frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Mythos, Glasswing, and the hardware disclosure problem nobody is discussing

1•TedDallas•1h ago
Coverage of Anthropic's Claude Mythos Preview and Project Glasswing has focused almost entirely on software vulnerabilities. That is where the demos are and where controlled release maps cleanly onto existing disclosure practice. I have not seen anyone engage with the next obvious question: what happens when a Mythos-class model is given detailed hardware architecture documentation and asked to do a security-oriented review? My intuition is the hardware case is meaningfully worse, for reasons beyond "hardware is harder."

The tight feedback loop that makes Mythos effective on software partially breaks on hardware: no sandbox, no instant PoC iteration. But this is actually where an LLM could shine. Fusing disparate technical sources is what these models are unusually good at, and hardware security is bottlenecked by how few humans can hold all the context in their heads at once. Spectre, Meltdown, Downfall, Zenbleed, and LVI were all found by tiny teams of specialists. A model that can tirelessly cross-reference an ISA manual against errata against an RTL description is the tool that class of research has been waiting for.

The consequences are asymmetric in the attacker's favor. You cannot patch a logic flaw baked into a fab mask. The best you usually get is a microcode mitigation that costs performance, or an OS-level band-aid. For deep flaws the only real fix is a new silicon revision. Deployed hardware lives for a decade or more. A Chrome zero-day is patched by Tuesday. A zero-day in a 2021 Xeon is essentially permanent.

The defender coordination model does not map either. Glasswing works for software because Microsoft, Google, and Apple can push fixes to billions of devices in weeks. There is no Patch Tuesday for an Arm core already shipped in two billion phones. The vendors who would need to participate in a hardware equivalent — Intel, AMD, Arm, Qualcomm, Apple, TSMC, Samsung — have historically been far more secretive about internals than software vendors. The open collaborative disclosure model is much harder to replicate at that layer. And hardware implementation flaws are closer to strategic weapons than software bugs: usable against an adversary's entire installed base with no meaningful patching option.

One nuance: architecture review from published specs is the easier half of the hardware problem, and the half most exposed to current model capabilities. Finding logical flaws in a spec — race conditions in cache coherency, ambiguous memory ordering, speculation leaks — is something a capable model plausibly can do today. What it cannot do alone is analog behavior, physical side channels, fault injection, and bugs that only manifest at specific process corners. Those need silicon in a lab. But pair a Mythos-class model with a well-equipped hardware security lab and you have compressed PhD-years of work into weeks.

Constitutional training works against obvious malicious requests. But models can be induced to assist with offensive work when requesters segment the task and frame components as legitimate engineering questions. An end-to-end "help me exploit this chip" request gets refused. A hundred individually defensible questions about memory ordering, speculative corner cases, and cache timing variability may not. Humans fall for the same pattern. Models are not immune, which is likely part of why Anthropic is being as cautious as they are.

Software is where AI operates end-to-end autonomously today. Hardware is where the same capability produces more durable consequences, fewer remediation options, and a weaker disclosure ecosystem to absorb the shock. Whether anyone is seriously thinking about a hardware-focused Glasswing equivalent is something I have not seen addressed. Curious whether people here working in hardware security or silicon red-teaming think this is overstated, understated, or already being quietly worked on.

goose has a new home – the Agentic AI Foundation (AAIF)

https://goose-docs.ai/blog/2026/04/07/goose-moves-to-aaif/
1•wicket•52s ago•0 comments

Did Airbnb, Medium, Beats, and Flipboard Rip Off Their Logos? (2016)

https://thehustle.co/airbnb-medium-beats-flipboard-logo
1•bookofjoe•3m ago•0 comments

Verification Is the Next Bottleneck in AI-Assisted Development

https://www.opslane.com/blog/verification-bottleneck
1•aray07•4m ago•0 comments

OpenAI looks to take on Anthropic with $100 per month ChatGPT Pro subscriptions

https://www.cnbc.com/2026/04/09/openai-chatgpt-pro-subscription-anthropic-claude-code.html
1•HiroProtagonist•5m ago•0 comments

AI micro-dramas are shaking up Chinese entertainment

https://economist.com/china/2026/04/09/ai-micro-dramas-are-shaking-up-chinese-entertainment
1•andsoitis•7m ago•0 comments

The AI Jobs Blind Spot: Why Job Creation Is the Default

https://substack.norabble.com/p/the-ai-jobs-blind-spot
1•nedruod•8m ago•0 comments

Gitbutler

https://gitbutler.com/
1•handfuloflight•9m ago•0 comments

Perplexity computer is based on the OSS browser use library

https://twitter.com/mamagnus00/status/2042339700082610345
2•whytai•10m ago•0 comments

BYD teams up with KFC to offer 9 minute EV charging

https://electrek.co/2026/04/09/byd-fast-food-giant-offer-9-minute-ev-charging/
1•breve•11m ago•0 comments

Sora Fuel Raised $14.6M to Bottle the Sky

https://www.siliconsnark.com/sora-fuel-raised-14-6-million-to-bottle-the-sky-honestly-respect/
1•SaaSasaurus•12m ago•0 comments

IMDB created my account for merely visiting the site

4•astr0n0m3r•15m ago•1 comments

CNN investigation: Exposing a global 'rape academy'

https://www.cnn.com/interactive/2026/03/world/expose-rape-assault-online-vis-intl/index.html
4•1659447091•19m ago•0 comments

New to Hackerview

1•foxxyyybusiness•20m ago•3 comments

Show HN: Idontuselinkedin.com

https://idontuselinkedin.com
7•jmholla•21m ago•4 comments

InterviewGPT: Stop Guessing. Start Scaling. Land Your Dream FAANG Offer

https://interviewgpt.deepchill.app/
2•tiancaioyzy•22m ago•0 comments

Do Science in Bed

https://monsharen.github.io/Peer/
2•ycombinatornu•22m ago•0 comments

How Microsoft Abuses Its Users

https://lzon.ca/posts/other/microsoft-user-abuse/
3•jpmitchell•23m ago•0 comments

Apple and Lenovo have the least repairable laptops, analysis finds

https://arstechnica.com/gadgets/2026/04/apple-has-the-lowest-grades-in-laptop-phone-repairability...
1•josephcsible•25m ago•0 comments

Show HN: Solving digital piracy with game theory instead of DRM

https://piecely.app/explore
2•johndebord•25m ago•1 comments

Ford patents lip reading and emotion detection inside the car [video]

https://www.youtube.com/watch?v=g5V3cxjDaFU
3•_DeadFred_•28m ago•0 comments

Researchers turn recovered car battery acid, plastic waste into clean hydrogen

https://www.cam.ac.uk/research/news/researchers-turn-recovered-car-battery-acid-and-plastic-waste...
2•gmays•28m ago•0 comments

Open source, agentic knowledge bases for all of humanity's knowledge

https://alpharesearch.nyc/blog/launching-alpha-research/
2•rprend•29m ago•0 comments

Launch of Artemis II: Rocket Camera Views [video]

https://www.youtube.com/watch?v=mn7WMowM1xY
1•Yukonv•32m ago•0 comments

Moving from WordPress to Jekyll (and static site generators in general)

https://www.demandsphere.com/blog/rebuilding-demandsphere-with-jekyll-and-claude-code/
3•rgrieselhuber•32m ago•0 comments

Secure AI Agent Connections to Enterprise Tools

https://www.arcade.dev/blog/connect-ai-agents-enterprise-tools/
2•manveerc•32m ago•0 comments

What About Website Form Outreach

2•hjconstas•33m ago•1 comments

Show HN: We built the "LLM knowledge base" Karpathy described 9 yrs ago

https://mythos.one/me/brianswichkow/54528e
2•brianswichkow•36m ago•2 comments

Show HN: I built a weather site for the Eastern Caribbean

6•ashitlerferad•37m ago•0 comments

Rīgā, Madonas ielā, autovadītājus sagaida bīstami iegruvumi un bedres

https://lente.lv/latvija/raksts/riga-madonas-iela-autovaditajus-sagaida-bistami-iegruvumi-un-bedr...
1•janwebdev•38m ago•0 comments

I built an AI-powered Kanban board for your GitHub repos

https://github.com/Kill-The-Backlog/Kill-The-Backlog
1•jvaill•39m ago•1 comments