Live data from Hacker News

Project Glasswing: what Mythos showed us

blog.cloudflare.com

51–60 of 152 posts

Re: Project Glasswing: what Mythos showed us

#51

What does this mean? > It's a different kind of tool doing a different kind of work, and that makes a clean apples-to-apples comparison to earlier models difficult. They claim it’s a different kind of tool and then describe using it the same way you’d use any other model. This really felt way worse than the average Cloudflare blog and really just rehashed the Mythos announcement which had already called out the key p…

Sounds different because it’s hidden advertisement not a regular blog post

Re: Project Glasswing: what Mythos showed us

#52

What does this mean? > It's a different kind of tool doing a different kind of work, and that makes a clean apples-to-apples comparison to earlier models difficult. They claim it’s a different kind of tool and then describe using it the same way you’d use any other model. This really felt way worse than the average Cloudflare blog and really just rehashed the Mythos announcement which had already called out the key p…

I think what they might mean is:

Because of it's capabilities, a new kind of harness can be built for it, thus the entire system (model + harness) is a different kind of tool than say Claude code

Re: Project Glasswing: what Mythos showed us

#53

What does this mean? > It's a different kind of tool doing a different kind of work, and that makes a clean apples-to-apples comparison to earlier models difficult. They claim it’s a different kind of tool and then describe using it the same way you’d use any other model. This really felt way worse than the average Cloudflare blog and really just rehashed the Mythos announcement which had already called out the key p…

Sounds different because it’s hidden advertisement not a regular blog post

But why would cloudflare advertise Anthropic? They are competing with Anthropic by hosting open weights models.

Re: Project Glasswing: what Mythos showed us

#54
> The harder question is what the architecture around the vulnerability should look like. The principle is to make exploitation harder for an attacker even when a bug exists, so that the gap between when a vulnerability is disclosed and when it is patched matters less. That means defenses that sit in front of the application and block the bug from being reached. It means designing the application so that a flaw in one part of the code cannot give an attacker access to other parts. It means being able to roll out a fix to every place the code is running at the same moment, rather than waiting on individual teams to deploy it.

So nothing new then.

Re: Project Glasswing: what Mythos showed us

#55
post #38
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

I had a dude in a conversation non-ironically use "load-bearing." I could only follow up with, "that is a genuine insight." Not a single person visibly flinched in pain.

Let's double-click on that. It's important to keep top of mind that using disruptive words and patterns in conversation isn't always driven by LLMs — reasoning from first principles tells us that problematic usages like this existed beforehand. One of my load-bearing career learnings is that people used this shape of language as a shibboleth long before game-changing tools like ChatGPT started slopping so much of what people read. It's a performant way of categorizing people into a very specific tech culture in-group based on vibes.

Re: Project Glasswing: what Mythos showed us

#56
post #3

The real question is whether it was Mythos or Opus that wrote this post. > "Why it matters" It doesn't, it's a corporate blog, they were rarely written in one-author's voice anyway, but it's interesting to see that even large organisations are outsourcing their blogs to LLMs.

This is not just any large organization, it's Anthropic. Their entire shtick is that AIs can do Real Work now and it'd be weird if they didn't behave accordingly themselves.

This is also why Claude Code is full of weird bugs and why their support says that it did refunds when it didn't and so on and so forth.

Re: Project Glasswing: what Mythos showed us

#57
post #53

Earlier quoted context omitted.

Sounds different because it’s hidden advertisement not a regular blog post

But why would cloudflare advertise Anthropic? They are competing with Anthropic by hosting open weights models.

https://www.cloudflare.com/press/press-releases/2025/cloudfl...

Re: Project Glasswing: what Mythos showed us

#58

Earlier quoted context omitted.

When writing is too heavily LLM-assisted, it does actually cease to be substantive, because it becomes impossible to know which parts of it represent actual claims which the author believes as stated and which are interpolations.

No no, it the LLM-assistance makes it hard to know what is substantive . That means it puts more work on the reader, which is a totally valid thing to complain about, but which is totally different from "the poor writing is actually the whole point "

But how can the reader do the work? They don't have access to Mythos and can't review Cloudflare's internal findings or harnesses. The only practical options are to accept the article at face value or not accept it if the expected density of LLM interpolations is too high.

Re: Project Glasswing: what Mythos showed us

#59
post #40

I was expecting some more concrete numbers and surprises. It just seems like a balanced promotion article probably written using LLM itself.

In the last few days I was recommending to read the insights from XBOW [1], it's a competitor but it adds more information to the discussion. [1] https://xbow.com/blog/mythos-offensive-security-xbow-evaluat...

That is a good article.

Interesting that gpt-5.5, while not as good as mythos, also seems like a decent step up

Re: Project Glasswing: what Mythos showed us

#60
post #38
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

I had a dude in a conversation non-ironically use "load-bearing." I could only follow up with, "that is a genuine insight." Not a single person visibly flinched in pain.

I use load-bearing all the time, mostly in jokes about something
Post reply on HN