Post #1455824
2026-04-15 16:11 UTC
@dsalo my sense from discussions I’ve seen, e.g. https://lwn.net/Articles/1065620/ and the blog post it is replying to, and what Daniel Stenberg has been saying lately, is that even without Mythos there has been a massive step change in the last few months: going from “AI reports are almost all useless” to reliable, repeated AI-powered discovery of real vulnerabilities, or at least defects.
That increases the odds I would place that Mythos is scary-good at this specific task.
Replies (1)
-
@JMarkOckerbloom@mastodon.social 2026-04-17 13:08
@mdekstrand @dsalo The problem with public security vulnerability identification tools is that even if they have a high false positive rate but a real, if small, true positive rate, that's still bad news for a high-visibility target, since it's likely that some set of bad guys who have access to the same tools will check out one of those true vulnerabilities and exploit it. (And these days, pretty much any well-known consumer software or public-facing website is a high-visibilty target.)