Live data from Hacker News

NSA is using Anthropic's Mythos despite blacklist

axios.com

141–150 of 378 posts

Re: NSA is using Anthropic's Mythos despite blacklist

#141
post #118

Earlier quoted context omitted.

> The whole artificial scarcity Anthropic created around Mythos / Glasswing is quite brilliant to be honest Isn’t that just the same strategy OpenAI has used over and over? Sam Altman is always “OMG, the new version of ChatGPT is so scary and dangerous”, but then releases it anyway (tells you a lot about his values—or lack thereof) and it’s more of the same. Pretty sure Aesop had a fable about that. “The CEO who crie…

Anthropic has not in fact released it, and it does in fact appear to be that dangerous, judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg. Certainly it’s a strategy OpenAI has used before, and when they did so it was a lie. Altman’s dishonesty does not mean it can never be true, however.

> judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg

Maybe I've missed anything, but what Stenberg been complaining about so far been the wave of sloppy reports, seemingly reported by/mainly by AIs. Has that ratio somehow changed recently to mainly be good reports with real vulnerabilities?

Re: NSA is using Anthropic's Mythos despite blacklist

#142

Earlier quoted context omitted.

It’s easy to find sketchy lines of code in any large C project. The big advance that they are claiming with Mythos is the ability to triage all the hundreds of candidate vulns and automatically generate exploits to prove that the real ones are real. And if they’re really finding 27-yr-old 0-days in OpenBSD, then it’s not just hype.

I do not think you need a great model to do this, just great automation. There’s a reason they haven’t open sourced the actual process in which did this, stubbing out the mythos model itself.

About five minutes in in this video: https://www.youtube.com/watch?v=1sd26pWhfmg

They also say publicly in their Opus 4.6 post (https://red.anthropic.com/2026/zero-days/):

>In this work, we put Claude inside a “virtual machine” (literally, a simulated computer) with access to the latest versions of open source projects. We gave it standard utilities (e.g., the standard coreutils or Python) and vulnerability analysis tools (e.g., debuggers or fuzzers), but we didn’t provide any special instructions on how to use these tools, nor did we provide a custom harness that would have given it specialized knowledge about how to better find vulnerabilities. This means we were directly testing Claude’s “out-of-the-box” capabilities, relying solely on the fact that modern large language models are generally-capable agents that can already reason about how to best make use of the tools available.

Re: NSA is using Anthropic's Mythos despite blacklist

#143
post #118

Earlier quoted context omitted.

> The whole artificial scarcity Anthropic created around Mythos / Glasswing is quite brilliant to be honest Isn’t that just the same strategy OpenAI has used over and over? Sam Altman is always “OMG, the new version of ChatGPT is so scary and dangerous”, but then releases it anyway (tells you a lot about his values—or lack thereof) and it’s more of the same. Pretty sure Aesop had a fable about that. “The CEO who crie…

Anthropic has not in fact released it, and it does in fact appear to be that dangerous, judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg. Certainly it’s a strategy OpenAI has used before, and when they did so it was a lie. Altman’s dishonesty does not mean it can never be true, however.

How many months till they release a better model than mythos to general audience?

Gpt 2 wasn't released fully because OpenAI deemed it too dangerous, rings a bell? https://openai.com/index/better-language-models/#sample1

Re: NSA is using Anthropic's Mythos despite blacklist

#144

Earlier quoted context omitted.

Side note, how did the word "lose" become "loose"? I've seen this so many times on HN.

Because your pronounce them backwards. "Loose" is a short word that ends sharply, but "lose" is a long word that slowly peters out. They should be the other way around imo.

Loose rhymes with moose, noose, caboose...

Re: NSA is using Anthropic's Mythos despite blacklist

#145
post #142

Earlier quoted context omitted.

I do not think you need a great model to do this, just great automation. There’s a reason they haven’t open sourced the actual process in which did this, stubbing out the mythos model itself.

About five minutes in in this video: https://www.youtube.com/watch?v=1sd26pWhfmg They also say publicly in their Opus 4.6 post ( https://red.anthropic.com/2026/zero-days/ ): >In this work, we put Claude inside a “virtual machine” (literally, a simulated computer) with access to the latest versions of open source projects. We gave it standard utilities (e.g., the standard coreutils or Python) and vulnerability analysi…

Again, marketing materials by Anthropic. You realize this is by anthropic themselves right? And again, not reproducible by outsiders. So useless.

Re: NSA is using Anthropic's Mythos despite blacklist

#146

Earlier quoted context omitted.

> This puts the US government into a loose / loose position. You might even call it... a tight spot

Side note, how did the word "lose" become "loose"? I've seen this so many times on HN.

I always assume not everyone is an English speaker and let it go.

Re: NSA is using Anthropic's Mythos despite blacklist

#147

Earlier quoted context omitted.

Anthropic has not in fact released it, and it does in fact appear to be that dangerous, judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg. Certainly it’s a strategy OpenAI has used before, and when they did so it was a lie. Altman’s dishonesty does not mean it can never be true, however.

> judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg Maybe I've missed anything, but what Stenberg been complaining about so far been the wave of sloppy reports, seemingly reported by/mainly by AIs. Has that ratio somehow changed recently to mainly be good reports with real vulnerabilities?

Yes:

> The challenge with AI in open source security has transitioned from an AI slop tsunami into more of a ... plain security report tsunami. Less slop but lots of reports. Many of them really good.

> I'm spending hours per day on this now. It's intense.

https://mastodon.social/@bagder/116336957584445742

Re: NSA is using Anthropic's Mythos despite blacklist

#148

Earlier quoted context omitted.

Anthropic has not in fact released it, and it does in fact appear to be that dangerous, judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg. Certainly it’s a strategy OpenAI has used before, and when they did so it was a lie. Altman’s dishonesty does not mean it can never be true, however.

> judging by the flood of vulnerability reports seen by e.g. Daniel Stenberg Maybe I've missed anything, but what Stenberg been complaining about so far been the wave of sloppy reports, seemingly reported by/mainly by AIs. Has that ratio somehow changed recently to mainly be good reports with real vulnerabilities?

He has changed his opinion completely. Yes, the ratio has turned.

Re: NSA is using Anthropic's Mythos despite blacklist

#149

Earlier quoted context omitted.

> This puts the US government into a loose / loose position. You might even call it... a tight spot

Side note, how did the word "lose" become "loose"? I've seen this so many times on HN.

It's fine, nothing to see. Just focus on the intended meaning not the underlying delivery. Mere words don't really impact communication. Right?
Post reply on HN