3 ms·
Perhaps this was due to their red-teaming partnership [1][2] with Anthropic which they wrote about a few months earlier in March? 1: https://www.anthropic.com/
by ayewo 2mo ago
Perhaps this was due to their red-teaming partnership [1][2] with Anthropic which they wrote about a few months earlier in March?
1: https://www.anthropic.com/news/mozilla-firefox-security https://www.anthropic.com/news/mozilla-firefox-security
2: https://blog.mozilla.org/en/firefox/hardening-firefox-anthropic-red-team/ https://blog.mozilla.org/en/firefox/hardening-firefox-anthro...
Previous discussion: https://news.ycombinator.com/item?id=47273854 https://news.ycombinator.com/item?id=47273854
- MostlyStable 2mo agoI just did a search and apparently this fact (the specific one about no payouts for the first time in almost 20 years) has not gotten a discussion on HN. Given the degree of skepticism around the utility of AI bug finding and fixing (this very thread is full of it), I would have thought that concrete evidence that it can help actually make real software more secure against attacks would have gotten a write-up somewhere.
- warkdarrior 2mo agoWe KNOW AI is bad, so why would we have a use for "concrete evidence that it can help"??
- MostlyStable 2mo agoI'm honestly unsure if this is a Poe's law thing or not. I'm going to go ahead assume that you are doing the honorable thing of purposefully not including a /s for the integrity of the joke.
- MostlyStable 2mo agoAfter doing a bit more research, this fact is somewhat less impressive. Apparently, this was also the first time in nearly 20 years that there was such a large capacity crunch and many researchers weren't able to get into the competition. One of the rejected researchers did apparently have a working exploit, which, upon not getting into the event, they responsibly disclosed, and it was then patched before the event.
- unprovable 2mo agoThis was, itself, driven by AI vuln finding, ironically :-P however, I took the example of @ggwhyp's Firefox RCE - quite a long chain, rejected by the organizers but probably would have won some cash from Mozilla... Details aren't public, so we won't know. Maybe their vuln was patched with Bug 2024918? At this point it's anyone's guess... But the fact that nobody else who made it through had an exploit and claimed $$$ on Firefox tells me that improvements were made. And this is what blew my mind, personally; a _browser_ - huge, complicated target codebase with myriad features, many of which are 'on the internet' - didn't have any disclosures with money on the table. That's definitely a datapoint worth registering. But you're absolutely right to remain skeptical!
- MostlyStable 2mo agoYes, I agree that this is still a datapoint for real world utility of AI assisted vulnerability fixing. But it's not as simple as an apples-to-apples comparison with previous years.
- unprovable 2mo agoIt absolutely was. 436 (or thereabouts) critical updates on their bugtraq in April. Wild.