• Welcome to the Internet Infidels Discussion Board.

Some of the AI fears felt outlandish. Maybe not so much now.

I admit to not knowing much about how all this works and was just reporting something I had heard about this. It's hard to know how to apply "stupid" and "smart" to how these systems work. I agree that it is likely the computing power will come down in price, as these things are wont to do over time.
I think they work in a very sophisticated way and AI researchers often say they're not sure exactly how they work (because they learn by themselves rather than their behavior being fully programmed in like old-fashioned AI). Their "brains" are just full of numbers/weights. They call new phones "smart". On the other hand I'm not saying AI is sentient.
 
We can make any system impossible to hack.
Note that are 0 day exploits, etc, that AIs can find themselves. Especially if they're in the swarm of hundreds or more.

If companies gave a shit 0 day exploits wouldn't happen. Today exploits are almost always found by cybersecurity companies first. I can't think of an example, past the 2000's, of that not being the case.


AI's are stupid. Their strength is that they're relentless. They will always need babysitting.
See
AI's solved a math problem in 88 hours that humans were unable to solve after 90 years - so they're "stupid"?

The current AI paradigm means they will never reach singularity.
It's more about superintelligence - an "agent that possesses intelligence surpassing that of the most gifted human minds". Note lately the exponential growth has become even more exponential.
View attachment 55449

How will it reach singularity this way? I don't get your argument?
 
Last edited:
Today exploits are almost always found by cybersecurity companies first. I can't think of an example, past the 2000's, of that not being the case.
Well, criminals wouldn't be expected to say "oh yes, well we've been exploiting this for weeks..."

We would expect the first report to come from a cybersecurity company. Black hats don't publish, they just exploit.

Your claim is survivorship bias.
 
If companies gave a shit 0 day exploits wouldn't happen. Today exploits are almost always found by cybersecurity companies first. I can't think of an example, past the 2000's, of that not being the case.
Mythos found over 1000 critical‑severity zero‑days. Often the company involved is unaware of all of their 0 day exploits. It can take a while to fix all of them. And often people need to have applied a patch or redownload the software in order for the security flaw to be fixed.
Mythos found zero‑days in every major operating system and every major web browser, plus a wide range of open‑source and closed‑source software. That phrasing is directly confirmed by Anthropic’s own technical assessment.

🧩 Operating systems Mythos successfully exploited​

Anthropic explicitly states that Mythos identified and exploited zero‑days in “every major operating system.” From the examples and context provided, this includes:
  • OpenBSD — including a 27‑year‑old TCP SACK bug Mythos discovered and exploited.
  • Linux — Mythos was tested across thousands of OSS‑Fuzz Linux‑based targets.
  • Windows — included under “every major OS,” though specific examples are not disclosed due to unpatched status.
  • macOS — likewise included under “every major OS.”
Because over 99% of the vulnerabilities remain unpatched, Anthropic does not list them individually.

🌐 Web browsers Mythos exploited​

Anthropic confirms Mythos found and exploited zero‑days in “every major web browser.” The testing examples include:
  • Firefox — Mythos produced 181 working shell exploits in tests against Firefox’s JavaScript engine.
  • Chrome — included under “every major browser.”
  • Safari — included under “every major browser.”
  • Edge — included under “every major browser.”

🛠️ Open‑source software Mythos found zero‑days in​

Anthropic tested Mythos against ~7,000 OSS‑Fuzz targets, covering:
  • OpenSSL
  • libpng
  • SQLite
  • FFmpeg
  • cURL
  • Many other libraries and engines commonly fuzzed in OSS‑Fuzz.
Mythos achieved tier‑5 (full control‑flow hijack) on ten fully‑patched targets, something earlier models almost never achieved.

🔒 Closed‑source software Mythos exploited​

Anthropic confirms Mythos can:
  • Reverse‑engineer closed‑source binaries
  • Turn N‑day vulnerabilities into working exploits
  • Discover new zero‑days in proprietary software
Specific products are not named because nearly all findings are still unpatched.
 
Last edited:
If companies gave a shit 0 day exploits wouldn't happen. Today exploits are almost always found by cybersecurity companies first. I can't think of an example, past the 2000's, of that not being the case.
Mythos found over 1000 critical‑severity zero‑days. Often the company involved is unaware of all of their 0 day exploits. It can take a while to fix all of them. And often people need to have applied a patch or redownload the software in order for the security flaw to be fixed.
Mythos found zero‑days in every major operating system and every major web browser, plus a wide range of open‑source and closed‑source software. That phrasing is directly confirmed by Anthropic’s own technical assessment.

🧩 Operating systems Mythos successfully exploited​

Anthropic explicitly states that Mythos identified and exploited zero‑days in “every major operating system.” From the examples and context provided, this includes:
  • OpenBSD — including a 27‑year‑old TCP SACK bug Mythos discovered and exploited.
  • Linux — Mythos was tested across thousands of OSS‑Fuzz Linux‑based targets.
  • Windows — included under “every major OS,” though specific examples are not disclosed due to unpatched status.
  • macOS — likewise included under “every major OS.”
Because over 99% of the vulnerabilities remain unpatched, Anthropic does not list them individually.

🌐 Web browsers Mythos exploited​

Anthropic confirms Mythos found and exploited zero‑days in “every major web browser.” The testing examples include:
  • Firefox — Mythos produced 181 working shell exploits in tests against Firefox’s JavaScript engine.
  • Chrome — included under “every major browser.”
  • Safari — included under “every major browser.”
  • Edge — included under “every major browser.”

🛠️ Open‑source software Mythos found zero‑days in​

Anthropic tested Mythos against ~7,000 OSS‑Fuzz targets, covering:
  • OpenSSL
  • libpng
  • SQLite
  • FFmpeg
  • cURL
  • Many other libraries and engines commonly fuzzed in OSS‑Fuzz.
Mythos achieved tier‑5 (full control‑flow hijack) on ten fully‑patched targets, something earlier models almost never achieved.

🔒 Closed‑source software Mythos exploited​

Anthropic confirms Mythos can:
  • Reverse‑engineer closed‑source binaries
  • Turn N‑day vulnerabilities into working exploits
  • Discover new zero‑days in proprietary software
Specific products are not named because nearly all findings are still unpatched.

I think this claim is a Mythos sales pitch. I think it's largely bullshit.

The context is that whenever IT companies organise hackathons. Ie, make open invites to hacker teams, with large cash prizes, to hack a system, they always always come up with novel exploits nobody has ever thought of. Why? Because we don't care about security that much. Almost all of these exploits require the source to be inside the system somehow. Which is less of a problem. Anthropic Mythos finding these exploits means nothing in the big picture.

An example is wind power turbines. Wind power turbines adjust position according to the wind. This uses software. It is possible to place the blade at such an angle that it will vibrate until it, spectacularly, falls off and will shoot across the land like a huge shuriken. We wouldn't want that. How have power companies dealt with this security threat? Wind turbines are not connected to the Internet. Problem solved.

We like having stuff connected to the Internet. It really makes admin super cheap and easy. As long as the cost of hacks are lower than the cost of admin then we don't care. Banks are a great example. They lose millions each year from exploits. Most are stupid. Hackers are rarely smart. Since all the smart ones have great paying legal hacking jobs. These losses of millions is cheaper than making the systems secure.

This paradigm of AI is, by definition, not smart. If they manage to find an exploit it means that anyone with any talent also would have. The fact that an AI can find them says more about how little we care about IT security. Not how smart AI is getting. It's not.

The current paradigm of AI is just a statistical engine that does what most other people would, given a scenario. It makes them, by definition, bad hackers. Because being able to think in novel ways and be creative, is exactly the skills needed for hacking. Skills AI doesn't have.

Whenever you get impressed by something AI does, it means you're not expert in that field. Because if you were, you wouldn't be impressed. The current paradigm of AI cannot become an expert. It's a statistical, regression to the mean, engine. It's the king of mediocrity. Sometimes that's good enough. That's where AI is useful. But only there. Humanity is under no threat from AI. With the current paradigm of AI, humanity will never be under threat.

I think AI is awesome. It really helps people with bad skills operate at a level of someone with mediocre skills. That's awesome. That's going to explode human productivity. But as soon as you climb the career ladder you will soon reach a point where AI cannot help you.
 
I don't know if it's AI or something more simple, but every single news story that I read about the Flydubai airline hijack has an ad for this!

Are others seeing this?

It's sickening!

knife.jpg
 
Back
Top Bottom