Live data from Hacker News

Mythos Finds a Curl Vulnerability

daniel.haxx.se

231–240 of 298 posts

Re: Mythos Finds a Curl Vulnerability

#231
post #222

Earlier quoted context omitted.

Context from 2019: https://en.wikipedia.org/wiki/GPT-2 >While previous OpenAI models had been made immediately available to the public, OpenAI initially refused to make a public release of GPT-2's source code when announcing it in February, citing the risk of malicious use;[8][5] limited access to the model (i.e. an interface that allowed input and provided output, not the source code itself) was allowed for selected…

It's kind of funny watching the behavior on the forum of different groups with different beliefs. "AI can't do anything harmful at all, kick this shit up to 11. It's all marketing, bla bla" and "My grandma gave away all her money to AI bots and is now starving in the street. My uncle murdered his wife and is trying to get married to GPT-4o. He thinks they are going to elope to a data center on a tropical island and l…

Related: https://youtu.be/Ykvf3MunGf8?si=UEIMRdrMWUFF6V8Q

AI chatbots have caused real harm. It has tragically convinced and encouraged a number of people to commit suicide, to say nothing about scams. It is having a real effect on the social fabric of our society.

I don't understand what point the people who blame the dangers of AI on marketing.

Re: Mythos Finds a Curl Vulnerability

#233
post #119

Earlier quoted context omitted.

Actually, OpenAI made a similar claim about one of their GPT models a while ago… Funnily enough that was while Dario Amodei was their research director.

If you're referring to gpt-2 in 2019, that primarily about concerns with it being used by spammers and fake content generators. In retrospect, that was a totally valid concern.

They had a reddit with GPT2 back and forth I have to say I got suckered into a conversation before I figured it out -- it was definitely the OG Moltbook of non sequiturs

Re: Mythos Finds a Curl Vulnerability

#234
post #44
post #4

> The single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June My mind still cannot understand the quality and refinement that's gone into cURL. It really is the perfect example of something done so right, that people barely think twice about.

Easy, it shows what is achievable if there is a high bar for quality in every single line of code that gets commited, reviewed and merged, regardless of the programming language. However in the days of race to bottom, offshoring for penies, and now LLM powered code generation, this is a quality most companies won't care unless there is liability in place.

> Easy, it shows what is achievable if there is a high bar for quality in every single line of code that gets commited

This is becoming a more and more overlooked/underrated feature. I genuinely believe it would be impossible in any company that depends on shareholder value. I am yet to convince any company I've worked in without bloody hands that we need to solve old tech debt and refactor certain things etc.

Re: Mythos Finds a Curl Vulnerability

#235
post #227

Earlier quoted context omitted.

The point is that Anthropic claims it’s a huge leap over everything else. But it isn’t.

But both things can be true. It could be a huge leap (see Firefox’s example) but also find almost nothing in an already well maintained and audited codebase, and that could mean there isn’t much to find.

Okay, but how do we know that all 400 plus hits were actual vulnerabilities? I didn't read too deeply into it so I might've missed something but did someone test and validate each of those vulns to confirm that they were actually vulns?

Re: Mythos Finds a Curl Vulnerability

#236
I guess we miss fundamental information: how much in terms of time and token usage took to the "middle guy" to create the report?

Next question: could it be that OP can use Mythos in a better way since he knows better the project?

Re: Mythos Finds a Curl Vulnerability

#238
post #44

Earlier quoted context omitted.

Easy, it shows what is achievable if there is a high bar for quality in every single line of code that gets commited, reviewed and merged, regardless of the programming language. However in the days of race to bottom, offshoring for penies, and now LLM powered code generation, this is a quality most companies won't care unless there is liability in place.

> Easy, it shows what is achievable if there is a high bar for quality in every single line of code that gets commited This is becoming a more and more overlooked/underrated feature. I genuinely believe it would be impossible in any company that depends on shareholder value. I am yet to convince any company I've worked in without bloody hands that we need to solve old tech debt and refactor certain things etc.

Which is liability is relevant, that is the only language shareholders understand.

Re: Mythos Finds a Curl Vulnerability

#239
post #150

Earlier quoted context omitted.

I had a totally different take. The fact that Mythos found only one vulnerability is testament to how solid curl is, not how bad Mythos is. Look at the Firefox blog post where they found something like 400 (or more) findings. I have no doubt Mythos is very good at this, but I also don't think it's something unattainable by other labs within the next few months, with focus.

The point is that Anthropic claims it’s a huge leap over everything else. But it isn’t.

There is no way to tell until we find examples of vulnerabilities that mythos missed. For all we know curl currently has 0 vulnerabilities right now

Re: Mythos Finds a Curl Vulnerability

#240

> An amazingly successful marketing stunt for sure. This. Well done by Antropic. It even reached the CISO of my small semi-government org in the Netherlands, who slightly panicked at the announced 'tsunami' of vulnerabilities that was coming with Mythos. Got us some more money and priority with the board, though. Never waste a good marketing scare.

Anthropic has is quickly destroying customer goodwill by repeatedly pulling the same stunt. Horrible marketing, imho. It's an entirely different thing to have the company conduct research on LLMs in general being a cybersecurity threat, instead of going " our new model is just too powerful" and shift the discussion to revolve around that. It's slimey.

Hasn't almost every new frontier model had an early period of limited access? I don't get why everyone is acting like Mythos is particularly egregious for this.
Post reply on HN