Live data from Hacker News

“Too dangerous to release” or just too expensive?

kingy.ai

131–140 of 189 posts

Re: “Too dangerous to release” or just too expensive?

#131
post #119

It's pretty clear at this point that Mythos' capability to discover and exploit zero-day vulnerabilities at scale is but an incremental improvement over existing models like the ones available to OpenAI's Plus/Pro subscribers. Anthropic tries to create marketing hype around Mythos using two psychological tricks. 1. Put large numbers in the headlines. "Mythos discovered 271 vulnerabilities in Firefox" makes the model…

I work for a company that has been using Mythos for vulnerability detection in our software. The results we're getting are revolutionary to the point that our software security teams are heavily overloaded addressing the deluge of thousands of real bugs/vulnerabilities and design flaws across our billions of lines of code. For comparison, we are invested heavily the the AI space to the point where Anthropic is one of…

> billions of lines of code.

Billions as in 10^9?

Re: “Too dangerous to release” or just too expensive?

#132

Earlier quoted context omitted.

Which does sort of hint at a (power/profitability) ceiling on the LLM line of AI… That should make the industry nervous.

Does that follow at all? High end AI is at its most useful when you use it to replace high end human labor. You can't buy 9000 cybersec specialists on demand, but you can buy more Mythos tokens. Then we get into all the scaling curves. Such as: LLMs getting more capable per FLOP, per byte of weights, per byte of VRAM, etc. And: inference compute getting cheaper over time. I see a lot of "should make the industry nerv…

As the article states, right now Anthropic does not have the compute capacity. I suppose they could charge an enormous amount of money, but if it is indeed that powerful there are folks that would pay and they would degrade everything. To make matters worse, bad actors could use it to find zero-day exploits in the power grid and banking system.

Re: “Too dangerous to release” or just too expensive?

#133
post #115
post #71

Earlier quoted context omitted.

Multiple people who have already used Mythos or been given its reports on their software have publicly stated that it's all hype, and that it is not really finding any new critical bugs which other models cant.

Do you have any good sources on that? I have seen things to suggest that not all of the hype is true, but so far I have not encountered anyone claiming all of the hype is untrue. Which is what I interpret "its all hype" (sic) to mean.

CURL has been scanned with multiple LLMs. Mythos was last and as a result found only 1 issue. If Myhos was really much better I'd expect it to find a lot more issues despite the others already there.

Also, the competing models are getting better. Opus 4.5 was better than everyone else when it was new, but only a few months later and there are a lot of models that are better (not just the newer Opus models)

Re: “Too dangerous to release” or just too expensive?

#134
post #75

Earlier quoted context omitted.

I don't think it is. Just the (somewhat lame) graphics are.

Sorry to say, but it almost certainly is AI. - 51 EM-dashes - Section headings - Excessive repetitions: "The [...] are real. The [...] are real. The [...] is real. All three things are true at once." - Excessive use of "genuine", "genuinely", "honest", "real", "true" - Excessive use of "gap": "near-term gap", "the Compute Gap", "the Narrative Gap", "critical gap" - Corny and meaningless closing sentence: "Understandi…

I don't believe my 20 year old university essays were written by AI, despite your criteria.

Re: “Too dangerous to release” or just too expensive?

#136

When your logo is AI, your illustrations are AI, and you profile pic is AI, I'm going to assume the text is AI too and won't read it.

The text is just as you predict, but in fairness to the author using a .ai domain is a good way to set expectations up front.

Re: “Too dangerous to release” or just too expensive?

#137
post #119

Earlier quoted context omitted.

I work for a company that has been using Mythos for vulnerability detection in our software. The results we're getting are revolutionary to the point that our software security teams are heavily overloaded addressing the deluge of thousands of real bugs/vulnerabilities and design flaws across our billions of lines of code. For comparison, we are invested heavily the the AI space to the point where Anthropic is one of…

> billions of lines of code. Billions as in 10^9?

https://research.google/pubs/why-google-stores-billions-of-l...

Re: “Too dangerous to release” or just too expensive?

#138

It's pretty clear at this point that Mythos' capability to discover and exploit zero-day vulnerabilities at scale is but an incremental improvement over existing models like the ones available to OpenAI's Plus/Pro subscribers. Anthropic tries to create marketing hype around Mythos using two psychological tricks. 1. Put large numbers in the headlines. "Mythos discovered 271 vulnerabilities in Firefox" makes the model…

[deleted]

Re: “Too dangerous to release” or just too expensive?

#139
I think it's plausible that a substantial fraction of the increase in cyber attacks we saw recently was caused by GPT-5.5. So the "too dangerous" framing is plausible, even if the more important reason is a lack of RAM (as the article author suspects) or compute to serve Claude Mythos. We already know from other events that OpenAI is far less interested in AI safety and ethics than Anthropic.

Re: “Too dangerous to release” or just too expensive?

#140
post #61

Earlier quoted context omitted.

Are there any publicly verifiable sources that Mythos is that much more intelligent than Opus, so to be considered much more dangerous (as it is presented in the public discourse by Anthropic)

It doesn't have to be _much more intelligent_ than Opus to be a risk. It doesn't even need to be _more intelligent_. It just needs to be _better at finding security problems_. Which could happen from just minor improvements in training data, or the harness, etc. Even a small improvement could shift it from finding very few new security holes, to reliably finding many at scale.

Yeah, I think a lot of the disconnect here is that people think of "model intelligence" as some sort of IQ score, rather than a combination of scores that measure abilities at a large variety of domains.
Post reply on HN