• morrowind@lemmy.ml
    link
    fedilink
    English
    arrow-up
    73
    arrow-down
    2
    ·
    3 days ago

    In a weird sort of way it does. Consider all of the following

    1. big companies are often incompetent and inefficient in a lot of ways
    2. The mozilla foundation has confirmed the security issues that Anthropic found were real
    3. Generally over the past few years, anthropic has some of the best, most reliable models
    4. Claude code has been kinda bad for a while
    5. Claude code has been mainly bot-written for a while as well. This can lead to functional, decent code that’s still terrible in many ways as seen from the leak. Also it’s entirely possible that bots are worse at detecting issues in bot written code. You could argue if they were good at it, they would be less likely to write those security issues in the first place?
    6. Anthropic could have very skilled ml engineers but mediocre software developers
    • dfyx@lemmy.helios42.de
      link
      fedilink
      English
      arrow-up
      41
      ·
      3 days ago

      On the other hand: if their new tool is so great, why haven’t they used it to fix Claude’s security issues?

      • kkj@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        They don’t claim that it fixes issues, only that it finds them. Maybe they know about all the issues but can’t wade through the spaghetti well enough to do anything about them.

      • bort@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        15
        ·
        3 days ago

        sorry for the snark, but

        big companies are often incompetent and inefficient in a lot of ways

      • eru@mouse.chitanda.moe
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        3 days ago

        because their new tool is new and the leaked code for claude’s frontend was written before mythos was considered mature enough to throw at your codebase?