Live data from Hacker News

NSA director: 'Mythos "broke into almost all of our classified systems in hours"

economist.com

51–60 of 131 posts

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#51
Not a surprise. I got in a LOT of trouble for identifying and outlining a trivial privilege escalation attack that worked on both NIPR and SIPR.

In the end I got to help write up the issue but to my knowledge they never patched it as it would have caused major issues with maintenance by closing off access needed for some legacy software patches.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#52
post #5

What happens when open source models achieve Mythos level capabilities in six months' time?

We'll see Mythos 2.0 patching all the Mythos 1.0 vulnerabilities before we see an open-source Mythos 1.0.

What matters isn't the power of the tool, but whether defenders have had time to secure against. Today's cyberweapon is tomorrow's laughably obsolete.

Stuxnet used to be a national security threat, now I'm not sure it would be useful for anything.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#53
Not surprised, our security systems are 95% security through obscurity these days. Mythos didn't find new ways to break security, it just went down the list of common security exploits and exposed them for being common even among government agencies.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#54
>On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”.

From outside? Or did you have a shit ton of unpatched systems that only internal users could access?

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#55

Not surprised, our security systems are 95% security through obscurity these days. Mythos didn't find new ways to break security, it just went down the list of common security exploits and exposed them for being common even among government agencies.

Next Headline: Government bans nMap.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#56

Not a surprise. I got in a LOT of trouble for identifying and outlining a trivial privilege escalation attack that worked on both NIPR and SIPR. In the end I got to help write up the issue but to my knowledge they never patched it as it would have caused major issues with maintenance by closing off access needed for some legacy software patches.

It is very interesting the different reactions between your experience (and many whistleblowers), and how people react to software doing the same thing. Although in this case, maybe it isn't so different? They did essentially have the tool buried, out of sight out of mind for a little while at least.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#59

If mythos can break into almost all of their classified systems in hours then other models including opus, gpt, gemini and large open weight models can do so as well, maybe you'll have to double hours or it may become days, but they also will, there is no "maybe" in here. State sponsored, non-public penetration fine tunes (of possibly public ones) likely can do it even faster. Unsupervised penetration RL loop is idea…

I don't think that is necessarily true. - With a weaker model, the time to break into the system might grow so larger that it becomes infeasible, similar to how password hashes can be bruteforced, but if the password is long enough, that is not going to happen in our lifetime. - There might be problems which are inherently unsolvable with a lower level of intelligence. For example, your dog won't derive calculus from…

I think you're missing the point. Everything you said is theoretically correct, but the parent comment was talking about the concrete circumstance of pentesting with the top models today.

Let's just take GPT 5.5 and Opus 4.8 as an example. Both are worse than Mythos 5, but they're capable of quite a bit when the guardrails are lifted and they're paired with a skilled human operator. They more than "good enough" to reach the same result with the addition of some human effort.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#60

Earlier quoted context omitted.

I think it's probably more like a year or a year and a half. I don't want to say two years, but it's what I'm actually thinking.

GLM 5.2 is already between 4.6 Opus 4.7 Opus level based on Artificial Analysis aggregation. 4.6 Opus is about 4 months old at this point, so seems like open source is maybe 4-6 months behind. It could still take a year but seems closer to 6 months.

Artificial Analysis is just as benchmark-maxxed as they come. Aggregating tons of benchmark-maxxing means you're still benchmark-maxxed.

There's simply no replacement for training on more, better tokens, with more parameters. Mythos/Fable was estimated to be closer to 10T parameters than the 800B like GLM 5.2 is.

Post reply on HN