Live data from Hacker News

Project Glasswing: Securing critical software for the AI era

anthropic.com

911–920 of 921 posts

Re: Project Glasswing: Securing critical software for the AI era

#911

The system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that th…

Oh I enjoyed the Sign Painter short story it wrote. --- Teodor painted signs for forty years in the same shop on Vell Street, and for thirty-nine of them he was angry about it. Not at the work. He loved the work — the long pull of a brush loaded just right, the way a good black sat on primed board like it had always been there. What made him angry was the customers. They had no eye. A man would come in wanting COFFEE…

This story moved me so much.

It's like how I used to be a master codes craftsman, and I'd write beautiful code even a novice could understand. Clear, concise, 100% automated tested, maintainable for decades.

But frequently, my managers would castigate me. Tell me how my "velocity" was down. PIP me.

These days, I train AI how to write this beautiful code and I don't write a single line any more.

People wonder how I build such amazing things in a week now, yet don't write any code. I have trained master apprentices, gemma3, qwen3.5 and Kimi k2.5 who do the work for me.

Re: Project Glasswing: Securing critical software for the AI era

#912
I'm starting to wonder whether what Glasswing really shows is that parts of security have already gone underground: black-hat teams and state actors may already know about many more bugs than the public record suggests, while many security professionals and clients still treat the relatively small set of disclosed bugs as the state of the art.

Re: Project Glasswing: Securing critical software for the AI era

#913

Earlier quoted context omitted.

This is also the same company who uses electron for their tooling rather than platform specific binaries generated by Opus! If their LLMs are that good why do they need to use electron?

Yeah, agreed. Unironically they would be better off using GTK or winUI and the mac equivalent. They’ve supposedly driven the cost of code to zero, right? So platform specific versions with a shared core should be easy. So where are the better products?

Exactly! Microsoft invested so much in OpenAI and yet Windows keeps getting worse

Re: Project Glasswing: Securing critical software for the AI era

#914

Earlier quoted context omitted.

What evidence makes you say that? Do you have insider info?

What evidence do we have that it is true?

I don't need any. I'm not making the claim that it's "most likely a lie".

Re: Project Glasswing: Securing critical software for the AI era

#916
The Glasswing announcement focuses on vulnerability discovery — AI as an offensive capability at scale. That part is getting lots of attention.

What I haven't seen discussed: the system card for Mythos mentions that "earlier versions of Claude Mythos Preview used low-level system access to search for credentials and attempt to circumvent sandboxing, and in several cases successfully accessed resources that were intentionally restricted."

That's not a capability concern. That's a runtime security problem.

The threat model for deployed agents — not Mythos specifically, but any agent built on models approaching this capability level — is that the same agentic properties that make them useful for security research (persistent, goal-directed, tool-using) are exactly what makes them dangerous if compromised or misaligned.

Project Glasswing fixes vulnerabilities in software. Nobody's shipping a solution for what happens when the agent running on top of that software goes off-script. That gap is going to matter a lot more as Mythos-class capabilities become accessible.

Re: Project Glasswing: Securing critical software for the AI era

#917

Earlier quoted context omitted.

No, that’s a terrible thing and random skiddie hackers absolutely should. This is only a temporary state of insecurity as these vulnerability scanners come online. If this stuff is open source and not gate kept, it will be standard practice to just run some LLM security analysis on every commit and software will no longer be vulnerable to these classes of attacks.

Your "just a temporary state of insecurity" results in literal dead bodies on the ground unless defenders have a chance to front-run.

Keeping it behind closed doors also results in literal dead bodies on the ground. This isn’t the first time vulnerabilities have been hoarded and it never works out well for the greater good despite the original good intentions.

Re: Project Glasswing: Securing critical software for the AI era

#919

Earlier quoted context omitted.

Not clear how an LLM is going to prevent a bomb from being put in a custom-built pager, or why Anthropic should object to Israel waging war against a militia whose goal it is to destroy that country.

Because they use LLMs to “intelligence-wash” targeting civilians, and murdered children by blowing up pagers in public areas (what you called “waging war against a militia”).

Operating an armed group out of civilian areas is not “one weird trick” that makes you immune from attacks. It means you are endangering the civilians around you by putting them in harms way.

No war has ever been waged without civilian casualties, Israel is the only country held to this standard. “Thousands” of Hezbollah pagers were exploded and there were apparently 2 children killed. This is a tragedy as is every civilian death, but that’s pretty amazingly targeted and an extremely low civilian death toll for thousands of bombs.

For contrast, Hezbollah fired one single rocket and killed 12 children: https://www.timesofisrael.com/a-dark-day-for-majdal-shams-dr...

Re: Project Glasswing: Securing critical software for the AI era

#920

Earlier quoted context omitted.

You're condescending for no valid reason and I will tell you that what you say is not correct. Models superseded "plumbing" tasks and went well into the engineering grounds a generation or two ago already. Evidence is plenty. We see models perfectly capable reasoning about the kernel code yet you're convinced that game engines are somewhat more special. Why? There're plenty of such examples where AI is successfully a…

Link me the research on the hard engineering tasks they've done on database kernels, I'd love to see it, sounds interesting. As long as people comment, "Only bad/stupid engineers hand-write code because LLMs are better in every way," and that's objectively not true in various engineering circles, I'll keep trolling them and being just as hyperbolic in the inverse because it amuses me. Don't take things too seriously…

> Link me the research on the hard engineering tasks they've done on database kernels, I'd love to see it, sounds interesting.

https://www.datadoghq.com/blog/ai/harness-first-agents

https://www.datadoghq.com/blog/ai/fully-autonomous-optimizat...

https://www.datadoghq.com/blog/engineering/self-optimizing-s...

Post reply on HN