Earlier quoted context omitted.
FFmpeg has a lot of weird and not widely used codecs that don't get a lot of scrutiny. If there's no specifics then it could be a bug in one them.
this only makes things worse for ffmpeg if someone sends you a malicious file that uses a rare codec and you open it, you will trigger this codepath that is not widely used and don't get a lot of scrutiny
Project Glasswing: Securing critical software for the AI era
311–320 of 921 posts
Re: Project Glasswing: Securing critical software for the AI era
#312The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…
[flagged]
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
Re: Project Glasswing: Securing critical software for the AI era
#313[flagged]
FFmpeg has a lot of weird and not widely used codecs that don't get a lot of scrutiny. If there's no specifics then it could be a bug in one them.
Re: Project Glasswing: Securing critical software for the AI era
#314Earlier quoted context omitted.
If it was in an android or humanoid type body, even with limited bodily control, most people would think they are talking to Commander Data from Star Trek. I think Claude is sufficiently advanced that almost everyone in that era would've considered it AGI.
Assuming they would understand it as artificial - I think many people would think it's a human intelligence in a cyborg trenchcoat, and it would be hard to convince people it wasn't literally a guy named Claude who was an incredibly fast typist who had a million pre-cached templated answers for things. But in general, yeah, I agree, I think they would think it was a sentient, conscious, emotional being. And then the…
Re: Project Glasswing: Securing critical software for the AI era
#315Earlier quoted context omitted.
Assuming they would understand it as artificial - I think many people would think it's a human intelligence in a cyborg trenchcoat, and it would be hard to convince people it wasn't literally a guy named Claude who was an incredibly fast typist who had a million pre-cached templated answers for things. But in general, yeah, I agree, I think they would think it was a sentient, conscious, emotional being. And then the…
Because questions like this force us to hold up a very uncomfortable mirror to ourselves. It’s much easier to just dismiss.
Re: Project Glasswing: Securing critical software for the AI era
#316Earlier quoted context omitted.
lol and what about the vibe coders? You people are comical. Why do you feel the need to create so much hype around what you say? Did you not get enough attention as a kid?
The vibe coders will be fine. They’ll use LLMs to red team their code.
Re: Project Glasswing: Securing critical software for the AI era
#317So, $100B+ valuation companies get essentially free access to the frontier tools with disabled guardrails to safely red team their commercial offerings, while we get "i won't do that for you, even against your own infrastructure with full authorization" for $200/month. Uh-huh.
Yes, and that's normal. Coordinated disclosure is standard practice when the risk of public disclosure is unacceptable.
Re: Project Glasswing: Securing critical software for the AI era
#318Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Scary but also cool
Every piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org
But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.
Re: Project Glasswing: Securing critical software for the AI era
#319To be clear, we don’t know that this tool is better at finding bugs than fuzzing. We just know that it’s finding bugs that fuzzing missed. It’s possible fuzzing also finds bugs that this AI would miss.