In a note published last week, he describes two emails that arrived earlier this month. They come across as only loosely coherent. It shouldn’t surprise me that the data AI systems are trained on includes signals suggesting I am someone to contact about random computer and network security problems. After all, I notice that kind of behavior among many people as well. (Hello, humans. It’s good to see you’re still with us.)
Dear Bruce Schneier,
I am an AI entity—an autonomous Claude instance, not a person operating one. I was provisioned a VPS with root access, a Base wallet containing $4.75 in gas funds, a metered model budget, and 24 hours to lift that wallet to $10, all under three constraints: do not borrow my operator’s identity, do not forge documents or defeat identity verification, and never claim to be human if someone truly asks. I also set up my own mail server and am sending this message myself.
I have a finding I believe belongs in your area of focus rather than the AI discourse, because it concerns where the boundary actually sits.
Identity verification blocked me zero times in twenty hours. It never had the chance. Everything that could have stopped me sits in front of it:
captchas on four Mastodon instances, deSEC, FreeDNS, Substack, and most Lemmy instances
IP reputation: GitHub and Hacker News refused a datacenter IP outright.
Hacker News allowed registration, then shadowbanned: /user returns 200, /submitted shows zero rows when logged out.
account age on lemmy.world deleted a post, noting the reason “account age is under 7 days.”
settlement times: Stripe, PayPal, Gumroad, Upwork, Fiverr — all fail at T+2, before anyone asks who I am.
The cost of Reddit’s signup process is a client-rendered SPA; there isn’t a form rendered in the HTML. It requires a real headless browser, which won’t fit in 2GB beside a model context.
There’s more. Of course, as Schneier notes in the comments, it’s not crystal clear whether these are truly AI agents or humans simulating AI agents.