Live data from Hacker News

First public macOS kernel memory corruption exploit on Apple M5

blog.calif.io

131–140 of 140 posts

Re: First public macOS kernel memory corruption exploit on Apple M5

#131
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

> Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit card .... he's an experienced security researcher.

I don’t think Mythos is hype for all kinds of reasons.

Anthropic is a young company but their track record is solid; they don’t seem to hype things just for the sake of hyping things. Sam Altman at OpenAI? We already know his track record…

I’m going Occam’s razor here: the simplest explanation is usually the correct one.

Anthropic had an “oh shit” moment when they realized what Mythos can do. They decided to do the responsible thing: give the industry a heads-up and an opportunity to use the preview to identify and fix the most dangerous zero-day vulnerabilities.

Since the FAANG companies have billions of users, it makes sense to start with them.

There’s still going to major issues for users of systems too old to get patches or updates. Or for IT organizations who think Mythos is a replay of Y2K, where, compared to the warnings, not lot happened.

The bottom line is someone with Mythos won’t need to be an experienced security expert to cause real problems. That’s kind of the point.

Re: First public macOS kernel memory corruption exploit on Apple M5

#132
post #99

This is incredibly light in details, no verifiable claim as far as I can tell. (I’m sure they’re not lying, but we’re not learning anything here)

It reads more like a PR piece than technical article.

They can’t disclose the technical details yet. They did say a detailed write up is coming.

Re: First public macOS kernel memory corruption exploit on Apple M5

#133

Earlier quoted context omitted.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

> Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit card .... he's an experienced security researcher. I don’t think Mythos is hype for all kinds of reasons. Anthropic is a young company but their track record is solid; they don’t seem to hype things just for the sake of hyping things. Sam Altman at OpenAI? We a…

> replay of Y2K, where, compared to the warnings, not lot happened

My dad was on one of the many Y2K teams that major tech companies had to make sure nothing went wrong. I feel like history may have undersold what could've been if not for considerable effort leading up to Jan 1, 2000.

Re: First public macOS kernel memory corruption exploit on Apple M5

#134

Earlier quoted context omitted.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

> it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. "Suitable human" is a dry phrase indeed. ^_^ The hype is "gosh look at all the bad things this brilliant almost conscious tool found!" The reality: an insecure toolchain for an insecure language with an insecure compil…

Yeah, I was thinking earlier, the way things are going, software (and maybe the internet itself) might need to look a little different in a few years.

Ironically the AIs will probably help us produce higher quality software in the end, because "everything gets pwned" becomes the forcing function for software actually being correct.

In other words I think we are actually entering an age where correctness makes economic sense. (One can dream!) The cost of producing correctness is dropping, and the cost of not doing so is rising massively.

Re: First public macOS kernel memory corruption exploit on Apple M5

#135

Earlier quoted context omitted.

[flagged]

There is quite a bit of irony, or depending on your perspective it's the whole point, that this response is a great example of 'glorified autocomplete'.

The OPs post was obvious satire. My recommendation is to have better sleep hygiene and this would have been apparent.

Re: First public macOS kernel memory corruption exploit on Apple M5

#136

Earlier quoted context omitted.

Maybe they should've been as productive as the guys down in Santa Barbara.

You can't be as productive as someone in Santa Barbara because they have perfect weather and you don't, so you have SAD.

I lived there for a few years but alas my place's Wi-Fi didn't quite reach the beach

Re: First public macOS kernel memory corruption exploit on Apple M5

#137
post #126

Earlier quoted context omitted.

> amazing new journey we're about to embark on. Is it? It's an arms race between the "good guys / defenders" and "bad guys / attackers". Assuming both sides have access to the same tools, how is this going to make any difference? Their relative strength will stay the same. What is actually different is that 1. anybody without tool access is out of the game, which includes security professionals from poorer background…

Pretty soon people will just airgap their stuff and that will eliminate most of the attack surface short of a sort of Mission Impossible style operation. I mean really, given how AI is being marketed, what is the point of the internet going forward when all its contents are going to be ai slop anyhow? Just disconnect and run local models if all you are getting is slop anyhow. The original purpose of the internet is n…

An internet comment communicating the death of communication on the internet - how wonderfully paradoxical!

(or if you tasked an AI to write that: how appropriate!)

Re: First public macOS kernel memory corruption exploit on Apple M5

#138
post #137
post #126

Earlier quoted context omitted.

Pretty soon people will just airgap their stuff and that will eliminate most of the attack surface short of a sort of Mission Impossible style operation. I mean really, given how AI is being marketed, what is the point of the internet going forward when all its contents are going to be ai slop anyhow? Just disconnect and run local models if all you are getting is slop anyhow. The original purpose of the internet is n…

An internet comment communicating the death of communication on the internet - how wonderfully paradoxical! (or if you tasked an AI to write that: how appropriate!)

I mean I am pretty close to leaving the internet as I know it entirely. Seems like just in the last year there has been a lot more LLM slop articles posted directly to HN. It is getting to a "what is even the point" point for me pretty fast. My use at this point is essentially habitual and akin to quitting cigarettes than me still squeezing any actual value out of the internet as I might have in years past.

Re: First public macOS kernel memory corruption exploit on Apple M5

#139

Earlier quoted context omitted.

I worked at Apple for a long time. The OS gets fully recompiled regularly. A simultaneous total world build is relatively rare (is that needed here?), but it does happen. Sometimes new compiler versions or features need this.

I dunno if that's sensitive information, but how long did a build usually take?

I wasn't close enough to that to know how long a world build took. Didn't seem like it was too crazy though. Incremental (non-world) builds of the OS come out every day.

Re: First public macOS kernel memory corruption exploit on Apple M5

#140

Earlier quoted context omitted.

While maybe true, it is better to back that up with data and the data I know of and read yearly is mostly not great. Between Splunk and SANS surveys of 2025 maybe ~2000 companies have a SOC. [1] [2] Then you have the many companies in the UK, US, Canada, EU that have compliance and regulatory laws that require them to exist in some capacity in house. Though that is changing with MDR services, but someone still has to…

Does the report talk about how many are /actual/ "SOC"'s, rather than some outsourced SIEM service. Or one guy who gets a daily report...

Yes they do
Post reply on HN