Post #2246711
2026-05-07 19:56 UTC
Replies (7)
-
@Epic_Null@infosec.exchange 2026-05-07 20:01
@dangoodin@infosec.exchange at least sift through them in good faith and with an open mind Actually I think this might be part of the problem. Developlent teams are busy. Backlogs are huge. If the tool does nothing but add to that backlog, then is it truly useful?
-
@keithzg@fediverse.keithzg.ca 2026-05-07 20:14
@dangoodin@infosec.exchange Mozilla as an org though has some top-down interests in hyping LLMs, so it's a somewhat skewed thing to begin with. Personally I'd be much more interested in going into such details with an open mind if, say, they finally gave access to the `curl` folks (who were theoretically accepted into the early access program for this "dangerous model" and then . . . haven't been given that access yet still).
-
@ohmu@social.seattle.wa.us 2026-05-07 20:30
@dangoodin@infosec.exchange - This would have more credibility if it was from an org other than Mozilla. Their cred is beyond cooked at this point. But you kind of acknowledged that. - This goes zero feet of depth into the conclusions of other studies that Mythos has been performing at best equally with searches with small, cheap, and local LLM tools.
-
@merospit@infosec.exchange 2026-05-07 20:42
@dangoodin@infosec.exchange It needs to be good faith on both sides. Having a human hide behind a robot facade and then release the recent ImageMagick vulnerability after their LLM failed in 7 days of feedback with maintainers pushed the good faith argument on both sides.
-
@toddsundsted@epiktistes.com 2026-05-07 22:23
@dangoodin@infosec.exchange you don’t even need mythos. anyone who cares to can run a state of the art model against their code, and with a little persistence find exploitable vulnerabilities. this shouldn’t even be surprising. before LLMs, anyone who cared to could run a high quality pen test on their code and find exploitable vulnerabilities. all LLMs have done is lowered the cost of doing that!
-
@lwriemen@social.librem.one 2026-05-08 13:42
@dangoodin@infosec.exchange LWN has an interesting article on this. https://lwn.net/SubscriberLink/1070698/f0546e940e1ed08d/ One takeaway from both articles is that these tools can be used for good or bad, and that the LLM will only look for what it's told. Evaluation and fix is drinking from the fire hose, and while one team reports zero false positives, another may find a bigger number. Is this help or an attempt to kill free software?
-
@flyingpenguin@infosec.exchange 2026-05-24 04:18
@dangoodin@infosec.exchange doing my best here https://www.flyingpenguin.com/could-mozilla-security-hot-air-fill-mythos-sails/ and of course here https://www.flyingpenguin.com/?s=mythos