Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

701–710 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#701
One thing I keep thinking about with AI security is that most of the focus is on model behavior — alignment, jailbreaks, guardrails. But once agents start calling tools, the attack surface shifts to the execution boundary. A request can be replayed, tampered with, or sent to the wrong target, and the server often has no way to distinguish that from a legitimate call.

Cryptographic attestation at the tool-call level (sign the request, verify before execution) would close a gap that behavioral controls alone can't cover. Curious whether Glasswing's threat model includes the agent-to-tool boundary or focuses primarily on the model layer.

Re: Project Glasswing: Securing critical software for the AI era

#702
I’m sure it’s a decent model. But it’s also clear folks are running out of runway and desperate to find something that sticks and keeps the party going.

All the promises of amazing things in general work never happened. Companies consistently say they’re seeing no ROI. The AI crowd now hard pivots to cyber and, right out of the Palantir playbook, runs with the “our stuff is so amazing we can’t talk about it, but trust us bro” move that isn’t really fooling anyone.

Meanwhile the folks let in on the “secret” are those that also desperately need for the hype to continue to protect their own positions in this game.

Look forward to a model upgrade but the hype fluff games are getting old. Watching OpenAI completely crash out of pole position on the hype train though has been at least amusing.

Re: Project Glasswing: Securing critical software for the AI era

#703
post #76

Earlier quoted context omitted.

You should watch this talk by Nicholas Carlini (security researcher at Anthropic). Everything in the talk was done with Opus 4.6: https://www.youtube.com/watch?v=1sd26pWhfmg

Just a thought: The fact that the found kernel vulnerability went decades without a fix says nothing about the sophistication needed to find it. Just that nobody was looking. So it says nothing about the model’s capability. That LLMs can find vulnerabilities is a given and expected, considering they are trained on code. What worries me is the public buying the idea that it could in any way be a comprehensive security…

People have, of course, been looking. Linux has been the #1 corpus for the methods for ages.

Re: Project Glasswing: Securing critical software for the AI era

#704
post #323

Earlier quoted context omitted.

It’s insane. This is what - could we say it’s beyond AGI at least in cybersecurity? This is a real wake up call. On some of this stuff, the AI’s “uneven intelligence” is becoming absurdly high at its local peaks.

Please stop using terms you don’t understand like “AGI” because you feel overwhelmed by something doing cool stuff. It’s exhausting.

You’re right. What I mean is - is this superhuman intelligence at cybersecurity? Or did we just build an amazing tool? But that’s kind of the whole debate

Re: Project Glasswing: Securing critical software for the AI era

#705

Earlier quoted context omitted.

It’s insane. This is what - could we say it’s beyond AGI at least in cybersecurity? This is a real wake up call. On some of this stuff, the AI’s “uneven intelligence” is becoming absurdly high at its local peaks.

> could we say it’s beyond AGI at least in cybersecurity? AGI is like the Holy Grail. Either in the Arthurian Hero's Journey sense, or in the sense of having been a myth all along.

It’s true I misspoke. What I mean is - is this then a form of localised super intelligent tool for cybersecurity ?

Re: Project Glasswing: Securing critical software for the AI era

#706
post #281

Earlier quoted context omitted.

Limiting it to the area of cybersecurity is by definition not general.

Perhaps "ASI" is the better acronym here

Yes that’s true. I misspoke. I meant - is this a super intelligent tool then for cybersecurity?

Re: Project Glasswing: Securing critical software for the AI era

#707
With Anthropic able to use this model internally (since February), is this the kickoff of ramping up the flywheel of recursive self improvement of AI? It seems like as long as there are still humans in the loop at most steps, exponential recursion isn’t possible.

Re: Project Glasswing: Securing critical software for the AI era

#708

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

Even more 'disquieting' when you take into account who's currently the president of US. "A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump

The art of the deal, baby

Re: Project Glasswing: Securing critical software for the AI era

#709
post #525

Earlier quoted context omitted.

It's very good but it's also recycled Ayn Rand, the Fountainhead.

There is a similar theme in both of an artistic person not wanting to compromise their vision to suit common tastes. But this goes in a completely different direction than Rand.

Well of course in 700 pages you'll be about way more than any super short story as this one. But it's there for me quite vividly. Of course LLMs give an amalgamation of many things, but it's like when you look at AI generated pictures and can see the base of the inspiration quite vividly. And then all of this is subjective anyway. People review that book and come away with wildly different interpretations already.
Post reply on HN