Live data from Hacker News

Mythos Finds a Curl Vulnerability

daniel.haxx.se

261–270 of 298 posts

Re: Mythos Finds a Curl Vulnerability

#261
post #238

Earlier quoted context omitted.

Which is liability is relevant, that is the only language shareholders understand.

If you can get that message across the right way, you're a better company man than me. There's always someone more important than me to say 'but this needs to be delivered first'.

Sure, my point was more in general from government level.

Re: Mythos Finds a Curl Vulnerability

#262

Earlier quoted context omitted.

None of those other LLM tooling made the claims they're too dangerous to be released and used though, unlike Anthropic did with Mythos. What it highlights, is that Mythos doesn't seem so much better than other LLM driven tooling at finding security issues, which was the strongest claim Anthropic made in the first place.

It's important to keep in mind that very, very few projects are as rigorously tested as curl, so while it's interesting to hear this feedback I think curl would be a torture test for any security scanning. I'd be more interested to hear about other random libraries that aren't as thoroughly analyzed as curl; show me some results for GnuTLS, for example, or dpkg/rpm/apt/dnf/pacman/etc.

I think one of the points of TFA was that other AI tools found many vulnerabilities; after having fixed those, mythos did find another vulnerability the others missed, but that seems to imply this model is only marginally better than the competition instead of being on a different league altogether like it's marketed. Paraphrasing the author: sure mythos will find lots of security issues in gnutls, but so will gpt or opus (they acknowledge explicitly that all those tools are getting very good).

Re: Mythos Finds a Curl Vulnerability

#263

Earlier quoted context omitted.

Not to discredit anything that was said in any particular blog post. Folks also need to remember that a lot of blog posts are written by engineers or managers that have their own agendas and careers and often external blog posts can be a form of self marketing or idea marketing that an engineer or director has been pushing internally. I have no idea if this happened in mozilla's case but the person that wrote it seem…

Also, the people at Mozilla who helped achieve a highly visible collaboration with the hottest AI company in the zeitgeist that included a lot of expensive data center time to harden their flagship product are definitely going to be happy/excited/proud about pulling it off successfully. There's a lot of kneejerk "so you're accusing Mozilla of a conspiracy to boost Anthropic?" which is an overly simplistic lens. Parti…

Okay so supposing everybody is acting in a benign manner, following their incentives and passions, not meaning to mislead anybody. Do you think that this results in writing a misleading blog post? Because the blog post makes Mythos out to be a big friggin deal. (It had certainly convinced me).

Re: Mythos Finds a Curl Vulnerability

#264

Earlier quoted context omitted.

What you have typed does not address anything the person you are responding to said. With those 50 million subscribers, how much do they pay and how much do they cost? That is the only relevant piece of information when discussing the investment and returns of OpenAI.

> "invest 5 billion to make 10 million" business is contextual, and is a game of numbers? If you agree, then there is a difference between "I made money selling lemon drinks at my driveway, but I sold a car to make room" .. versus "I have recurring revenue of 50 million x $80 USD per month, and it is growing, and I am using cheap credit to build that" .. Numbers have a meaning, and the larger dollar recurring revenue…

They have no moat.

Re: Mythos Finds a Curl Vulnerability

#265

I can't help but think that curl is, by nature, a relatively simple and well-contained tool. Compare to an operating system or web browser or database or billion dollar company codebase. It makes some sense that Mythos/ChatGPT 5.5 might be that much better with complexities that curl just doesn't have because it's a basic tool. Like yeah curl is obviously extremely fully featured as an "anything client" but it's orde…

From the post: "curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Peace. ... curl is installed in over twenty billion instances. It runs on over 110 operating systems and 28 CPU architectures. It runs in every smart phone, tablet, car, TV, game console and server on earth." I wo…

someone(mythos?) should write some simple-curl with 20% of features implemented in rust used by 98% of users.

Re: Mythos Finds a Curl Vulnerability

#266

Earlier quoted context omitted.

What you have typed does not address anything the person you are responding to said. With those 50 million subscribers, how much do they pay and how much do they cost? That is the only relevant piece of information when discussing the investment and returns of OpenAI.

> "invest 5 billion to make 10 million" business is contextual, and is a game of numbers? If you agree, then there is a difference between "I made money selling lemon drinks at my driveway, but I sold a car to make room" .. versus "I have recurring revenue of 50 million x $80 USD per month, and it is growing, and I am using cheap credit to build that" .. Numbers have a meaning, and the larger dollar recurring revenue…

Is it growing?

Don't they report annualized revenue AKA the best month times 12? How is that comparable?

Re: Mythos Finds a Curl Vulnerability

#267

As far as I can tell, the messaging around Mythos is that it takes the expertise of the top security experts and top-level language, protocol and code experts and makes that available to anyone with access. The danger was in giving that access to the world before the defenders had access to that level of expertise. Curl HAS had security, protocol and language experts poking at it for years because of how central it i…

Take my upvote. Anthropic never claimed superhuman performance, only speed and scale. That it doesn't find much in terms of new vulnerabilities in a well-studied piece of software says nothing about its overall potential for dangerous misuse.

Re: Mythos Finds a Curl Vulnerability

#268

Earlier quoted context omitted.

That whitepaper did not need 19 authors. They're there for show. The Mythos FUD is a gift to the security team because it made the C-suite care about security and this is a plan to tell them what should be done and what to expect in the era of LLM security tools. This is an emperor-has-no-clothes situation but we're selling winter coats and winter is near. Not focusing on how the Mythos FUD is exaggeration and instea…

Isn't that all the more reason to publish your process & results using Codex to do the same thing they're claiming? Presuming any bugs Codex found would be fixed and no longer a security concern.

Why would you publish something unremarkable and benign?

Is it actually that hard for you to go try this out yourself?

Re: Mythos Finds a Curl Vulnerability

#269
post #31

Earlier quoted context omitted.

I seem to be totally outside the hype bubble, but I have to suspect there is a lot of imagineering and wild extrapolations in the elss technical hype bubbles. I am curious but no enough to go looking.

>I seem to be totally outside the hype bubble I'm surprised you say that because it is all over Hacker News. Every single post is co-opted into promoting AI. Try finding a submission with fifty points or more than doesn't have AI or LLM's mentioned somewhere in the comments.

That's a good point, I guess I see the Hacker News hype a bit more realistically then maybe I should. HN has definitely changed in the sense that I rarely see interesting technology or achievements hit the front page, that aren't AI related. It feels like AI has taken all the oxygen from the room.
Post reply on HN