logoalt Hacker News

3sk_ask8yesterday at 4:19 PM2 repliesview on HN

Anthropic has the marketing of a weight loss product.

- They still claim 10000 issues, but they found only one in curl.

- They did not find rsync issues but Claude rather introduced rsync issues.

- Facebook is a member of this cult program but Mythos did not find the account takeover flaw.

- Mythos did not find the issues in Anthropic's own Bun rewrite.

They will not release Mythos because it would be exposed as a fraud before the IPO.


Replies

rfgplkyesterday at 6:06 PM

It's just pure marketing, and most people are falling for it. The primary issue stems from their definition of "vulnerability". Most C code will be _swimming_ in vulnerabilities depending on how you analyze it (ie function that accepts a pointer but doesn't validate -> potential vulnerability right there). The only thing that matters is if it's de facto exploitable or not.

poemxoyesterday at 7:01 PM

To be fair the curl author is excellent at what he does.