Elektrine lite

← Feed

@dangoodin@infosec.exchange

Post #2173374

2026-05-07 17:12 UTC

Mozilla has provided behind-the-scenes details on the 271 vulnerabilities it discovered with the help of Mythos. Those details include full Bugzilla reports on 12 of the vulnerabilities. I'd be curious for people to look at the reports and hear what they think. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

Replies (7)

  • @Viss@mastodon.social 2026-05-07 17:14

    @dangoodin@infosec.exchange considering the mythos papers that anthropic wrote which said they found hundreds, mozilla confirming less than 10% of those seems to me like a desperate grasping at straws by anthropic to somehow prove they werent lying through their teeth with their writeup

    Open ##2175320

  • @ekari@mementomori.social 2026-05-07 20:17

    @dangoodin@infosec.exchange to put the achievement in perspective, I'd like to know how much power was used to get this result, training included. But that unsexy point is seldom discussed.

    Open ##2177359

  • @kn4ntu@mastodon.radio 2026-05-07 17:22

    @dangoodin@infosec.exchange I'd take the numbers with a grain of salt. Anything that helps find more is good imho. Also I wonder what the average exploit/$ is across different projects as a whole. Thank you

    Open ##2219588

  • @passocacornio@tech.lgbt 2026-05-07 17:36

    @dangoodin@infosec.exchange I... 12 is not a bad number but like... Note that a number of these bugs are sandbox escapes, which would need to be combined with other exploits to achieve a full-chain Firefox compromise if they had paid the 20k to a professional code auditor they would have found more... dangerous and relevant exploits Anyone building software can start using a harness with a modern model to find bugs and harden their code today. We recommend getting started now. You will find bugs, and you will set yourself up to take advantage of new models as soon as they become available. this sound straight up off of a entry-level "advertising 101" book... also I looked at some of the bug repports and... meh

    Open ##2219589

  • @dangoodin@infosec.exchange second that. Sharing for visibility

    Open ##2219597

  • @PsySal@mastodon.social 2026-05-07 18:34

    @dangoodin@infosec.exchange I looked at the first one and although I don't know the codebase at all so am missing context, I think I understand it partly (I am a good c++ programmer ) and it certainly looks real to me. There is also discussion on the bugzilla where a developer acknowledges they introduced the bug when doing code cleanup.

    Open ##2219598

  • @mhitza@third-party.cyou 2026-05-07 18:43

    @dangoodin@infosec.exchange half of a continuation of a report, and half a tech blog discussing the internal security harnessing. Strange to read how it switched between the two and answering interesting questions in the FAQ. I find confusing the fact that I couldn't find a list for all the invidually tracked bugs (?). Even though they are "rolled up"/grouped under a single CVE, they are tracked individually and that would be a more interesting thing to look at. And I'm really surprised about the no. of fixed bugs graph, especially for April. How could they handle that jump in volume? More people working on Firefox? More focus on security than other work? "Looks good to me" merges?

    Open ##2219599