6 ms·
AISLE’s autonomous analyzer found all CVEs in the January OpenSSL release
- TalkWithAI 8mo ago[dead]
- dnw 8mo ago"We submitted detailed technical reports through their coordinated security reporting process, including complete reproduction steps, root cause analysis, and concrete patch proposals. In each case, our proposed fixes either informed or were directly adopted by the OpenSSL team." This sounds like a great approach. Kudos!
- ktimespi 8mo agoLink seems to be down... But also, considering curl recently shut down its bug bounty program due to AI spam, this doesn't really inspire much confidence.
- M0dEx 8mo ago[dead]
- baby 8mo agoThis sounds amazing but not too much info on how it worked
- blibble 8mo ago> Finding a genuine security flaw in OpenSSL is extraordinarily difficult. history suggests otherwise > The fact that 12 previously unknown vulnerabilities could still be found there, including issues dating back to 1998, suggests that manual review faces significant limits, even in mature, heavily audited codebases. no, the code is simply beyond horrible to read, not to mention diabolically bad if you've never tried it, have a go, but bring plenty of eyebleach
- hnmullany2 8mo ago[dead]
- lumost 8mo agoIt really is just a collection of several dozen research grade implementations for algorithms + a small handful of load bearing algorithms for the entire internet. Surprisingly, OpenSSL isn't the only critical piece of internet architecture like this.
- ryandvm 8mo agoThe longer I develop software, the more I realize just how awful most software engineering it.
- dwattttt 8mo agoReferencing the classic https://xkcd.com/2030 https://xkcd.com/2030 "I don't quite know how to put this, but our entire field is bad at what we do, and if you rely on us everyone will die" "They say they've fixed it with something called <del>blockchain</del> AI" "Bury it in the desert. Wear gloves"
- doodlesdev 8mo agoHonestly, this is absurdly funny, but it makes me wonder whether we'll ever see Computer Science and Computer Engineering as seriously as other branches of STEM. I've been debating recently whether I should keep working in this field, after years of repeatedly seeing incompetence and complacency create disastrous effects in the real world. Oftentimes, I wonder if the world wouldn't be a bit better without the last 10 or 15 years of computer technology.
- dumpsterdiver 8mo ago> makes me wonder whether we'll ever see Computer Science and Computer Engineering as seriously as other branches of STEM It's about as serious as a heart attack at this point...
- move-on-by 8mo agoPretty impressive. Whether you think AI is a bubble or not, we all benefit from these findings. As for all the slop the Curl team has been putting up with, I suppose a fool with a tool is still a fool.
- apexalpha 8mo agoThe author of cURL posted on LinkedIn about this with praise and the addition that AISLE has reported vulns to them in the past. https://www.linkedin.com/posts/danielstenberg_vulnerabilities-activity-7422052648339623936-T_j_?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAWUgYkBLv74b28yufDnM55PYlwWWRX1KHE https://www.linkedin.com/posts/danielstenberg_vulnerabilitie...
- bandrami 8mo agoI'm bearish on AI creating working software but bullish on AI doing this kind of thing
- cryptonector 8mo agoAI is definitely creating working software. It's also leading people to submit hallucinations as security vulns in open source. I've had to deal with some of them.
- bandrami 8mo agoNah, if that were true there would be a lot more new software available. What's it working at is making developers feel busy, which is itself a worthwhile task.
- dboreham 8mo agoThere may be some other limiting factors on the rate of generation of new useful software. E.g. money to market it, humans to specify it, perhaps there's enough software already...
- bandrami 8mo agoIf there's enough software already than LLMs are the worst-timed invention in human history...
- rascul 8mo agoMaybe it's available but you don't realize it.
- bandrami 8mo agoMaybe. Sounds like a real marketing failure in that case
- lmm 8mo ago
- martinald 8mo agoThis really is quite scary. I suspect this year we are going to see a _lot_ more of this. While it's good these bugs are being found and closed, the problem is two fold 1) It takes time to get the patches through distribution 2) the vast majority of projects are not well equipped to handle complex security bugs in a "reasonable" time frame. 2 is a killer. There's so much abandonware out there, either as full apps/servers or libraries. These can't ever really be patched. Previously these weren't really worth spending effort on - might have a few thousand targets of questionable value. Now you can spin up potentially thousands of exploits against thousands of long tail services. In aggregate this is millions of targets. And even if this case didn't exist it's going to be difficult to patch systems quickly enough. Imagine an adversary that can drip feed zero days against targets. Not really sure how this can be solved. I guess you'd hope that the good guys can do some sort of mega patch against software quicker than bad actors. But really as the npm debacle showed the industry is not in a good place when it comes to timely secure software delivery even without millions of potential new zero days flying around.
- CharlesW 8mo agoIt's good these bugs are being found and closed. The problems have nothing to do with AI, unless I'm missing something.
- c-hendricks 8mo agoPicture the traumatized Mr. Incredible meme with the text "lowering the barrier means more exploits are found"
- xboxnolifes 8mo agoIf people can use AI to find bugs to close them, people can use AI to find bugs to exploit them. The scale has changed.
- semiquaver 8mo agoAnd the project maintainers or their allies can use AI to find bugs and fix them.
- crm9125 8mo ago"Humans + AI" ... Without Humans, AI does nothing. Currently, at least.
- pizlonator 8mo agoImpressive. I checked the stack overflow that was marked High, and Fil-C prevents that one. One of the out-of-bounds writes is also definitely prevented. It's not clear if Fil-C protects you against all of the others (Fil-C won't prevent denial of service, and that's what some of these are; Fil-C also won't help you if you accidentally didn't encrypt something, which is what another one of these bugs is about). The one about forgetting to encrypt some bytes is marked Low Severity because it's an API that they say you're unlikely to use. Seems kinda believable but also ....... terrifying? What if someone is calling the AESNI codepath directly for reasons? Here's the data about that one: "Issue summary: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated. Impact summary: The trailing 1-15 bytes of a message may be exposed in cleartext on encryption and are not covered by the authentication tag, allowing an attacker to read or tamper with those bytes without detection."
- arcfour 8mo agoIt would be very surprising to see someone use OCB when GCM exists and is what everyone uses. Although I agree in principle it is quite scary!
- pizlonator 8mo ago> It would be very surprising to see someone use OCB when GCM exists and is what everyone uses. That is reassuring
- SAI_Peregrinus 8mo agoOCB can be a bit faster than GCM, the only reason GCM took over is because OCB was patented. That patent has now lapsed, but since everyone uses GCM the performance advantage of OCB isn't likely worth switching for. Especially since GCM has hardware acceleration, and IIRC OCB can't benefit from that so it may actually decrease performance on modern CPUs.
- arcfour 8mo ago
- jeffbee 8mo agoI don't know why you're still using OpenSSL but if you're able to switch I note that BoringSSL was not affected by any of the January 2026 OpenSSL advisories, and was also not affected by any of the advisories from 2025, and was affected by only one of the 2024 advisories. I also note that I don't see any hasty commit activity to s2n-tls that looks like a response to these advisories. Better software is out there.
- cookiengineer 8mo agoI wanted to mention WolfSSL. I like to recommend that project because it has a very transparent vulnerabilities approach, and is in my opinion written a lot more sane than OpenSSL which is somewhat not using standard C features because it always implements everything from scratch like a kernel does. But yeah, anyways, WolfSSL comes from the embedded area in case that's your thing. [1] https://www.wolfssl.com/ https://www.wolfssl.com/ [2] https://github.com/wolfssl/wolfssl https://github.com/wolfssl/wolfssl
- aster0id 8mo agoHow many false positives did the AI throw up?
- ape4 8mo agoI wonder too. Did it take many human hours to verify everything?
- tyre 8mo agoDoes it matter? They found 12 vulnerabilities. Clearly there was enough signal:noise that they could uncover these as real. It doesn't look like they had 1 AI run for 20 minutes and then 30 humans sift through for weeks.
- awesome_dude 8mo ago> It doesn't look like they had 1 AI run for 20 minutes and then 30 humans sift through for weeks. It does, though, look like they were running their AI over the codebase for an extended period of time (not per run, but multiple runs over the period of a year) > Does it matter? Hell yes, false reports are the bane of the bug bounty industry.
- microtonal 8mo agoDoes it matter? Yes, we have been on the receiving end of AI generated bug reports and in the vast majority of cases they are really bad. But you still need humans to sift through them. And when you ask the submitter questions, it’s often clear that they just give the questions to an LLM again to answer. It costs a huge amount of human manpower, so if the company who made this had an AI based solution with a far lower false-positive rate, that would be great.
- awesome_dude 8mo agoThey don't appear to go into detail about anything except how great it is that they found the bugs, what those bugs were, and how rare it is for other people to find bugs. I think that it would be helpful from a research point of view to know what sort of noise their AI tool is generating, but, because they appear to be trying to sell the service, they don't want you to know how many dev months you will lose chasing issues that amount to nothing.
- ChrisArchitect 8mo agoRelated: OpenSSL: Stack buffer overflow in CMS AuthEnvelopedData parsing https://news.ycombinator.com/item?id=46782662 https://news.ycombinator.com/item?id=46782662
- panzi 8mo agoWhat kind of AI does this use?
- _JoRo 8mo agoDoes anyone have any recommendations on best practice security methods? As others have said, it sounds like there may be an order of magnitude more vulnerabilities found / exploited, and I'm wondering if security such as 2FA and Password Managers will be enough? Should people be getting on board with other protections such as security keys?
- ggm 8mo agoOpenSSL is a very odd codebase, it's grown by accretion, under many stewards, with several flavours of coding belief, over time from SSLEAY which Eric Young coded over 2 decades ago. It had chip-specific speedups from the days of the Intel 486. I was part of a body which funded work to include some stuff in the code, and the way you take something like X509 and incorperate a new ASN.1 structure inside the code, to be validated against conformance requirements (so not just signing blindly over the bitstream, but understanding the ASN.1 and validating it has certain properties about what it says, like not overlapping assertions of numeric ranges encoded in it) is to invoke callouts from deep down, to perform tasks and then return state. You basically seem to have to do about a 5 layer deep callout and return. It's a massive wedding cake of dependency on itself, it personifies the xkcd diagram of "...depends on <small thing>" risks. I'm not surprised people continue to find flaws. I would like to understand if this approach also found flaws in e.g. libsodium or other more modern crytography, or in the OpenBSD maintained libreSSL code (or whatever it is) or Peter Gutmann's code. OpenSSL is a large target.
- jibal 8mo agoThe title change from "AISLE" to "AI" is misleading. As the article states, > This doesn't mean that AI can replace human expertise. The OpenSSL maintainers' deep knowledge of the codebase was essential for validating findings and developing robust fixes. But it does change the SLA of security. When autonomous discovery is paired with responsible disclosure, it collapses the time-to-remediation for the entire ecosystem.
- mvkel 8mo agoSo here we have OpenSSL, coded by humans, universally adopted by the Internet, universally deemed to be terrible code. More evidence that "coding elegance" is irrelevant to a product's success, which bodes well for AI generated code.
- kajaktum 8mo agoOpenssl? Code elegance?
- hnmullany2 8mo ago[dead]
- jkingsman 8mo agoI think they're saying that OpenSSL is NOT elegant, but that it is successful regardless; hence, code elegance is irrelevant to whether a product is successful or not (and thus that horribly ugly LLM-generated code has a shot at becoming successful).
- deleted 8mo ago[deleted]
- not_a_bot_4sho 8mo agoIf anything, this is evidence that coding elegance has value. The unexpected part here being that AI brings specks of elegance to a terrible, inelegant codebase.
- chris_wot 8mo agoIt seems to me that after seeing some of the presentations by the LibreSSL folks that OpenSSL is not evidence of elegant code.
- lmm 8mo agoThe sad reality is that if your code is available for free and works most of the time, nothing else matters. I'm not sure I would call it "product success" given that OpenSSL's income is enough to cover, like, one dude in a LCOL country some of the time.
- Thaxll 8mo agoWhat's the kind of prompt / flow to get Claude to work on those security tasks?
- viraptor 8mo agoSame as for people. You establish what the threat model is and then have multiple approaches. For example going through all interesting operations, tracking down their inputs and data flow, then looking for edge cases along the way. If you have enough time / tokens, this becomes more of a spreadsheet/checklist exercise. The more experience you have, the better you can prioritise that list towards paths that are more likely to be disrupted.
- wolfi1 8mo agook, so the USP for this analyzer is: 'He hackers, if you look for zero-days we've got the tool for you!'
- rascul 8mo agoOnly 12?
- portender 8mo agoThe fun thing to me here is that a ton of really creative thinkers are going to have access to tools (LLM agents) that allow them to test their thinking quickly. I dearly hope that this leads to a prolonged phase of pain and loss. We made good choices when we decided the information on the internet should be delivered by simple, open protocols. We made bad choices when we decided that the information on the internet didn't need to be verified, or verifiable. Then we slipped on our good choices, because our bad choices let robber barons claim the verified or verifiable case. And then we were left an explosive entropy shit-pile. But now the new tools the new overlords are paying us to use will help us break free from their shackles, bwahahahahahahahahahahahah!!!!
- mrbluecoat 8mo agoLike any powerful tool, used responsibly in the right hands it could lead to great good; in the wrong hands or used irresponsibly, it could be extremely dangerous.
- yes_man 8mo agoI don’t want to discredit the authors but just want to offer couple of hypothetical points in these paranoid times. From a marketing angle, for a startup whose product is an AI security tool, buying zero-days from black market and claiming the AI tool found them might be good ROI. After all this is making waves. Or, could it be possible the training set contains zero-day vulnerabilities known to three-letter agencies and other threat actors but not to public? These two are not mutually exclusive either. You could buy exploits and put them in the training set. I would not be surprised if it is legit though.
- mnicky 8mo agoTo your second point - why would you need this? There are _plenty_ of previously found CVEs to train on. Also, I don't think the three letter agencies would share one of the most prized assets they have...
- ChrisArchitect 8mo agoRelated: AI discovers 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty) https://www.lesswrong.com/posts/7aJwgbMEiKq5egQbd/ai-found-12-of-12-openssl-zero-days-while-curl-cancelled-its https://www.lesswrong.com/posts/7aJwgbMEiKq5egQbd/ai-found-1...
- tqk_x 8mo agoUnfortunately you have to "request a demo" while supplying a company name and getting past a Cloudflare CAPTCHA. So again this is not reproducible and everything is hidden behind an SaaS platform. That is apparently the future people want.