Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

621–630 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#622
post #450

Earlier quoted context omitted.

Well yeah, it’s a toy example to illustrate a point in an HN discussion :). Imagine “silly mistake” is a parameter, and rename it “error_code” (pass by reference), put a label named “cleanup” right before the if statement, and throw in a ton of “goto cleanup” statements to the point the control flow of the function is hard to follow if you want it to model real code ever so slightly more. It will be interesting to se…

That's what I'm saying; a static analyser will be able to determine whether the code and/or state is reachable without any AI, and it will be completely deterministic in its output.

Why hasn't it then? The Linux kernel must be asking the most heavily-audited pieces of software in existence, and yet these bugs were still there.

Re: Project Glasswing: Securing critical software for the AI era

#623

Earlier quoted context omitted.

Is there any actual independent data though, or verification of any of these claims? As it stands this is just a marketing programme for all involved.

Ffmpeg confirmed on Twitter that they sent the patches.

Although, they also said, "Because the patches appear to be written by humans".

Re: Project Glasswing: Securing critical software for the AI era

#624

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

It’s great marketing to lead with how the n+1 model is so amazing that you can’t have it yet.

Re: Project Glasswing: Securing critical software for the AI era

#625

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

In my view it would be extremely strange if it was any other way round. Anthropic is the US based company. There are no "citizens of world" at that scale, or at almost any other scale for that matter.

Re: Project Glasswing: Securing critical software for the AI era

#626

Earlier quoted context omitted.

Homie chill. I use Opus every day and I love it. I’m not saying it’s all hype, just that these companies are here to make money and that every advertisement should be taken with salt yeah? Also maybe consider what this kind of visceral reaction indicates on a personal level :/

[flagged]

We have been hearing this since GPT-2. They’ve been crying wolf for too long, that’s on them (the model providers). That and the fact they never publish anything interesting around their claims. It’s the ffmpeg thing all over again (very old bug in a decoder for a format used by one game from the early 90’s sold as some major breakthrough).

Re: Project Glasswing: Securing critical software for the AI era

#627

Earlier quoted context omitted.

Just because the plane can fly on one engine doesn't mean you don't fix the other engine when it fails.

Except it didn't fail. You just looked at the left engine and said what if I fed it mashed potatoes instead of fuel. And then dropped the mic and left the room.

It's more like finding a way to shut down the engine but only if there was a movie in the entertainment system than was longer than 5 hours. You can't exploit it now, and probably never will, but it's a risk that's sitting there that I'm sure you agree should be fixed

Re: Project Glasswing: Securing critical software for the AI era

#628

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

> what does Anthropic do to prevent malicious use of its software by its own government?

Anthropic has ameliorated that danger by being designated a supply-chain risk by the DoW, preventing the USG from using it.

Re: Project Glasswing: Securing critical software for the AI era

#629

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

Do you think they're lying about the vulnerabilities they claim Mythos has found? Seems like a very short-term play, if so.

Re: Project Glasswing: Securing critical software for the AI era

#630

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

Even more 'disquieting' when you take into account who's currently the president of US.

"A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump

Post reply on HN