Live data from Hacker News

First public macOS kernel memory corruption exploit on Apple M5

blog.calif.io

121–130 of 140 posts

Re: First public macOS kernel memory corruption exploit on Apple M5

#121

Wait a minute - clearly I missed something here. Last I read, Mythos was only available to a handpicked list of megacorps under project glasswing. Did the hourly changing AI soap opera air yet another plot twist that I missed amidst my quest better known as “trying to find a job”? If not, how’d a small time outfit get access to something the rest of us can’t have because we’re (apparently) not trustworthy enough? No…

I'm guessing they have some friends at Anthropic.

Re: First public macOS kernel memory corruption exploit on Apple M5

#123
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

Anthropic just doesn't (didn't) have compute, so they make up a bunch of PR to delay it

They got all that compute with the SpaceX partnership but now the PR has taken a life of its own, so might as well keep hyping up Mythos and artificial scarcity if they have an asset people want now

Just roll with it

Open AI has a history of doing the same thing and it's the same people. GPT 5 was supposed to be AGI at one point, remember.

Re: First public macOS kernel memory corruption exploit on Apple M5

#124
post #43

Earlier quoted context omitted.

That is actually unfair. Most companys spend enormous amounts on security with vast armys of security employees. Not that it is effective, but it is not for lack of resources or trying. I mean we are literally in a thread about how the 4 trillion dollar company, literally the 3rd most valuable company in the world, with a core competency in software has, yet again, released a core product riddled with security defect…

Maybe they should've been as productive as the guys down in Santa Barbara.

You can't be as productive as someone in Santa Barbara because they have perfect weather and you don't, so you have SAD.

Re: First public macOS kernel memory corruption exploit on Apple M5

#125
post #80
post #74

Earlier quoted context omitted.

I suppose that if you don’t believe that models will be good enough to work completely without senior engineer help, positioning yourself as a master prompter is a good move to improve your chances of not getting fired.

Even so, it literally means as business owner I need less warm bodies to write prompts. Will we now have leetcode of prompt writing?

[deleted]

Re: First public macOS kernel memory corruption exploit on Apple M5

#126
post #104

Well, this was fun read. Discovering such a high-ranking critical exploit within a week by coupling experts with frontier models is an amazing new journey we're about to embark on.

> amazing new journey we're about to embark on. Is it? It's an arms race between the "good guys / defenders" and "bad guys / attackers". Assuming both sides have access to the same tools, how is this going to make any difference? Their relative strength will stay the same. What is actually different is that 1. anybody without tool access is out of the game, which includes security professionals from poorer background…

Pretty soon people will just airgap their stuff and that will eliminate most of the attack surface short of a sort of Mission Impossible style operation.

I mean really, given how AI is being marketed, what is the point of the internet going forward when all its contents are going to be ai slop anyhow? Just disconnect and run local models if all you are getting is slop anyhow. The original purpose of the internet is now dead. Real people communicating and sharing information with eachother? Ha! That is no longer valued.

In fact actual innovation might no longer be valued anymore. What is innovation but opening Pandora's box and potentially seeing a disruptive competitor take your slice of the federal reserves money print? Better to nip that in the bud and control all the devils we already know, from a pure sociopathic profitmaking standpoint, which seems to be a very dominant viewpoint among the people in charge of the worlds power structures right now.

Re: First public macOS kernel memory corruption exploit on Apple M5

#127
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

Over time that will change. Technology has proven time and time again that as we add a new layer of abstraction over the fundamental functionality, knowing the previous layer quickly becomes vestigial knowledge. It is true not just in software but absolutely all technology there is, going back to the first fire made or atl atl or rock sling.

Re: First public macOS kernel memory corruption exploit on Apple M5

#128
post #74
post #67

Earlier quoted context omitted.

The tragedy is having a bunch of those senior engineers writing blog posts and what not of how productive they are, without realising that it means business now needs less of them.

I suppose that if you don’t believe that models will be good enough to work completely without senior engineer help, positioning yourself as a master prompter is a good move to improve your chances of not getting fired.

If all you have are being good at prompting you are gone. Business is going to prefer new grads who have taken some class in ai prompting (which many schools now offer). Doesn't matter if the class in ai prompting isn't any good. What matters is the idea that they had a formal training in this thing, and that they are willing to work for far less pay than any senior.

Re: First public macOS kernel memory corruption exploit on Apple M5

#129

Wait a minute - clearly I missed something here. Last I read, Mythos was only available to a handpicked list of megacorps under project glasswing. Did the hourly changing AI soap opera air yet another plot twist that I missed amidst my quest better known as “trying to find a job”? If not, how’d a small time outfit get access to something the rest of us can’t have because we’re (apparently) not trustworthy enough? No…

They list Anthropic as one of their customers and appear to have conducted penetration testing for them previously, so they're likely one of those trusted organizations.

Re: First public macOS kernel memory corruption exploit on Apple M5

#130
post #80

Earlier quoted context omitted.

Even so, it literally means as business owner I need less warm bodies to write prompts. Will we now have leetcode of prompt writing?

Dune guild navigator AI whisperer? with fine taste.

Floating in a vat of aerosolized psychedelic drug doesn't seem so bad all things considered.
Post reply on HN