Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

751–760 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#751
post #690

Earlier quoted context omitted.

Check out from this onwards and the following point. You get a nice summary on top right. Mind that Anthropic alone is doing 30B/y annualized already. Take a snapshot and check again in a few months. It's not perfect but it's much more falsifiable than a lot of the noise. https://ai-2027.com/#narrative-2026-04-30

> Mind that Anthropic alone is doing 30B/Y annualised already How many crypto exchanges were pulling in hundreds of millions in funding and doing billions in trades in 2021/2022? That blog post is… really something, I’ll give you that. Im not entirely sure what else to say about it other than that.

Trade volume and buying API credits are very dissimilar ways of measuring value. One can be wash traded into oblivion, the other is burning a hole in corporate accounts.

Re: Project Glasswing: Securing critical software for the AI era

#752

Earlier quoted context omitted.

Maybe Americans should take responsibility for electing a maniac as their President. In the end, the buck stops with Americans.

~1/3rd of US citizens voted for him. Don’t lump us all in.

Good. But the parent was blaming Trump on disinformation propaganda, and it is important to point out that the remaining 1/3-rd of the country is not some kind of idiot army that replaced their brains with FB propaganda. They voted for this actively.

Also, in a democracy you don't get to disavow 1/3rd of the population that didn't vote with you.

Re: Project Glasswing: Securing critical software for the AI era

#753

There is a huge gap between the shining examples and actual use case: What is the false positive rate? How to judge false positive? If you need 1000 run that cost 20000 USD to find a vulnerability, and you need 2000 USD to generate a exploit (which makes it self-verifiable to be not false positive), than your cost is not 22000 USD but 1000x2000+2000 which is 2 million USD: you have to try generating exploit for every…

My impression from the article is that it took $20,000 to perform all 1,000 runs.

yet the poc exploit itself take $2000 and one day, I don't know how the math works, maybe there is some extremely clever way to figure out runs that are not worthy to attempt exploit.

Re: Project Glasswing: Securing critical software for the AI era

#754

I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.

To me it makes absolutely zero sense that they would decide to not release the model to the public because of the effects that it would have due to its exploitation capabilities. Previous models were also capable of providing harmful information, yet that wasn't a problem, because models can actually be effectively censored using RHLF. So what is preventing Anthropic to simply forbid the model from letting people vibe-code exploits???

Re: Project Glasswing: Securing critical software for the AI era

#755
post #318

Earlier quoted context omitted.

Every piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org

Once you get the compartmentalization working well, and “all” of the vulnerabilities are out of it too, of course… But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.

> and “all” of the vulnerabilities are out of it too

This is a good point; however the isolating code should be much smaller and easier to verify.

Re: Project Glasswing: Securing critical software for the AI era

#756

Earlier quoted context omitted.

I wouldn't paint the image in such black terms. LLMs can be good in finding bugs and potential issues. And if you like, they can be like IntelliSense on steroids. Even agentic workflows can be good, e.g. for an initial assessment of a new large codebase. And potentially millions of other small tasks like writing one-off helper scripts etc.

So which apps are seeing 10x the bug fixes and improvements in stability and quality? From my side, I see one shot CRUD apps, platforms like AWS and windows actively deteriorating, to the point of causing massive outages and needing to have development processes changed [0]. Who is actually shipping 10x more stuff, or fixing 10x more bugs? [0] https://arstechnica.com/ai/2026/03/after-outages-amazon-to-m...

It actually seems like people are shipping 10x more bugs, not fixing 10x more bugs.

Re: Project Glasswing: Securing critical software for the AI era

#757

So Mozilla is not part of this consortium, i'm guessing for deliberate reasons to make safari and chrome the default browsers. I don't think Firefox can survive the upcoming attacks, without robust support from foundational AI providers to secure the browser.

Anthropic works with Mozilla already. https://www.anthropic.com/news/mozilla-firefox-security

Re: Project Glasswing: Securing critical software for the AI era

#758

Earlier quoted context omitted.

~1/3rd of US citizens voted for him. Don’t lump us all in.

Good. But the parent was blaming Trump on disinformation propaganda, and it is important to point out that the remaining 1/3-rd of the country is not some kind of idiot army that replaced their brains with FB propaganda. They voted for this actively. Also, in a democracy you don't get to disavow 1/3rd of the population that didn't vote with you.

Clearly you do, since Donald Trump has been aggressively doing this for his whole political career. I agree that it's a morally problematic thing to do, and it can be bad tactically depending on the situation. Practically, it does happen without consequences.

Re: Project Glasswing: Securing critical software for the AI era

#759

Earlier quoted context omitted.

~1/3rd of US citizens voted for him. Don’t lump us all in.

Good. But the parent was blaming Trump on disinformation propaganda, and it is important to point out that the remaining 1/3-rd of the country is not some kind of idiot army that replaced their brains with FB propaganda. They voted for this actively. Also, in a democracy you don't get to disavow 1/3rd of the population that didn't vote with you.

2/3rd’s* that didn’t vote with you.

Re: Project Glasswing: Securing critical software for the AI era

#760

Earlier quoted context omitted.

Are they actually too dangerous to publicly release? It seems like a little bit of marketing from the model-producing companies to raise more funding. It's important to look at who specifically is making that statement and what their incentives are. There are hundreds of billions of dollars poured into this thing at this point.

You really think some marketers got leaders from companies across the industry to come together to make a video - and they're all in on the conspiracy because money?

Yes? Saying "conspiracy" is overstating things. A company can make a marketing push overselling their product and then have exclusive corporate partners that benefit from being associated with that marketing. That just seems like normal business that happens every day, and being skeptical of marketing messages should be your default position.
Post reply on HN