Live data from Hacker News

NSA director: 'Mythos "broke into almost all of our classified systems in hours"

economist.com

41–50 of 131 posts

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#42

If mythos can break into almost all of their classified systems in hours then other models including opus, gpt, gemini and large open weight models can do so as well, maybe you'll have to double hours or it may become days, but they also will, there is no "maybe" in here. State sponsored, non-public penetration fine tunes (of possibly public ones) likely can do it even faster. Unsupervised penetration RL loop is idea…

I don't think that is necessarily true. - With a weaker model, the time to break into the system might grow so larger that it becomes infeasible, similar to how password hashes can be bruteforced, but if the password is long enough, that is not going to happen in our lifetime. - There might be problems which are inherently unsolvable with a lower level of intelligence. For example, your dog won't derive calculus from…

[dead]

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#43

If mythos can break into almost all of their classified systems in hours then other models including opus, gpt, gemini and large open weight models can do so as well, maybe you'll have to double hours or it may become days, but they also will, there is no "maybe" in here. State sponsored, non-public penetration fine tunes (of possibly public ones) likely can do it even faster. Unsupervised penetration RL loop is idea…

Also, this is just security through obscurity. The holes that mythos exploited still exist after you've tried to limit mythos accessibility. And the fact that all our systems are riddled with security holes shouldn't be too much of a surprise given the way that we all know that software is developed and how tech debt / chores are constantly underbudgeted (plus I think this underscores that any one human's knowledge a…

Yes, exactly, quite shocking, if something like this is true, as NSA (!!) director you keep it quiet, right?

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#44
This quote from TFA is highly likely to be a conflation, exaggeration or extrapolation of what actually happened:

> "On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”"

Why:

1. It's a paraphrase of a 2nd hand conversation and (at least) the last two 'telephone game' recipients are a U.S. Senator and a general, not security domain or IT experts. 2. Motivated communication: The Senator claimed this to justify the necessity of unprecedented restrictions that he agrees with. 3. The original testimony to the Intelligence Committee was almost certainly detailed, nuanced and highly classified, making this an extreme paraphrase.

In saying this, I'm not claiming Mythos may not be a security issue or that something directionally like this wasn't reported. But given the indirect, circuitous path, it's quite easy to imagine the original testimony was more like "Mythos identified a potential vulnerability we rated "Severe" in a critical system and we believe it could find similar vulnerabilities in any of our systems."

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#47
post #5

What happens when open source models achieve Mythos level capabilities in six months' time?

I think it's probably more like a year or a year and a half. I don't want to say two years, but it's what I'm actually thinking.

GLM 5.2 is already between 4.6 Opus 4.7 Opus level based on Artificial Analysis aggregation. 4.6 Opus is about 4 months old at this point, so seems like open source is maybe 4-6 months behind. It could still take a year but seems closer to 6 months.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#48

This quote from TFA is highly likely to be a conflation, exaggeration or extrapolation of what actually happened: > "On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”" Why: 1. It's a p…

Why not use Mythos to hack them and see what the report was

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#49

Earlier quoted context omitted.

Also, this is just security through obscurity. The holes that mythos exploited still exist after you've tried to limit mythos accessibility. And the fact that all our systems are riddled with security holes shouldn't be too much of a surprise given the way that we all know that software is developed and how tech debt / chores are constantly underbudgeted (plus I think this underscores that any one human's knowledge a…

Yes, exactly, quite shocking, if something like this is true, as NSA (!!) director you keep it quiet, right?

Not if the existential threat (to your organization’s current setup) is uncontainable.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#50

Earlier quoted context omitted.

Also, this is just security through obscurity. The holes that mythos exploited still exist after you've tried to limit mythos accessibility. And the fact that all our systems are riddled with security holes shouldn't be too much of a surprise given the way that we all know that software is developed and how tech debt / chores are constantly underbudgeted (plus I think this underscores that any one human's knowledge a…

Yes, exactly, quite shocking, if something like this is true, as NSA (!!) director you keep it quiet, right?

That is literally just more security through obscurity.

And the threat actors that would find that information "useful" already know it.

All of our IT security is a mess, the NSA director is just confirming what should be common knowledge.

Post reply on HN