Cryptographic attestation at the tool-call level (sign the request, verify before execution) would close a gap that behavioral controls alone can't cover. Curious whether Glasswing's threat model includes the agent-to-tool boundary or focuses primarily on the model layer.
Project Glasswing: Securing critical software for the AI era
701–710 of 921 posts
Re: Project Glasswing: Securing critical software for the AI era
#702All the promises of amazing things in general work never happened. Companies consistently say they’re seeing no ROI. The AI crowd now hard pivots to cyber and, right out of the Palantir playbook, runs with the “our stuff is so amazing we can’t talk about it, but trust us bro” move that isn’t really fooling anyone.
Meanwhile the folks let in on the “secret” are those that also desperately need for the hype to continue to protect their own positions in this game.
Look forward to a model upgrade but the hype fluff games are getting old. Watching OpenAI completely crash out of pole position on the hype train though has been at least amusing.
Re: Project Glasswing: Securing critical software for the AI era
#703Earlier quoted context omitted.
You should watch this talk by Nicholas Carlini (security researcher at Anthropic). Everything in the talk was done with Opus 4.6: https://www.youtube.com/watch?v=1sd26pWhfmg
Just a thought: The fact that the found kernel vulnerability went decades without a fix says nothing about the sophistication needed to find it. Just that nobody was looking. So it says nothing about the model’s capability. That LLMs can find vulnerabilities is a given and expected, considering they are trained on code. What worries me is the public buying the idea that it could in any way be a comprehensive security…
Re: Project Glasswing: Securing critical software for the AI era
#704Earlier quoted context omitted.
It’s insane. This is what - could we say it’s beyond AGI at least in cybersecurity? This is a real wake up call. On some of this stuff, the AI’s “uneven intelligence” is becoming absurdly high at its local peaks.
Please stop using terms you don’t understand like “AGI” because you feel overwhelmed by something doing cool stuff. It’s exhausting.
Re: Project Glasswing: Securing critical software for the AI era
#705Earlier quoted context omitted.
It’s insane. This is what - could we say it’s beyond AGI at least in cybersecurity? This is a real wake up call. On some of this stuff, the AI’s “uneven intelligence” is becoming absurdly high at its local peaks.
> could we say it’s beyond AGI at least in cybersecurity? AGI is like the Holy Grail. Either in the Arthurian Hero's Journey sense, or in the sense of having been a myth all along.
Re: Project Glasswing: Securing critical software for the AI era
#706Re: Project Glasswing: Securing critical software for the AI era
#707Re: Project Glasswing: Securing critical software for the AI era
#708From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…
Even more 'disquieting' when you take into account who's currently the president of US. "A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump
Re: Project Glasswing: Securing critical software for the AI era
#709Earlier quoted context omitted.
It's very good but it's also recycled Ayn Rand, the Fountainhead.
There is a similar theme in both of an artistic person not wanting to compromise their vision to suit common tastes. But this goes in a completely different direction than Rand.
Re: Project Glasswing: Securing critical software for the AI era
#710Got it.