Assessing Claude Mythos Preview's cybersecurity capabilities
41–50 of 59 posts
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#42The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…
Things like an Internet-connected central heating seem absolutely insane to me, yet people look at me like I'm crazy when I say so. Do you really want your home' heating entirely controller by a publicly accessible device that likely will never be upgraded in case of security issues?
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#43Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#44Since this level of security ”scanning” requires heaps of money, this is going to kill off a substantial part of F/OSS.
Well, maybe not... see Simon Willison's ongoing reporting [0] on all the bug reports for `curl` people are finding with LLMs. Interesting to see them go from "DON'T GIVE US AI SLOP!" to "Wow, lots of actual bugs found, including [ed: at least one] bug found by two people!" [0]: https://simonwillison.net/search/?q=curl
Both of those things can be true.
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#45My two cents is LLMs are way stronger in areas where the reward function is well known, such as exploiting - you break the security, you succeed. It's much harder to establish whats a usable and well architected, novel piece of software, thus in that area, progress isn't nearly as fast, while here you can just gradient descent your way to world domination, provided you have enough GPUs.
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#46> This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings.
The vulnerability in question is a DOS one in the TCP implementation, which is nasty but it's far from the multiple local privilege escalations found in the Linux kernel.
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#47The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#48The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…
You should either implement over-the-air updates or not connect your device to the network at all.
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#49The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…
You should either implement over-the-air updates or not connect your device to the network at all.
Re: Assessing Claude Mythos Preview's cybersecurity capabilities
#50The elephant in the room here is that there are hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. The only practical defense is for these frontier models to generate _beneficial_ attacks to innoculate older binaries by remote e…
> The only practical defense is for these frontier models Another practical defence for many of these devices would be to just disconnect them... I feel like an old man yelling at a cloud, but too much is connected to the Internet these days.
Why didn't this smartboard tell me my plane was delayed? Oh we implemented creata's advice
ad nauseum