Is Mythos a significant danger?
The curl experience does not suggest that hysteria is warranted, but this gives me pause.
Is Mythos a significant danger?
The curl experience does not suggest that hysteria is warranted, but this gives me pause.
Mythos's great strength was finding multiple vulnerabilities and chaining them together to break a whole system.
Look at it like this: It found one confirmed, minor vulnerability in Curl (but I don't think they have said what it was?). In another system that used Curl it's possible it could have exploited that vulnerability to chain to another, bigger vulnerability that was normally inaccessible.
That's how systems get broken.
And the government's response was to limit access to US citizens? I don't believe this for a minute. If Mythos could actually break into all these systems, the government would declare it a national security risk and it would never see the light of day for anyone outside government staff with security clearance.
"[the statement] was oversimplified... In reality, the tests involved “red teams” of N.S.A. analysts who were using Mythos in a highly tailored environment that would be extremely unlikely for an adversary to replicate, officials said. The red teams began their tests within classified N.S.A. systems designed to be accessible only from certain computers and completely cut off from the broader internet.
The tests found that Mythos was able to identify cybersecurity flaws within that classified network quickly, but it did not actually break into those systems, the officials said."
What about the Firefox experience?
Or are we conveniently ignoring things that don't confirm conclusions we've already reached?
I just think that a coreutils flaw is not as substantial as a rendering engine exploit.
Which I think points at Mythos not being some big jump in capability finding things earlier LLMs didn't, it seems to mostly come down to massively increased compute budget and they finally catching up in context sizes.