Zvi covered this in a recent roundup. In gist, the smaller models don’t have Mythos’ ability to chain vulnerabilities and write effective exploits. They also have a much higher false positive rate. So their output would need extensive skilled manual effort to achieve anything near the same result. In contrast, Mythos output is directly useful to an attacker … or, fortunately, to a defender.
Zvi covered this in a recent roundup. In gist, the smaller models don’t have Mythos’ ability to chain vulnerabilities and write effective exploits. They also have a much higher false positive rate. So their output would need extensive skilled manual effort to achieve anything near the same result. In contrast, Mythos output is directly useful to an attacker … or, fortunately, to a defender.
See also this discussion on HN.