Live data from Hacker News

US summons bank bosses over cyber risks from Anthropic's latest AI model

theguardian.com

41–50 of 101 posts

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#41

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

Need to dump the bag on retail investors and pensions before they implode

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#42

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

A good percentage of cybersecurity has always been theater. If their model helps to separate the wheat from the chaff, maybe it'll be an improvement.

It sounds like it’ll just kill the wheat and the chaff.

Still probably a benefit depending on your philosophy.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#43
post #38
post #3

Promoting the model as potentially dangerous might backfire with the government banning it from being released by executive order.

> the government banning it from being released by executive order. There's no legal mechanism for the president or the government at all to do that.

I'm sure they will find something when it really starts to bother them personally.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#44

I wonder whether this kind of release of model could become the spark that ignites a new digital "cold war" between us, europe, india and china, in which they will try to outwit their rivals and compromise their critical infrastructure using artificial intelligence. Also I’d like to believe that this really is such a huge step forward compared to Opus, but lately I’ve found it hard to believe when I look at the state…

> ignites a new digital "cold war"

Already been going on for over a decade - export controls on dual use technology like Xeon processors already began being enforced back in the Obama admin.

> until the launch takes place

It's already launched. Some companies had access to Mythos for months.

> fuelling the hype

This is true. Commercially available models from a year ago are already good enough from an offensive security perspective. Their big issue was noise, but that could be managed.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#45
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

You're making a hubris-laden assumption coders know the gaps their baking into their software — that any human has a decent enough grip on the multitudes of spinning logic duct taped together to make the internet run. Most vulnerabilities aren't "ignored"; they're in a neverending backlog or unknown.

If you closed all of the AI-discovered security vulnerabilities tomorrow - by the next day there'd be a host of new ones. That's software, baby.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#46
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

Highly disagree.

It's most of the time a question of management not caring about security or disliking the inconvenience that security can bring.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#48
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

> it mostly boils down to recklessness of developers

I disagree. I think in big tech and the corporate world, it boils down to the organization fundamentally not valuing security and punishing developers if they "move slow", which is often the outcome when you maintain a highly security-oriented process while developing software and infrastructure.

When big leaks happen, the worst that occurs is that some trivial financial penalty is applied to the company so the incentive to ignore security problems until you're forced to acknowledge them is high.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#49
post #38
post #3

Promoting the model as potentially dangerous might backfire with the government banning it from being released by executive order.

> the government banning it from being released by executive order. There's no legal mechanism for the president or the government at all to do that.

There are ways for the government to do that sort of thing on an emergency basis, and it would take quite some time to make it's way through the courts. There are precedents from nuclear weapons technology and cryptography. I don't think it'll hold up or be particularly effective because the horse has left the barn already, but they could probably slow things down if they really wanted to.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#50
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

You missed the management factor. And even if managers don't explicitly ask you to build insecure stuff they will up to the pressure to the point that you have no choice or leave the company for someone who will do just that. So the end result is the same. Rarely will individual push back with some force and then they will eventually be let go because they're 'troublemakers'.
Post reply on HN