Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

301–310 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#302
post #11

Let's fast forward the clock. Does software security converge on a world with fewer vulnerabilities or more? I'm not sure it converges equally in all places. My understanding is that the pre-AI distribution of software quality (and vulnerabilities) will be massively exaggerated. More small vulnerable projects and fewer large vulnerable ones. It seems that large technology and infrastructure companies will be able to…

I suspect it will converge on minimal complexity software. Current software is way too bloated. Unnecessary complexity creates vulnerabilities and makes them harder to patch.

Re: Project Glasswing: Securing critical software for the AI era

#303

To be clear, we don’t know that this tool is better at finding bugs than fuzzing. We just know that it’s finding bugs that fuzzing missed. It’s possible fuzzing also finds bugs that this AI would miss.

Different methods find different things. Personally, I'd rather use a language that is memory safe plus a great static analyzer with abstract interpretation that can guarantee the absence of certain classes of bugs, at the expense of some false positives.

The problem is that these tools, such as Astrée, are incredibly expensive and therefore their market share is limited to some niches. Perhaps, with the advent of LLM-guided synthesis, a simple form of deductive proving, such as Hoare logic, may become mainstream in systems software.

Re: Project Glasswing: Securing critical software for the AI era

#304

Earlier quoted context omitted.

> Yes that is correct. I would like a large body of experience and consenus to rely on as opposed to the regular 'trust the experts' argument, which has been shown for decades that is a deeply flawed and easy to manipulate argument. Yes, it is far inferior to the 'Trust torginus and his ability to understand the large body of experience that other actual subject-matter-experts have somehow not understood' strategy

It's not my credibility I want to measure against Anthropic's. I just said to apply the same logic to biology you would apply for software development. The parallels here are quite remarkable imo, but defer to your own judgement on what you make of them.

The big thing you're missing here is that biology people don't (in my experience) post opinions about the future/futility/ease/unimportance of computer science especially when their opinion goes against other biologists' evidence-backed views. This is a cultural thing in biology.

It's not your fault that you don't know this, but this whole subthread is very CS-coded in its disdain for other software people's standard of evidence.

Re: Project Glasswing: Securing critical software for the AI era

#305
I think this is a largely inflated PR stunt.

Opus 4.6 was already capable of finding 0days and chaining together vulns to create exploits. See [0] and [1].

[0] https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-...

[1] https://xbow.com/blog/top-1-how-xbow-did-it

Re: Project Glasswing: Securing critical software for the AI era

#306

Earlier quoted context omitted.

If it was in an android or humanoid type body, even with limited bodily control, most people would think they are talking to Commander Data from Star Trek. I think Claude is sufficiently advanced that almost everyone in that era would've considered it AGI.

Assuming they would understand it as artificial - I think many people would think it's a human intelligence in a cyborg trenchcoat, and it would be hard to convince people it wasn't literally a guy named Claude who was an incredibly fast typist who had a million pre-cached templated answers for things. But in general, yeah, I agree, I think they would think it was a sentient, conscious, emotional being. And then the…

Because questions like this force us to hold up a very uncomfortable mirror to ourselves. It’s much easier to just dismiss.

Re: Project Glasswing: Securing critical software for the AI era

#307

Earlier quoted context omitted.

Honest question: how do state-sponsored attacks from China, Iran, North Korea, and Russia affect civilian life?

Presumably, those have influenced elections, though I guess it depends what you count as an attack. Plenty of bots try to modify public opinion. Someone hacked the DNC in 2015/16, the result of which also alleged attempted manipulation in 2008: https://en.wikipedia.org/wiki/Democratic_National_Committee_... Since we (as old Rummy said) do not know what we do not know, we cannot be certain about the extent of cyber at…

Yes... they might have influenced elections and now, as a result, the world must cope with the Trump regime.

Let's now fool ourselves.... Trump is probably the best, most successful attempt at world de-stabilisation all those rogue states ever achieved.

Re: Project Glasswing: Securing critical software for the AI era

#308
post #74

Earlier quoted context omitted.

[flagged]

lol and what about the vibe coders? You people are comical. Why do you feel the need to create so much hype around what you say? Did you not get enough attention as a kid?

The vibe coders will be fine. They’ll use LLMs to red team their code.

Re: Project Glasswing: Securing critical software for the AI era

#309

Earlier quoted context omitted.

They made a claim that 100% of code would be AI generated in a year, over a year ago.

They were right, it's hit 100% at a number of large tech companies. (They missed their initial prediction of 90% 6 months ago, because the models then available publicly weren't capable enough.)

So why aren’t they laying people off and pumping the extra money towards research efforts associated with Llm’s? Lmao.

They should all cut down their labour input right now if what you claim is true.

Post reply on HN