Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

581–590 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#581

It's all just really genius marketing. In 6 months Mythos will be nothing special, but right now everyone is being manipulated into fearing its release, as a marketing ploy. This is the same reason AI founders perennially worry in public that they have created AGI...

I can't believe the effectiveness of this type of marketing. It's one-shotting normie journalist and getting a lot of press for what is ultimately going to turn out to be an incrementally improved model.

I'm sure all they've done here is spend unlimited tokens to find bugs in mostly open source projects (and fuzz some closed source ones).

Re: Project Glasswing: Securing critical software for the AI era

#582

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

There is step changes that actually merit this though. And a zero day machine IS one of those. It went from 4% zero day success rate to 85% on firefox.

Can you not see the significance of that?

Re: Project Glasswing: Securing critical software for the AI era

#583

Earlier quoted context omitted.

There is an entire section on crafting chemical/bio weapons so yeah I think we are cooked.

LLMs are useless for this type of thing for the same reason that the Anarchist Cookbook has always been. The skills required to convert text into complicated reactions completing as intended (without killing yourself) is an art that's never actually written down anywhere, merely passed orally from generation to generation. Impossible for LLMs to learn stuff that's not written down. This is the same reason why LLMs ar…

There's still RL

Re: Project Glasswing: Securing critical software for the AI era

#584

It's all just really genius marketing. In 6 months Mythos will be nothing special, but right now everyone is being manipulated into fearing its release, as a marketing ploy. This is the same reason AI founders perennially worry in public that they have created AGI...

It's effectively 2026's version of "Doctors hate this one weird trick!"

The fact that they are not going to release this DANGEROUS model is also a huge tell that it's nothing but an incremental improvement over the status quo.

Re: Project Glasswing: Securing critical software for the AI era

#585
I'm not one to believe the Silicon Valley hype usually (GPT-2 being too dangerous to release, AI giving us UBI, and so on), but having run Claude Opus 4.6 against my codebase (a MUD client) over the weekend, I can believe this assessment.

Opus alone did a good job of identifying security issues in my software, as it did with Firefox [1] and Linux [2]. A next-generation frontier model being able to find even more issues sounds believable.

That said, this is script kiddies vs sql injections all over again. Everyone will need to get their basic security up on the new level and it will become the new normal. And, given how intelligence agencies are sitting on a ton of zero-days already, this will actually help the general public by levelling out the playing field once again.

1 - https://www.anthropic.com/news/mozilla-firefox-security 2 - https://neuronad.com/ai-news/claude-code-unearthed-a-23-year...

Re: Project Glasswing: Securing critical software for the AI era

#586
post #582

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

There is step changes that actually merit this though. And a zero day machine IS one of those. It went from 4% zero day success rate to 85% on firefox. Can you not see the significance of that?

I mean I work in this world and overhype is constant.

Additionally those numbers are somewhat meaningless without more context.

Re: Project Glasswing: Securing critical software for the AI era

#587

Earlier quoted context omitted.

OpenAI is not Anthropic, these companies behave as polar opposites

Anthropic came out of OpenAI. The founding members of Anthropic worked on GPT3.

Both your post and the parent post can be true.

Re: Project Glasswing: Securing critical software for the AI era

#589

Earlier quoted context omitted.

The only people who are "cooked" are those who rely on SOTA models to function in their jobs, and companies who are desperate to regulate open / local models to maintain their marketshare.

If you aren't relying on a SOTA model to do your job, you aren't doing your job right (and are cooked.)

How are you preparing?

Re: Project Glasswing: Securing critical software for the AI era

#590

Earlier quoted context omitted.

I mean yeah. I’ve had these successes without scaffolding or really anything past Claude CLI and a small prompt as well?

You've taken control of a remote server running OpenBSD? Or similarly expert level exploit? Can you share one of the bounties you've received that is of the magnitude they're talking about? Edit: Wait, you wrote "As someone in cybersecurity for 10+ years" elsewhere in this thread. You wrote "a small prompt" using e.g. Opus 4.6 and it found critical vulnerabilities of the magnitude they're describing, presumably witho…

I mean, yes? And my point is that this isn’t exactly a new capability. Sure it’s probably better but we’ve been able to do this. They didn’t just suddenly “turn on the security”. LLMs have excelled at code since widely being released. I have no idea why that’s news and the fact that they’re treating it as such makes it seem like hype.
Post reply on HN