Live data from Hacker News

Post-Mythos Cybersecurity: Keep calm and carry on

cephalosec.com

51–60 of 83 posts

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#51
post #15
post #5

Earlier quoted context omitted.

> outrage in the news if the Chinese government had been the first to pull this kind of stunt. I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.

It seems our government still has a lot to learn.

At this point, it has a lot to re-learn, as the Trump administration has been systematically lobotomizing it for 18 months.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#53

The CCC talk in December showed me how good llms are at ctf. Ctf fundamentaly have to change. It also showed how critical it is to use llms now. A lot has changed in just 12 month tbh. If you still don't invest time and money into adding llms to your security you didn't hear the bang.

I'd be interested in a link to that talk if it's recorded

Maybe this one? https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-t...

Hoping op will confirm.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#54

Earlier quoted context omitted.

You also have government apparatchiks influencing almost every corporate board, not just the state owned enterprises. Every private company that employs at least 3 CCP members is required by law to form a party committee within the company to represent party interests. In smaller companies, they will often simply coordinate with local governments on securing permits, etc, but I’m sure national party leadership commun…

> I’m sure national party leadership communicates directly with the committees at the AI labs They do now. Top AI researchers in China are barred from getting an exit visa [0] (the PRC has done this for other employees as well such as Foxconn China employees who were working on shifting Apple supply chains to India [1]), and "AI Safety" from a national security perspective has been codified as party policy now [2]. T…

Any recommendations / alternatives for higher signal to noise ratio?

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#55
post #54

Earlier quoted context omitted.

> I’m sure national party leadership communicates directly with the committees at the AI labs They do now. Top AI researchers in China are barred from getting an exit visa [0] (the PRC has done this for other employees as well such as Foxconn China employees who were working on shifting Apple supply chains to India [1]), and "AI Safety" from a national security perspective has been codified as party policy now [2]. T…

Any recommendations / alternatives for higher signal to noise ratio?

Everything is offline now. Public boards like HN are from a bygone era of the Internet.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#56
post #7

The fear porn around this all has been horrible. I work in Cybersecurity and Mythos is all the vendors will talk about because they want to sell something. It started the day of the announcement which is what told me it was all BS. They had no information about it yet would happily tell me about all their solutions for it. Anyone in my profession worth a damn will tell you the vast majority of security issues are rel…

Mythos actually does change that calculus. Going forward, with access to a mythos caliber llm actors are not tied to bad configs or lazy admins for access. I get that the bs is real. But it's important for you to not rest on your laurels having recognizing that salesmen sell. You actually have to pay attention to and understand the new developments your field. It's sad that the marketing department odd doing a better…

Mythos finds exploits largely by reading source code.

Your open source dependencies may need to be version bumped quickly, but most companies are not going to be immediately exploitable without a large scale source code leak, and an attacker motivated to spend large amounts of money/compute on finding lucrative exploits (not just any exploits).

To me the reaction has been way overblown, though again, very real for large scale open source projects.

And going forward there's not going to be as many issues due to using models defensively, e.g. this vulnerability spike is likely a one time event.

So the fear porn is a bit much.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#57
post #46

With so much cloud being at risk from AI now, soon or in the future, it seems like self-hosting or at least managed custody of your own gear is going to become more of a thing.

Is the idea that self hosters tend to make less security mistakes than the big hosting companies?

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#58
post #13

it all looks suspicious: - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems - June 9th 2026: Anthropic releases Mythos model - June 12th 2026: Model gets export regulations placed on it by US Gov - June 26th 2026: US gov announces they will let some comp…

Anthropic losing their ability to release new models to most customers (and thereby revenue, and thereby ability to train new models) makes you think investors will value it more highly than if they could release new models to everyone who wanted to pay them?

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#59
post #8

[flagged]

I tend to agree but open weight model seem to still be lagging behind in terms of capacity, even the recent ones like GLM 5.2. If anything I hope the sudden, unpredictable changes of policy will make EU companies think twice before putting all their eggs in the same AI vendors's basket, all US based. Vendors coming back on their retention policies like they did with Fable 5 or plainly cutting the service without noti…

> I tend to agree but open weight model seem to still be lagging behind in terms of capacity, even the recent ones like GLM 5.2.

Haven't they been mere months behind frontier for year(s) now? And if US frontier models are going to be restricted by the US gov from a massive share of their worldwide potential customer base going forward, that also correspondingly cuts US labs’ revenue and ability to train new models, so unless Chinese models are wholly dependent on distilling more powerful models…

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#60
post #13

it all looks suspicious: - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems - June 9th 2026: Anthropic releases Mythos model - June 12th 2026: Model gets export regulations placed on it by US Gov - June 26th 2026: US gov announces they will let some comp…

Anthropic losing their ability to release new models to most customers (and thereby revenue, and thereby ability to train new models) makes you think investors will value it more highly than if they could release new models to everyone who wanted to pay them?

Since training/inference/datacenters are a money sink (as you can read in any financial insights of anthropic, openai, etc.) having more customers might actually be detrimental.

Just look at the consumer side: the current attitude of most people is they'd rather not pay the actual cost of the LLM they're using. Therefore the big money is probably in an IPO by boosting your product to be so unfathomably potent, it must be ridiculously valuable to own and control.

It also helps to pretend it's actually too dangerous for the general public: high-paying government contracts only please.

Post reply on HN