I don't think anyone doubts that subcontracts exist. They doubt that Anthropic's insistence that Claude isn't capable of being the operating system for an automated killbot and associated terms the DoD previously agreed to means that there's any danger to the US military from Lockheed Martin using Claude as a code assistant to build GUIs.
What if it’s a GUI to manage deployment of the kill bots? I worked for a DOD contractor on software. All our scenarios were more related. It was like “OK you’ve overthrown the civilian government of this Middle Eastern country, including the radio regulators, and now we need to coordinate radio frequency assignments for the tactical squads.”
Code which renders dots on a map isn't going to magically reorder itself if the GNSS endpoints get switched from manned to unmanned assets just because it was authored by Claude, and if the subcontractor isn't auditing and testing the code outputs properly then they're the supply chain risk, not a specific code-gen tool they use. Obviously if instead of being used as code or report generating assistants, LLM agents are used to execute combat decisions in real time that introduces a lot more risk. That's... literally Anthropic's argument against using them for that specific purpose.
It doesn't make much sense to determine that because Anthropic continues to insist that Claude is unsuitable for use as some sort of super advanced loitering munition, Lockheed using it to write job ads is as much a threat to national security as a Chinese comms terminal.
It's not like the DoD and their subcontractors and their subcontractors' subcontractors aren't used to all sorts of fine-grained separation when it comes to what is and isn't classified or export controlled under normal circumstances, or that Hegseth taking a break from fantasising about soldiers' testosterone levels for long enough to decry Anthropic's stance as 'woke' makes the decision look like one based on operational effectiveness.
"Supply chain risk" specifically refers to risk of malicious attack or sabotage through the supply chain, not all risks associated with supply chains.
A vendor with particularly poor QA might be a risk in your supply chain but isn't a "supply chain risk" according to this designation and neither would Anthropic be.
Supply chain risks are usually when someone does a attack over the supply chain. Like when the mossad planted literally explosives in radio devices for Hezbollah.
Antrophic merely said they don't allow their tools to be used for autonomous killing.
A very specific case.
So where is the danger making it necessary preventing all suppliers from using Claude at all? That only concerns those who work directly on autonomous killing and only they will have to go to Altman or Musk.
So none of that is any threat to the military - so it was just black mailing to make them do the governments will - which is something usually dictatorships do, not democratic systems.
In a democratic society, the default should be, the military just buy somewhere else, then force companies to build them the terminator. So no private company controls what the military does, they just control their product. You want the military to control private companies? There is a name for that kind of system, where this is conmon.
Eh this just we wont buy from you because you are putting limitations on the use. Anthropic will be fine if they don’t like it they can accept the terms of the contract or walk away.
Why has this never previously been done to an American company from which the DoD decided not to purchase something?
Perhaps people who are noticing politics here - including in the decision of two Trump-appointed judges, against the he vote of another Republican-appointed judge- are not the ones who are choosing not to see reality?
President Truman literally seized the assets of a steel company to avert a strike that would hurt the Korean War effort. The Supreme Court stopped him, but three Justices voted it was okay!
We also have the Defense Production Act: https://www.congress.gov/crs-product/R43767. It doesn’t happen more often because most people aren’t stupid enough to say “no” to the U.S. military. These Effective Altruists, however, are too big for their britches.
I don't know, I am just guessing because not a single American company has publicly stated they are against its product use up to a certain degree by DoD? If they have not publicly declared it then yes, DoD simply don't sign the contract.
So your argument is that the government is punishing Anthropic for its public statements? And it is correct to do so?
(I think it's also the case that Anthropic didn't make any public statements about the negotiations until after the DoD was already publicly threatening this designation. But that seems less important than the question of: is it good for the US government to try to destroy companies whose public statements it dislikes?)
Honestly I would find a certain satisfaction in a world where the next Democratic administration takes away Fox broadcast licenses, forbids use of Oracle by any government contractor unless Ellison hands CBS over to Rachel Maddow, and tells Bezos that Amazon is going to be banned from public roads unless the Washington Post front page has positive stories every day. But I doubt the same is true for the many pro-Trump people who complained vociferously about Biden officials expressing preferences to social media companies because of the merely implicit threat that they might take government action of some kind if they weren't listened to.
So we have a pen that may refuse to sign certain orders, and is clearly labeled as such.
If the DoD needs to sign such orders, they won't buy this pen.
If a supplier needs to sign such orders, the supplier also won't buy the pen.
If a supplier needs to sign other orders, and this pen is the best one available, the supplier may decide to buy this pen. Since the orders are within the range of what the pen will sign, they get signed, and the supplier fulfills its contract with the DoD.
Where is the supply chain risk? The ink isn't going to erase itself post-hoc.
---
Now, if the DoD suspects that Anthropic will train its models to try to actively sabotage military operations, that's a very different story. Does anyone actually believe that?
> If a supplier needs to sign other orders, and this pen is the best one available, the supplier may decide to buy this pen. Since the orders are within the range of what the pen will sign
Who decides what’s within the scope of “what orders are within the range of what the pen will sign?” The boundaries are never clear cut. You’ve got a vendor who could kill switch critical military technology if it’s used in a way they decide falls outside the scope of what they want.
> You’ve got a vendor who could kill switch critical military technology if it’s used in a way they decide falls outside the scope of what they want.
If the DoD hires ACME to build some software to make widgets, and ACME uses Claude to build that software, where is the kill switch?
I guess the Claude model could hide a kill switch in the widget manufacturing code, but so could ACME's human subcontractor. Why is Anthropic being considered a supply chain risk here?
The model can refuse to build something, but it can't take back what has already been built.
Your article was well worth the read. Thank you for that. It's merely a HN trend where lazy people who can't read an article bad-mouth it as AI. You'll find the lazy AI comment in every article's top first or second comment now. Don't bother justifying yourself, keep it up and keep writing.
> what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow
This seems really naive? That's the only flow that's at the basis if you get locked out. What else, do you put people on the phone to verify people by asking their name and date of birth? That's even worse!
I think they're referring to sites where that is the only way to sign in, which I have seen a few of. Basically you can never register a password or passkey, every sign in requires going to your email and waiting for the link to arrive.
I get the idea. If email links are secure enough to use for password resets, just do that every time. Then you eliminate a whole category of password attacks.
But it’s definitely annoying for a frequently used service.
Maybe this gets us closer to some idea of email being a more protected digital service, that has some legal guarantees?
Putting the potential negatives under the rug for a second…
I would be nice to have email that (1) you can’t get locked out of arbitrarily, (2) acts similarly to US mailbox (in its protections and universal service), (3) acts as an identity
Only if it's run by the state and free for every citizen. Forcing more bureaucracy on email providers will just make everything more centralized under Google and Microsoft.
It should be a mailbox with E2E encryption where the keys are stored on your ID card. Backups stay on secure servers that are legally protected from anyone including the police and only given out when you're getting a new ID at a government service center, encrypted with the cards public key so a hacker in the card issuing system can't steal it.
Every user gets a persistent address used as their identity, and any number of anonymous ones. Locking someone out would be both illegal and inconvenient for the government if all their official business is going through the mailbox.
Horrible idea. This will require every email vendor to certify with every country they provide service to that wants to do something like this, which will pretty much kill any small/indie email hosting providers.
I'd much rather have stricter legislation around password resets built into existing reg frameworks like PCI or HIPAA. If you store a form of payment or PII with a provider, then some form of human verification should be needed to perform a password reset.
I get more annoyed by the timeout it adds. Logging in 10 years ago? A thing of seconds.
Logging in today? Either magic links through mail (delivered to you within the next 30min thanks to graylisting or spam filters) or a login flow with requires 5 dialogs and 5 confirmation of "no, just log me in".
I think all Shopify sites also do it now? I'm migrating password managers and have been going over all of the old accounts I've had. Several sites that use Shopify for their stores now just don't accept any kind of a password.
I despise that too. One website (was it walmart?) gives me option to use that or a password, I select password and after entering it it tells me that it needs to verify my e-mail "for security" where I get link or code to log in.
At that point what's the point of password? Just an optional extra step?
For services that have your PII or payments details, yeah, that should be the only way to do a reset. Super inconvenient but much less so than dealing with stolen identity or credit cards.
It's the stupidity of Service Providers to adopt passkeys in the first place.
As a service provider myself, I've evaluated and said "Nah" to passkeys - because it's simply increased Customer Service contacts I have to invest in, whenever a user changes or loses devices, or any of the hundreds of ways Passkeys are not portable.
And guess what, the Tech companies pushing this have zero liability for user login support or security breaches. It's always me. There is no need for me to work hard and spend CS contacts, to wall off my users to the OS or Browser vendor.
I'll simply do passwordless Email or SMS 2FA / Magic Links and own my users without the overhead of Customer contacts, thank you.
I understand many passkey complaints but not this one. Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords? You collect and verify an email address at signup and the account can be recovered in the same way as with passwords, or passwordless-email. No CS-verified recovery needed.
All right, my framing was a little too tight. Sure I can see why an email/SMS passwordless loop is easier for you, but it’s a more annoying user experience than your OS/browser/password manager just filling in your credential directly.
Everyone here saying about execs and so on - don't seem to catch a few nuances in this chain.
1. Bill Gates is doing the "Internal Disruptor" CEO style
2. Everyone is reacting in a way Bill Gates expects them to react
3. The results of his disruptor style is that Windows is absolutely further unbearable and horrendous, as seen today own the line.
Make no mistake: "Internal Disruptor" CEOs kill their own products and people from the inside, rather than competing or building good products outside.
reply