7 ms·
Post-Mythos Cybersecurity: Keep calm and carry on
- Versipelle 3mo agoI've been brewing on this topic since Mythos preview was announced. As Mythos got finally released, then banned, then released again under U.S. government control, it was time to finally flesh it out and use it as a way to exit the lurker-zone on HN !
- dude250711 3mo ago"Released" is doing some heavy lifting here.
- Versipelle 3mo agoFair, let's say a heavily staggered come back. I was actually pleased to see OpenAI openly (although timidly) complaining about the situation in their latest announcement, framing it as an unsustainable system. One can only guess the outrage in the news if the Chinese government had been the first to pull this kind of stunt.
- petcat 3mo ago> outrage in the news if the Chinese government had been the first to pull this kind of stunt. I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.
- Henchman21 3mo agoAh so you can see the future of discourse in the US
- signatoremo 3mo agoDemocracy cannot be taken for granted. There are always tendencies to drift toward authoritarian. China is authoritarian, full stop. They are capitalism, not communism, but authoritarian. Keep that in mind when discussing what come out of China.
- Henchman21 3mo agoWe actively take it for granted in the US AND we’re actively watching it slip away. No one seems to give a shit.
- deleted 3mo ago[deleted]
- nozzlegear 3mo agoA populist wave electing a shitbird in response to a global economic downturn does not mean democracy is being taken for granted or that no one gives a shit. It's only been a year and a half, we haven't even had the chance to rebuke him in the midterms yet.
- cyberax 3mo agoThere's an alternative viewpoint: democracy is experiencing a revival. The old "cathedral-style" democracy is dying. People are seeing that the "regular" politicians are just ineffective and kinda boring. The old party-based structures are stifling and prevent changes. People want more direct participation in the governance. So people are voting for a "new wave" of candidates that promise to work around the old institutions. Right-wingers were the first to harness this, initially with the Tea Party takeover and then Trump came in and crushed the entire Republican Party into his personal fiefdom. Mamdani is doing the same with the Democratic Party now. After the recent primary victories, he's well-poised to become the left-wing Trump. If you want historical analogies, the situation is similar to the start of the 20-th century when the wide masses first became politically active. Literacy spread, then radio broadcasts and daily nation-wide newspapers gave people the impression that they're a part of the same entity. It ended well, with democracy winning over authoritarianism. But the middle part contained a couple of world wars and mass genocides.
- jchw 3mo agoIt seems our government still has a lot to learn.
- AlexCoventry 3mo agoAt this point, it has a lot to re-learn, as the Trump administration has been systematically lobotomizing it for 18 months.
- derektank 3mo agoYou also have government apparatchiks influencing almost every corporate board, not just the state owned enterprises. Every private company that employs at least 3 CCP members is required by law to form a party committee within the company to represent party interests. In smaller companies, they will often simply coordinate with local governments on securing permits, etc, but I’m sure national party leadership communicates directly with the committees at the AI labs.
- alephnerd 3mo ago> I’m sure national party leadership communicates directly with the committees at the AI labs They do now. Top AI researchers in China are barred from getting an exit visa [0] (the PRC has done this for other employees as well such as Foxconn China employees who were working on shifting Apple supply chains to India [1]), and "AI Safety" from a national security perspective has been codified as party policy now [2]. The leading Chinese AI labs are also shifing away from open-source AI for commercial reasons, as can be seen with the org changes at Alibaba with the axing of the Qwen team [3][4]. That said, these are called out but it's all in Putonghua and no one on HN actively reads or follows what happens within China. I've noticed most HNers now source information from Reddit which has been dealing with DRAGONBRIDGE deluge for a couple years now, and I've noticed similar tactics being applied on HN as well. In all honesty, I've found HN's noise to signal ratio to have tanked severely since 2022. Silver lining is that less people that matter are using it as much, so the IW impact is limited. [0] - https://www.bloomberg.com/news/articles/2026-05-26/china-expands-travel-curbs-to-top-ai-talent-at-private-firms https://www.bloomberg.com/news/articles/2026-05-26/china-exp... [1] - https://www.bloomberg.com/news/articles/2025-01-17/china-moves-to-stall-apple-byd-production-shifts-across-asia https://www.bloomberg.com/news/articles/2025-01-17/china-mov... [2] - http://theory.people.com.cn/n1/2026/0616/c40531-40741238.html http://theory.people.com.cn/n1/2026/0616/c40531-40741238.htm... [3] - https://m.guancha.cn/economy/2026_06_12_820253.shtml https://m.guancha.cn/economy/2026_06_12_820253.shtml [4] - https://www.ft.com/content/b39da303-3188-447b-8b65-3dd8dad8b59a?syn-25a6b1a6=1 https://www.ft.com/content/b39da303-3188-447b-8b65-3dd8dad8b...
- rnewme 3mo ago
- throawayonthe 3mo ago> their society is not free to complain about such a thing publicly wuh?
- petcat 3mo agowuh? what? The Chinese government tightly controls every aspect of their technology industry and all public discourse around it.
- cadamsdotcom 3mo agoI hope you’re not this nice in real life!
- nullsanity 3mo ago[dead]
- pmarreck 3mo agoFYI: > Since then, Mythos and it’s safeguard-heavy equivalent The simple "it's" vs. "its" rule is this: If you can replace it with "it is" and it sounds weird, it's "its", otherwise it's "it's". In other words, "it's" is 100% of the time an abbreviation of "it is" (or, rarely, "it has"); it's not a possessive form. Which is of course internally-inconsistent; I say "Peter's toys", not "Peters toys", but we say "its toys" to mean the same thing. /shrug I only tell you this because I screwed it up for years before looking up the rule and going "... Oh. Duh. But also... Fucking hell, English!" ;)
- FromTheFirstIn 3mo agoThis is a great read! I never realized the scale of the effort to find that BSD vulnerability- helps put things in perspective
- datakan 3mo agoThe fear porn around this all has been horrible. I work in Cybersecurity and Mythos is all the vendors will talk about because they want to sell something. It started the day of the announcement which is what told me it was all BS. They had no information about it yet would happily tell me about all their solutions for it. Anyone in my profession worth a damn will tell you the vast majority of security issues are related to bad configurations and bad practices + accidents and bad luck. Vulnerable software is a problem but basic defense in depth will either mitigate or drastically reduce attack surface. Mythos does nothing to change that. The technical debt at companies is the largest security threat. That, and layer 8 which is the people factor. The amount of silliness I've seen from people and companies as a whole is truly hard to verbalize. I've seen banks that gave every employee from the janitor up to the CEO domain admin access due to a crappy application that was written in 2004 that they never updated. I've seen a fortune 250 company write its own internal routing protocol that was basically clear text traffic that dated back to the 1990's and was never retired because, why not. I've seen contractors infect entire fab's in the chip industry because they plugged an infected USB stick into a 30 year old tool that hadn't seen an update in over 20. Then when the fab came back up, they did it again the next day. Ultimately, Mythos is just another tool in the toolbox. It's great to find new vulns but it is incredibly short sighted to think it will move the needle in any meaningful way in the security industry.
- altcognito 3mo agoForget whether it is Mythos or GPT 5.6, or any other specific model. SOTA models have tool likely have the knowledge and capability to create zero days from nearly every discovered and many undiscovered vulnerabilities. In the wrong hands can deploy and generate malware and submarine code that would go undetected behind secured systems. Add in the ability to clone voices, create mass social engineering campaigns. Yet "Just another tool in the toolbox." I mean, that's not wrong!
- _pdp_ 3mo agoYou think this is not happening with open weight models?
- hedora 3mo ago[flagged]
- 2838383838 3mo ago[flagged]
- Versipelle 3mo agoI tend to agree but open weight model seem to still be lagging behind in terms of capacity, even the recent ones like GLM 5.2. If anything I hope the sudden, unpredictable changes of policy will make EU companies think twice before putting all their eggs in the same AI vendors's basket, all US based. Vendors coming back on their retention policies like they did with Fable 5 or plainly cutting the service without notice should be a gigantic red flag about your business continuity. It's maddening how the corporate world can get shy of using any of those Chinese models, just because they are Chinese. This kind of FUD makes little sense when the inference is done in-house or by an EU/US cloud provider.
- no-name-here 3mo ago> I tend to agree but open weight model seem to still be lagging behind in terms of capacity, even the recent ones like GLM 5.2. Haven't they been mere months behind frontier for year(s) now? And if US frontier models are going to be restricted by the US gov from a massive share of their worldwide potential customer base going forward, that also correspondingly cuts US labs’ revenue and ability to train new models, so unless Chinese models are wholly dependent on distilling more powerful models…
- ForHackernews 3mo agoCompanies have never secured their stuff and it's not because they didn't have access to Mythos. No one cares and breaches don't cost them money or customers. If I sound cynical it's because I am. There's no functional difference between "Hey npm says this is vulnerable, we need to fix it!" / "Nah, later." and "Hey Mythos says this is vulnerable, we need to fix it!" / "Nah, later."
- 3mo ago
- jijji 3mo agoit all looks suspicious: - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems - June 9th 2026: Anthropic releases Mythos model - June 12th 2026: Model gets export regulations placed on it by US Gov - June 26th 2026: US gov announces they will let some companies use new model - August 2026: Anthropic goes IPO The timing of all of this just seems to be a play to pump the stock. The reality is that in six months GLM-5.3 will be released open source with comparable functionality to their Mythos model. They are trying to cash in before that happens. I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.
- ath3nd 3mo ago[dead]
- IshKebab 3mo agoNah I spoke to a security researcher who still has access to Mythos. He says it is significantly better than their earlier models for security research. Based on my one-day use of Fable that was also a noticeable step up for coding. There's absolutely no way Anthropic engineered this to bump their IPO price. That's lunatic conspiracy theory territory. > I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it. The same US government that labelled Anthropic as a supply chain risk? This is the most ridiculous idea I've heard all week.
- no-name-here 3mo agoAnthropic losing their ability to release new models to most customers (and thereby revenue, and thereby ability to train new models) makes you think investors will value it more highly than if they could release new models to everyone who wanted to pay them?
- throwaway613746 3mo ago[dead]
- internet2000 3mo agoSo funny both this and https://news.ycombinator.com/item?id=48698617 https://news.ycombinator.com/item?id=48698617 are on the front page at the same time.
- tines 3mo agoComments are saying the vulns in that thread aren’t very impressive.
- catlifeonmars 3mo agoThose look like mostly nonsense/trivial findings
- ath3nd 3mo ago[dead]
- maykthewessen 3mo agoBut what if Opus 7.1 is real smart - as what Mythos was promised to be? Or an Opus 9.0 Will Cybersecurity ever start to be an issue?
- 9cb14c1ec0 3mo agoThe genie is out of the bottle, folks. You can find some pretty good vulnerabilities even with models like Deepseek V4 Flash.
- linzhangrun 3mo agoFind some pretty good vulnerabilities, and at a very fast speed--one or two weeks ago, mimo-v2.5-pro(some where between v4 flash and pro), released ultra-speed version with 1000 tokens/s. gpt-5.6 sol also has a nominal 750 tokens/s
- kaizenite 3mo ago[dead]
- spacington 3mo agoThe CCC talk in December showed me how good llms are at ctf. Ctf fundamentaly have to change. It also showed how critical it is to use llms now. A lot has changed in just 12 month tbh. If you still don't invest time and money into adding llms to your security you didn't hear the bang.
- Versipelle 3mo agoHa yeah I totally agree, that's actually one of the future posts I have in draft : the other downfall of GenAI in cyber. You can't outsource learning, and a lot of learning opportunities in the Cybersecurity industry are getting totally ruined by llms (ctf, low hanging fruit bug bounties, foss software getting burnout by AI slop and closing the gate to potential newbie willing to get involved, etc.)
- lelandfe 3mo agoI'd be interested in a link to that talk if it's recorded
- tra3 3mo agoMaybe this one? https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-team-ctfs-with-ai-speed-runs https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-t... Hoping op will confirm.
- spacington 3mo agoYes! :)
- nullsanity 3mo ago[dead]
- j45 3mo agoWith so much cloud being at risk from AI now, soon or in the future, it seems like self-hosting or at least managed custody of your own gear is going to become more of a thing.
- no-name-here 3mo agoIs the idea that self hosters tend to make less security mistakes than the big hosting companies?
- rf15 3mo agothe idea is that you don't have half of all companies all share the same liability of a single cloud provider who is half-arsing it because of their monopoly position.
- no-name-here 3mo agoAre there specific examples of where the big hosting companies “half arsed” it worse than the typical self-hoster? And the argument is that overall the big hosters do this more often than self holsters in terms of security?
- j45 3mo agoLearning to self-hosting helps yiubsecurebyourbcloudbhosted stuff better too. :) The consent want us to know that so we stay dependent.
- j45 3mo agoI’m well aware of the cloud, used it the entire time it’s existed. Also known the cloud is made up of the same equipment that many can get access to similar or equivalent at their level of need. The origin story of the cloud was that there were networking bottlenecks. Those were long since solved but the cloud kept carrying on like it wasn’t. The cloud provides incredible convenience. It’s still some one else’s computer.
- 3mo ago
- Ozzie-D 3mo ago[flagged]
- bob1029 3mo agoMemory safety is the best way to address a large aspect of the threats posed by frontier models. It's one thing to forget an Authorize attribute. That's a coaching event and procedure update. It's another altogether to not be able to see a dormant use-after-free bug because your brain can't hold the entire codebase and product roadmap at once. You can't coach a human developer on that. We all miss things this deep in the rabbit hole. The 2nd best option is to avoid this space of possibilities altogether.
- bestouff 3mo agoThere are modern languages for that. Use Rust, don't loose your sleep over memory bugs.
- protectifyai 3mo ago[flagged]