“why won’t the AI haters admit claude mythos is good?” when it turns out the exploits it found are utterly overblown (ie the firefox exploit that only works on a custom build with the sandbox disabled amongst many other non-exploitable bugs), were found at extreme expense, and required a ton of human staff to verify (just like with existing non-LLM techniques), why won’t you admit this is a grift? why won’t you admit you’ve been falling for the same grift since 2019?

@zzt i agree with your general statement, but requiring a custom build with sandbox disabled is pretty standard in the browser exploitation world

i see using llms to find vulns in software as just another tool that's gonna find a bunch of stuff initially and less later on, the same way new fuzzing methods come with a surge of new bugs, it's overhyped for sure