Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

221–230 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#221

It's messed up that Anthropic simultaneously claims to be a public benefit copro and is also picking who gets to benefit from their newly enhanced cybersecurity capabilities. It means that the economic benefit is going to the existing industry heavyweights. (And no, the Linux Foundation being in the list doesn't imply broad benefit to OSS. Linux Foundation has an agenda and will pick who benefits according to what is…

Or (and hear me out), they are close to an IPO and want to ensure that there is a world-ending threat around which they can cluster the biggest names, with themselves leading that group. I think I just broke my cynicism meter :-(

You might want to recalibrate your cynicism meter. As strange it might sound, most companies act according to their principles when the founding team is at the helm. The garbage policies tend to materialize once the company is purchased by, or merged into, another entity where the leadership doesn't care about the original aim of the organization. They just want "line go up".

Also, it makes sense that OpenAI feels the pressure of getting to an IPO because of their financial structure. I don't know whether or not Anthropic operates under a similar set of influences (meaning it could be either, I just don't know.)

Re: Project Glasswing: Securing critical software for the AI era

#222
post #201

Earlier quoted context omitted.

I mean it was messed up, which is why the other world powers raced to develop their own capabilities. And it remains messed up to this day - some countries get to be under their own nuclear umbrella, while others don't. This kind of selective distribution of superpowers doesn't lead to great outcomes

in that case in particular it led to 80 years of relatively calm geopolitics kinetically, all things considered. I'm not sure I want to live through an AI cold war, but it sure seems I don't get to choose.

> relatively calm geopolitics kinetically

Relative to what?

There's this trend in history that every hundred years there's a giant blow up, lots of violence, followed by peace.

It's likely that we would have had 80 years of relative calm due to that cycle even if nukes hadn't happened

Re: Project Glasswing: Securing critical software for the AI era

#223

I think this is bad news for hackers, spyware companies and malware in general. We all knew vulnerabilities exist, many are known and kept secret to be used at an appropriate time. There is a whole market for them, but more importantly large teams in North Korea, Russia, China, Israel and everyone else who are jealously harvesting them. Automation will considerably devalue and neuter this attack vector. Of course thi…

I don't think it matters one way or the other to your thesis but I'm skeptical that state-level CNE organizations were hoarding vulnerabilities before; my understanding is that at least on the NATO side of the board they were all basically carefully managing an enablement pipeline that would have put them N deep into reliable exploit packages, for some surprisingly small N. There are a bunch of little reasons why the economics of hoarding aren't all that great.

Re: Project Glasswing: Securing critical software for the AI era

#224

Earlier quoted context omitted.

For comparison, 5x the cost of Opus 4.6, and 1.67x for Opus 4.1 I think this would be very heavily used if they released it, completely unlike GPT 4.5

Opus 4 & 4.1 are still on Vertex+Bedrock @ $75/1mm out. They were used very heavily and in my subjective opinion are better than 4.5 and 4.6.

Interesting, what makes them better to you?

Re: Project Glasswing: Securing critical software for the AI era

#227
post #155

Earlier quoted context omitted.

In the long term, you're right, but in the short term, it's going to be a bloodbath.

That's assuming the model is actually as good as they say it is. Given the amount of AI researchers over the past 3 years claiming supernatural capability from the LLM they have built, my bayesian skepticism is through the roof.

Anthropic has behaved the least like this of the AI companies.

Re: Project Glasswing: Securing critical software for the AI era

#228
post #39
post #30

Earlier quoted context omitted.

I'm pretty optimistic that not only does this clean up a lot of vulns in old code, but applying this level of scrutiny becomes a mandatory part of the vibecoding-toolchain. The biggest issue is legacy systems that are difficult to patch in practice.

Wait. Wasn't AI supposed to alleviate the burden of legacy code?!

If you’re still an AI skeptic at this point, I don’t know what sort of advancement could convince you that this is happening.

Re: Project Glasswing: Securing critical software for the AI era

#229
post #124

Earlier quoted context omitted.

Software security heavily favours the attacker (ex. its much easier to find a single vulnerability than to patch every vulnerability). Thus with better tools and ample time to reach steady-state, we would expect software to remain insecure.

If we think in the context of LLMs, why is it easier to find a single vulnerability than to patch every vulnerability? If the defender and the attacker are using the same LLM, the defender will run "find a critical vulnerability in my software" until it comes up empty and then the attacker will find nothing. Defenders are favored here too, especially for closed-source applications where the defender's LLM has access…

You also need to deploy the patch. And a lot of software doesn't have easy update mechanisms.

A fix in the latest Linux kernel is meaningless if you are still running Ubuntu 20.

Re: Project Glasswing: Securing critical software for the AI era

#230

> On the global stage, state-sponsored attacks from actors like China, Iran, North Korea, and Russia have threatened to compromise the infrastructure that underpins both civilian life and military readiness. AITA for thinking that PRISM was probably the state sponsored program affecting civilian life the most? And that one state is missing from the list here?

> Large American AI company does not list the US as an adversarial actor

This is not a surprise or a gotcha.

Post reply on HN