Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

881–890 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#881

Earlier quoted context omitted.

I do. The good ones use AI.

You are in a bubble. Some segments use essentially no AI, while others have gone all in. Just because the type of engineers you're surrounded by do engineering that is obsolete doesn't mean that's the case across the board. All the best game engineers I know still write at least 90% of the code (probably closer to 99%). The bad ones use AI nearly exclusively - just like yourself. They can't create very complex or per…

> They simply can't build super complex, performant, or novel systems.

Neither can single humans.

If you introduce some reasonable constraints AI will come out ahead most of the time, especially for optimization cases where AI will run circles around your average programmer and is perfectly happy to inline some ASM for you.

You still have bespoke cordwainers/cobblers 100 years after that process has been well and truly automated. But they're rare and almost nobody cares.

Re: Project Glasswing: Securing critical software for the AI era

#882

Earlier quoted context omitted.

You are in a bubble. Some segments use essentially no AI, while others have gone all in. Just because the type of engineers you're surrounded by do engineering that is obsolete doesn't mean that's the case across the board. All the best game engineers I know still write at least 90% of the code (probably closer to 99%). The bad ones use AI nearly exclusively - just like yourself. They can't create very complex or per…

> They simply can't build super complex, performant, or novel systems. Neither can single humans. If you introduce some reasonable constraints AI will come out ahead most of the time, especially for optimization cases where AI will run circles around your average programmer and is perfectly happy to inline some ASM for you. You still have bespoke cordwainers/cobblers 100 years after that process has been well and tru…

Inking ASM isn't generally a good thing. This line of commenting reeks of confidently incorrect energy.

Re: Project Glasswing: Securing critical software for the AI era

#883
post #882

Earlier quoted context omitted.

> They simply can't build super complex, performant, or novel systems. Neither can single humans. If you introduce some reasonable constraints AI will come out ahead most of the time, especially for optimization cases where AI will run circles around your average programmer and is perfectly happy to inline some ASM for you. You still have bespoke cordwainers/cobblers 100 years after that process has been well and tru…

Inking ASM isn't generally a good thing. This line of commenting reeks of confidently incorrect energy.

Inlining*

Re: Project Glasswing: Securing critical software for the AI era

#884
post #820

Earlier quoted context omitted.

The product they launched?

This product is explicitly not being released for usage

The product is being provided to some of the most influential companies. That can definitely serve to Anthropic's advantage. (Regardless, I suspect the hype is real.)

Re: Project Glasswing: Securing critical software for the AI era

#885

Earlier quoted context omitted.

Even more 'disquieting' when you take into account who's currently the president of US. "A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump

The art of the deal, baby

These people are willfully ignorant to ignore what was obviously going on here, that it was a negotiating tactic.

Re: Project Glasswing: Securing critical software for the AI era

#886

Earlier quoted context omitted.

A 0 day is just a vulnerability that wasn’t known before now. What’s the criticality of these? Are they realistically exploitable? En mass? Through a complex and highly contextual set of actions? What’s the impact? Etc etc etc. Yes those numbers are a big change but they’re also not spelling doom for us in the security world until we actually know what they mean. The demonstrated ones that they have on the red team b…

> The demonstrated ones that they have on the red team blog are neat, the kernel chain is impressive and fun So by your estimation, for rogue actors being able to uncover hundreds of this class in each major software product roughly for free would not be a big issue?

We must have read two different red team blogs from Anthropic if that’s what you think is happening. But let’s go ahead and assume what you’re asking at face value.

It would not be a doomsday issue as implied, no. Org security has gone far beyond static detections and “just exclude some IPs that fail to log in too much and we’re good”. SOAR exists. Behavioral analysis and monitoring exists. Layered defenses exist.

Believe it or not for those of us in security in large highly targeted companies we’ve been dealing with the potential for multiple chained 0 days for years and the processes, monitoring, and (yes, automated) response architecture is already there.

I get that this is absolutely frightening for some and that causes panic but for us this is Tuesday.

Re: Project Glasswing: Securing critical software for the AI era

#888

Another Anthropic PR release based on Anthropic’s own research, uncorroborated by any outside source, where the underlying, unquestioned fact is that their model can do something incredible. > AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities I like Anthropic, but these are becoming increasingly transparent att…

I have yet to see any real world difference between sonnet 4.5 and opus 4.6. All I can tell is the version number went up for both series.

I don't know if they are a even an improvement over previous models. I never used them.

Re: Project Glasswing: Securing critical software for the AI era

#889

Earlier quoted context omitted.

wasn’t there a news story about the app store reviews being delayed because of an increase in app influx?

that doesnt tell us much about the subjective quality of the apps in said influx

And thus the goalpost was shifted. The first question was "where are all the AI coded apps?" And once this was answered, the subject is immediately switched to quality.

Re: Project Glasswing: Securing critical software for the AI era

#890

Earlier quoted context omitted.

I find it very unlikely that Mythos will "be nothing special". Current Opus is already "special" enough to find dozens of real bugs in Firefox and the Linux kernel, and Mythos is, it seems, a full OOM above it.

What I mean by "nothing special" is 1 year from now you will say it is an extremely limited model compared to whatever is out then

But then in the second portion of your comment you seem to be implying that it's all hype and nothing to worry about.

Just because something more powerful will be out in a year, doesn't mean we shouldn't worry about the one arriving in 6 months.

Post reply on HN