Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

671–680 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#671
post #623

Earlier quoted context omitted.

Ffmpeg confirmed on Twitter that they sent the patches.

Although, they also said, "Because the patches appear to be written by humans".

"Mythos writes code like a human" incoming

Re: Project Glasswing: Securing critical software for the AI era

#672
post #550

Earlier quoted context omitted.

What evidence makes you say that? Do you have insider info?

Neither party provided the evidence. I wonder why people like to take the side of the optimistic.

We already know Opus can find real vulnerabilities ([1], [2], ...), so it's not exactly surprising that a bigger model is better at it.

[1] https://news.ycombinator.com/item?id=47273854

[2] https://news.ycombinator.com/item?id=47611921

Re: Project Glasswing: Securing critical software for the AI era

#673

Earlier quoted context omitted.

> how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. It's much the dynamic between parents and a child. The child, with limited hindsight, almost zero insight and no ability to forecast, is annoyed by their parents. Nothing bad ever happens! Why won't parents stop being so worried all the time and make a fuss over nothing? The parents, which the child somewhat star…

Disagree - we’re being told on one hand that we are 6 months away from AI writing all Code, and 3 months into that the tools are unusable for complex engineering [1]. Every time I mention this I’m told “but have you tried the latest model and this particular tool” - yes I have, but if I need to be on the hottest new model for it to be functional that means the last time you claimed it was solved, it wasn’t solved. [0…

> “I think… I don’t know… we might be six to twelve months away from when the model is doing most, maybe all of what SWEs (software engineers) do end to end.”

I think it's disingenuous (as disingenuous as you're accusing these marketing teams of being) to paraphrase that as "being told on one hand that we are 6 months away from AI writing all Code". It's merely stating that it's a real possibility. (It's also disingenuous to use a post complaining about a behavioral regression bug as evidence that it's not progressing)

Dismissing it as impossible is silly, considering how close it already is to a junior dev. Keep in mind that 14 months prior to that statement was before we even had any public reasoning models. Things really are moving that fast, it's just, at the moment, unclear how fast.

Re: Project Glasswing: Securing critical software for the AI era

#674

Earlier quoted context omitted.

I’m pretty close to the point of saying that human intelligence is not special.

Despite the stupendous amount of evidence to the contrary? So far no evidence has been detected in space or on earth, for all of history, of anything being intelligent in the way humans are. One certain outcome of the Fermi Paradox: humans are outstandingly unique, according to all available evidence, which is the only measure that matters.

Seems like that's more to do with human intelligence being first.

Re: Project Glasswing: Securing critical software for the AI era

#675

Earlier quoted context omitted.

> how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. It's much the dynamic between parents and a child. The child, with limited hindsight, almost zero insight and no ability to forecast, is annoyed by their parents. Nothing bad ever happens! Why won't parents stop being so worried all the time and make a fuss over nothing? The parents, which the child somewhat star…

Disagree - we’re being told on one hand that we are 6 months away from AI writing all Code, and 3 months into that the tools are unusable for complex engineering [1]. Every time I mention this I’m told “but have you tried the latest model and this particular tool” - yes I have, but if I need to be on the hottest new model for it to be functional that means the last time you claimed it was solved, it wasn’t solved. [0…

> Every time I mention this

I feel like there’s a bunch of factors for why it will never be the same for many folks, from the models and harnesses, to the domains and existing tests/tooling.

I feel bad for the people for whom it doesn’t work, but Claude Opus has written most of my code in 2026 so far. I had to build some tools around linting entire projects and most of my tokens are probably referencing existing stuff and parallel review iterations and tests, but it’s pretty nice and even seeing legacy code doesn’t make me want move to a farm and grow potatoes.

It might be counter productive to be like: "Oh, just do X!" which works for the person suggesting it, and then have to do "But have you tried Y?" when it doesn't for the other person, if it just keeps being a never ending string of what works for one person not working for another.

Re: Project Glasswing: Securing critical software for the AI era

#676

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

Even more 'disquieting' when you take into account who's currently the president of US. "A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump

When I was reading https://ai-2027.com, which is quite a scary read, I couldn't help but think the US president being mentioned in the story acts too rational compared to the real world. It can get a lot crazier than this fictional piece.

Re: Project Glasswing: Securing critical software for the AI era

#677
post #352

Earlier quoted context omitted.

This opens up an interesting new avenue for corporate FOMO. What if you don't partner with Anthropic, miss out on access to their shiny new cybersec model, and then fall prey to a vuln that the model would have caught?

Since when did corporations care? Most seem to just pay their insurance premium for cyber liability and call it a day.

There is a difference between leaking user accounts and passwords and getting your business destroyed overnight entirely.

Imagine if an AI can infiltrate your SaaS database and delete your entire database and every single backup. The business is dead immediately.

Re: Project Glasswing: Securing critical software for the AI era

#678

Earlier quoted context omitted.

There is plenty of overhyping, no one denies that. But the antidote is not to dismiss everything. Ignore the words and look at the data. In this case, I see a pretty strong case that this will significantly change computer security. They provide plenty of evidence that the models can create exploits autonomously, meaning that the cost of finding valuable security breaches will plummet once they're widely available.

Is there any actual independent data though, or verification of any of these claims? As it stands this is just a marketing programme for all involved.

That's pretty disingenuous, bordering on ridiculous.

Do they have a record of lying to you? No.

Go read the system card. It's a lot more tame than you think, peoples are taking pieces out of this and hyping it. Doesn't mean it's not valid.

Re: Project Glasswing: Securing critical software for the AI era

#679

Earlier quoted context omitted.

Are they actually too dangerous to publicly release? It seems like a little bit of marketing from the model-producing companies to raise more funding. It's important to look at who specifically is making that statement and what their incentives are. There are hundreds of billions of dollars poured into this thing at this point.

You really think some marketers got leaders from companies across the industry to come together to make a video - and they're all in on the conspiracy because money?

That’s literally exactly the kind of thing marketing does, and has been doing for a very long time. Did you just arrive on earth from outer space or something?

Re: Project Glasswing: Securing critical software for the AI era

#680

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

There is very little Anthropic can do - that job is up to US citizens creating and enforcing checks and balances. You can’t ask a company legally bound by your country laws (made by your own representatives) to protect you or anyone else from said laws. That is your job.

And it is other countries job to protect themselves from other countries weapons. As EU citizen I’d much rather if EU had a frontier model on par, but here we are.

Post reply on HN