Earlier quoted context omitted.
its very possible that this is Anthropic marketing puffery It isn't.
Two possibilities: 1) You have access to the model, and so are as incentivized as the rest of this unscrupulous bunch to puff it up; while also sharing in the belief that malignantly narcissistic sociopaths are the only ones who can be trusted with it. 2) You lack access to the model, and are just doing more PR puffery.
Project Glasswing: Securing critical software for the AI era
871–880 of 921 posts
Re: Project Glasswing: Securing critical software for the AI era
#872Earlier quoted context omitted.
I wouldn't paint the image in such black terms. LLMs can be good in finding bugs and potential issues. And if you like, they can be like IntelliSense on steroids. Even agentic workflows can be good, e.g. for an initial assessment of a new large codebase. And potentially millions of other small tasks like writing one-off helper scripts etc.
So which apps are seeing 10x the bug fixes and improvements in stability and quality? From my side, I see one shot CRUD apps, platforms like AWS and windows actively deteriorating, to the point of causing massive outages and needing to have development processes changed [0]. Who is actually shipping 10x more stuff, or fixing 10x more bugs? [0] https://arstechnica.com/ai/2026/03/after-outages-amazon-to-m...
Re: Project Glasswing: Securing critical software for the AI era
#873Earlier quoted context omitted.
> how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. It's much the dynamic between parents and a child. The child, with limited hindsight, almost zero insight and no ability to forecast, is annoyed by their parents. Nothing bad ever happens! Why won't parents stop being so worried all the time and make a fuss over nothing? The parents, which the child somewhat star…
I feel like you’re muddying 2 different arguments here. Or rather, 2 different positions. You’re asserting that people who are tired of this line being wheeled out hold a position analogous to “what’s the big deal, nothing bad happens, just relax”. In reality, that’s only 1 position. The other position is “I understand fully, the consequences, but the relentless doomer language is tiring in the face of continuing-to-…
Re: Project Glasswing: Securing critical software for the AI era
#874I’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.
To me it makes absolutely zero sense that they would decide to not release the model to the public because of the effects that it would have due to its exploitation capabilities. Previous models were also capable of providing harmful information, yet that wasn't a problem, because models can actually be effectively censored using RHLF. So what is preventing Anthropic to simply forbid the model from letting people vib…
Re: Project Glasswing: Securing critical software for the AI era
#875Earlier quoted context omitted.
Thanks, I find it very interesting as well. I think very many people would assume they must be interacting with another person, and I don't think there's really a way to _prove_ it's not that, just through conversation. But we do have a lot of mechanisms for understanding how others think through conversation only, and so I think the approach of having a clinical psychiatrist interact with the model make sense.
There’s definitely a way to prove it, ask it to spell out a moderately complex program.
Re: Project Glasswing: Securing critical software for the AI era
#876Earlier quoted context omitted.
That's what I'm saying; a static analyser will be able to determine whether the code and/or state is reachable without any AI, and it will be completely deterministic in its output.
You cannot tell if code is actually reachable if it depends on runtime input. Those really evil bugs are the ones that exist in code paths that only trigger 0.001% of the time. Often, the code path is not triggerable at all with regular input. But with malicious input, it is, so you can only find it through fuzzing or human analysis.
That is precisely what a static analyser can determine. E.g. if you are reading a 4-byte length from a file, and using that to allocate memory which involves adding that length to some other constant, it will assume (unless told otherwise) that the length can be all 4G values and complain about the range of values which will overflow.
Re: Project Glasswing: Securing critical software for the AI era
#877Earlier quoted context omitted.
That's what I'm saying; a static analyser will be able to determine whether the code and/or state is reachable without any AI, and it will be completely deterministic in its output.
Why hasn't it then? The Linux kernel must be asking the most heavily-audited pieces of software in existence, and yet these bugs were still there.
Re: Project Glasswing: Securing critical software for the AI era
#878Earlier quoted context omitted.
Can you explain why they are meaningless without more context?
A 0 day is just a vulnerability that wasn’t known before now. What’s the criticality of these? Are they realistically exploitable? En mass? Through a complex and highly contextual set of actions? What’s the impact? Etc etc etc. Yes those numbers are a big change but they’re also not spelling doom for us in the security world until we actually know what they mean. The demonstrated ones that they have on the red team b…
So by your estimation, for rogue actors being able to uncover hundreds of this class in each major software product roughly for free would not be a big issue?
Re: Project Glasswing: Securing critical software for the AI era
#879I used Opus 4.6 to find security vulnerabilities in couple of my own projects, it found 33 vulnerabilities in one largeish django project.
The prompt wasn't even that impressive, just telling it to find vulnerabilities from certain files, and referring to OWASP. Then looping that.
Re: Project Glasswing: Securing critical software for the AI era
#880Earlier quoted context omitted.
Well of course in 700 pages you'll be about way more than any super short story as this one. But it's there for me quite vividly. Of course LLMs give an amalgamation of many things, but it's like when you look at AI generated pictures and can see the base of the inspiration quite vividly. And then all of this is subjective anyway. People review that book and come away with wildly different interpretations already.
I don't mean that Rand wrote more. I mean that her idea was different and nearly opposite. This is a short story about an artist learning to reframe their frustration with customers wanting utility over artistry as a positive. The similarity to Rand is in the first few sentences. The point is entirely different. If you judge stories to be the same based on this level of similarity, then The Fountainhead is just the s…