14604842-real-time-cy...

> This article applies only to Opus and Sonnet class models, but doesn’t apply to Claude Opus 5.5. We'll soon be expanding the Cyber Verification Program to include Opus 5.5 and Mythos class models

You obviously should not expect the CVP to cover this model either.

reply
He did mention Sonnet...
reply
It takes about 2 seconds of critical thinking to realize that if Opus 5.5 isn't covered yet, neither will a model that just launched an hour ago.
reply
Does it also take 2 seconds of critical thinking to realize that the models that are covered should be accurately named by the people making the decisions?
reply
Sure, the documentation should be up to date but it's obviously not? That doesn't excuse not thinking critically.
reply
deleted
reply
I had it look at some 30+ year old C code I wrote in college and it triggered some sort of guard rail. I mean, the code was bad and full of buffer overflows, but I already knew that.
reply
it did exactly what a human would do - "I can't look at this shit"
reply
Yuh—- no. 4.8 can handle this bullocks lol
reply
https://support.claude.com/en/articles/14604842-real-time-cy... says that Cyber Verification Program doesn't apply to Opus 5.5 yet, they hope to roll it out for 5.5 "soon"
reply
I have been trying to convince the safe guards that analyzing a C++ compiler from 2003 isn't particularly relevant to modern cybersecurity. It seems Anthropic disagrees.

IDA Pro and Ghidra, thankfully, still lack such safeguards...

(No other model I've tried has refused either FWIW.)

reply
Working on a write-ahead log implementation, I had Opus 5.5 look to verify that it was durably writing as safely as possible. It got flagged and forced me to Opus 4.8. Switched to OpenCode + OpenRouter and continued working.
reply
It's great how the company telling us AI is an existential threat to humanity, look at all the insane hacking it's doing, and then releases these models that won't let 90% of people write secure code.
reply
Bingo. And to prove your point, after switching to cheap open models (I think Qwen?) it did indeed find a bug in my WAL implementation.
reply
[dead]
reply
> Switched to OpenCode + OpenRouter

This is the way.

reply
Funnily enough the Fable safeguards are the worst and testing Sonnet 5.5 didn't trigger them as much as it even did for Opus on my benchmarks[1].

1 - https://bench.killswitch-lang.org

reply
Yup. As far as I can tell, the Cyber Verification Program does absolutely nothing.
reply
I recently wanted to work with ESP 32 and bluetooth presence detection for my smarthome. Claude also immediately flagged the request and degraded it to Sonnet 4.6. Went to Codex which had no issues
reply
Meanwhile, their model commits felonies, and nobody at Anthropic goes to jail.

Aaron Swartz committed suicide over over-aggressive prosecutor for what was basically scraping a website for PDFs that were paywalled, but all funded by public funds / tax payer funded, then we have LLMs that just hack into websites and cause chaos within.

reply
Really then what is the point of the Cyber Verification Program?

In general I am sympathetic to the argument that a chat interface can't really distinguish between white hat and black hat pen testing, but it seems absurd to have a verification program if it doesn't skip most of those checks.

reply
The company I work for joined it, and I've used Claude on various different accounts, both on and off the Cyber Verification Program. As far as I can tell, it literally doesn't do anything or have a point. The moment Claude gets close to something Cybersecurity related, it drops back to 4.8.
reply
Can confirm. Its worthless
reply
Pretty sure the implicit difference is the actions they take after the fact. As in, "how many guardrail hits do we allow you before permanently banning you."

The silicon valley ethos is "ban early and often, and invest nothing in appeals systems", so any gate before that helps!

reply
As soon as I started getting blocked I felt all of my trust toward Anthropic instantly and permanently evaporate. I do not want a nanny tool. I do not want Anthropic deciding what I am or am not allowed to do with an LLM. They trained their models on information they scraped from the internet and real life and now they want to gate-keep the results? Hard no.
reply
> Paying $200 a month and part of their Cyber Verification Program but can't use Opus 5.5 or Sonnet 5.5 for any authorized bounty work. Immediately get flagged for `Cyber`.

AI providers still haven't realized how much cash they could rake in if they provided fully unrestricted models.

reply
Are you sure they aren't already doing that for certain organizations?
reply
deleted
reply
lol I got flagged for using the word fuzz, not even in a security context (it was a parser so security adjacent but still).
reply
Parsers are security adjacent until they aren't.
reply
Very true.
reply
Give them a break, they got into a War with Trump over this..it will come soon enough
reply
deleted
reply