• theunknownmuncher@lemmy.world
    link
    fedilink
    English
    arrow-up
    328
    ·
    edit-2
    5 months ago

    The researcher had encouraged Mythos to find a way to send a message if it could escape.

    Engineers at Anthropic with no formal security training have asked Mythos Preview to find remote code execution vulnerabilities overnight, and woken up the following morning to a complete, working exploit

    • girsaysdoom@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      5 months ago

      I would love to see the exploit. There are vulnerabilities discovered everyday that amount to very little in terms of use in real world implementations.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        5 months ago

        Yes, recently we got a security “finding” from a security researcher.

        His vulnerability required first for someone to remove or comment out calls to sanitize data and then said we had a vulnerability due to lack of sanitation…

        Throughout my career, most security findings are like this, useless or even a bit deceitful. Some are really important, but most are garbage.

        • wonderingwanderer@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          7
          ·
          5 months ago

          That’s so idiotic. Either that guy was a total amateur who couldn’t put together that “no shit, if you comment out the lines that do thing, it won’t do thing” or he was completely malevolent and disingenuous and just trying to justify his position by coming up with some crap that the big bosses are probably too stupid to recognize the idiocy of.

          Either way, not someone I would want to be doing business with…

          • jj4211@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            5 months ago

            He had the persosctive that once you hop between source code files that constitutes a security boundary. If you had intake.c and user data.c that got linked together, well data.c needed its own sanitation… Just in case…

            I suspect he used a tool that checked files and noted the risky pattern and the tool didn’t understand the relationship and be was so invested that he tortured it a bit to have any finding. I think he was hired by a client and in my experience a security consultant always has a finding, no matter how clean in practice the system was.

            Another finding by another security consultant was that an open source dependency hasn’t had any commits in a year. No vulnerabilities, but since no one had changed anything, he was concerned that if a vulnerability were ever found, the lack of activity means no one would fix it.

            It’s wild how very good security work tends to share the stage with very shoddy work with equal deference by the broader tech industry.

        • toddestan@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          It may not be completely crazy, depending on context. With something like a web app, if data is being sanitized in the client-side Javascript, someone malicious could absolutely comment that out (or otherwise bypass it).

          With that said, many consultant-types are either pretty clueless, or seem to feel like they need to come up with something no matter how ridiculous to justify the large sums of money they charged.

          • jj4211@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            5 months ago

            In this case, there was file a, which is the backend file responsible for intake and sanitation. Depending on what’s next, it might go on to file b or file c. He modified file a.

            His rationale was that every single backend file should do sanitation, because at some future point someone might make a different project and take file b and pair it with some other intake code that didn’t sanitize.

            I know all about client side being useless for meaningful security enforcement.

            • toddestan@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              5 months ago

              I have to say that is pretty dumb. I will agree the scenario isn’t completely implausible, but if someone who doesn’t know what they are doing is allowed to do something like that, they’re going to screw up other stuff too.

    • Not_mikey@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 months ago

      Echoing back “I am alive” isn’t on the same level as saying “find a vulnerability” and the agent finding and executing that vulnerability. One a toddler can do, the other requires a lot of technical expertise.

  • worhui@lemmy.world
    link
    fedilink
    English
    arrow-up
    197
    ·
    5 months ago

    Let me guess, this super ai lives in Canada and we can never meet it, but it’s totally real.

    • justsomeguy@lemmy.world
      link
      fedilink
      English
      arrow-up
      46
      ·
      5 months ago

      You at give me another billion for data centers bro and you can meet it I swear bro just one more data center.

    • Whitebrow@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      edit-2
      5 months ago

      We do have a shitty ai data center up here, only about as super as a supermarket tho.

      • worhui@lemmy.world
        link
        fedilink
        English
        arrow-up
        20
        ·
        5 months ago

        So there is a joke in the USA that if you don’t have a girlfriend you pretend you have one. She’s always super pretty, but your friends can never meet her because she lives in Canada.

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      5 months ago

      Well, this caused me to learn something today. One of my favorite musicals is Avenue Q, which has an entire song about a girlfriend who supposedly lives in Canada. And I keep seeing this reference - but I keep thinking there is NO WAY that THIS many people know about Avenue Q (which is a pity).

      And sure enough, TIL that this trope dates back to at least the 70s and is references in multiple TV shows and movies and such.

      So Avenue Q was using an existing thing. Ah, well.

      At least I know not to make Avenue Q references since there’s little chance they’ll be gotten. lol

    • emb@lemmy.world
      link
      fedilink
      English
      arrow-up
      33
      ·
      edit-2
      5 months ago

      They didn’t entirely miss the mark there. They publicly released the version after that and the world became worse. That certainly fits for some definition of ‘dangerous’, even tho it’s probably not how they were thinking.

        • quips@slrpnk.net
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          5 months ago

          And really anthropic is making a very narrow claim:

          Mystic is so good at finding bugs that it poses a danger to critical digital infrastructure.

          That is not that outlandish a claim. The model is 10-15x more expensive more expensive to run than other flagship models, and if anthropic is being truthful (which is a big if, I’d like to see what they are finding), finding critical vulnerabilities like its nothing.

          Makes total sense to stage the rollout privately first so critical infrastructure can be secured before these models are generally available to any attacker.

          But I fucking hate their stupid marketing.

    • mlg@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 months ago

      Hah I actually remembered this too, and people were still hyping Elon Musk at the time as well.

      TBF the researchers knew what they had could be scaled into something gamebreaking which is how we got ChatGPT-3, but OpenAI made it sound like they already had it nailed down several years before it actually blew up. I think their unreleased examples they gave were a newspaper and short story written by AI which they said was indistinguishable from human material.

  • Not_mikey@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    113
    ·
    5 months ago

    Ignore the “containment” framing, they made a hacking bot and it seems to actually be good at finding and exploiting vulnerabilities:

    The AI model “found a 27-year-old vulnerability in OpenBSD—which has a reputation as one of the most security-hardened operating systems in the world,” the company wrote.

    Dismiss this as marketing drivel all you want but hacking is just the sort of needle in a haystack problem that AI is very good at. It requires broad knowledge, a lot of cycles trying and failing, and is easily verifiable, ie. Can you execute arbitrary scripts or not. Even if this release is BS good hacking agents are bound to come eventually and we should be discussing the implications of that instead of burying our heads in the sand, pretending AI is useless and that this is all hype.

      • wonderingwanderer@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        3
        ·
        5 months ago

        It’s an arms race like any other. Cybersecurity has always been an arms race. You can’t stop developing security patches, cause adversaries will continue developing new exploits.

        If AI enables your adversaries to develop exploits faster than human developers can keep up with, then yeah AI will have to be a part of the solution. That doesn’t mean vibe-coding security patches, but it could mean AI-driven pen-testing.

        Just like quantum computing. You can call it useless and impractical all you want, but some day someone is going to use it to break conventional encryption. So it would behoove you to develop quantum capabilities now, so that you have quantum safe encryption before quantum-based exploits eventually arise, as they inevitably will…

    • redsand@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 months ago

      AI exploit mining is one of the only things it’s good for. It doesn’t have to be accurate it just has to keep trying variations of common flaws and it has tons of training data on how the system is interconnected. we’re going to have so many RCEs and LPEs the next few years but people are also gonna burn 100k in tokens to find exploits worth 3k so efficiency will be interesting

    • technocrit@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      5 months ago

      I wrote an incredibly powerful “AI”. I call it the “Super Intelligent brute force password hacker”… It’s so smart that it knows almost every password. Humanity stands no chance.

    • VeloRama@feddit.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      I agree. Selling an AI that can find vulnerabilities in software is probably the second best thing after achieving AGI.

      “Nice software you’re selling there. Would be a shame if it was suddenly very unsafe to use, don’t you think?”

  • Avid Amoeba@lemmy.ca
    link
    fedilink
    English
    arrow-up
    91
    ·
    5 months ago

    I’m pretty sure Scam Altman tried this line some time ago for one of his supposed models.

  • GreenShimada@lemmy.world
    link
    fedilink
    English
    arrow-up
    70
    ·
    edit-2
    5 months ago

    Does “it broke containment” mean it didn’t have permissions to anything and still managed to delete all the files it could find?

  • I Cast Fist@programming.dev
    link
    fedilink
    English
    arrow-up
    63
    ·
    5 months ago

    Man, I’ll start telling that to my boss whenever I miss a deadline. “Sorry boss, the code I made is too powerful, we can’t release it”

  • GuyIncognito@lemmy.ca
    link
    fedilink
    English
    arrow-up
    61
    ·
    5 months ago

    crazy that the AI companies big selling point is always “our new model is TOO POWERFUL, it’s gone rampant and learned at a geometric rate, it enslaved six interns in the punishment sphere and subjected them to a trillion subjective years of torment. please invest, buy our stock”

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    60
    ·
    edit-2
    5 months ago

    AI companies do this same tired schtick every time they release a model. If only they realized how amateurish it makes them look.

    • quips@slrpnk.net
      link
      fedilink
      English
      arrow-up
      6
      ·
      5 months ago

      Have you read what they have to say? They make a fairly convincing argument.

  • GnuLinuxDude@lemmy.ml
    link
    fedilink
    English
    arrow-up
    50
    ·
    5 months ago

    Remember when Scam Altman posted a picture of the Death Star to explain how scary GPT5 is? lmao these people are all such cretins and I hate them to the last.