Live data from Hacker News

US summons bank bosses over cyber risks from Anthropic's latest AI model

theguardian.com

71–80 of 101 posts

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#71
post #56

Earlier quoted context omitted.

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

"Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about." I agree that cyber security is taken too lightly. However, I think that many developers don't actually know about vulnerabilities. In many companies those reports get filter through other teams and prioritiz…

I frankly believe that many know what they are doing, take the average freelancer, developing for multiple clients on the same workspace (suicidal and ethically wrong on top of it) without even disk encryption enabled or straight up syncing everything in cleartext to dropbox.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#72
post #62

Earlier quoted context omitted.

Will you eat your words when major vuln disclosures come out 3-4 months from now?

Will you eat your words when you find out major vuln disclosures have been happening for decades?

They obviously meant on an unprecedented scale.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#73
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

I read your list and all of that is normal computer use. How can it be reckless to use a computer normally?

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#74

Earlier quoted context omitted.

Will you eat your words when you find out major vuln disclosures have been happening for decades?

They obviously meant on an unprecedented scale.

Sure, and healthy skepticism before proof is a sign of wisdom.

Which makes taking claims from companies at face value…?

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#75
post #67

Earlier quoted context omitted.

> ignites a new digital "cold war" Already been going on for over a decade - export controls on dual use technology like Xeon processors already began being enforced back in the Obama admin. > until the launch takes place It's already launched. Some companies had access to Mythos for months. > fuelling the hype This is true. Commercially available models from a year ago are already good enough from an offensive secur…

I was in the industry when key lengths for SSL were different between US domestic and US products for export. That’s one reason so much Open Source cryptography software expertise built up in Europe so quickly.

Much of that muscle was already well built in Western Europe well before the SSL stuff because of KU Leuven, COSIC, and IMEC.

The issue is by the late 2000s to 2010s, most European organizations didn't take advantage of that base despite being US comparable in the 1970s-90s.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#76
post #73

Earlier quoted context omitted.

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

I read your list and all of that is normal computer use. How can it be reckless to use a computer normally?

normal doesn't mean "right", we have piled-up a ton of bad decisions and users that are aware should now better than default settings.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#77

Earlier quoted context omitted.

Two things can be true. Historically bad security that people just got by with matched with powerful tools that aren't any better than the best people, but now can be deployed by mediocre people.

Which is exactly what Anthropic understands the situation to be. They state at the beginning of the Glasswing blogpost that Mythos is not better than the best vulnerability researchers. But it doesn't have to be to become a tremendously big deal.

There is not just a lower barrier to entry. The best use of a tool will still be made by the most knowledgeable users. So we’re looking at lowering the bar some, but another big deal is the scale at which the top experts can work. That might actually be the longer lever. Imagine a top expert burning tokens across whole repo histories of a few dozen projects looking for likely but unconfirmed flaws, then having the model flag and rank those suspects for their own review in triaged order.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#78
post #56

Earlier quoted context omitted.

"Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about." I agree that cyber security is taken too lightly. However, I think that many developers don't actually know about vulnerabilities. In many companies those reports get filter through other teams and prioritiz…

I frankly believe that many know what they are doing, take the average freelancer, developing for multiple clients on the same workspace (suicidal and ethically wrong on top of it) without even disk encryption enabled or straight up syncing everything in cleartext to dropbox.

Or they're a freelancer because they arent good enough for a big salary job

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#79
post #38
post #3

Promoting the model as potentially dangerous might backfire with the government banning it from being released by executive order.

> the government banning it from being released by executive order. There's no legal mechanism for the president or the government at all to do that.

There's no legal mechanism for the vast majority of what the president has done.

Often it happens anyway, along with some protests, some resignations and maybe an eventual court case reversal months or years later.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#80
I'm wondering whether the NSA will be granted access. It's already the largest collection of mathematicians on the planet and now they'd be given tools that could automate a lot of discovery. Or they're panicking that their "old faithful" back door will be patched soon.
Post reply on HN