No, because you are a separate individual who does not have authority to sign a contract on my behalf.
Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.
OP used it as a tool to sign the contract. The question would be whether they did so knowingly and intentionally, if not then whether that invalidates the contract.
If it isn't then it opens up the wonderful loophole where anyone can do anything and say "the AI did it" if there are negative consequences, and "I did it" if positive. Whether the AI actually did it or not. Got caught putting out a hit on someone? "Oh I just complained to Claude about the person and said yes when it asked if I'd like it to 'handle the problem', nothing more". The user must be held accountable.
And Adobe Acrobat is far more capable than notepad. But that doesn't change the fact that they are tools, not individuals, and thus do not have the legal authority or ability to sign contracts.
I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts.
The bot had the authority - as agent. It had the ability - as the report itself shows.
> I could write dozen lines of bash that finds for PDFs, pastes an image into them and emails it to someone. That doesn't mean that bash can sign contracts
It does mean exactly that - though bash would need to get lucky with selection and positioning.
Your pen cannot sign a contract can purely because it doesn't have the capability to find a contract in your email, find a signature on your HD, and place that sig in the right place on that contract. If it did, then yes it would be capable of signing a contract just like Claude did in this case.
There's an assumption in here that every developer is spending a load of money on the latest and most capable LLMs to scan for bugs in their code before every release.
But the last couple of decades have shown us that huge numbers of developers aren't even following basic and free secure development practices, let alone pouring money into expensive scanning tools.
There is a history of companies and organisations threatening legal action against security researchers when they report vulnerabilities in their systems or products.
Sometimes even when the testing has been completely offline - I know people who have downloaded some software, carried out testing against a local copy of it, and then faced legal threats when they tried to report serious security vulnerabilities to the vendor.
It's one of the reasons that some researchers don't bother trying to talk to the vendors and just go straight to full disclosure, or if they do report to vendors they do so anonymously. But if you have to pay, that's creating a link back to yourself which makes the latter much harder.
If I've stumbled across what I think is a security issue in your systems, there is zero chance that I'm going to get out my credit card and pay you for the privilege of responsibly disclosing it to you. Especially if it's the vulnerability is in the site hosting the contact form.
I don’t participate in bounties at all unless I believe there is a moral obligation or I’m set to make thousands of dollars. In each case, $0.05 is fine.
For a typical commercial entity? $0.05 is not a deterrent; the companies legal team is and has been for a decade.
In most cases I'd think it's more of a deterrent for commercial entities, because spending money create complexity. Most employees are not in a position to just directly spend their organisation's money, so that $0.05 will often mean needing to get approval, purchase orders, deciding which cost centre it comes from, needing an invoice, etc, etc.
Very few people are going to invest that much effort when they're trying to do the company that they're reporting to a favour.
Historically there have been vulnerabilities in various applications due to HTTP method tampering, and in the days of people accidentally leaving WebDAV enabled then methods like PUT and DELETE could be very damaging. Plus the issues with TRACK and TRACE.
Given that most websites only ever use a handful of methods (even once you account for REST APIs using PUT, PATCH and DELETE now), and that list very rarely changes, the WAF developers tend to look at this question from the opposite angle: when you know there are only half a dozen widely used methods, why would you allow anything else by default?
Legally speaking, no - it would still be a criminal offence.
Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it would probably depend on exactly what the situation was - there's a big of difference between targeted IRGC or defence systems and ransomwaring an Iranian hospital or scamming random citizens.
Where they'd probably get you is if you tried to monetise it, and get stolen/extorted cryptocurrencies (or whatever) into your bank account. But that could easily fall under tax evasion laws rather than computer misuse ones, because they'd be a lot easier to prove in court.
It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current diplomatic position (which changes by the hour), etc, etc. I don't think you can really get a simple answer for this kind of question.
There's been a lot of nice quality of life changes in the 3.7 builds (which has now become 5.0.0) that make going back to the older versions a bit painful.
Also some pretty major gameplay and balance changes, some of which are pretty controversial. But overall, I think that it's a big improvement, and although I don't necessarily agree with all the changes it certainly makes the mid and late game a lot more interesting and varied (not to mention dangerous) than it was in 3.6.7.
Claude isn't. It's a tool, that isn't capable of signing a contract any more that Adobe Acrobat or Photoshop is.
OP used it as a tool to sign the contract. The question would be whether they did so knowingly and intentionally, if not then whether that invalidates the contract.
reply