Live data from Hacker News

A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

flyingpenguin.com

21–30 of 41 posts

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#21
post #19

Earlier quoted context omitted.

Will absolutely walk back, but I simply don't think the Linux Foundation, Apple, etc are lying when they are calling Mythos a genuine issue. There is healthy skepticism and then there is sticking your head in the sand. When companies and orgs with no financial interest in Anthropic issue a joint statement describing a problem, it is likely that the problem is real (unless you go off into wacky conspiracy territory.)

Has an actual Linux dev said anything about it?

Or Apple, or any of the other organisations mentioned on the marketing piece?

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#23
post #22

A cunning move from Anthropic, nevertheless - their system has now seen and trained on a many big organization's source code.

Some of those organizations (Linux and Mozilla) work on open source code for which they are already trained on. For clients like Apple, they almost surely have agreements to not do that.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#24
post #19

Earlier quoted context omitted.

Has an actual Linux dev said anything about it?

Or Apple, or any of the other organisations mentioned on the marketing piece?

Mozilla has: https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul...

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#25

Earlier quoted context omitted.

We already have access to a smaller version of the Mythos tier with Opus 4.7: based on the usual delta between the full fat models and their distills, do you really think Mythos breaks cybersecurity? It's a good model update. We've had these before, and it looks like OpenAI is gearing up to match it this week. - Mythos launch has felt like a showsman overlplaying their hand. Opus 4.5 put them in an awkward position a…

If Glasswing was a marketing exercise for Anthropic, why did Linux Foundation issue a joint statement with them? What about Apple? Conspiracy theories aside - what's your Occam's Razor explanation?

I'll go even simpler than the others: you're being given completely subsidized early access to the latest and greatest model. Why not take it?

I'm not saying they're lying about it being a great model, they're just presenting a great model in a very intentional way. That way happens to be drumming up its cybersecurity skills, but those skills are present in all their previous LLMs too.

If you run Project Glasswing with Opus 4.7 instead of Mythos, it still works, just not as effectively... or honestly, maybe even more effectively if you account for final token cost! Since they'll likely want to squeeze better margins out of Mythos than the workhorse models, Mythos might be so expensive that just getting un-moderated access to 4.7 and throwing in the same number of dollars worth of tokens at various codebases uncovers more vulnerabilities!

But the latter half of that paragraph is assuming you're outside Anthropic: Anthropic is doing all of this at cost, so obviously the best model they can muster is the best option to offer.

-

The key is, Mythos isn't using scaffolding or and approach that no other model can meet the floor of. People jumped to small models and that's a bit of a stretch... but the best non-Mythos models can obviously be put in harnesses and used to find vulnerabilities at scale.

Part of the proof there is Anthropic themselves cranking up their cybersecurity request filters and going overboard with CC prompt injections.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#27

How about the boy who called nonsense security vulnerabilities. This is the same author who posts with incredulity that the ability to change a config file with a shell command in it gives you the ability to run the shell command you posted and wants it treated as some big CVE. Absolutely inconceivable that you might already have your harness in a sandbox where this is okay, and inconceivable that anyone might have a…

Unleashing a bull in a china shop?

I'm sure the hyper-paranoid cybersecurity researchers are all about ensuring well-behaved model stays well behaved.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#28
post #26

off topic: may I ask why and how this has been flagged? How does flagging work and why do I still see the post on the second or third page listed?

Anyone (with sufficient karma, I guess; I don't recall, but HN gates a few features behind that) can flag for any reason, and sufficient flags will get a post taken down. HN is prickly - my guess is this got flagged because it's mostly poorly supported speculation. I didn't flag it myself, but did find it pretty ridiculous.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#29

"Sonnet sees the same two “obvious” bugs. It just cannot close the exploitation step. Mythos’s entire frontier advantage over the prior model is therefore bupkis." What a bizarre conclusion. It "just" cannot close the exploitation step? "Just?" Developing the working exploit is the hardest part , not finding the bugs. A self-proclaimed security professional should know this. How is this stuff even making it to the to…

you think anthropic didn't earn their hate?

Most normal people: "Only you decide what you feel."

HN busybodies: "You have forced me to hate you, im an incapable child"

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#30

Earlier quoted context omitted.

you think anthropic didn't earn their hate?

Most normal people: "Only you decide what you feel." HN busybodies: "You have forced me to hate you, im an incapable child"

They said earned, not forced
Post reply on HN