Live data from Hacker News

Mythos Finds a Curl Vulnerability

daniel.haxx.se

41–50 of 298 posts

Re: Mythos Finds a Curl Vulnerability

#41
post #31

Earlier quoted context omitted.

I'd go out and say the marketing is not subtle. The hype and fanboys/girls are so in line with the marketing that any level of skepticism is seen a an act of defection, but if you look at the words, hyperbole and volume that is used, there is nothing subtle about it. It's almost Trump-esque - "this model will change everything forever; we are doomed; we are saved; we will all be fired; we will all be rich", etc

I seem to be totally outside the hype bubble, but I have to suspect there is a lot of imagineering and wild extrapolations in the elss technical hype bubbles. I am curious but no enough to go looking.

>I seem to be totally outside the hype bubble

I'm surprised you say that because it is all over Hacker News. Every single post is co-opted into promoting AI. Try finding a submission with fifty points or more than doesn't have AI or LLM's mentioned somewhere in the comments.

Re: Mythos Finds a Curl Vulnerability

#42

It's a shame he seems to reject the idea of actually diving in and using these tools interactively: > It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. His expertise I think would elevate the results quite a bit. Although if he never uses LLMs, which it reads like he doesn't, I guess it might backfire just as well. Prompting style (still?) does matter…

He states in the article that they use LLMs for this purpose and find them extremely useful.

Re: Mythos Finds a Curl Vulnerability

#43
post #3

Quote: "My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in co…

Mythos marketing really leans into that "too powerful to be legal" vibe, much like how PS2s were allegedly banned from North Korea because their chips were basically missile-grade.

Re: Mythos Finds a Curl Vulnerability

#44
post #4

> The single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June My mind still cannot understand the quality and refinement that's gone into cURL. It really is the perfect example of something done so right, that people barely think twice about.

Easy, it shows what is achievable if there is a high bar for quality in every single line of code that gets commited, reviewed and merged, regardless of the programming language.

However in the days of race to bottom, offshoring for penies, and now LLM powered code generation, this is a quality most companies won't care unless there is liability in place.

Re: Mythos Finds a Curl Vulnerability

#45
post #35
post #17

Earlier quoted context omitted.

Doubt it considering that Daniel Stenberg is Swedish. English dictation when you speak English as a second language with an accent is quite annoying.

Voice input works really well for people speaking English with a Swedish accent. I think the accent of most educated Swedes is mostly a case of prosody. For sure there are some sounds we say slightly differently than native English speakers. We often have some trouble with /s/ and /z/, but I don't know, "war and peace", I think that's easily understood. Source: voice typing this with Swedish vocal chords, and only ha…

Android voice input works with kids using both English and native words, here in India. The country runs schools in 25+ primary languages, each with dialects, so a TV/phone with voice input is more marvelous than the nitpicks discussed here.

Re: Mythos Finds a Curl Vulnerability

#46

> Not particularly “dangerous” I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.

Sure, but isn't it a verdict on Mythos compared to other models?

If so, it would still follow. "Most software" isn't analyzed as much as curl, by either other tooling or other models, that might well find close to the same as Mythos did. As such, Mythos then isn't especially/particularly dangerous.

Re: Mythos Finds a Curl Vulnerability

#47
post #16

Earlier quoted context omitted.

> It's a good reminder for us all that the competition in this space is rough and lots of more or less subtle marketing is involved. About as subtle as a personal injury lawyer's billboard

A thankfully American reference

Can you expand on this? Do you mean in contrast to the European AI milieu?

Re: Mythos Finds a Curl Vulnerability

#48
post #29
post #24

I don't know about Mythos but in recent weeks I've noticed Opus is constantly failing to fix things in tsz[0] vs GPT 5.5 can easily churn out fixes that are solid and pass tests. I've stopped paying for Claude for now and all my money is going to OpenAI at the moment. Either Opus is massively nerfed or GPT 5.5 is really head and shoulder higher in terms of very difficult tasks. The last percent of conformance tests i…

The new Opus feels like a step backwards. More expensive, thinks more, and it does not get the job done.

From a user’s perspective 4.7 is a downgrade compared to 4.6 . It’s intended to give Anthropic more control about their compute resources and profitability:

https://news.ycombinator.com/item?id=48072916

Re: Mythos Finds a Curl Vulnerability

#49

> Not particularly “dangerous” I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.

But Mythos is not marketed as a tool that can do the same as other tools already available maybe slightly better, but as a revolution.

Re: Mythos Finds a Curl Vulnerability

#50
post #42

It's a shame he seems to reject the idea of actually diving in and using these tools interactively: > It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. His expertise I think would elevate the results quite a bit. Although if he never uses LLMs, which it reads like he doesn't, I guess it might backfire just as well. Prompting style (still?) does matter…

He states in the article that they use LLMs for this purpose and find them extremely useful.

Which can be true without this also being true:

> using these tools interactively

I did read the article. It seems to me they're using LLMs in a prepared manner instead, as mere scanners that produce reports.

Post reply on HN