lapo@f.lapo.it
@lapo@f.lapo.it
Posts
-
Today I delivered to a client the first installation of Sylve on FreeBSD that I have prepared. -
@bms48 @downey@downey @david_chisnall @bms48
a code review of one of my projects done with Claude 4.6 (which, apparently, is as good at Mythos at finding bugs but less good at producing PoC exploits)
There is a huge difference there, though: a pipeline producing actual PoC exploits implicitly filter out all reports that are not actionable, so it produces far less false positives (if at all, depending on the internal validation done on the exploits). -
@bms48 @downey@downey @david_chisnall @bms48 I have the same fear. On the other hand, Firefox 150 apparently fixes 251 bugs, and I wonder how they did it.
For a hardened target, just one such bug would have been red-alert in 2025, and so many at once makes you stop to wonder whether it’s even possible to keep up.