Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

841–850 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#841

Earlier quoted context omitted.

which statement, specifically, led you to interpret this claim?

> Over the past few weeks, we have used Claude Mythos Preview to identify thousands of zero-day vulnerabilities (that is, flaws that were previously unknown to the software’s developers), many of them critical, in every major operating system and every major web browser, along with a range of other important pieces of software. They don’t explicitly rule out, I suppose, that these were only limited partial scans they…

i was trying to map "vulnerability scan all important software repos in the world" to an actual quote on their writing, but "every major operating system and every major web browser, along with a range of other important pieces of software" is not the same.

Re: Project Glasswing: Securing critical software for the AI era

#842

Few thoughts 1. Per the blog post[0]: "This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings" Since they said it was patched, I tried to find the CVE, it looks like Mythos indeed found a 27 years old OpenBSD bug (fantastic), but…

Now we have to wonder if they ran Mythos on their Calude source and it missed it or why they chose not to run it.

I do agree and wonder why that's not marked as security. In their security page [0] it says: > Since exploitability is not proven for many of the fixes we make, do not expect the relevant commit message to say "SECURITY FIX!".

Does that mean they considered it not to be exploitable?

[0] https://www.openbsd.org/security.html

Re: Project Glasswing: Securing critical software for the AI era

#844
post #836

Previously Anthropic subscribers got access to the latest AI but it seems like there’s a League of Software forming who have special privileges. To make or maintain critical software will you have to be inside the circle? Who gates access to the circle? Anthropic or existing circle members or some other governance? If you are outside the circle will you be certain to die from software diseases? Having been impressed…

It's only a moat if you believe no competing lab will achieve similar or better results in a large enough time frame to profit from it.

Thats not what a moat means in business. It doesn’t mean impregnable, it just means expensive or difficult to cross.

It is absolutely a moat if only $1T companies can afford the capex to compete.

Re: Project Glasswing: Securing critical software for the AI era

#845

Earlier quoted context omitted.

> Over the past few weeks, we have used Claude Mythos Preview to identify thousands of zero-day vulnerabilities (that is, flaws that were previously unknown to the software’s developers), many of them critical, in every major operating system and every major web browser, along with a range of other important pieces of software. They don’t explicitly rule out, I suppose, that these were only limited partial scans they…

i was trying to map "vulnerability scan all important software repos in the world" to an actual quote on their writing, but "every major operating system and every major web browser, along with a range of other important pieces of software" is not the same.

Important to understand it's not one-and-done; you can't "Mythos" Chrome and then put a checkmark next to it. It's a continuous process.

Re: Project Glasswing: Securing critical software for the AI era

#846

Earlier quoted context omitted.

The transition is pretty complete at e.g. Google and Meta, IIUC. Definitely whoever builds the AI tools you're using every day isn't writing code by hand.

I'm literally looking at Claude in the other window telling me that the bug we're working on is a "Clear-cut case", telling me to remove a "raise if this is called on this object" guard from a method, because "the data is frozen at that point" and is effectively proposing a solution that both completely misses the point (we should be calling a different method that's safe) AND potentially mutates the frozen data. We'…

No, that matches my experience pretty well. Yesterday Claude implemented some functionality I asked for in entirely the wrong component, and then did it again after I clarified. If I'd been coding on my own, the clock time to a complete solution would probably have been lower - but then I would have had to be coding, instead of reviewing other people's PRs.

A careful observer would note from when I'm posting this, of course, that this is perhaps not the only thing I get up to while Claude is busy. But I really do review PRs in a much more timely manner now. (There's people who insist that there's no need to review Claude-generated code, and to be frank I think they're the same people who used to insist that their 2000 line PRs should be reviewed and merged within a day.)

Re: Project Glasswing: Securing critical software for the AI era

#847
post #842

Few thoughts 1. Per the blog post[0]: "This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings" Since they said it was patched, I tried to find the CVE, it looks like Mythos indeed found a 27 years old OpenBSD bug (fantastic), but…

Now we have to wonder if they ran Mythos on their Calude source and it missed it or why they chose not to run it. I do agree and wonder why that's not marked as security. In their security page [0] it says: > Since exploitability is not proven for many of the fixes we make, do not expect the relevant commit message to say "SECURITY FIX!". Does that mean they considered it not to be exploitable? [0] https://www.openbs…

I really don't know, all I know is that usually when you find a critical vulnerability, and it's patched, it comes with a CVE, even a low one, that's the process for the past 27 years when the CVE program started (as old as the vulnerability itself it seems..) but maybe with AI-native, CVEs don't matter because everyone will just rewrite their clean room open source alternative (I wish this was a joke...)

Re: Project Glasswing: Securing critical software for the AI era

#848

Earlier quoted context omitted.

Is Anthropic lying about model capabilities? If not, where is the overselling?

March 2025, Anthropic was claiming that 90% of code would be written by LLMs in three to six months, and "essentially all" code within twelve months. This was one week after closing a Series E round for $3.5 billion. When they began working on their Series F round for $13 billion. You shouldn't need more than that to understand what's going on here. The Claude Code leak revealed that Anthropic runs Claude-operated bo…

You're talking about marketing predictions and I'm talking about data presented in a whitepaper. They are not the same thing.

Re: Project Glasswing: Securing critical software for the AI era

#849

Earlier quoted context omitted.

i was trying to map "vulnerability scan all important software repos in the world" to an actual quote on their writing, but "every major operating system and every major web browser, along with a range of other important pieces of software" is not the same.

Important to understand it's not one-and-done; you can't "Mythos" Chrome and then put a checkmark next to it. It's a continuous process.

Can't you? My understanding is that that's exactly how security scans usually work - you run an analysis, find all the vulnerabilities, and then the continuous process is only there to check against the introduction of new vulnerabilities. Is that not the right mental model?

Re: Project Glasswing: Securing critical software for the AI era

#850

Earlier quoted context omitted.

Did a LLM tell you that?

common sense and interviewing around did. no one wants to hire someone that is not AI native anymore, unless you are looking at positions that pay peanuts

I guess if you get fed the same thing over and over it becomes the truth. This is what happens when you outsource critical thinking to AI
Post reply on HN