Live data from Hacker News

A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

flyingpenguin.com

31–40 of 41 posts

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#32

Earlier quoted context omitted.

Or Apple, or any of the other organisations mentioned on the marketing piece?

Mozilla has: https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul...

Thank you! I had missed that one, and it's an excellent read!

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#33

Earlier quoted context omitted.

If Glasswing was a marketing exercise for Anthropic, why did Linux Foundation issue a joint statement with them? What about Apple? Conspiracy theories aside - what's your Occam's Razor explanation?

what's wrong in admitting you don't know something for a fact? i would love to see some proof for mythos or a white paper or something smaller companies, even startups, are held to much much higher standards is anthropic somehow immune? what have they done to earn that immunity? what good will, good stewardship, good faith have they shown to the developer community in the past few quarters? call a spade a spade

Perhaps hardening Firefox? https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul...

The developer community is wildly fickle. They turn on you at the drop of a hat if you don't puritanically adhere to what they want. The question isn't "what have they done for the developer community" (no one working at a real company gives a shit), the question is "are they lying about Mythos".

I don't see why Mozilla would write that blogpost if they were. Is Mozilla lying too now?

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#34

Earlier quoted context omitted.

If Glasswing was a marketing exercise for Anthropic, why did Linux Foundation issue a joint statement with them? What about Apple? Conspiracy theories aside - what's your Occam's Razor explanation?

You'd look like an idiot for turning down Anthropic's help, but if Anthropic are over-blowing it, you probably won't have any reputational harm.

So is this article exaggerated and/or lying? https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul...

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#35
post #16

"Sonnet sees the same two “obvious” bugs. It just cannot close the exploitation step. Mythos’s entire frontier advantage over the prior model is therefore bupkis." What a bizarre conclusion. It "just" cannot close the exploitation step? "Just?" Developing the working exploit is the hardest part , not finding the bugs. A self-proclaimed security professional should know this. How is this stuff even making it to the to…

I don't think there is a general consensus in the security community that finding bugs is easier than writing exploits.

It definitely is. You can use all sorts of vuln scanners to find vulns. Most codebases have vulns, and most vulns aren't even reachable. The hard part is chaining them together in a fire-and-forget exploit that gets you what you want from the target.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#36

Earlier quoted context omitted.

If Glasswing was a marketing exercise for Anthropic, why did Linux Foundation issue a joint statement with them? What about Apple? Conspiracy theories aside - what's your Occam's Razor explanation?

You'd look like an idiot for turning down Anthropic's help, but if Anthropic are over-blowing it, you probably won't have any reputational harm.

If it turns out Mythos isn't real, who's going to believe the Linux Foundation or Mozilla the next time there may or may not be a wolf?

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#37
post #9

I wouldn’t be surprised if the glasswing thing comes with an NDA akin to what the NSA wants you to sign when you join. That would be the Anthropic-optimistic interpretation of the sound of crickets from participants - and ‘responsible disclosure’ would be an ok-ish reason for Anthropic itself to not publish what they found themselves alone. If it’s indeed as bad as the article says it’s going to be a (yet another) PR…

Apparently Mozilla didn't have to sign it if there is one.

https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul...

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#38

Earlier quoted context omitted.

what's wrong in admitting you don't know something for a fact? i would love to see some proof for mythos or a white paper or something smaller companies, even startups, are held to much much higher standards is anthropic somehow immune? what have they done to earn that immunity? what good will, good stewardship, good faith have they shown to the developer community in the past few quarters? call a spade a spade

Perhaps hardening Firefox? https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul... The developer community is wildly fickle. They turn on you at the drop of a hat if you don't puritanically adhere to what they want. The question isn't "what have they done for the developer community" (no one working at a real company gives a shit), the question is "are they lying about Mythos". I don't see why Mozilla would w…

I don't understand why you're stuck on the word lie?

These are both true statements:

- We've just developed our new top model for agentic coding

- We've just developed a model capable of finding cybersecurity vulnerabilities at a scale never before seen

The problem is/was when you say the 1st statement, you're saying something that everyone says. OpenAI said something similar for 5.5 just this morning. Once you loudly frame your release in the latter terms, you're not lying... but you're being very intentional in trying to grab headlines.

Every top release from a frontier lab now enables the same thing. That's why we've already had response-level filters on cybersecurity for months now from both OpenAI and Anthropic.

Technically every time either has released a top model for the last several months they've been "enabling automated cybersecurity penetration at a scale never before seen.": it was Anthropic that decided to quadruple down on the language and create a ton of buzz.

But OpenAI today showed that the existing cybersecurity mitigations already addressed the concern of misuse. Anthropic has the same (or even stricter) detection for widescale automated attacks and could have used it to ship Mythos if not for the marketing points.

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#39

Earlier quoted context omitted.

what's wrong in admitting you don't know something for a fact? i would love to see some proof for mythos or a white paper or something smaller companies, even startups, are held to much much higher standards is anthropic somehow immune? what have they done to earn that immunity? what good will, good stewardship, good faith have they shown to the developer community in the past few quarters? call a spade a spade

Perhaps hardening Firefox? https://blog.mozilla.org/en/firefox/ai-security-zero-day-vul... The developer community is wildly fickle. They turn on you at the drop of a hat if you don't puritanically adhere to what they want. The question isn't "what have they done for the developer community" (no one working at a real company gives a shit), the question is "are they lying about Mythos". I don't see why Mozilla would w…

You don't know what Mozilla got access to. They may just be covering their own asses.

My hunch is that it's a marketing ploy. I don't trust a company that says they can protect others if they let their own tools leak, it feels like logic to me, am I wrong?

Re: A Boy That Cried Mythos: Verification Is Collapsing Trust in Anthropic

#40

Earlier quoted context omitted.

We already have access to a smaller version of the Mythos tier with Opus 4.7: based on the usual delta between the full fat models and their distills, do you really think Mythos breaks cybersecurity? It's a good model update. We've had these before, and it looks like OpenAI is gearing up to match it this week. - Mythos launch has felt like a showsman overlplaying their hand. Opus 4.5 put them in an awkward position a…

If Glasswing was a marketing exercise for Anthropic, why did Linux Foundation issue a joint statement with them? What about Apple? Conspiracy theories aside - what's your Occam's Razor explanation?

Another take on Mythos = marketing: https://berryvilleiml.com/2026/04/09/too-dangerous-to-releas.... That's from the author of a fundamental text on exploiting software, so he knows what he's talking about.
Post reply on HN