Live data from Hacker News

First public macOS kernel memory corruption exploit on Apple M5

blog.calif.io

91–100 of 140 posts

Re: First public macOS kernel memory corruption exploit on Apple M5

#91
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

> I thought Mythos was just a bunch of hype?

My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations.

Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit card .... he's an experienced security researcher.

Random inexperienced people thinking Mythos can replace the need for experienced pen-testers, auditors etc. are likely to be sorely disappointed if/when they get their hands on Mythos.

Re: First public macOS kernel memory corruption exploit on Apple M5

#92

Earlier quoted context omitted.

There's so much much lower hanging fruit. Every job I've had has had basically everything massively out of date. Just keeping packages and framework versions up to date is a full time job and none of these companies have someone assigned to doing it. So much out of date software with known exploits left running for years. The only reason there hasn't been total disaster is no one has tried to hack it yet.

Right and with AI now we have the ability to try hacking everything all at once.

Yes, exactly, that’s the main change. And not just in a script kiddy way. What we see now is LLM + experts can develop extremely complex exploit chains in no time. It’s one thing to exploit a known vulnerability that you can patch by upgrading your Wordpress, it’s something else when the attacker is able to completely take over your systems in ways you didn’t even consider was possible and adapt in 1 day to your attempts at patching

Re: First public macOS kernel memory corruption exploit on Apple M5

#93
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

> likely to be sorely disappointed if/when they get their hands on Mythos.

At first they will be delighted. So much money and time saved. When their adversaries get their hands on their system (with or without Mythos), then they'll be sorely disappointed.

Re: First public macOS kernel memory corruption exploit on Apple M5

#94
post #80
post #74

Earlier quoted context omitted.

I suppose that if you don’t believe that models will be good enough to work completely without senior engineer help, positioning yourself as a master prompter is a good move to improve your chances of not getting fired.

Even so, it literally means as business owner I need less warm bodies to write prompts. Will we now have leetcode of prompt writing?

Dune guild navigator AI whisperer? with fine taste.

Re: First public macOS kernel memory corruption exploit on Apple M5

#96
post #43
post #25

Earlier quoted context omitted.

Most companies in the world do not have “blue teams”. They barely have any kind of security employee.

That is actually unfair. Most companys spend enormous amounts on security with vast armys of security employees. Not that it is effective, but it is not for lack of resources or trying. I mean we are literally in a thread about how the 4 trillion dollar company, literally the 3rd most valuable company in the world, with a core competency in software has, yet again, released a core product riddled with security defect…

For every Apple, there are 100 mom-and-pop companies who have nothing.

Even more so in the future when a software company can be launched by a farm of AI Agents with a founder at helm with no clue about computing or security.

What's debateable is how many of those companies actually need irontight security, because they are never realistically going to be targets of criminals and/or they have nothing valuable to steal/corrupt in the first place (other than the owner's pride).

Re: First public macOS kernel memory corruption exploit on Apple M5

#97
post #83

So like ... I thought Mythos was just a bunch of hype? Or maybe the researchers are having their skills boosted due to using a model with such a cool name? I jest, but I did notice having more confidence to take on more ambitious work lately. We're all centaurs now.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

I think it's worth to look at the recent XBOW benchmark: https://xbow.com/blog/mythos-offensive-security-xbow-evaluat... they realized that ChatGPT 5.5 works better so the secret is in the architecture (including humans in the loop).

Re: First public macOS kernel memory corruption exploit on Apple M5

#98
post #97

Earlier quoted context omitted.

> I thought Mythos was just a bunch of hype? My opinion is that it is over-hyped because like any LLM, it requires a suitable human in the loop to keep the LLM on the straight and narrow, and then to weed through the inevitable false-positives and hallucinations. Nicholas Carlini, for example, whose name is on many of the recent high-profile Mythos findings is not just some random dude with a Claude sub on his credit…

I think it's worth to look at the recent XBOW benchmark: https://xbow.com/blog/mythos-offensive-security-xbow-evaluat... they realized that ChatGPT 5.5 works better so the secret is in the architecture (including humans in the loop).

'frontier tokens are not fungible'

Re: First public macOS kernel memory corruption exploit on Apple M5

#100
post #92

Earlier quoted context omitted.

Right and with AI now we have the ability to try hacking everything all at once.

Yes, exactly, that’s the main change. And not just in a script kiddy way. What we see now is LLM + experts can develop extremely complex exploit chains in no time. It’s one thing to exploit a known vulnerability that you can patch by upgrading your Wordpress, it’s something else when the attacker is able to completely take over your systems in ways you didn’t even consider was possible and adapt in 1 day to your atte…

For now, after the dust settles all of the low hanging fruit will have been patched and we will have hurried up the move to safer languages.

The root problem is the world runs on C code that is riddled with vulnerabilities.

Post reply on HN