Transcript
Jordan Schneider (0:00)
Claude Mythos and national power. Has the atomic bomb just been discovered for cybersecurity? We have the two perfect guests on disgust to discuss Ben Buchanan, a big deal in the Biden White House on AI policy, who, full disclosure advises anthropic, as well as Michael Solmeier, who was a big deal in the Pentagon for cyber policy, lastly serving as Assistant Secretary of Defense for cyber policy. So how big a deal is Claude Myth?
Ben Buchanan (0:32)
This is a big one. I've been thinking about cybersecurity and AI for more than a decade. And I think a lot of us who were thinking about AI and cyber back then imagine that a day like this might come where you could see automated vulnerability discovery. It does feel like something that had long been imagined is actually now finally here. And it's up to all of us to figure out what that means.
Jordan Schneider (0:55)
So what can the model do?
Ben Buchanan (0:56)
What this system does at its core is it takes a general purpose capability. It is not a cyber built, cyber specific model. It takes a general purpose capability and then it applies that to the business of vulnerability discovery and exploit development. And as Michael can attest very well, these are fundamental tasks in cybersecurity. Finding a weakness in a piece of computer code and then figuring out how to exploit that weakness to do something as an attacker or as an intruder that you're not allowed to do. And the evidence is very clear that Claude Mythos is by far the best automated system in the world ever to do this, and is better than even some of the best expert humans in the world, or close to some of the absolute top tier expert humans in the world at this task of vulnerability discovery and exploit development. The proof is in the pudding here. It found vulnerabilities in code that all of our operating systems, all of our browsers are running. Those vulnerabilities in some cases had lurked there for multiple decades. In some instances, we thought that code was secure. Millions of automated tests had been run on that code, and yet Mythos found ways to exploit it. And I think there's a real raw capability there that is vital. And then I think the question is like, what's the analogy for that? That is really important question.
Jordan Schneider (2:16)
Let's stay on the sort of finding a 27 year old bug in a piece of open source software that the entire world uses. Like Michael, how wild is that?
Michael Sulmeyer (2:27)
That's pretty wild. It's pretty wild. I ended up talking, I think, to one of the original developers of some of that software and it was just silence, silence on the other end because.
