Live data from Hacker News

NSA director: 'Mythos "broke into almost all of our classified systems in hours"

economist.com

71–80 of 131 posts

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#71
post #5

What happens when open source models achieve Mythos level capabilities in six months' time?

We'll see Mythos 2.0 patching all the Mythos 1.0 vulnerabilities before we see an open-source Mythos 1.0. What matters isn't the power of the tool, but whether defenders have had time to secure against. Today's cyberweapon is tomorrow's laughably obsolete. Stuxnet used to be a national security threat, now I'm not sure it would be useful for anything.

They were not saying f Open Spurce Mythos 1.0. They were talking about performance / capability parity in other open source models.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#73

It's sad that they did the research[1] and solved computer security about 40 years ago[2], and then proceeded to lose that hard won knowledge over time. [1] https://csrc.nist.rip/publications/history/index_1.html [2] https://en.wikipedia.org/wiki/KeyKOS

People will think you are exaggerating, you aren’t. They will also think I’m exaggerating that you aren’t, I’m not. Learning about capability-based microkernels and realizing this has been a solved problem for years, and is actually one of the rare easy freebie problems in computing, is a highly sobering experience!

Only thing I disagree on is that we lost that knowledge, we did not, there isn’t much to capabilities, they actually simplify OS design IMO.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#74
post #67

Earlier quoted context omitted.

I’m not familiar with this, but what does “solved” mean in this case? Guaranteed inability to compromise systems?

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

[deleted]

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#75

It must be a wild time in the corporate espionage world these days. The annual operating budget of the CIA is like 20B. That's a rounding error compared to the burn rates of these labs. Maybe it's conspiratorial, but it seems like the direction this is going is for the US to nationalize these companies. Somewhere between "too big to fail" and "national security."

You probably don't want to nationalize them. You keep them private like how Lockheed et al are set up, so there can be no freedom of information act requests or any congressional meddling over the secrets and technologies within their purview.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#77

Earlier quoted context omitted.

Yes, exactly, quite shocking, if something like this is true, as NSA (!!) director you keep it quiet, right?

That is literally just more security through obscurity. And the threat actors that would find that information "useful" already know it. All of our IT security is a mess, the NSA director is just confirming what should be common knowledge.

[dead]

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#78
post #5

What happens when open source models achieve Mythos level capabilities in six months' time?

Open source models get banned.

in America, maybe, but all of our adversaries will still have access to them, and continue working on them.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#79
post #67

Earlier quoted context omitted.

I’m not familiar with this, but what does “solved” mean in this case? Guaranteed inability to compromise systems?

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

seL4[0] being the formally-proven modern representative.

0. https://sel4.systems/

Post reply on HN