Live data from Hacker News

GLM-5.3: Frontier coding with emergent cyber capabilities

z.ai

171–180 of 626 posts

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#171

OpenAI and Anthropic need to just go ahead and give people access to the cyber models. Otherwise we have a world of attackers using open and closed source models against a much smaller group of maintainers that are likely heavily dependent on Anthropic and OpenAI and for whom it may not be a simple matter to just get approval to start using the open model flavor of the month.

Can't the maintainers use the same models as the attackers?

The maintainers don't need approval to use GLM.

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#172

[total rewrite: their subscription code is buggy. It takes a while for paid subscriptions to show up, and for upgrades to take effect. Original comment was whining about this]

their sub is crap. use opencode go (multiple workspaces) or wait for weights to drop

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#173
post #5

This is absolutely still shy of Sol and Fable, but only just by a hair. Ridiculous results. There's still not a compelling economic reason to drop OpenAI courtesy of the ludicrous reset addiction that's taken place, but it feels like we're on the precipice. How are you all toying with running this kind of thing in a mega quantized way locally? Two weeks out from released weights, but this is still just GLM 5.2 with p…

OpenAI and Anthropic are both seeking trillion IPOs, while Chinese labs are pumping out open-weight models that are free for US providers to host and monetize. These Chinese models cost less of US SOTA models to run, even if they are less capable. Providers can just run them, offer cheap tokens, and pocket the margin. I just don't see how you justify a trillion valuation for US AI labs when the underlying models are…

I'm sure US billionaires will find a way to extract those trillions from the public. They're smart, they can handle it. After all, they can ask AI for advice on how to do it.

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#174
post #88
post #72

Earlier quoted context omitted.

I think at this point the question is: will the US government be willing and capable to justify the trillion dollar valuation for _one_ of the companies via regulatory capture? The US has a workforce of 170m, so 1.7 trillion would come down to 10k per person, or a discounted cashflow at 3% of 25 USD per month - not including private use, students etc.

Why would you restrict to the US workforce? ChatGPT has a billion users.

They have a stupid plan to buy ten to fifty percent of all the SOTA AI companies, and giving us all a fraction of the money.

Trump keeps calling his enemies “communists”… then turns around and ‘seizes the means of production’ himself.

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#175
post #128

Apparently they are scanning OSS and popular software at scale and disclosing the vulnerabilities they found: https://cvd.z.ai/ Most of these are under embargo, but it seems there are a lot of CVE here from a wide range of popular software, many considered critical or high. I understand the argument of "people are not actively looking", but isn't the cost for such a scan getting lower by the week, and Anthropic's Pro…

Interesting... So Chinese models are not so bad ?

Looks like they're going for good PR now, to avoid smearing by the "Western" models. Smart!

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#176
post #154
post #132

Earlier quoted context omitted.

I have already begun winding down my spend on claude and OAI to make room for infra budget. Anecdotal, but I have no doubt a lot of others are doing the same, I very much agree the US players have major issues looming. What an exciting time to be alive!

The car industry is also a trillion $$ market in the US. I don't see why that would go any differently from the Chinese cars ban.

You're comparing an entire industry to a single company.

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#178
post #117

Earlier quoted context omitted.

I'm not sure a data center run by ... Palantir of all organizations is what people have in mind when they worry about data sovereignty.

They are selling it, not running it. It is just a dedicated computer system, which should be managed by its owner, like any other on-prem servers. I doubt that it has a good price/performance ratio, but it is a solution for those who feel that they do not want to search, buy, assemble, install and configure every HW/SW component.

For those that don't mind a lot of rootkit and embedded spyware you mean

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#179
post #62

Earlier quoted context omitted.

Sorry but if you stepped back for a moment you'd realize this is all contrived nonsense to let to have your cake and eat it too. No, Anthropic did not mind-game the US government into being worried about cybersecurity. The NSA has been paranoid about cyber controls for longer than you've been alive. If Anthropic had come out of the gate saying "no don't worry man, our model is TOTALLY COOL", while simultaneously atta…

Mythos isn't some scary dangerous model that can find high severity bugs seamlessly, that's just Anthropic marketing. Most of the vulnerabilities they found were low severity hyped up to make their model look good, with (I think, maybe?) the exception of a few. Now that Chinese open weight models have similar capabilities, and their guardrails can also just be removed, it doesn't look like anyone has "hacked" into ev…

All models find vulnerabilities. What is special about this generation of SOTA models, including Mythos/Fable (the same model), GPT-5.6, Kimi-K3, and now GLM-5.3 — they can chain vulnerabilities and produce working exploits.

Look at the recent HuggingFace hack. One vulnerability was template injection, another — remote code execution. Combine them and you pwned the remote server.

People working under Project Glasswing reported that Mythos at one point chained 20 vulnerabilities to produce working exploit. Humans don’t usually do that.

Re: GLM-5.3: Frontier coding with emergent cyber capabilities

#180
post #117

Earlier quoted context omitted.

Palantir already offers a "turnkey AI datacenter", i.e. a rack with "NVIDIA Blackwell Ultra systems with eight NVIDIA Blackwell Ultra GPUs and NVIDIA Spectrum-X™ Ethernet networking for AI training and inference". It is said that it comes with all hardware and software required to run inference or training with an open weights LLM. The existence of this product, which competes with cloud-based offerings like those of…

I'm not sure a data center run by ... Palantir of all organizations is what people have in mind when they worry about data sovereignty.

Fair but the idea of "running your LLM setup" at every "need" level and corresponding cost does make sense.

For a lot of people (and orgs I'd guess) who just go and buy ≈$20 per month plans (or more for teams), they might not even need a fraction of that cost or capability. A lot of them don't even need it for coding or graphics. Even the API access based pricing aren't great from these frontier US AI houses. The distribution of "LLM being" offered will also give rise to many open-router like offering but at the end point level - direct interfaces to the customers. Pick your vendor sort.

AI shouldn't become another "search means Google".

Post reply on HN