Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

761–770 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#761
This has all happened before, back in the day we has spinners and weavers, then we got the spinning Jenny(Engine) and this made thread so cheap we needed to speed up weaving = machine weavers(AKA automatic looms) and we had people who hated them.https://en.wikipedia.org/wiki/Luddite We all know how that ended up. We have an analogous hand task = coding versus coding machines. They will probably eliminate 80-95% of coding, as the spinners/weavers went away, but there remains a residual artisanal spinner/weaver industry that carries on at a lower pace. In a similar way this machine code will have the coupled ability to make some code and then test it in use with it's own AI in a repeated/recursive way to make/test/improve code at a rate 10,000 to 1 million times faster than a human. Each module can then be tested in millions of interactively monitired ways to find/fix/kill bad modules. It can also pentest in a similar manner, assaulting a system with a blizzard of attack/reset hits to find any bugs etc. Each assault that works might use a human or AI to trouble shoot. This is like the old armored night, once he was unhorsed the peasants would have at him with needles at his his joints/eyes unless his fellows save him = gone. So this might well reduce low end jobs, but they will still need high end coders to eliminate all flaws in the armor of your code. I might be simplistic, but I see a parallel in sub 5 nm chip design where the design machines have eliminated almost all of the old hand work.

Re: Project Glasswing: Securing critical software for the AI era

#762

Earlier quoted context omitted.

Or maybe it's that our archaic system was designed so that some people's votes literally matter more than others, and more than half the country does not have a meaningful voice in our Federal elections.

This is negligence with extra steps. > more than half the country does not have a meaningful voice in our Federal elections There is almost certainly an election on your ballot every time that is meaningful. Relinquishing that civic duty is how we get Trump. People to lazy, stupid or proud to vote absolutely bear responsibility for this mess.

I agree to an extent but I have a hard time blaming many in the LGBT community/supporters of Palestine for sitting out when Harris and co so thoroughly abandoned them in the general. They stood behind Biden in 2020 then watched as the democrats gave in on trans rights and did nothing to stop Israel’s campaign. Now they’re watching Newsome and folks gleefully accept trans erasure going into the mid terms/next election, so they’ve been validated in many ways.

Is it tactically sound? No. Is it what I did? No. But I’ve had enough conversations with folks that I get where they’re coming from, even if I thought it was the wrong decision.

Re: Project Glasswing: Securing critical software for the AI era

#765

Earlier quoted context omitted.

Just a thought: The fact that the found kernel vulnerability went decades without a fix says nothing about the sophistication needed to find it. Just that nobody was looking. So it says nothing about the model’s capability. That LLMs can find vulnerabilities is a given and expected, considering they are trained on code. What worries me is the public buying the idea that it could in any way be a comprehensive security…

Regardless of how impressive you find the vulnerabilities themselves, the fact that the model is able make exploits without human guidance will enable vastly more people to create them. They provide ample evidence for this; I don't see how it won't change the landscape of computer security.

Yeah the marginal cost of discovery going towards 0 (I mean, not there yet, but directionally) is the problem; it doesn't really matter if the agent isn't equivalent to a human artistic hand-crafted bug discovery if it can make it up on volume. Mass production of exploits!

Re: Project Glasswing: Securing critical software for the AI era

#767
It feels like the current trend is a bit scary: the more AI advances, the more people with money and resources will gain disproportionately greater advantages. For example, they can make their own software more secure, while also finding it easier to discover ways to attack other software.

Re: Project Glasswing: Securing critical software for the AI era

#768

It's all just really genius marketing. In 6 months Mythos will be nothing special, but right now everyone is being manipulated into fearing its release, as a marketing ploy. This is the same reason AI founders perennially worry in public that they have created AGI...

[dead]

Re: Project Glasswing: Securing critical software for the AI era

#769
post #230

Earlier quoted context omitted.

> Large American AI company does not list the US as an adversarial actor This is not a surprise or a gotcha.

Said company is literally in court against said government at the moment, after said government attempted to designate it too dangerous to do business with.

AFAIK Apple also "denied FBI to decrypt iPhone" while participating in PRISM

Re: Project Glasswing: Securing critical software for the AI era

#770

This is the same company that accidentally released the source for one of their flagship products last week and has been furiously DMCA-ing every repository that even mentions claude in the days since.

This is also the same company who uses electron for their tooling rather than platform specific binaries generated by Opus! If their LLMs are that good why do they need to use electron?

[dead]
Post reply on HN