Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

711–720 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#711
post #690

Earlier quoted context omitted.

Disagree - we’re being told on one hand that we are 6 months away from AI writing all Code, and 3 months into that the tools are unusable for complex engineering [1]. Every time I mention this I’m told “but have you tried the latest model and this particular tool” - yes I have, but if I need to be on the hottest new model for it to be functional that means the last time you claimed it was solved, it wasn’t solved. [0…

Check out from this onwards and the following point. You get a nice summary on top right. Mind that Anthropic alone is doing 30B/y annualized already. Take a snapshot and check again in a few months. It's not perfect but it's much more falsifiable than a lot of the noise. https://ai-2027.com/#narrative-2026-04-30

> Mind that Anthropic alone is doing 30B/Y annualised already

How many crypto exchanges were pulling in hundreds of millions in funding and doing billions in trades in 2021/2022?

That blog post is… really something, I’ll give you that. Im not entirely sure what else to say about it other than that.

Re: Project Glasswing: Securing critical software for the AI era

#712

Earlier quoted context omitted.

Disagree - we’re being told on one hand that we are 6 months away from AI writing all Code, and 3 months into that the tools are unusable for complex engineering [1]. Every time I mention this I’m told “but have you tried the latest model and this particular tool” - yes I have, but if I need to be on the hottest new model for it to be functional that means the last time you claimed it was solved, it wasn’t solved. [0…

> Every time I mention this I feel like there’s a bunch of factors for why it will never be the same for many folks, from the models and harnesses, to the domains and existing tests/tooling. I feel bad for the people for whom it doesn’t work, but Claude Opus has written most of my code in 2026 so far. I had to build some tools around linting entire projects and most of my tokens are probably referencing existing stuf…

> I feel like there’s a bunch of factors for why it will never be the same for many folks

Yeah, and the problem arises simply because some people are unable to accept the fact. They insist that if LLM-assisted coding doesn't work for one, it's because “you're holding it wrong”.

Re: Project Glasswing: Securing critical software for the AI era

#713
post #666

Earlier quoted context omitted.

Yeah but who pays the enormous cost?

obviously the people responsible for the software. Would you rather anthropic kept the vulns quiet?

Off course not, but there is infinitely more vulnerable software escaping Anthropic's scrutiny. And when AI-powered discovery becomes a necessity, that will lead to concentration of power to these kinds of companies.

Bruce Scheier made a comprehensive analysis of the pros and cons and forces at play for adversary and defenders [1].

I think it's safe to predict yet more money previously directed to us techies will find its way to the Anthropics of this world.

[1] https://www.schneier.com/blog/archives/2026/04/cybersecurity...

Re: Project Glasswing: Securing critical software for the AI era

#714

From a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infras…

Anthropic stood up to the Pentagon because they were worried of potential abuse of their model. Never before a US company was labeled supply chain risk by the US government. That's a lot of business. Action speaks louder than words.

As for what your country can do, it's up to you to decide, isn't it? Instead of complaining about the US, think about the alternatives. Do you trust China to be your partner? Suppose you are being objective and say no, then what do your country need to do?

You have to decide whether AI capability is critical that your country must own. What factors prevent it from happening in the first place, what need to change and whether you accept changes that may come as the results.

On the other hand, if you say that AI is just a bubble, that the huge investment pouring into it is just greed and fraud, then I suppose you are ok with the status quo.

Re: Project Glasswing: Securing critical software for the AI era

#715
post #550

Earlier quoted context omitted.

Neither party provided the evidence. I wonder why people like to take the side of the optimistic.

We already know Opus can find real vulnerabilities ([1], [2], ...), so it's not exactly surprising that a bigger model is better at it. [1] https://news.ycombinator.com/item?id=47273854 [2] https://news.ycombinator.com/item?id=47611921

That is not thousands high-severity vulnerabilities as above commenter stated. Even many local models have found individual vulnerabilities.

Re: Project Glasswing: Securing critical software for the AI era

#716
Previously Anthropic subscribers got access to the latest AI but it seems like there’s a League of Software forming who have special privileges. To make or maintain critical software will you have to be inside the circle?

Who gates access to the circle? Anthropic or existing circle members or some other governance? If you are outside the circle will you be certain to die from software diseases?

Having been impressed by LLMs but not believing the AGI hype, I now see how having access to an information generator could be so powerful. With the right information you can hack other information systems. Without access to the best information you may not be able to protect your own system.

I think we have found the moat for AI. The question is are you inside or outside the castle walls?

Re: Project Glasswing: Securing critical software for the AI era

#717

Earlier quoted context omitted.

Disagree - we’re being told on one hand that we are 6 months away from AI writing all Code, and 3 months into that the tools are unusable for complex engineering [1]. Every time I mention this I’m told “but have you tried the latest model and this particular tool” - yes I have, but if I need to be on the hottest new model for it to be functional that means the last time you claimed it was solved, it wasn’t solved. [0…

> Every time I mention this I feel like there’s a bunch of factors for why it will never be the same for many folks, from the models and harnesses, to the domains and existing tests/tooling. I feel bad for the people for whom it doesn’t work, but Claude Opus has written most of my code in 2026 so far. I had to build some tools around linting entire projects and most of my tokens are probably referencing existing stuf…

> I had to build some tools around linting entire projects

OK, everybody is doing that. And everybody is doing their best at making LLMs more reliable when working on non-trivial tasks. Yet, it looks like nobody came up with a universal solution yet. This is particularly true for non-trivial projects.

Re: Project Glasswing: Securing critical software for the AI era

#718

I think this is a largely inflated PR stunt. Opus 4.6 was already capable of finding 0days and chaining together vulns to create exploits. See [0] and [1]. [0] https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-... [1] https://xbow.com/blog/top-1-how-xbow-did-it

I don't see why you think this evidence makes this release less likely to be real, rather than more. It's a pretty straightforward scenario: Opus is already good at finding vulns, they scaled it up another OOM, they got something which is good enough at finding vulns to be a major threat.

I think you misunderstood, I do think it's real. I just think they're being disingenuous that this is a new threat. This is the same company that reported that their models were being used by a state actor to perform exploits in real-time - https://www.anthropic.com/news/disrupting-AI-espionage

They know how to run a good marketing campaign.

Re: Project Glasswing: Securing critical software for the AI era

#719
The harder problem isn't finding vulnerabilities — it's preventing AI from violating constraints in the first place. Prompt-level safety is probabilistic. Filesystem-level constraints (mkdir 禁/behavior) are deterministic. The AI can't violate a rule that's physically encoded as a folder path in its system prompt.

Re: Project Glasswing: Securing critical software for the AI era

#720

Earlier quoted context omitted.

> Every time I mention this I feel like there’s a bunch of factors for why it will never be the same for many folks, from the models and harnesses, to the domains and existing tests/tooling. I feel bad for the people for whom it doesn’t work, but Claude Opus has written most of my code in 2026 so far. I had to build some tools around linting entire projects and most of my tokens are probably referencing existing stuf…

> I feel like there’s a bunch of factors for why it will never be the same for many folks, from the models and harnesses, to the domains and existing tests/tooling. If the argument is “you have to use the right model, harness, test and tooling for it to work” then it’s not replacing software engineers any time soon. The other thing is - where are all the web apps, mobile apps, games, desktop apps, from these 100x pro…

I wouldn't paint the image in such black terms. LLMs can be good in finding bugs and potential issues. And if you like, they can be like IntelliSense on steroids. Even agentic workflows can be good, e.g. for an initial assessment of a new large codebase. And potentially millions of other small tasks like writing one-off helper scripts etc.
Post reply on HN