Hacker Newsnew | past | comments | ask | show | jobs | submit | endunless's commentslogin

Another Anthropic PR release based on Anthropic’s own research, uncorroborated by any outside source, where the underlying, unquestioned fact is that their model can do something incredible.

> AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities

I like Anthropic, but these are becoming increasingly transparent attempts to inflate the perceived capability of their products.


We'll find out in due time if their 0days were really that good. Apparently they're releasing hashes and will publish the details after they get patched. So far they've talked about DoS in OpenBSD, privesc in Linux and something in ffmpeg. Not groundbreaking, but not nothing either (for an allegedly autonomous discovery system).

While some stuff is obviously marketing fluff, the general direction doesn't surprise me at all, and it's obvious that with model capabilities increase comes better success in finding 0days. It was only a matter of time.


Cynicism always gets upvotes, but in this particular case, it seems fairly easy to verify if they're telling the truth? If Mythos really did find a ton of vulnerabilities, those presumably have been reported to the vendors, and are currently in the responsible nondisclosure period while they get fixed, and then after that we'll see the CVEs.

If a bunch of CVEs do in fact get published a couple months (or whatever) from now, are you going to retract this take? It's not like their claims are totally implausible: the report about Firefox security from last month was completely genuine.


> If a bunch of CVEs do in fact get published a couple months (or whatever) from now, are you going to retract this take?

I would like to think that I would, yes.

What it comes down to, for me, is that lately I have been finding that when Anthropic publishes something like this article – another recent example is the AI and emotions one – if I ask the question, does this make their product look exceptionally good, especially to a casual observer just scanning the headlines or the summary, the answer is usually yes.

This feels especially true if the article tries to downplay that fact (they’re not _real_ emotions!) or is overall neutral to negative about AI in general, like this Glasswing one (AI can be a security threat!).


I would've basically agreed with you until I'd seen this talk: https://www.youtube.com/watch?v=1sd26pWhfmg

Maybe a bad example since Nicholas works at Anthropic, but they're very accomplished and I doubt they're being misleading or even overly grandiose here

See the slide 13 minutes in, which makes it look to be quite a sudden change


Very interesting, thanks for sharing.

> I doubt they're being misleading or even overly grandiose here

I think I agree.

We could definitely do much worse than Anthropic in terms of companies who can influence how these things develop.


I watched the talk as well and it's very interesting. But isn't this just a buffer overflow in the NFS client code? The way the LLM diagnosed the flaw, demonstrated the bug, and wrote an exploit is cool and all, but doesn't this still come down to the fact that the NFS client wasn't checking bounds before copying a bunch of data into a fixed length buffer? I'm not sure why this couldn't have been detected with static analysis.


I guess so, but there's a ton of buffer overflow vulnerabilities in the wild, and ostensibly it wasn't detected by static analysis

The red team post goes over some more impressive finds, and says that there's hundreds more they can't disclose yet: https://red.anthropic.com/2026/mythos-preview/


I have yet to see any real world difference between sonnet 4.5 and opus 4.6. All I can tell is the version number went up for both series.

I don't know if they are a even an improvement over previous models. I never used them.


I do like these fonts, but DJR had this idea with the (excellent) Input family of fonts years ago:

https://input.djr.com/

A bit weird to not mention that.

Unfortunately until editors start supporting this (and I’m not sure what would motivate them to), these remain great ideas only.


Input's method seems to be fundamentally very different to this. Monaspace keeps the grid intact and only changes the characters visually (situationally overlaps wide letters to neighbouring narrow characters' spaces). Input just pretends to be monospace in its aesthetics, I don't really understand what's supposed to be special with that.


Fair points on the technical implementation.

I more meant the idea of using different fonts in the same buffer to represent different kinds of text.


Input is a proportional font.

Monaspace is a monospace font that uses contextual alternatives: it changes how letters look depending on surrounding letters.

They are nothing alike in their approach to this problem.

(Also this is a marketing piece. Contextual alternatives is not a new tech.)


> Input is a proportional font.

it is also a monospaced font


Yes there is a version of Input that is a monospaced font and doesn't solve the problem tackled by Monaspace and the proportional version of Input and is therefore as relevant to this discussion as .. I dunno .. Courier New.


I’m not sure why you think this conversation is about the proportional variant.


Honest question: does emacs (GUI) not support this?


Emacs totally supports this!

Mixing monosoace and proportional fonts can be a little strange, but there are some 3rd party packages or guides (prot has one iirc) to workaround it.


Which editors?


Given GitHub is owned by Microsoft, I think VS Code supporting mixing fonts in a buffer would be a good start!


Yes, I configured VS Code to use Monaspace a while ago.


What is the auto-update mechanism on macOS? One of the primary reasons I use ungoogled chromium is because I can update it via homebrew myself. I don’t trust browsers with running invisible background auto-updaters.


Keystone had a pretty mixed history on macOS, with things like the WindowServer bug and that one time it deleted the /var symlink. Do you know if the new updater is safer to use? I can't find out much about it.


> Do you know if the new updater is safer to use?

I have no data on that. All software has bugs, the updater included.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: