Live data from Hacker News

Post-Mythos Cybersecurity: Keep calm and carry on

cephalosec.com

71–80 of 83 posts

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#71
post #7

The fear porn around this all has been horrible. I work in Cybersecurity and Mythos is all the vendors will talk about because they want to sell something. It started the day of the announcement which is what told me it was all BS. They had no information about it yet would happily tell me about all their solutions for it. Anyone in my profession worth a damn will tell you the vast majority of security issues are rel…

I've seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate. All those moments will be lost in time, like tears in rain. Time to die.

Anthropic: It seems you feel our work is not a benefit to the public.

Me: LLMs are like any other machine. They're either a benefit or a hazard. If they're a benefit, it's not my problem.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#73

I've been brewing on this topic since Mythos preview was announced. As Mythos got finally released, then banned, then released again under U.S. government control, it was time to finally flesh it out and use it as a way to exit the lurker-zone on HN !

FYI:

> Since then, Mythos and it’s safeguard-heavy equivalent

The simple "it's" vs. "its" rule is this:

If you can replace it with "it is" and it sounds weird, it's "its", otherwise it's "it's". In other words, "it's" is 100% of the time an abbreviation of "it is" (or, rarely, "it has"); it's not a possessive form.

Which is of course internally-inconsistent; I say "Peter's toys", not "Peters toys", but we say "its toys" to mean the same thing. /shrug

I only tell you this because I screwed it up for years before looking up the rule and going "... Oh. Duh. But also... Fucking hell, English!" ;)

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#74
post #66

Earlier quoted context omitted.

Everything is offline now. Public boards like HN are from a bygone era of the Internet.

Offline where though?

SF, NYC, Austin, Seattle, Boston, DC, Beijing, Bangalore, London, Hyderabad, Tel Aviv, Singapore, and other major tech and finance hubs.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#75
post #63
post #36

Earlier quoted context omitted.

There's an alternative viewpoint: democracy is experiencing a revival. The old "cathedral-style" democracy is dying. People are seeing that the "regular" politicians are just ineffective and kinda boring. The old party-based structures are stifling and prevent changes. People want more direct participation in the governance. So people are voting for a "new wave" of candidates that promise to work around the old insti…

Right wingers dont repreaemt democracy. They are openly and actively trying to change it to authoritariam dictatorship. Mamdani is NOT doing the same nor like Trump. For all the scaremongering, he is pragmatic politic with policies full of compromises. There ia no symmetry between what those parties do.

So do left-wingers. Just go on to one of the anarchist bro groups and listen all about "capitalism is failing us" and "we need to enforce the will of the people".

Remember, democracy doesn't mean that "good" people win.

> Mamdani is NOT doing the same nor like Trump. For all the scaremongering, he is pragmatic politic with policies full of compromises.

Just wait. He's well poised to fail upwards with his policies. They can't and won't work long term, but they'll create a lot of buzz by the time he aims for a higher office. But anyway, that's beside the point.

> There ia no symmetry between what those parties do.

The horseshoe theory works: the extremes are very much alike. And that's why Republicans were taken over by Tea Party radicals, and Democrats are now getting taken over by Mamdani radicals.

Both are the result of the same sentiment: "the current elites are not representing us, and we need to destroy the political system".

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#77
post #8

[flagged]

> things like ethnic cleansing (which these models are already being used for). Got a cite?

Israeli whistleblowers, and separately, the incident that got Anthropic to be classified as a supply chain risk by the DoD.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#78
post #54

Earlier quoted context omitted.

> I’m sure national party leadership communicates directly with the committees at the AI labs They do now. Top AI researchers in China are barred from getting an exit visa [0] (the PRC has done this for other employees as well such as Foxconn China employees who were working on shifting Apple supply chains to India [1]), and "AI Safety" from a national security perspective has been codified as party policy now [2]. T…

Any recommendations / alternatives for higher signal to noise ratio?

This person only ever complains about HN, downvotes, everybody not listening to him, people "not mattering since they are not VCs". Best to ignore them.

Posts questionable info, gets called out or downvoted -- throws a fit, doesn't reply with anything concrete. Rinse and repeat.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#79
post #64

Memory safety is the best way to address a large aspect of the threats posed by frontier models. It's one thing to forget an Authorize attribute. That's a coaching event and procedure update. It's another altogether to not be able to see a dormant use-after-free bug because your brain can't hold the entire codebase and product roadmap at once. You can't coach a human developer on that. We all miss things this deep in…

There are modern languages for that. Use Rust, don't loose your sleep over memory bugs.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#80
post #46

With so much cloud being at risk from AI now, soon or in the future, it seems like self-hosting or at least managed custody of your own gear is going to become more of a thing.

Is the idea that self hosters tend to make less security mistakes than the big hosting companies?

Self hosters can come from a background of hosting.

Self hosting is extremely more streamlined and secure than it was 5,10,20 years ago.

Because it’s the same gear.

Post reply on HN