Live data from Hacker News

“Too dangerous to release” or just too expensive?

kingy.ai

171–180 of 189 posts

Re: “Too dangerous to release” or just too expensive?

#171
post #119

It's pretty clear at this point that Mythos' capability to discover and exploit zero-day vulnerabilities at scale is but an incremental improvement over existing models like the ones available to OpenAI's Plus/Pro subscribers. Anthropic tries to create marketing hype around Mythos using two psychological tricks. 1. Put large numbers in the headlines. "Mythos discovered 271 vulnerabilities in Firefox" makes the model…

I work for a company that has been using Mythos for vulnerability detection in our software. The results we're getting are revolutionary to the point that our software security teams are heavily overloaded addressing the deluge of thousands of real bugs/vulnerabilities and design flaws across our billions of lines of code. For comparison, we are invested heavily the the AI space to the point where Anthropic is one of…

Yeah I’m a security researcher and my colleagues who have access say it’s insanely good… but interestingly they also work for places like nvidia which have a deep vested interest selling tokens and hardware. So of course they are pushing this narrative.

Re: “Too dangerous to release” or just too expensive?

#172
post #170
post #121

Earlier quoted context omitted.

For example, It was recently let loose on cURL and its maintainer is less than impressed: https://www.theregister.com/security/2026/05/11/anthropics-b...

If you remove the fluff that the register added and stick with https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v... it seems like a claim that's a claim fairly distant to "its all hype". Less than expected perhaps? Maybe the code really is unexpectedly robust? I guess time will tell on that point.

His direct quotes are:

> "My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing."

> "I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos."

> "An amazingly successful marketing stunt for sure."

Personally I see this as a very strong claim of hype. I take away from this that Mythos is a hyped up marketing stunt, and not what it was preesented to be by Anthropic at all.

Re: “Too dangerous to release” or just too expensive?

#173

Earlier quoted context omitted.

As far as my understanding goes. It is not a breakthrough model itself but finetuned model with right tools and skills. Fairly similiar to today's coding agents with difference that they are made for software engineering not cyber security.

Mythos is the next point on the scaling curve. It has considerably more parameters than most frontier models of today. Which gives it a lot more oomph per token. Is it a "breakthrough" as in "something novel and unexpected"? No. Is it a "breakthrough" as in "something we know works, but made to work on a greater scale"? Very much so.

So it's just a bigger model? Like for example todays 1T models?

Re: “Too dangerous to release” or just too expensive?

#174
post #58

Earlier quoted context omitted.

Now imagine that your work specs are generated by an AI agent that the EM is using. Do you still care about the work?

Brother, I don't care who writes the specs as long as they sign the checks on time. And yes, I do care about my work even if upstream is slop. In a relay race, you can lower your performance to weakest leg, or you can be the strongest leg. And maybe I just like to run.

Fair enough, but now imagine that the code is slop too. You're getting slopped from both sides, do you still care?

Re: “Too dangerous to release” or just too expensive?

#175

Earlier quoted context omitted.

Mythos is the next point on the scaling curve. It has considerably more parameters than most frontier models of today. Which gives it a lot more oomph per token. Is it a "breakthrough" as in "something novel and unexpected"? No. Is it a "breakthrough" as in "something we know works, but made to work on a greater scale"? Very much so.

So it's just a bigger model? Like for example todays 1T models?

Supposedly 10T scale. Literally the next big thing. A bit like what OpenAI tried with GPT-4.5 - but Anthropic actually made it work with MoE, reasoning, tool use, RLVR, etc.

It matters because the "g factor" of today's LLMs is at least in part a function of raw scale. Larger models are just smarter - assuming you can handle the training and inference at this increased scale.

Re: “Too dangerous to release” or just too expensive?

#176

Earlier quoted context omitted.

So it's just a bigger model? Like for example todays 1T models?

Supposedly 10T scale. Literally the next big thing. A bit like what OpenAI tried with GPT-4.5 - but Anthropic actually made it work with MoE, reasoning, tool use, RLVR, etc. It matters because the "g factor" of today's LLMs is at least in part a function of raw scale. Larger models are just smarter - assuming you can handle the training and inference at this increased scale.

So, realistically, how much further can this go? How many more orders of magnitude?

Re: “Too dangerous to release” or just too expensive?

#177
post #71

Earlier quoted context omitted.

Multiple people who have already used Mythos or been given its reports on their software have publicly stated that it's all hype, and that it is not really finding any new critical bugs which other models cant.

In this very thread we have a counter-example. What to think? https://news.ycombinator.com/item?id=48149519

Read the replies to that comment, they are very valid in their cyncism.

The cURL creators report is the only real substance we have to go on. There are plenty of random comments both ways, but Im sure you and I would both agree that we shouldnt base our opinions on random internet comments and should wait for more official reports like the cURL one to make best judgement.

Re: “Too dangerous to release” or just too expensive?

#178

Earlier quoted context omitted.

are you able to detail a single safeguard you plan to implement, so that I can stop believing it's vaporware and/or a scam?

How would it be vaporware? It's out in the wild and has been used by individuals/corporations.

The security/safety controls they have to add to make it safe enough to release?

Re: “Too dangerous to release” or just too expensive?

#179
I am very concerned, particularly if Anthropic and/or other frontier model producers begin to hit an inference performance ceiling, that Anthropic will use its safety scare tactics to lobby for the marginalization of the open weight model ecosystem. As the open models catch up, or become "good enough", they may amplify their open model hostility "to protect their moat". I see Mythos and Glasswing as cynical beginnings of this. Also note that Google, Meta, and even OpenAI have released open weight models and have nodded to the obvious research benefits they provide, whereas the Anthropic "Public Benefit Corporation" has done no such public benefit. The valuation and success of Anthropic coupled with its "trust us and no one else" culture may be dangerous for the legal survival of open weight models.

Re: “Too dangerous to release” or just too expensive?

#180
post #167

Earlier quoted context omitted.

CURL has been scanned with multiple LLMs. Mythos was last and as a result found only 1 issue. If Myhos was really much better I'd expect it to find a lot more issues despite the others already there. Also, the competing models are getting better. Opus 4.5 was better than everyone else when it was new, but only a few months later and there are a lot of models that are better (not just the newer Opus models)

Curl had a prominent bug bounty programme, has 180k lines of prod code, and is mainly a client app/lib. I would look at other projects before making judgements about mythos on this one.

Don't you want to test mythos against state of the art projects? They are the best chance of making visible what mythos uniquely brings to the table.

We already know that mythos will be branded catnip for sub-SOTA projects. They could have build SOTA secure software development practices last week, last month or last year. But didn't care. What will their experience with mythos tell us other than AI hype can create corporate will to take security seriously?

Post reply on HN