Anthropics Project Glasswing Update
News Source : Schneier.com
News Summary
- Anthropic has published a Project Glasswing status report.
- It’s finding a lot of vulnerabilities in software—yay!
- Some of them are even dangerous.
- But almost none of them has been patched.
- That Anthropic refuses to release details—that it just says “trust us”—is a big problem here.
- All but a very tiny fraction of what Mythos found were not already known to the developers and in effect of inconsequence.
- This is quite common not just in FOSS but all software development in the ICT industry that is not of trivial size.
- And when seen against the cost not of fixing but of actually testing, why we have a veritable tsunami of “technical debt” It is what triage essentially does.
In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software.
Never miss a story from us, subscribe to our newsletter