@freddy@social.security.plumbing
Post #2198214
2026-05-07 16:15 UTC
Replies (5)
-
@endareth@disobey.net 2026-05-08 04:01
@freddy@social.security.plumbing Curious exactly how many critical/high #Firefox bugs were reported by #Mythos, vs how many were confirmed/accepted as such by your team?
-
@yoasif@mastodon.social 2026-05-07 16:20
@freddy@social.security.plumbing You fixed the bugs with AI too?
-
@AlesandroOrtiz@infosec.exchange 2026-05-07 18:44
@freddy@social.security.plumbing Thanks for sharing and making those reports public early. Great insight into what's happening with browser VRPs. Is Mozilla planning changes to the Firefox VRP in response to this, similar to recent changes to the Chrome VRP? (Or have changes already been made? I'm not closely following the Firefox VRP, unfortunately.)
-
@enigmatico@mk.absturztau.be 2026-05-07 20:26
@freddy@social.security.plumbing Between Google Chrome shoving AI models into their browser and Mozilla Firefox also shoving AI to their users and bragging about how they're using AI, I don't know what's worse. Did Claude also vibe coded the patches? You were supposed to destroy Corporatism, not join them
-
@nf3xn@mastodon.social 2026-05-09 14:01
@freddy@social.security.plumbing tldr; Not where are the bugs. Where are the PoC. Poc||GTFO. I hunch if there was a single interesting bug that we would never hear the end of it. Not that I think after CopyFail etc that anyone can doubt that AI tools can be used to x10 real security researchers. It is imho harmful and counterproductive to flood the zone low quality bugs that 'might' be interesting just to do AI techbros marketing shit for them. We have long endured overblown, unscrupulous claims. 423 -> 12 -> 0?