Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

611–620 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#611

Earlier quoted context omitted.

Homie chill. I use Opus every day and I love it. I’m not saying it’s all hype, just that these companies are here to make money and that every advertisement should be taken with salt yeah? Also maybe consider what this kind of visceral reaction indicates on a personal level :/

[flagged]

I mean if it helps I support the move to not release mythos right off the bat yeah? That makes sense, treat new models like new vulnerabilities and give companies time to scan with them etc.

But you have to admit it does serve a savvy business purpose of creating a moat where one wasn’t by getting these tech companies on board and the threat does make for good marketing yeah?

Re: Project Glasswing: Securing critical software for the AI era

#613
From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government?

> Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infrastructure is a top national security priority for democratic countries—the emergence of these cyber capabilities is another reason why the US and its allies must maintain a decisive lead in AI technology.

Not a single word of caution regarding possible abuse. Instead apparent support for its "offensive" capabilities.

Re: Project Glasswing: Securing critical software for the AI era

#614

The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…

Oh I enjoyed the Sign Painter short story it wrote. --- Teodor painted signs for forty years in the same shop on Vell Street, and for thirty-nine of them he was angry about it. Not at the work. He loved the work — the long pull of a brush loaded just right, the way a good black sat on primed board like it had always been there. What made him angry was the customers. They had no eye. A man would come in wanting COFFEE…

Good for a bot, but pretty rough and bland compared to human writing. I guess most of the customers have no eye.

Re: Project Glasswing: Securing critical software for the AI era

#615
"We have also extended access to a group of over 40 additional organizations that build or maintain critical software infrastructure so they can use the model to scan and secure both first-party and open-source systems."

Yeah, yeah. Back in the day IBM Purify gave access to software organizations and found very little. Of course they did not have the free money of a marketing driven organization run by a weirdo (Amodei) that got rich by stealing and laundering IP.

This will fizzle out and the weirdo will have to pivot to their next marketing scheme.

Re: Project Glasswing: Securing critical software for the AI era

#617
post #124

Earlier quoted context omitted.

If we think in the context of LLMs, why is it easier to find a single vulnerability than to patch every vulnerability? If the defender and the attacker are using the same LLM, the defender will run "find a critical vulnerability in my software" until it comes up empty and then the attacker will find nothing. Defenders are favored here too, especially for closed-source applications where the defender's LLM has access…

You also need to deploy the patch. And a lot of software doesn't have easy update mechanisms. A fix in the latest Linux kernel is meaningless if you are still running Ubuntu 20.

It's not because fixes get backported.

Re: Project Glasswing: Securing critical software for the AI era

#618

Earlier quoted context omitted.

Apple has already largely crushed hacking with memory tagging on the iPhone 17 and lockdown mode. Architectural changes, safer languages, and sandboxing have done more for security than just fixing bugs when you find them.

If what you are saying is true, then you would see exploit marketplaces list iOS exploits at hundreds of millions of dollars. Right now a cursory glance sets the price for zero click persistent exploit at $2m behind Android at $2.5m. Still high, and yes, higher than five years ago when it was around $1m for both, but still not "largely crushed". It is still easy to get into a phone if you are a state actor.

Hi, would you mind explaining how this works? Something is finding an exploit in Android/iOS and then he sells it for 2.5m/2m on some dark market?

Re: Project Glasswing: Securing critical software for the AI era

#619

Earlier quoted context omitted.

[flagged]

I mean if it helps I support the move to not release mythos right off the bat yeah? That makes sense, treat new models like new vulnerabilities and give companies time to scan with them etc. But you have to admit it does serve a savvy business purpose of creating a moat where one wasn’t by getting these tech companies on board and the threat does make for good marketing yeah?

[flagged]

Re: Project Glasswing: Securing critical software for the AI era

#620

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

I think Claude Code with Sonnet 4.6 is already at the level of paradigm shift and can change the entire tech industry.

If you're paranoid it doesn't mean you're not being followed. If something is overhyped it doesn't mean it's not game-changing.

Post reply on HN