Simon Willison's Weblog·1 month ago·
27
● 37 sources
Anthropic researchers used Claude Mythos to discover cryptographic weaknesses in the HAWK algorithm and a reduced-version of AES through iterative prompting. The model spent 60 hours on the task at an estimated cost of $100,000 in API fees, with human prompts primarily serving to prevent the model from abandoning the search. The findings have no practical security impact on current systems but demonstrate how language models can assist in mathematical cryptanalysis research when properly guided.
Zvi (Don't Worry About the Vase)·1 month ago·
10
● 5 sources
Anthropic released Claude Opus 5, positioning it as a cheaper alternative to their flagship Fable 5 model at half the API token cost while delivering comparable performance on most real-world tasks. Opus 5 achieves state-of-the-art scores on benchmarks like Frontier-Bench and GDPval-AA, and is notably the most resistant to prompt injection attacks of any Claude model to date. However, the model struggles with high-level autonomous reasoning compared to Fable, has polarizing personality traits that many users find off-putting, and ultimately does not expand what's possible—it mainly offers a cost-effective option for specific use cases like subagent work and bounded tasks.
A programmer reflects on his changing relationship with AI coding tools, noting that after years of skepticism he now uses Claude and local models for work while remaining frustrated by rapid AI-generated projects in the vintage computing community. The author contrasts his years-long manual development efforts with AI tools that can produce comparable functionality in weeks, creating tension between appreciating the technology's utility and worrying his handcrafted work will be overshadowed. He concludes that while AI-generated tools may be useful to the community, he can continue his own projects at his own pace without viewing them as wasted effort.
Every AI story that matters,
in your inbox by 8am.
TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the
day in two minutes. Follow companies and topics for alerts, or get the
briefing in Slack. Free, no spam, unsubscribe anytime.
Reading TLDRocket needs no cookies, and the readership counts we rely on come from
our own cookieless analytics. Google Analytics is the exception: it sets cookies and
reports to Google, so it stays switched off until you allow it. You can change your
mind any time from “Cookie settings” in the footer.
Strictly necessary
Session security and form protection (tldrocket-session,
XSRF-TOKEN, 2 hours). The site cannot work without them,
so they need no consent.
Always on
Google Analytics 4 (_ga,
_ga_<id>, up to 2 years). Measures which
stories and sections readers use. Google acts as a third-party processor and may
store the data outside the EU. No advertising, no profiling, no data sold.