We Have to Talk About Anthropic's Mythos
We Have to Talk About Anthropic’s Mythos
Summary
In this special early-release episode of Hard Fork, Kevin Roose and Casey Newton break down Anthropic’s announcement of Claude Mythos Preview, a new AI model the company says is too dangerous to release to the public. Anthropic claims that during internal testing the model autonomously discovered critical “zero-day” exploits in core internet infrastructure — including a 27-year-old security flaw in OpenBSD that decades of professional security researchers had missed, and a vulnerability in the open-source video tool FFmpeg that had survived 5 million automated scans. Rather than ship the model, Anthropic is launching Project Glasswing, a consortium of more than 40 tech companies (including Cisco, Broadcom, Microsoft, Apple, and Amazon) whose blue-team cybersecurity defenders get exclusive access to harden their systems before the technology spreads.
The hosts explore why this isn’t just marketing hype. Selling a tool that can find novel exploits in any operating system would expose Anthropic to enormous liability and congressional scrutiny, and giving away $100 million in Claude credits to competitors is, as Casey puts it, “not how I personally would market a spooky new model.” They cite Alex Stamos, the former Yahoo and Facebook security chief, who confirms this is a genuine inflection point: AI models can now autonomously chain together exploits that human teams would never see. The optimistic scenario is that defenders patch the top 1% of critical infrastructure in six months. The pessimistic scenario is that Mythos can simply invent new exploits faster than anyone can patch them, especially as legacy code on routers and small-business networks lags behind.
The episode closes with two uncomfortable observations. First, the U.S. government has spent months trying to declare Anthropic a supply-chain risk and has banned federal agencies from using Claude — meaning a private San Francisco company now holds cybersecurity capabilities that the national security establishment cannot legally use. Second, model development at this scale remains entirely unregulated after the previous administration’s AI rules were rolled back. Kevin notes this reopens a “capability gap” between frontier labs and the public that hasn’t existed since the GPT-2 days. Casey recommends listeners take basic action — use a password manager, stop reusing passwords, enable multi-factor authentication — while defenders race to patch the internet before the bad guys catch up.
Highlights
”Are we going to have to rewrite all software?”
“When we were talking about the show this week and we were kicking around the idea of like, hey, exactly how big do we think this is, you pointed out that one question people have been asking this week is, ‘Are we going to have to rewrite all software?’ And I feel like usually when folks are kicking that question around, it’s a big story.” — Casey Newton, 1:55
Clip command
yt-dlp --download-sections "*1:55-2:25" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "rewrite-all-software.mp4"
”A 27-year-old security flaw in OpenBSD”
“This model apparently found a 27-year-old security flaw in OpenBSD. OpenBSD is an open-source operating system that runs on firewalls and routers. It is sort of like a critical security layer on the internet, and it was designed specifically to be hard to hack. And this model because of its advanced coding and reasoning capabilities was able to find this bug that 27 years worth of professional security researchers had not been able to find.” — Casey Newton, 4:03
Clip command
yt-dlp --download-sections "*4:03-5:13" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "openbsd-27-year-flaw.mp4"
”$100 million of Claude credits to competitors is not how you market a spooky new model”
“So instead of selling it, you give $100 million of Claude credits away to a consortium of companies that includes many of your competitors, which is what Anthropic is doing. That is not how I personally would market a spooky new model if I were in the business of marketing spooky new models.” — Casey Newton, 9:00
Clip command
yt-dlp --download-sections "*9:00-9:52" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "100m-claude-credits-competitors.mp4"
”A forced reset for the entire cybersecurity industry”
“I think this is going to be a kind of forced reset for the entire cybersecurity industry and a very significant event in the history of technology.” — Kevin Roose, 13:16
Clip command
yt-dlp --download-sections "*13:16-13:58" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "forced-reset-cybersecurity.mp4"
”Iran is currently hacking our critical infrastructure”
“Just to make it concrete, like we are currently at war with Iran, and Iran is currently hacking our critical infrastructure. There was a story in Wired this week about them successfully hacking like water and energy infrastructure. Right now they’re able to do that without a Mithos-quality model. I would be quite nervous about what they could do if something like that fell into their hands.” — Casey Newton, 13:41
Clip command
yt-dlp --download-sections "*13:41-14:30" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "iran-hacking-infrastructure.mp4"
”Model development of this scale remains essentially unregulated”
“It is crazy to me that model development of this scale and seriousness remains essentially unregulated in this country, right? Here you have a private company saying, ‘Well, we have now created software that can create so many different kinds of novel exploits that all software might have to be rewritten,’ and they are not really under any kind of regulatory regime.” — Casey Newton, 15:12
Clip command
yt-dlp --download-sections "*15:12-15:54" "https://www.youtube.com/watch?v=oBZ5W758y4o" --force-keyframes-at-cuts --merge-output-format mp4 -o "model-development-unregulated.mp4"
Key Points
- Ship it or zip it exception (0:54) - Hard Fork’s rule about only covering shipped AI models is being broken because the implications are too significant to ignore
- Project Glasswing announced Tuesday (2:37) - Named after the glasswing butterfly with transparent wings; consortium gets exclusive access to do defensive cybersecurity testing
- Consortium membership (3:10) - Cisco, Broadcom, Microsoft, Apple, Amazon and “basically every big tech company that is not OpenAI or Meta”
- 27-year OpenBSD bug found (4:03) - In an OS designed specifically to be hard to hack, used in firewalls and routers worldwide
- FFmpeg flaw missed by 5 million scans (5:13) - Critical exploit in popular open-source video software found despite millions of automated security scans
- Alex Stamos confirms it’s a real inflection point (6:30) - Former Yahoo and Facebook security chief says models can now autonomously chain exploits humans would never find
- Why this isn’t a marketing strategy (8:19) - Liability, congressional hearings, and rational corporate self-interest mean companies don’t sell cyber weapons on the open market
- $100M in Claude credits to competitors (9:00) - Anthropic giving away access including to its competitors, structured for blue-team defenders only
- Two scenarios from Stamos (10:52) - Either there’s a finite number of critical bugs to patch, or Mythos can just invent new exploits indefinitely
- The legacy code problem (12:00) - Even if patches are issued, there’s a human bottleneck to review them and a long lag before users update routers and firmware
- Forced reset for cybersecurity (13:16) - Kevin predicts a very significant event in the history of technology over the coming months
- Iran already hacking infrastructure without Mythos (13:41) - Wired report on Iranian attacks on water and energy infrastructure raises stakes if such tools leak
- Government banned from using Anthropic’s tech (13:58) - U.S. government has tried to declare Anthropic a supply-chain risk and ordered federal agencies to stop using Claude
- Unregulated frontier development (15:12) - Previous administration’s AI regulations were thrown out by current one citing American competitiveness concerns
- The capability gap returns (15:54) - First major gap between lab and public capabilities since GPT-2 in 2019
- Anthropic’s founding thesis in action (18:22) - Build at the frontier to influence its safer direction; Pentagon fight and Mythos as examples
- Self-fulfilling prophecy concern (19:46) - Casey worries innovations trickle down even when frontier development isn’t actually inevitable
- Practical user advice (21:00) - Use a password manager, never reuse passwords, enable multi-factor authentication everywhere
Mentions
Companies
- Anthropic (0:07) - Maker of Claude Mythos Preview; Casey’s fiance works there; running Project Glasswing consortium
- Cisco (3:10) - Internet infrastructure maker; member of the Project Glasswing consortium
- Broadcom (3:10) - Internet infrastructure maker; consortium member
- Microsoft (3:10) - Big Tech consortium member; also being sued by NYT
- Apple (3:10) - Big Tech consortium member
- Amazon (3:10) - Big Tech consortium member
- OpenAI (1:25) - Being sued by NYT; notably excluded from Project Glasswing consortium
- Meta (3:10) - Notably excluded from Project Glasswing consortium
- Perplexity (1:25) - Being sued by the New York Times over alleged copyright violations
- Yahoo (6:30) - Where Alex Stamos formerly led security
- Facebook (6:30) - Where Alex Stamos went after Yahoo
- Wired (13:41) - Reported on Iran successfully hacking U.S. water and energy infrastructure
- The New York Times (1:25) - Kevin’s employer; suing OpenAI, Microsoft, and Perplexity
- Platformer (0:02) - Casey Newton’s publication
- 1Password (21:00) - Password manager Casey personally uses
Products & Technologies
- Claude Mythos Preview (0:07) - The new unreleased Anthropic model at the center of the episode
- Project Glasswing (2:37) - Anthropic initiative giving 40+ tech companies controlled access to Mythos for defensive cybersecurity
- OpenBSD (4:03) - Open-source OS used in firewalls and routers; Mythos found a 27-year-old flaw in it
- FFmpeg (5:13) - Popular open-source video software where Mythos found a critical exploit missed by 5 million automated scans
- Linux kernel (8:19) - Cited as an example of critical infrastructure that could be exploited by such a model
- GPT-2 (15:54) - The 2019 model OpenAI initially held back over misinformation fears; last comparable capability gap
People
- Alex Stamos (6:30) - Former head of security at Yahoo and Facebook; provided independent gut-check that Mythos is a real inflection point
- Ronan Farrow (0:35) - New Yorker writer interviewed in next episode about Sam Altman profile
- Andrew Marantz (0:35) - New Yorker writer co-authoring the Sam Altman profile
- Sam Altman (0:35) - OpenAI CEO; subject of upcoming New Yorker profile mentioned at top of episode
Surprising Quotes
“This model apparently found a 27-year-old security flaw in OpenBSD.” — Casey Newton, 4:03
“The entire internet is held together with spit and glue and we’re very lucky that there hasn’t been a catastrophe yet.” — Casey Newton, 6:30
“If you’re a corporation and you release a tool and people with no real technical expertise are able to use it and within a few hours discover a novel exploit in the Linux kernel and then take over other people’s machines to cause crimes, you might be held liable as a corporation.” — Casey Newton, 8:19
“A private company right here in San Francisco currently has a technology that they claim is capable of finding critical security vulnerabilities in every major operating system and web browser in the world, and the US government, to my knowledge, does not have access to this technology.” — Kevin Roose, 13:58
“I hope Casey doesn’t call off the wedding… I hope that you do not break your fiancé’s heart because he now has access to a model that could ruin your life.” — Kevin Roose, 19:55
Transcript
Kevin Roose: 0:00 I’m Kevin Roose, a tech columnist at the New York Times.
Casey Newton: 0:02 I’m Casey Newton from Platformer.
Kevin Roose: 0:04 And this is Hard Fork! Alright Casey, we are going to talk about Claude Mythos preview, the new scary, dangerous, unreleased model from Anthropic that has the whole cybersecurity world on edge. We’ll talk about Project Glasswing, which is their attempt to give the good guys a head start in using this model to secure the internet before the bad guys get it, and what it all means. And we’re going to release this ahead of our normally scheduled episode because…
Casey Newton: 0:33 We couldn’t hold it back any longer.
Kevin Roose: 0:35 Yeah. And tomorrow, we’ll release the rest of the show, including our interview with New Yorker writers Ronan Farrow and Andrew Marantz on their spicy new profile of Sam Altman.
Casey Newton: 0:44 You don’t have any disclosure merch to my knowledge, so I had these made for you.
Kevin Roose: 0:47 Come on!
Casey Newton: 0:49 One for each.
Kevin Roose: 0:51 Plus, one of our favorite segments, ‘One Good Thing’. Well Casey, as you know, on this podcast, we have a rule about discussing AI models called ‘ship it or zip it’.
Casey Newton: 1:05 Ship it or zip it! Unless you’re actually putting it in people’s hands, we usually do not want to hear about it.
Kevin Roose: 1:10 Yes, but today we are making an exception for the new Anthropic model, Claude Mythos preview, that just was announced but not released to the public for reasons that we will talk about. But first, since this will be a segment and a show about AI, our disclosures. I work for the New York Times, suing OpenAI, Microsoft, and Perplexity over alleged copyright violations.
Casey Newton: 1:33 And my fiancee works at Anthropic.
Kevin Roose: 1:35 Casey, this is I want to say like the biggest story of the year in AI. I know there’s been a lot of AI news, I know that people are probably saying, oh, here they go talking about another model again. I am telling you this is something that people need to be paying attention to because of the implications, because of the way it was rolled out, and because of the model itself, which we will get to all of that, but do you agree that this is a big deal?
Casey Newton: 1:55 Well, you know, when we were talking about the show this week and we were kicking around the idea of like, hey, exactly how big do we think this is, you pointed out that one question people have been asking this week is, ‘Are we going to have to rewrite all software?’ And I feel like usually when folks are kicking that question around, it’s a big story.
Kevin Roose: 2:14 Yes. So this has been, just for a little bit of background here, there have been rumors for weeks now about some new incredible model that Anthropic had cooked up.
Casey Newton: 2:25 And in part those rumors emerged when there was a leak of a blog that the company had drafted to talk about this model. That happened about two weeks ago and so people have been buzzing ever since.
Kevin Roose: 2:37 So let’s just talk through what was actually announced this week. So on Tuesday, Anthropic announced that it was starting something called Project Glasswing. I got to interview some executives over there about this. They told me that the name Project Glasswing refers to the glasswing butterfly, which has transparent wings and…
Casey Newton: 3:00 so it can hide in plain sight and that is thematically important for reasons that we will come back to.
Kevin Roose: 3:04 It’s also a delicacy in some countries.
Casey Newton: 3:07 I’ve never had glasswing butterfly.
Kevin Roose: 3:09 Oh, you gotta try it.
Casey Newton: 3:10 So notably, they are not releasing this model to the public because they claim it is too dangerous to do that. Instead, they are giving access to a consortium of tech companies including Cisco, Broadcom, sort of makers of internet infrastructure, as well as Microsoft, Apple, Amazon, basically every big tech company that is not OpenAI or Meta is getting access to this model, but not general access. Just access to do defensive cybersecurity testing, basically to go out and harden their systems and their infrastructure and their software before the general public can get its hands on this model.
Kevin Roose: 3:54 So what are some examples of what Mythos was doing in training that so alarmed Anthropic that it came to this point?
Casey Newton: 4:03 So Anthropic has been running this model internally for several weeks now and they claim that this thing has found vulnerabilities in every major operating system and web browser. They gave some examples that have already been patched. One of them was that this model apparently found a 27-year-old security flaw in OpenBSD. OpenBSD is an open-source operating system that runs on firewalls and routers. It is sort of like a critical security layer on the internet, and it was designed specifically to be hard to hack. And this model because of its advanced coding and reasoning capabilities was able to find this bug that 27 years worth of professional security researchers had not been able to find.
Kevin Roose: 5:11 Right. What else?
Casey Newton: 5:13 Another example was that it found a bug in a piece of popular open-source video software called FFmpeg that runs on a bunch of different services that had, according to Anthropic, been scanned for bugs 5 million times by automated security tools without finding this critical exploit.
Kevin Roose: 5:34 And that’s why it’s important to always look the 5 million and first time because you might find something. Now Casey, I think for people who are not cybersecurity experts it might be worth sketching the context here for how software works.
Casey Newton: 5:50 Yeah. Every piece of software, every operating system, every app, every web browser that people use is built on a mixture of tools. Some of those tools are proprietary to the companies that make the software. Some of them are sort of shared open-source tools that are just in everything. Companies will just grab this open-source thing and plug it into their thing.
Kevin Roose: 5:53 Because it’s compatible with everything else. Saves you a lot of time and trouble.
Casey Newton: 5:56 It’s already been security tested by decades sometimes of researchers and this piece of software
Kevin Roose: 6:00 It’s sort of a big piece of kind of the foundation layer of the internet are these open-source software projects. What is happening now, according to Anthropic, is that they can basically use this model, Claude Mithos Preview, to sort of proactively go out and find all of the unfound bugs, they call these zero-day exploits, in these critical pieces of software, with a sort of speed and efficiency that no human security research team could do.
Casey Newton: 6:30 Yeah. And, you know, I- I would say that it can be difficult to talk about cybersecurity in a way that resonates with people for a couple of reasons. Cybersecurity as a field exists essentially almost entirely to alarm people and say, ‘Here are a bunch of problems and these are really scary.’ And I think that, you know, I hope that folks in the cybersecurity field would not mind me saying, like, it- it is just like kind of an alarmist profession in that when I talk to these people over the past 15 years, they’ve been telling me like, ‘Look, the entire internet is held together with spit and glue and we’re very lucky that there hasn’t been a catastrophe yet,’ okay? So after all of this news came out, I was like, I- I want to talk to- some people who are at least not working for Anthropic or this consortium to try to give me a gut check on how big a deal this is. And so I talked to Alex Stamos, who formerly led security at Yahoo and then Facebook. And Alex said like, ‘Yes, this is a big deal,’ and he was hoping for a long time that we would see a consortium come together like this because of exactly what you just said, Kevin, the intelligence in these machines and their ability to work autonomously are now great enough that they can chain together exploits that human beings either would never see, would take them a long time to see, or they would just never get to because we’re- you know, we’re limited in ways that these machines are not. So, that got my attention.
Kevin Roose: 7:52 Now, we should also talk about, like, what the strategy is here from Anthropic, because I think a lot of people see an AI company that is known for sort of being alarmist about safety say, ‘We’ve created this powerful, spooky new model and we’re not going to show you because it’s too powerful and spooky’ as some kind of marketing tactic. So, I think we should just say, like, that is not, to my understanding, the case here.
Casey Newton: 8:19 No. And in- in my mind, it is obvious why. Like, if you’re a corporation and you release a tool and people with no real technical expertise are able to use it and within a few hours discover a novel exploit in the Linux kernel and then take over other people’s machines to cause crimes, you might be held liable as a corporation. You will get in trouble. At- like, there will be congressional hearings. So companies just in their rational self-interest do not want to sell cyber weapons on the open market.
Kevin Roose: 8:49 Yes, it’s also, like, if this was a marketing strategy, it is a horrible marketing strategy. Like, the government already thinks you’re a bunch of panicky doomers. You have a new model that you claim is the most powerful model…
Casey Newton: 9:00 on the world. So instead of selling it, you give $100 million of Claude credits away to a consortium of companies that includes many of your competitors, which is what Anthropic is doing. That is not how I personally would market a spooky new model if I were in the business of marketing spooky new models.
Kevin Roose: 9:18 Yeah. Now, look, it may be that despite everything that we just said, there is still some marketing benefit to Anthropic from doing this, right? Like we know that they saw a huge increase in their revenue after they took that stand against the Pentagon, and that is in that stand, they said like, we are determined to do things in a really safe way. It seemed like the business world really liked that. And so I could imagine there being a business benefit to Anthropic of coming out and saying, we have the most powerful model in the world and we’re not releasing it. Like, yes, I’m sure that there are plenty of businesses that are salivating over the chance to get their hands on it.
Casey Newton: 9:52 But they can’t. Unless they are part of this consortium, which is interesting in part because my understanding from talking to folks involved with the consortium this week is that it is not like all of the companies that are in this consortium are getting kind of employee-wide logins to this thing. It is being, my understanding is, reserved for the cybersecurity defense teams, the so-called blue teams at these companies who are in charge of doing penetration testing and other forms of cybersecurity research on their own products. So they are, at least claiming, that they are trying to get ahead of what they envision will be a sort of reckoning, was the word they used, for cybersecurity. And it seems plausible to me that in the next kind of six-ish months, every major piece of software in the world is going to need to be patched, rewritten, and re-released.
Kevin Roose: 10:52 So just an absolutely massive project. Let me ask you this, you know, Alex Stamos, the security expert that I mentioned, told me that he sees essentially like two broad possibilities. One is, and this is the good scenario, there are a finite number of critical bugs and vulnerabilities to be found, and that maybe if we all work really, really hard over the next six months or however long it turns out to be, we will be able to patch those vulnerabilities and our infrastructure will remain safe and stable. The other possibility is that this model is already good enough that it can just simply invent exploits that we never would have thought of, and so this will essentially just be a really, really big problem that potentially just keeps growing in scope because, you know, maybe eventually you hit some sort of true superintelligent point. So I’m curious if you’ve talked to people about what they see the scenarios are, and if you have any thoughts as to which of those two is more likely.
Casey Newton: 11:46 So I think that it’s somewhat unlikely. I think it’s possible that they will patch this sort of top 1% of critical software, right? The stuff that everyone knows is important. Your Linux, your, you know, your popular open-source libraries
Kevin Roose: 12:00 your routing equipment and networking equipment, like it seems plausible to me that a couple of companies with the right resources and the right models could like find and fix the worst security vulnerabilities. But I also talked to people who were telling me that it’s not as simple as that, because once you get outside that kind of top 1% of critical infrastructure, there’s just a lot of machines that are running on old code. Right? So it’s it’s it’s theoretically possible that all of these fixes could be submitted to the people who maintain these software projects, but that a) there aren’t enough humans to review all of the proposed bugs and fixes. So there just sort of is a human bottleneck there, or that there is just a lag in the time between when a piece of software is patched and when the person running the router at the, you know, medium-sized business in Tulsa decides to update the firmware or install the security patch. So I think there’s going to be, people are going to expect a lot of like apps that are asking them to like update their software or reinstall their software over the next few months. I’ve started getting a few of these already. Have you started getting these?
Casey Newton: 13:14 Um, yeah.
Kevin Roose: 13:16 Yeah, so I think this is going to be a kind of forced reset for the entire cybersecurity industry and a very significant event in the history of technology.
Casey Newton: 13:41 Yeah, well just to make it concrete, like we are currently at war with Iran, and Iran is currently hacking our critical infrastructure. There was a story in Wired this week about them successfully hacking like like water and energy infrastructure. Um, right now they’re able to do that without a Mithos-quality model. I would be quite nervous about what they could do if something like that fell into their hands. So this really is not an abstract concern that we’re laying out.
Kevin Roose: 13:58 Right. And we should talk about this government piece of this, because one weird characteristic of this moment is that this very powerful advanced model that Anthropic claims is capable of doing autonomous cybersecurity research and attacks is also a company that the U.S. government has spent the last several months trying to kill. Yeah. And has tried to declare Anthropic a supply chain risk. They have ordered all federal agencies to stop using Claude. And so my understanding is there have been some conversations between Anthropic and parts of the, you know, sort of national security establishment and apparatus about this model, but it is also simultaneously true that they cannot use this model without sort of running afoul of the administration. So a private company right here in San Francisco currently has a technology that they claim is capable of finding critical security vulnerabilities in every major operating system and web browser in the world, and the US government, to my knowledge, does not have access to this technology.
Casey Newton: 15:07 Yeah, it does seem like something that like our national security infrastructure would want to have access to. One more piece on the regulatory front: It is crazy to me that model development of this scale and seriousness remains essentially unregulated in this country, right? Here you have a private company saying, ‘Well, we have now created software that can create so many different kinds of novel exploits that all software might have to be rewritten,’ and they are not really under any kind of regulatory regime. And the regulatory regime that the previous administration tried to put into place was thrown out by the current one because it might harm American competitiveness. So I just want to say: that makes me really, really uncomfortable. I think that if you’re making stuff this powerful, regulators ought to be paying attention.
Kevin Roose: 15:54 Yeah. One interesting sort of historical note that I’ll make here is like, for the past few years, at least, there has not been kind of a significant gap between what the AI companies have built internally and what the public has access to. You know, maybe there’s a slightly better model that the companies are working on that they, you know, need to spend a few months testing before they release it.
Casey Newton: 16:21 Or it runs a little faster than the one that you have access to.
Kevin Roose: 16:23 Yeah, but there has not been kind of a significant gap since I think GPT-2, which was in 2019, which involved some of the leaders of Anthropic who were then at OpenAI, who made a decision to hold back this model, GPT-2, out of fear that it could be used for things like automating propaganda and misinformation.
Casey Newton: 16:46 In reality it could barely write a limerick, but you know, they erred on the side of caution.
Kevin Roose: 16:51 They did, and they got a lot of crap for that. People sort of said, ‘Oh, you’re using this to hype,’ some of the same stuff we’re hearing this week about Anthropic. And I think in that case, they were, you know, probably a little over-excited about what this model could do, but they wanted to make sure that they weren’t wrong, and so they held this back, and that created a gap of at least a couple months to maybe a year between what the average person could see and what was happening inside the AI labs. That gap is now open again. There is now a model that you and I cannot use, that our listeners cannot use unless they work at one of these companies in cybersecurity defense, and what the AI companies are claiming. And I think that is just a very tenuous situation, and I don’t like it, but I also understand why I think in this case this was the right decision.
Casey Newton: 17:43 Well, what do you mean when you say that it’s tenuous then?
Kevin Roose: 17:46 I think as hostile and suspicious as people feel toward the AI industry, that only gets worse if they think that there are secrets being kept in a basement that they can’t access. And I think that it creates paranoia and fear I think that it is generally responsible to have transparency from the AI companies about how capable their models are and I understand in this case that anthropic felt like it had to make an exception but uh I think this this gap may be here to stay is is the thing that I’m wondering
Casey Newton: 18:22 I think it probably is. I mean it’s worth saying that anthropic was founded on the idea that if it could build models that were at the state-of-the-art, at the frontier, that it could have some influence over that frontier and it could guide it to a safer place than it otherwise might have gone. To me, the pentagon fight and now Mythos are examples of that thesis in action, right? Where it made the best model and that gives it some room to try to do a little bit of good. So, you know, blocking domestic surveillance and autonomous weapons for a little while or preventing bad actors from getting their hands on, you know, tools that could create novel exploits. At the same time, in order to do that, they had to build the model in the first place and there is a risk that there is some sort of, I don’t know, intellectual property leakage that sort of somehow all of the innovations that they’re building are going to trickle down into other places. And my fear is just that it becomes this sort of self-fulfilling prophecy, right? Where we have to build this frontier even though it’s dangerous and we’re going to guide it to this safer place, but, you know, you did build the thing in the first place. So I just like reminding people of that tension because it is not actually inevitable that we build these systems and yet we do often act as if that were the case.
Kevin Roose: 19:46 Yeah. Can I tell you my honest… one of my first thoughts when I saw this Claude model?
Casey Newton: 19:54 Yeah.
Kevin Roose: 19:55 I hope Casey doesn’t call off the wedding. Because…
Casey Newton: 20:04 Why would I call off the wedding?
Kevin Roose: 20:05 I know, I know you’re not going to call off the wedding, but I hope that you do not break your fiancé’s heart because he now has access to a model that could ruin your life.
Casey Newton: 20:14 Oh trust me, I hear about that a lot. Yeah. Yes. Some people in my household are very excited about their fancy model that the other person in the household can’t use.
Kevin Roose: 20:22 Okay. So last thing, a lot of the people I know who are plugged into the cyber security world are being asked right now what people should do about their own security if they are worried that models like this will become public. Should they be like locking down all their accounts and moving their cryptocurrency into cold storage? Like, what do you think people should be doing in anticipation that something like this will become public?
Casey Newton: 20:44 You know, it’s funny, I had a friend ask me that just this morning as I was preparing for the podcast and I said, you know, a couple of things. Like one, to some extent we’re just going to have to wait. I mean to the extent that any of what we’ve just described is good news, it is that the defenders appear like they’re going to have some runway to fix some really bad problems before the bad guys catch up. So, I think we should give them a little bit of room to see what they can do. Uh, if it does emerge that there is a similar model that can wreak havoc, like rest assured there’ll be segments about it on Hard Fork and we’ll have some updated guidance. But I asked my friend, do you have a password manager and do you reuse passwords for the same thing? And she said, you know, I’ve never really been able to to get one of those uh password managers to work for me and I do sometimes reuse my passwords. So I said like, look, if if you’re looking for something that you can do, just make sure that you have done your basic online cybersecurity hygiene. You should use a password manager. I use 1Password, there are many uh others out there that are just as good. Uh, don’t use the same password for anything. Your passwords should be randomly generated and not, you know, the name of your pet or whatever. And then use multi-factor authentication where you can, right? So don’t let anybody get into like your Gmail or your banking account just by typing in eight letters. You should also be, you know, using an authenticator app, um, and so those are some of the basic things that I would tell people to do, Kevin.
Kevin Roose: 22:05 Yeah. I would— I am planning to deal with the uh possibility of a massive cybersecurity breach by just sort of selectively dribbling out incriminating things about myself. Uh just sort of trying to get ahead of any hacks that might expose my, you know, emails going back decades or anything like that. So I’ll just say in that spirit, I used to like the Black Eyed Peas.
Casey Newton: 22:26 Oh, okay.
Kevin Roose: 22:28 And I still do.
Casey Newton: 22:29 Let’s get it started.
Kevin Roose: 22:31 Now that was a critical vulnerability that I just exposed.
Casey Newton: 22:34 But but who will be the first to exploit it?
