Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

311–320 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#311
post #293

Earlier quoted context omitted.

FFmpeg has a lot of weird and not widely used codecs that don't get a lot of scrutiny. If there's no specifics then it could be a bug in one them.

this only makes things worse for ffmpeg if someone sends you a malicious file that uses a rare codec and you open it, you will trigger this codepath that is not widely used and don't get a lot of scrutiny

A prior bug discussed here was against a file format only used by specific 1990s Lucas Arts adventure games titles. Obscure enough that discussion of the bug report itself was the only search results. Your video player is unlikely to even attempt to open that.

Re: Project Glasswing: Securing critical software for the AI era

#312

The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…

[flagged]

Could you please stop posting unsubstantive comments and flamebait? You've unfortunately been doing it repeatedly. It's not what this site is for, and destroys what it is for.

If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.

Re: Project Glasswing: Securing critical software for the AI era

#313
post #293

[flagged]

FFmpeg has a lot of weird and not widely used codecs that don't get a lot of scrutiny. If there's no specifics then it could be a bug in one them.

They specifically mention "H.264, H.265, and av1 codecs, along with many others" here https://red.anthropic.com/2026/mythos-preview/

Re: Project Glasswing: Securing critical software for the AI era

#314

Earlier quoted context omitted.

If it was in an android or humanoid type body, even with limited bodily control, most people would think they are talking to Commander Data from Star Trek. I think Claude is sufficiently advanced that almost everyone in that era would've considered it AGI.

Assuming they would understand it as artificial - I think many people would think it's a human intelligence in a cyborg trenchcoat, and it would be hard to convince people it wasn't literally a guy named Claude who was an incredibly fast typist who had a million pre-cached templated answers for things. But in general, yeah, I agree, I think they would think it was a sentient, conscious, emotional being. And then the…

Some people at my office still confidently state that LLMs can’t think. I’m fairly convinced that many humans are incapable of recognizing non-human intelligence. It would explain a lot about why we treat animals the way we do.

Re: Project Glasswing: Securing critical software for the AI era

#315

Earlier quoted context omitted.

Assuming they would understand it as artificial - I think many people would think it's a human intelligence in a cyborg trenchcoat, and it would be hard to convince people it wasn't literally a guy named Claude who was an incredibly fast typist who had a million pre-cached templated answers for things. But in general, yeah, I agree, I think they would think it was a sentient, conscious, emotional being. And then the…

Because questions like this force us to hold up a very uncomfortable mirror to ourselves. It’s much easier to just dismiss.

I’m pretty close to the point of saying that human intelligence is not special.

Re: Project Glasswing: Securing critical software for the AI era

#316

Earlier quoted context omitted.

lol and what about the vibe coders? You people are comical. Why do you feel the need to create so much hype around what you say? Did you not get enough attention as a kid?

The vibe coders will be fine. They’ll use LLMs to red team their code.

What a load of nonsense.

Re: Project Glasswing: Securing critical software for the AI era

#317

So, $100B+ valuation companies get essentially free access to the frontier tools with disabled guardrails to safely red team their commercial offerings, while we get "i won't do that for you, even against your own infrastructure with full authorization" for $200/month. Uh-huh.

Yes, and that's normal. Coordinated disclosure is standard practice when the risk of public disclosure is unacceptable.

Risk for who? It feels unfair that the risk to myself is ignored "for the greater good of everyone else."

Re: Project Glasswing: Securing critical software for the AI era

#318

Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Scary but also cool

Every piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org

Once you get the compartmentalization working well, and “all” of the vulnerabilities are out of it too, of course…

But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.

Re: Project Glasswing: Securing critical software for the AI era

#319

To be clear, we don’t know that this tool is better at finding bugs than fuzzing. We just know that it’s finding bugs that fuzzing missed. It’s possible fuzzing also finds bugs that this AI would miss.

This line of reasoning makes no sense when the AI can just be given access to a fuzzer. I would guess that it probably did have access to a fuzzer to put together some of these vulnerabilities.
Post reply on HN