TRANSKRIPTEnglish

An initiative to secure the world's software | Project Glasswing

5m 42s953 ord35 segmentsEnglish

FULLSTÄNDIGT TRANSKRIPT

0:00

Most people who use software every day don't think about bugs. They don't think about what can happen if the software that they depend upon suddenly is less secure.

0:12

That's something that software developers have to deal with every single day.

0:20

So software has always had flaws and vulnerabilities. That's not new for an average person. The bugs are by and large not something they notice on a daily basis, because if they do, they get f.

0:32

But then every so often, there are vulnerabilities that have real severe impacts, like one single bug that works its way into shared software that many, many, many different products or websites use.

0:45

So one issue just gets magnified out around the world. So historically, finding and patching vulnerabilities has been a slow, time consuming and expensive process.

0:55

If LLMs are now able to write code at the level of some of the greatest software developers in the world, it can also be used to find bugs and exploit that software equally effectively.

1:10

These models have capabilities which are raising the bar from a cybersecurity point of view, with their ability to help defenders as well as potentially help adversaries.

1:23

We recently developed a new model called Claude Mythos Preview. Early on, it was clear to us that this model was going to be meaningfully better at cybersecurity capabilities.

1:33

There's a kind of accelerating exponential, but along that exponential, there are points of significance.

1:40

Claude Mythos Preview is a particularly big jump along that point. We haven't trained it specifically to be good at cyber.

1:48

We trained it to be good at code. But as a side effect of being good at code, it's also good at cyber.

1:53

The model that we're experimenting with is by and large as good as a professional human identifying bugs.

2:03

It's good for us because we can find more vulnerabilities sooner and we can fix them. It has the ability to chain together vulnerabilities.

2:10

So what this means is you find two vulnerabilities, either of which doesn't really get you very much independently.

2:16

But this model is able to create exploits out of three, four, sometimes five vulnerabilities that in sequence give you some kind of very sophisticated end outcome.

2:24

And we think that this model can do this really well because we notice that this model is very autonomous.

2:30

It's just generally better at pursuing really long range tasks that are kind of like the tasks that a human security researcher would do throughout the course of an entire day.

2:42

Obviously, capabilities in a model like this could do harm if in the wrong hands. And so we won't be releasing this model widely.

2:49

More powerful models are going to come from us and from others. But. And so we do need a plan to respond to this.

2:56

That's why we're launching what we're calling Project glasswing, where we partner with a number of the organizations that power some of the world's most critical code to put the model into their hands, to allow them to look at how they can use models like this to bring down risk and protect everyone.

3:12

And by giving these software developers advanced tools before anyone else, it gives all of us a collective head start.

3:22

It allows us to find things that we couldn't find before, and it helps us fix these things

3:29

much more quickly. Working with our partners, we've been finding vulnerabilities across essentially every major platform.

3:36

I found more bugs in the last couple of weeks than I found in the rest of my life combined. We've used the model to scan a bunch of open source code.

3:44

And the thing that we went for first was operating systems, because this is the code that underlies the entire Internet infrastructure.

3:52

For OpenBSD, we found a bug that's been present for 27 years where I can send a couple of pieces of Data to any OpenBSD server and crash it on Linux.

4:06

We found a number of vulnerabilities where as a user with no permissions, I can elevate myself to the administrator by just running some binary on my machine.

4:16

For each of these bugs, we told the maintainers who actually run the software about them, and they went and fixed them and have deployed the patches so that anyone who runs this software is no longer vulnerable to these attacks.

4:27

For a developer who tirelessly maintains software, a model that can help them discover vulnerabilities in their own code and fix them before they can be exploited, that is an invaluable tool.

4:40

We've spoken to officials across the US government and we've offered to work with them and collaborate to assess the risks of these models and to help defend against the risks of these models.

4:51

Everything that we do in our lives now depends on software. Software kind of ate the world. Every analog aspect of our life is somehow represented in digital domain.

5:01

And so all of our daily lives run on the idea that we can rely on the systems that power them. Cybersecurity is the security of our society.

5:11

It is essential that we come together and work together across industry to help build better defensive capabilities.

5:19

No single organization sees the whole picture and can tackle this on their own. This is not going to be done as part of a few week program.

5:25

This is going to be the work of certainly months, perhaps years. But what I do hope is that the at the end of this, we can be in a position where the world's software, its customer data, its financial transactions, its critical infrastructure are safer than they were before.

LÅS UPP MER

Registrera dig gratis för att få tillgång till premiumfunktioner

INTERAKTIV VISARE

Titta på videon med synkroniserad undertext, justerbart överlägg och fullständig uppspelningskontroll.

REGISTRERA DIG GRATIS FÖR ATT LÅSA UPP

AI-SAMMANFATTNING

Få en omedelbar AI-genererad sammanfattning av videoinnehållet, nyckelpunkter och slutsatser.

REGISTRERA DIG GRATIS FÖR ATT LÅSA UPP

ÖVERSÄTT

Översätt transkriptet till över 100 språk med ett klick. Ladda ner i valfritt format.

REGISTRERA DIG GRATIS FÖR ATT LÅSA UPP

MIND MAP

Visualisera transkriptet som en interaktiv mind map. Förstå strukturen med ett ögonkast.

REGISTRERA DIG GRATIS FÖR ATT LÅSA UPP

CHATTA MED TRANSKRIPT

Ställ frågor om videoinnehållet. Få svar från AI direkt från transkriptet.

REGISTRERA DIG GRATIS FÖR ATT LÅSA UPP

FÅ UT MER AV DINA TRANSKRIPT

Registrera dig gratis och lås upp interaktiv visning, AI-sammanfattningar, översättningar, mind maps och mer. Inget kreditkort krävs.

    An initiative… - Fullständigt Transkript | YouTubeTranscript.dev