5 ms·
Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Scary but also coo
by zachperkel 5mo ago
Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.
Scary but also cool
- fsflover 5mo agoEvery piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org https://qubes-os.org
- syndeo 5mo agoOnce you get the compartmentalization working well, and “all” of the vulnerabilities are out of it too, of course… But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.
- fsflover 5mo ago> and “all” of the vulnerabilities are out of it too This is a good point; however the isolating code should be much smaller and easier to verify.
- dakolli 5mo agoOr more likely, its just an exaggeration or lie.
- solenoid0937 5mo agoYes I'm sure this is all a massive conspiracy by the many companies that are making statements alongside Anthropic
- pertymcpert 5mo agoWhat evidence makes you say that? Do you have insider info?
- nicce 5mo agoNeither party provided the evidence. I wonder why people like to take the side of the optimistic.
- stratos123 5mo agoWe already know Opus can find real vulnerabilities ([1], [2], ...), so it's not exactly surprising that a bigger model is better at it. [1] https://news.ycombinator.com/item?id=47273854 https://news.ycombinator.com/item?id=47273854 [2] https://news.ycombinator.com/item?id=47611921 https://news.ycombinator.com/item?id=47611921
- nicce 5mo agoThat is not thousands high-severity vulnerabilities as above commenter stated. Even many local models have found individual vulnerabilities.
- muddi900 5mo agoWhat evidence do we have that it is true?
- pertymcpert 5mo agoI don't need any. I'm not making the claim that it's "most likely a lie".
- ex-aws-dude 5mo agoDid someone actually go through all of those and check if they are high-severity or did the AI just tell them that?
- DiffTheEnder 5mo agoThey mention that they have humans review the most crticial bugs before sending it to the maintainers in their dev blog.