Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all."

The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all."

Scheduled Pinned Locked Moved Uncategorized
firefoxopensource
7 Posts 4 Posters 21 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • glynmoody@mastodon.socialG This user is from outside of this forum
    glynmoody@mastodon.socialG This user is from outside of this forum
    glynmoody@mastodon.social
    wrote last edited by
    #1

    The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all." #firefox #opensource

    floppy@mastodon.me.ukF axx@mstdn.frA drajt@fosstodon.orgD 3 Replies Last reply
    0
    • glynmoody@mastodon.socialG glynmoody@mastodon.social

      The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all." #firefox #opensource

      floppy@mastodon.me.ukF This user is from outside of this forum
      floppy@mastodon.me.ukF This user is from outside of this forum
      floppy@mastodon.me.uk
      wrote last edited by
      #2

      @glynmoody "the defects are finite" sounds like "nobody will ever need more than 640k of memory" to me.

      glynmoody@mastodon.socialG 1 Reply Last reply
      0
      • glynmoody@mastodon.socialG glynmoody@mastodon.social

        The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all." #firefox #opensource

        axx@mstdn.frA This user is from outside of this forum
        axx@mstdn.frA This user is from outside of this forum
        axx@mstdn.fr
        wrote last edited by
        #3

        @glynmoody right but … software is a stream, not in a static settled state. The likelihood of never introducing a new bug is zero.

        …says he before reading the article. I should go do that.

        1 Reply Last reply
        0
        • floppy@mastodon.me.ukF floppy@mastodon.me.uk

          @glynmoody "the defects are finite" sounds like "nobody will ever need more than 640k of memory" to me.

          glynmoody@mastodon.socialG This user is from outside of this forum
          glynmoody@mastodon.socialG This user is from outside of this forum
          glynmoody@mastodon.social
          wrote last edited by
          #4

          @floppy yes, probably a hostage to fortune

          1 Reply Last reply
          0
          • glynmoody@mastodon.socialG glynmoody@mastodon.social

            The zero-days are numbered - https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/ "The defects are finite, and we are entering a world where we can finally find them all." #firefox #opensource

            drajt@fosstodon.orgD This user is from outside of this forum
            drajt@fosstodon.orgD This user is from outside of this forum
            drajt@fosstodon.org
            wrote last edited by
            #5

            @glynmoody static code analysis found hundreds of bugs in open source projects previously. Finding "bugs" with tools like this is easier than fixing them and stopping new ones creeping in in later changes.

            I believe several people have recently reported that AI bug reports have just changed from mostly slop to often useful.

            glynmoody@mastodon.socialG 1 Reply Last reply
            0
            • drajt@fosstodon.orgD drajt@fosstodon.org

              @glynmoody static code analysis found hundreds of bugs in open source projects previously. Finding "bugs" with tools like this is easier than fixing them and stopping new ones creeping in in later changes.

              I believe several people have recently reported that AI bug reports have just changed from mostly slop to often useful.

              glynmoody@mastodon.socialG This user is from outside of this forum
              glynmoody@mastodon.socialG This user is from outside of this forum
              glynmoody@mastodon.social
              wrote last edited by
              #6

              @drajt more eyes - even ai eyes - are better if reports are good

              drajt@fosstodon.orgD 1 Reply Last reply
              0
              • glynmoody@mastodon.socialG glynmoody@mastodon.social

                @drajt more eyes - even ai eyes - are better if reports are good

                drajt@fosstodon.orgD This user is from outside of this forum
                drajt@fosstodon.orgD This user is from outside of this forum
                drajt@fosstodon.org
                wrote last edited by
                #7

                @glynmoody well the early reports sent to the #cURL team were mostly #AIslop and placed an excessive burden on them, so they banned #AI bug reports.

                Code scanning has got better in the last few months and now can make interesting and useful insights, though not always security related. I believe the Linux kernel team have found quite a few bugs from recent AI submissions.

                The biggest problem is the resources to fix them, many volunteers are overloaded already.

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups