Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

371–380 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#371

Earlier quoted context omitted.

> PRISM was probably the state sponsored program affecting civilian life the most? No state-sponsored hacking affected Americans materially. I just don't think we were networked enough in the 2010s. The risk is higher now since we're in a more warmongering world. ( Kompromat on a power-plant technician is a risk in peace. It means blackouts in war.) The fact that Iran hasn't been able to do diddly squat in America sh…

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure - https://www.cisa.gov/news-events/cybersecurity-advisories/aa... - April 7th, 2026

Did they activate them to any noticeable effect?

Re: Project Glasswing: Securing critical software for the AI era

#372

Earlier quoted context omitted.

I think society is going to start paying the price for humans being human. As the paper points out there is a lot of good faith, serious software that has vulnerabilities. These aren't projects you would characterize as people being cavalier. It is simply beyond the limits of humans to create vulnerability-free software of high complexity. That's why high reliability software depends on extreme simplicity and strict…

100%, poorly architected software is really difficult to make secure. I think this will extend to AI as well. It will just dial up the complexity of the code until bugs and vulnerabilities start creeping in. At some point, people will have to decide to stop the complexity creep and try to produce minimal software. For any complex project with 100k+ lines of code, the probability that it has some vulnerabilities is ve…

> It doesn't fit into LLM context windows and there aren't enough attention heads to attend to every relevant part.

That's for one pass. And that pass can produce a summary of what the code does.

Re: Project Glasswing: Securing critical software for the AI era

#373

Earlier quoted context omitted.

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure - https://www.cisa.gov/news-events/cybersecurity-advisories/aa... - April 7th, 2026

Did they activate them to any noticeable effect?

To my knowledge, not yet. The attack surface in question is extensive, and in my opinion, targets are likely unprepared for a determined and sophisticated attacker.

https://www.politico.com/news/2026/04/07/iranian-hackers-ene...

Re: Project Glasswing: Securing critical software for the AI era

#374

Earlier quoted context omitted.

It is, but if you are the kind of person these exploits are likely to target, you should have it on. So far there have been no known exploits that work in Lockdown Mode.

> if you are the kind of person these exploits are likely to target, you should have it on You can also selectively turn it on in high-risk settings. I do so when I travel abroad or go through a border. (Haven't started doing it yet with TSA domestically. Let's see how the ICE fiasco evolves.)

For entering the US you want to fully wipe your phone first. Lockdown mode is useless since they will just hold you in a basement until you unlock the phone for them to clone.

Re: Project Glasswing: Securing critical software for the AI era

#375

Earlier quoted context omitted.

lol and what about the vibe coders? You people are comical. Why do you feel the need to create so much hype around what you say? Did you not get enough attention as a kid?

The vibe coders will be fine. They’ll use LLMs to red team their code.

[deleted]

Re: Project Glasswing: Securing critical software for the AI era

#376

Earlier quoted context omitted.

> if you are the kind of person these exploits are likely to target, you should have it on You can also selectively turn it on in high-risk settings. I do so when I travel abroad or go through a border. (Haven't started doing it yet with TSA domestically. Let's see how the ICE fiasco evolves.)

For entering the US you want to fully wipe your phone first. Lockdown mode is useless since they will just hold you in a basement until you unlock the phone for them to clone.

> Lockdown mode is useless since they will just hold you in a basement until you unlock the phone for them to clone

If this is a risk for you, sure. Wipe it. For most people they may ask to fiddle around with it before giving it back.

Re: Project Glasswing: Securing critical software for the AI era

#377

Earlier quoted context omitted.

I would have not believed your argument 3 months ago but I strongly suspect Anthropic actively engages in model quality throttling due to their compute constraints. Their recent deal for multi GWs worth of data center might help them correct their approach.

For what it's worth Anthropic explicity denies that. "To state it plainly: We never reduce model quality due to demand, time of day, or server load" Also can see https://marginlab.ai/trackers/claude-code/ It's very interesting to me how widespread this conception is. Maybe it's as simple as LLM productivity degrading over time within a project, as slop compounds. Or more recently since they added a 1m context window,…

That still leaves open the possibility that they reduce model quality due to profit. ;p

Re: Project Glasswing: Securing critical software for the AI era

#379

> On the global stage, state-sponsored attacks from actors like China, Iran, North Korea, and Russia have threatened to compromise the infrastructure that underpins both civilian life and military readiness. AITA for thinking that PRISM was probably the state sponsored program affecting civilian life the most? And that one state is missing from the list here?

I can think of two I’d add to the list. One was recently publicly denied access to Anthropics models and the other was busy exploding pagers.

Re: Project Glasswing: Securing critical software for the AI era

#380

Earlier quoted context omitted.

That's not what's happening here. This announcement is about the velocity with which Claude finds vulnerabilities in already-existing software.

Software already exists that has been written by Claude. They absolutely are selling the means to write software, and the means to securing the insecure software. At least for the time being. In the future Mythos will probably just make it possible to prompt good software from the start.

I don't think claude wrote openbsd but to be honest that was before my time so I'm not sure
Post reply on HN