Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

381–390 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#381

The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…

are we cooked yet? Benchmarks look very impressive! even if they're flawed, it still translates to real world improvements

People say we're cooked every single day. The only response is to continue life as if we aren't. When we are, you won't have to ask that question.

Re: Project Glasswing: Securing critical software for the AI era

#382

Earlier quoted context omitted.

Because questions like this force us to hold up a very uncomfortable mirror to ourselves. It’s much easier to just dismiss.

I’m pretty close to the point of saying that human intelligence is not special.

I would argue the opposite. It’s gotten us to a point were we can recreate human intelligence from electricity and a bunch of math!

Re: Project Glasswing: Securing critical software for the AI era

#383

Now, its very possible that this is Anthropic marketing puffery, but even if it is half true it still represents an incredible advancement in hunting vulnerabilities. It will be interesting to see where this goes. If its actually this good, and Apple and Google apply it to their mobile OS codebases, it could wipe out the commercial spyware industry, forcing them to rely more on hacking humans rather than hacking mobi…

Apple has already largely crushed hacking with memory tagging on the iPhone 17 and lockdown mode. Architectural changes, safer languages, and sandboxing have done more for security than just fixing bugs when you find them.

If what you are saying is true, then you would see exploit marketplaces list iOS exploits at hundreds of millions of dollars. Right now a cursory glance sets the price for zero click persistent exploit at $2m behind Android at $2.5m. Still high, and yes, higher than five years ago when it was around $1m for both, but still not "largely crushed". It is still easy to get into a phone if you are a state actor.

Re: Project Glasswing: Securing critical software for the AI era

#384

The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…

https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... "5.10 External assessment from a clinical psychiatrist" is a new section in this system card. Why are Anthropic like this? >We remain deeply uncertain about whether Claude has experiences or interests that matter morally, and about how to investigate or address these questions, but we believe it is increasingly important to try. We also report independen…

I totally agree with the premise that we should not anthropomorphize generative ai. And I find it absurd that anthropic spends any time considering the “welfare” of an ai system. (There are no real “consequences” to an ai’s behavior)

However, I find their reasoning here to have a valid second order effect. Humans have a tendency to mirror those around them. This could include artificial intelligence, as recent media reports suggest. Therefore, if an ai system tends to generate content that contain signs of neuroticism, one could infer that those who interact with that ai could, themselves, be influenced by that in their own (real world) behavior as a result.

So I think from that perspective, this is a very fruitful and important area of study.

Re: Project Glasswing: Securing critical software for the AI era

#386

Earlier quoted context omitted.

Did they activate them to any noticeable effect?

To my knowledge, not yet. The attack surface in question is extensive, and in my opinion, targets are likely unprepared for a determined and sophisticated attacker. https://www.politico.com/news/2026/04/07/iranian-hackers-ene...

It's 2026, and these PLCs etc. are directly connected to the internet? I think that's the most surprising aspect here.

Re: Project Glasswing: Securing critical software for the AI era

#387

Earlier quoted context omitted.

To my knowledge, not yet. The attack surface in question is extensive, and in my opinion, targets are likely unprepared for a determined and sophisticated attacker. https://www.politico.com/news/2026/04/07/iranian-hackers-ene...

It's 2026, and these PLCs etc. are directly connected to the internet? I think that's the most surprising aspect here.

It doesn’t surprise me at all. Show me the incentives, and I’ll show you the outcome. Security is simply not valued, in many cases.

Re: Project Glasswing: Securing critical software for the AI era

#388

Earlier quoted context omitted.

Software already exists that has been written by Claude. They absolutely are selling the means to write software, and the means to securing the insecure software. At least for the time being. In the future Mythos will probably just make it possible to prompt good software from the start.

Ok. But mostly its entirely the old software, not the new software, that the bugs are being found in.

Maybe because there’s no critical and widely used software written by LLMs so far? Which says a lot about LLMs are failing to even approach the level of capabilities you would expect from all the hype? The goal has always been, even before LLMs, to find something smarter than our smarter humans. So far the success at that is really minuscule. Humans are still the benchmark, all things considered. Now they’re saying LLMs are going to be better than our best vulnerability researchers in a few months (literally what an Anthropic researcher said in a conference). Ok, that might happen. But the funny part is that the LLMs will definitely be the ones writing most of these vulnerabilities. So, to hedge against LLMs you must use LLMs. And that is gonna cost you more.

Re: Project Glasswing: Securing critical software for the AI era

#389

Earlier quoted context omitted.

I'm too much of an anarchist for that. I believe what I said: > I think it would be net better for the public if they just made Mythos available to everyone.

10 Axios's within 5 days.

That was a supply chain issue.

The interesting thing about Mythos is its ability to find security vulns in software that has an uncompromised supply chain.

Re: Project Glasswing: Securing critical software for the AI era

#390

I guess we can throw out the idea that AGI is going to be democratized. In this case a sufficiently powerful model has been built and the first thing they do is only give AWS, Microsoft, Oracle ect ect access. If AGI is going to be a thing its only going to be a thing, its only going to be a thing for fortune 100 companies.. However, my guess is this is mostly the typical scare tactic marketing that Dario loves to pu…

The plan of Elon Musk for Macrohard is to replace all software companies with it, when they get AGI.

Thankfully he will be long dead before that happens. But of course that's his goal. Elon despises expensive engineers, and he yearns to get revenge for them costing him so much money over the years by replacing them.

A tech billionaires biggest expensive has been his engineering line-item. They resent the workers who've collected a large percentage of their potential profits over the years, its their driving motivation, to crush all labor.

Post reply on HN