#Anthropic #MythosPreview #AI #Zerodays
@chrisstoecker well, let me put it that way:
- you will find exploits in any software with enough ressources and time
- sharing found zero days responsibly is a responsible thing to do
- the idea that they will only be used for defensive purposes sounds heroic but I hardly believe they won't share this technology with state actors (think about OpenAI which will do anyhting for money)
There is nothing new in these three statements but the pace is accelerating.
Same shit, faster.
@chrisstoecker The concerning aspect about this situation is not that systems have weaknesses but that defensive measures are always underpaid and understuffed.
AI hype does shift budgets from reasonable security measures like defense in depth (build systems that have more than on security guard in them) and slow but sustainable secure system designs to hyped and flaky "AI defense agents" – which will break sooner than later because they are erratic like LLMs. Fairy dust but not sustainable.