Live data from Hacker News

Assessing Claude Mythos Preview's cybersecurity capabilities

red.anthropic.com

41–50 of 59 posts

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#42
post #21

The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…

And this is precisely why so many of these devices should not be connected to the Internet.

Things like an Internet-connected central heating seem absolutely insane to me, yet people look at me like I'm crazy when I say so. Do you really want your home' heating entirely controller by a publicly accessible device that likely will never be upgraded in case of security issues?

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#44

Since this level of security ”scanning” requires heaps of money, this is going to kill off a substantial part of F/OSS.

Well, maybe not... see Simon Willison's ongoing reporting [0] on all the bug reports for `curl` people are finding with LLMs. Interesting to see them go from "DON'T GIVE US AI SLOP!" to "Wow, lots of actual bugs found, including [ed: at least one] bug found by two people!" [0]: https://simonwillison.net/search/?q=curl

> Interesting to see them go from "DON'T GIVE US AI SLOP!" to "Wow, lots of actual bugs found, including [ed: at least one] bug found by two people!"

Both of those things can be true.

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#45

My two cents is LLMs are way stronger in areas where the reward function is well known, such as exploiting - you break the security, you succeed. It's much harder to establish whats a usable and well architected, novel piece of software, thus in that area, progress isn't nearly as fast, while here you can just gradient descent your way to world domination, provided you have enough GPUs.

[flagged]

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#46
Interestingly, it sounds like OpenBSD held up very well:

> This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings.

The vulnerability in question is a DOS one in the TCP implementation, which is nasty but it's far from the multiple local privilege escalations found in the Linux kernel.

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#47
post #21

The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…

You should either implement over-the-air updates or not connect your device to the network at all.

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#48
post #47
post #21

The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…

You should either implement over-the-air updates or not connect your device to the network at all.

The problem of course is that many of these devices are eager to connect to the internet so they can often user hostile updates.

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#49
post #47
post #21

The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…

You should either implement over-the-air updates or not connect your device to the network at all.

That doesn't help when the company behind the device disappears or stops supporting the device. Or is hacked to convert all the devices they manufactured into a botnet.

Re: Assessing Claude Mythos Preview's cybersecurity capabilities

#50
post #36
post #21

The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…

> The only practical defense is for these frontier models Another practical defence for many of these devices would be to just disconnect them... I feel like an old man yelling at a cloud, but too much is connected to the Internet these days.

Why doesn't this atm tell me my balance anymore? Oh we implemented creata's advice

Why didn't this smartboard tell me my plane was delayed? Oh we implemented creata's advice

ad nauseum

Post reply on HN