Live data from Hacker News

NSA lost access to Mythos amid Anthropic dispute

nytimes.com

291–300 of 308 posts

Re: NSA lost access to Mythos amid Anthropic dispute

#291
post #166

'Mythos “broke into almost all of our classified systems, not in weeks, but in hours.”' Is Mythos a significant danger? The curl experience does not suggest that hysteria is warranted, but this gives me pause.

'Mythos “broke into almost all of our classified systems, not in weeks, but in hours.”'

And the government's response was to limit access to US citizens? I don't believe this for a minute. If Mythos could actually break into all these systems, the government would declare it a national security risk and it would never see the light of day for anyone outside government staff with security clearance.

Re: NSA lost access to Mythos amid Anthropic dispute

#292
post #48

Earlier quoted context omitted.

You just intercept the traffic after its decrypted on the server side, or are you suggesting you somehow send encrypted traffic that never gets decrypted?

So the NSA streams the memory contents of every virtual machine and bare metal server on the internet to get the decrypted traffic? How would that even work at the scale of the internet?

How it works is they build a huge virtual strawman which decrypts and reads all of the data for them then posts online about how NSA spying on people is literally impossible.

Re: NSA lost access to Mythos amid Anthropic dispute

#293
post #53

Earlier quoted context omitted.

Explain to me how you are going to encrypt your LLM API calls with your let's encrypt cert. There are also multiple ways/places traffic you send to typical cloud/tech company is decrypted and can be intercepted. (Surprised I have to point this out to someone who 'actually works in security ' lol) Not to mention US tech companies fully cooperate with the NSA in many cases and are aware of this going on.

> Explain to me how you are going to encrypt your LLM API calls with your let's encrypt cert. I mean, there's goal post moving and there's just building a whole new stadium across the country.

This thread is literally about anthropic API, you should move that stadium back.

Re: NSA lost access to Mythos amid Anthropic dispute

#294

Earlier quoted context omitted.

> Why would I want the data to be decrypted at each point and why would datacenters do that? I think they mean the data must have existed in plain text before it was encrypted, and will exist in plain text after it is decrypted. At some point “your” server in a datacenter somewhere needs to decrypt the data to do something useful with it, after all you’re paying for compute, and homeomorphic encryption is too slow, s…

So the NSA streams the ram of every virtual machine and bare metal server on the internet to themselves so they can analyze the plain text that's being processed in ram and no one has noticed this network traffic? How could that even be possible? If I buy a 100Mbps network connection from someone, they just provision a bit more so that the NSA streaming doesn't impact or show up?

Why would they have to stream, and why would it have to be every server?

They could just do this to the specific servers they want, at specific times.

Just like wiretapping didn’t mean listening to every phone, and every conversation.

Re: NSA lost access to Mythos amid Anthropic dispute

#295

Earlier quoted context omitted.

> Everyone lost access. Yes. But unlike the rest of us, NSA didn't have to if the administration had thought about it for 30 seconds before sending their letter. It's a stupid own-goal.

Americans didn't have to lose access either. It was Anthropic who chose to cut access to more people than they needed to.

How is Anthropic going to make sure every person using an API key is a citizen?

Re: NSA lost access to Mythos amid Anthropic dispute

#296

Earlier quoted context omitted.

My trusted CA doesn't have my private key, they only attest that my public key belongs to me.

Your many, many default-trusted CAs can mint new certs for the sites you visit.

Which would be easily detectable if the cert I'm using on my server didn't match the one that was being served publicly.

There's really no way this conspiracy theory works if "they" have a copy of every single private cert generated. Which would be impressive because I can generate one myself and get it trusted without ever sending it and would be easily able to detect a MITM attack.

Not to mention most sites are going to use pinned certs so any repeat visitors to a site will notice a cert change associated with a MITM.

This whole idea relies on the assumption that everyone is trusting third parties with their private certs. That is not at all required.

Re: NSA lost access to Mythos amid Anthropic dispute

#297

Earlier quoted context omitted.

And you're saying "they" (red flag) have done this with every cert generated?

They've most certainly tried. https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Bullrun_(decryption_program) If you're a specific target of a nation-state level actor, things get worse; they just grab your hardware mid-shipment on its way to you. https://www.nbcnews.com/tech/tech-news/report-nsa-intercepts...

> They've most certainly tried.

And failed.

> If you're a specific target...

If you're a specific target, they have to spend an incredibly number of man-hours and money to get into your private data. This proves my point. This shows the effort required to infiltrate _one_ target and you're suggesting they've infiltrated everything by default.

Re: NSA lost access to Mythos amid Anthropic dispute

#298

Earlier quoted context omitted.

They've most certainly tried. https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Bullrun_(decryption_program) If you're a specific target of a nation-state level actor, things get worse; they just grab your hardware mid-shipment on its way to you. https://www.nbcnews.com/tech/tech-news/report-nsa-intercepts...

> They've most certainly tried. And failed. > If you're a specific target... If you're a specific target, they have to spend an incredibly number of man-hours and money to get into your private data. This proves my point. This shows the effort required to infiltrate _one_ target and you're suggesting they've infiltrated everything by default.

> And failed.

How would you know about the successes? Thinking this is the one and only time they tried it is... interesting.

(Plus: "it was, for seven years, one of four CSPRNGs standardized in NIST SP 800-90A")

> If you're a specific target, they have to spend an incredibly number of man-hours and money to get into your private data.

No, this demonstrates an actor of that power level doesn't even need to compromise encryption, and can get deeper access to everything, if it's worth it to them.

Re: NSA lost access to Mythos amid Anthropic dispute

#299

Earlier quoted context omitted.

Your many, many default-trusted CAs can mint new certs for the sites you visit.

Which would be easily detectable if the cert I'm using on my server didn't match the one that was being served publicly. There's really no way this conspiracy theory works if "they" have a copy of every single private cert generated. Which would be impressive because I can generate one myself and get it trusted without ever sending it and would be easily able to detect a MITM attack. Not to mention most sites are goi…

> Which would be easily detectable if the cert I'm using on my server didn't match the one that was being served publicly.

I'm not sure why your focus is so heavily on your server. Is that the only thing on the internet you care about?

> Not to mention most sites are going to use pinned certs so any repeat visitors to a site will notice a cert change associated with a MITM.

Most haven't even heard of pinned certs.

https://dl.acm.org/doi/10.1145/3517745.3561439

"we find that 0.9% to 8% of Android apps and 2.5% to 11% of iOS apps use certificate pinning at run time"

Re: NSA lost access to Mythos amid Anthropic dispute

#300
post #166

'Mythos “broke into almost all of our classified systems, not in weeks, but in hours.”' Is Mythos a significant danger? The curl experience does not suggest that hysteria is warranted, but this gives me pause.

additional context from the article regarding that particular statement:

"[the statement] was oversimplified... In reality, the tests involved “red teams” of N.S.A. analysts who were using Mythos in a highly tailored environment that would be extremely unlikely for an adversary to replicate, officials said. The red teams began their tests within classified N.S.A. systems designed to be accessible only from certain computers and completely cut off from the broader internet.

The tests found that Mythos was able to identify cybersecurity flaws within that classified network quickly, but it did not actually break into those systems, the officials said."

Post reply on HN