Elektrine lite

← Feed

@adamshostack@infosec.exchange

2026-09-09 22:52 UTC

Appsec • Google released a blog post How we’re making Chrome and the web safer in the AI Era (https://blog.google/security/chrome-stronger-with-every-update/), which includes, but isn’t limited to threat modeling, still done by humans and recorded in security.md files. • In Overhead of Recording Feature Locations with Embedded Annotations (https://se.rub.de/wp-content/uploads/2026/07/2026-variability-overhead.pdf), Johan Martinson, Kevin Hermann, and Thorsten Berger show that lightweight annotations that define where features are help find feature-related code. (There’s security relevance in knowing where your security features show up in the code.) (4/10)

Replies (1)

  • AI • In AI is more likely than humans to form biases when hiring (https://www.technologyreview.com/2026/07/20/1140655/ai-biases-hiring-humans/), Michelle Kim reports on a study that shows LLM hiring agents can literally invent new biases. • In an April pre-print, Nicholas Sofroniew and colleagues of Anthropic report on Emotion Concepts and their Function in a Large Language Model (https://arxiv.org/abs/2604.07729). Do you really want to spend the tokens they sell you on that, or have your outputs impacted by it? • Dan Goodin has a story, Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission (https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/). Key facts include 60 hours of work and $100,000 of tokens. (It's unclear if that was the only work that was done, or if there were other, unsuccessful experiments, which would change the token cost, perhaps dramatically.) Cryptographer Matt Green has good analysis in Some thoughts about Anthropic’s new cryptanalysis results (https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/). Axel Mierczuk, Spencer Michaels and Keith Hoodlet of 1Password’s new Off-by-1 Labs released Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D. (https://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf). This study is pretty devastating to the hope that LLMs can fix the deluge of vulns they discover. Adrian Sanabria has a great summary in Reviewing initial research on using AI for vulnerability remediation (https://www.defendersinitiative.com/p/reviewing-initial-research-on-using?r=74yjk&utm_campaign=post&utm_medium=web&triedRedirect=true). Contrast with Google’s opinion in Stronger with every update: How we’re making Chrome and the web safer in the AI Era (https://blog.google/security/chrome-stronger-with-every-update/), and note the important words “At this point, we have LLMs generating candidate fixes for most vulnerabilities, dramatically increasing the rate of security fixes in recent Chrome releases” (emphasis added). • I covered the OpenAI/HuggingFace incident (https://shostack.org/blog/lessons-from-openai-huggingface-ai-security/) separately. (5/10)

    Open ##4673162