Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

251–260 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#251

>>> the US and its allies must maintain a decisive lead in AI technology. Governments have an essential role to play in helping maintain that lead, and in both assessing and mitigating the national security risks associated with AI models. We are ready to work with local, state, and federal representatives to assist in these tasks. How long would it take to turn a defensive mechanism into an offensive one?

In this case there is almost no distinction. Assuming the model is as powerful as claimed, someone with access to the weights could do immense damage without additional significant R&D.

Yes, I can see this as non releasable for national security reasons in the China geopolitical competition. Securing our software against threats while having immense infiltration ability against enemy cyber security targets....not to mention, the ability to implant new, but even more subtle vulnerabilities into open software not generally detectable by current AI to provide covert action.

Re: Project Glasswing: Securing critical software for the AI era

#252
I'm sure it'll be better than Opus 4.6, but so much of this seems hype. Escaping its sandbox, having to do "brain scans" because it's "hiding its true intent", bla bla bla.

If it manages to work on my java project for an entire day without me having to say "fix FQN" 5 times a day I'll be surprised.

Re: Project Glasswing: Securing critical software for the AI era

#253

Earlier quoted context omitted.

Anthropic has behaved the least like this of the AI companies.

They made a claim that 100% of code would be AI generated in a year, over a year ago.

That was a prediction. It was not a claim of their current capabilities. If that is the one you reach for then I feel my point has been made.

Re: Project Glasswing: Securing critical software for the AI era

#255

Earlier quoted context omitted.

I'm too much of an anarchist for that. I believe what I said: > I think it would be net better for the public if they just made Mythos available to everyone.

10 Axios's within 5 days.

Yeah, I'm unsure why the OP thinks that massive chaos would somehow be "better for the public."

Re: Project Glasswing: Securing critical software for the AI era

#256

It's messed up that Anthropic simultaneously claims to be a public benefit copro and is also picking who gets to benefit from their newly enhanced cybersecurity capabilities. It means that the economic benefit is going to the existing industry heavyweights. (And no, the Linux Foundation being in the list doesn't imply broad benefit to OSS. Linux Foundation has an agenda and will pick who benefits according to what is…

Not really. It’s a lot better than the anarchy of releasing it and having a bunch of bad people with money use it to break software that everyone’s lives depend on. Many technologies should be gate kept because they’re dangerous. Sometimes that’s permanent, like a nuclear weapon. Sometimes that’s temporary, like a new LLM that’s good at finding exploits. It can be released to the wider public once its potential for damage has been mitigated.

Re: Project Glasswing: Securing critical software for the AI era

#257

It's messed up that Anthropic simultaneously claims to be a public benefit copro and is also picking who gets to benefit from their newly enhanced cybersecurity capabilities. It means that the economic benefit is going to the existing industry heavyweights. (And no, the Linux Foundation being in the list doesn't imply broad benefit to OSS. Linux Foundation has an agenda and will pick who benefits according to what is…

Releasing the model to bad actors at the same time as the major OS, browser, and security companies would be one idea. But some might consider that "messed up" too, whatever you mean by that. But in terms of acting in the public benefit, it seems consistent to work with companies that can make significant impact on users' security. The stated goal of Project Glasswing is to "secure the world's most critical software,…

This is not the only model. I assure you exploits are being found and taken advantage of without it, possibly even ones that this model is not even capable of detecting.

Sounds like people here are advocating a return to security through obscurity which is kind of ironic.

Re: Project Glasswing: Securing critical software for the AI era

#258

It's messed up that Anthropic simultaneously claims to be a public benefit copro and is also picking who gets to benefit from their newly enhanced cybersecurity capabilities. It means that the economic benefit is going to the existing industry heavyweights. (And no, the Linux Foundation being in the list doesn't imply broad benefit to OSS. Linux Foundation has an agenda and will pick who benefits according to what is…

Better security is a good thing, no a bad thing, regardless of which companies are more difficult to hack. Hemming and hawing over a clear and obvious good is silly.

Re: Project Glasswing: Securing critical software for the AI era

#260

Earlier quoted context omitted.

I'm too much of an anarchist for that. I believe what I said: > I think it would be net better for the public if they just made Mythos available to everyone.

10 Axios's within 5 days.

This is already happening. But not everyone has access to the tools to protect against it.
Post reply on HN