How secure is openwrt for Anthropic’s "Mythos" AI?

You probably already saw the news about Anthropic’s "Mythos" AI model.
Article on Scientific American.

I know China has same kind of AI, and they planning to make it open source to the public in a year.

When knowing this, I totally look different to the rj-45 connector on the wan port :rofl:.

How much security do we have? Openwrt is the most up-to-date firmware a enduser can use on a home router.

OpenWRT is as secure as the upstream repositories are, so as good as it gets.

But we indeed live in troubled times and you need to keep an eye on the available updates

No Mr. Snowden it would be best to disconnect from the Internet and build a cabin out in the woods.... /s

I guess you haven't seen the movie. ; )

I have the same question.

I read somewhere that these times open source is potentially more vulnerable than close source, because modern AI models specialized in finding security vulnerabilities like Claude Mythos can scan the source code and finds numerous vulnerabilities.

Claude Mythos is not yet available to the public as far as I know. Hence, IMHO it would be important that if possible some lead openwrt developer gets hands on Claude Mythos preview (like Mozilla firefox browser, see here), find the potentially existing vulnerabilities in openwrt and fix them before such powerful AI models get public and others exploit the vulnerabilities...

Anthropic has actually been collaborating with the Linux Foundation on securing the Linux kernel and related toolchains since long before software supply chain security became a mainstream topic.

What makes their approach especially interesting is their binary scanning capability. Unlike tools that only analyze source code, Mythos can scan compiled binaries directly to identify CVEs in executables, libraries, and firmware. It can also analyze proprietary or legacy binaries where source code is unavailable, and help verify that malicious code was not introduced during the build process itself.

Long live OSS.

That means, it can also be faster fixed then closed source firmwares.

It would be nice that those companies first give the possibility to scan for vulnerabilities to developers of software, especially open source. To let developers know what to fix.

How uncomfortable are the mass general windows users? Because that is so much used on desktops.

It's certainly not a step change to Opus 4.7 from the analyses I've read.

This is just Anthropic creating a marketing hooh-hah to cover for the fact that they underinvested in compute resource and don't dare make Mythos generally available yet because it will cause their service quality to drop like a stone.

"We can't release it yet because we don't have the compute resource to do so" becomes "We can't release it yet because we don't trust it in your hands". The latter definitely makes them look better!

See also this news from google threat intelligence group: https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?hl=en

In the Dutch news today (from public broadcast).

Urgent call due to AI hacking: 'We must be able to respond super fast'

Quickly and easily searching for security problems in computer programs: it is possible with artificial intelligence (AI). These AI systems work faster than a human and never get tired. And that can have major consequences for digital security for all kinds of companies and organizations.

The AI ​​systems can detect serious security problems. For example, vulnerabilities that can be used to hack or shut down computers. These could be errors that have been present in computer programs for years, while no one noticed.

"That is why companies and organizations must be able to respond super fast," warns Matthijs van Amelsfort, director of the National Cyber ​​Security Center (NCSC). "In the past, it took days for an attacker to exploit a flaw; now it takes hours," he says. "That will become minutes."

The urgent warning is known to the people in charge, says Dimitri van Zantvliet. He is chairman of the professional association for those people: the CISO Platform. "There is no panic, but it is certainly urgent," he says. This week, hundreds of them gathered at an event, partly to discuss this. "This development means that vulnerabilities are being found in systems that are already twenty years old. We need to accelerate so that we fix those errors before they are exploited."

Government hacked with the help of AI

Rogier Fischer of cybersecurity company Hadrian proves that you can find security problems quickly and automatically using AI programs. At the Amsterdam office, he demonstrates how he was able to hack the government using them.

Fischer had an AI system examine the programming code of a government website. He asked if there was a specific error that would allow him to gain access to files that are not supposed to be accessible. The AI ​​program replied that this was indeed the case.

Because of that error, Fischer was able to download a file, even though he is not supposed to be able to access it. He points it out on his screen. "Here you literally see the passwords," he says.

With that, Fischer was able to log into the website's database. "There was nothing stopping me," says the hacker. "Once you are inside, you can, for example, modify things. Or carry out new attacks in that database. We don't do that: we have already demonstrated that we had access. So we stopped the attack."

'Full access for 10 euros'

Hadrian was able to hack the government using a cheap AI program from OpenAI, the company behind ChatGPT, Fischer explains. He estimates the total attack cost him about 10 euros. "So that gave me full access."

Other cheap AI programs are also suitable for finding these types of errors, according to research by cybersecurity company AISLE. Since September, the company has found more than two hundred errors using various AI systems, says Jaya Baloo, one of the founders.

AISLE investigated, among other things, whether cheap systems could find errors in two computer programs that were also recently discovered using the AI ​​program Mythos. The company behind Mythos used those two errors found by the program to advertise the AI ​​system. This is so good, the company said, that only a very small group gets access to it.

"The story was that AI was 'suddenly' very good at finding vulnerabilities," says Baloo. "But we could find those same flaws with older AI systems. So how is that 'suddenly'? We have been doing this for months."

Finding even more flaws

Baloo and Fischer believe that defenders currently have the advantage. But there is urgency, they say: if criminal hackers get to work with these AI programs, they can also find and exploit these security problems.

"Technology is often used by people with bad intentions after a few months," says NCSC Director Van Amelsfort. It is important to take that seriously into account, because it concerns the digital security of us all, he says. We have already experienced a port being shut down or our data being stolen. The Netherlands is highly digital. That also makes us vulnerable. Attackers and defenders will continue to fight each other, even with this AI development. We really need to ensure that our defenses are in order.

You already know that updates won't save us against a zero-day. But those who ran stock home router firmware would be hacked first. Then it is irrelevant to further secure our system, even if it is hackable.