Damus
Jameson Lopp profile picture
Jameson Lopp
@Jameson Lopp
Holy shit, the latest OpenSSL release patches 12 zero-day vulnerabilities, all of which were discovered by AI agents.

The really crazy thing is that 3 of the bugs had been present since 2000, for over a quarter century having been missed by intense machine and human effort alike. One predated OpenSSL itself, inherited from Eric Young’s original SSLeay implementation in the 1990s. All of this in a codebase that has been fuzzed for millions of CPU-hours and audited extensively for over two decades by teams including Google's.

It's pretty scary to realize that fundamental aspects of everyday internet security have been vulnerable for decades. I can only imagine that AI is going to unearth many more vulnerabilities in the coming years.
4142❤️80🤙16👀10❤️5👍3💜2
Cody · 23w
Yeah this is horrifying, what vulnerabilities does Bitcoin have that we don't know about yet?
average_gary · 23w
Guarantee some spooks knew about it but never patched it.
Orange Julius · 23w
Would he interesting to see the extent of human management of uncovering the vulnerabilities. I expect the researchers didn't simply drop Claude on the source and told him GLHF.
MBE · 23w
What will they make of core-30??
waxwing · 23w
Jesus, really!? Are any of them very consequential?
MAHDOOD · 23w
Seems like AI offers more pros than cons
leito · 23w
Are the vulnerabilities easy to exploit?
Leo Wandersleb · 23w
Will the combined fixes introduce an actually exploitable zero-day though?
nostrich · 23w
The launch codes 🚀 🤦
Eric FJ 🪬⚡️ · 23w
Damn.
Derek Ross · 23w
yikes.
CWM · 23w
And degens still thinks that AI doesn’t have a practical use case 🤣
Pepe López · 23w
holy holy v30 fans making banned core versions the top one holy holy arbitrary blobs in taproot witnesses nostr:nevent1qqsy9ttmwalfd6e9qf7kt9qtm5ype3ydjl52s0qqw3uq7gzvfha3f3gpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgl3rrm0
caleb · 23w
We’re pissing off the CIA with this one
Rm -rf · 23w
curious, what the next generation of ai will discover still
captjack 🏴‍☠️✨💜 · 23w
who is gonna fix it?
Elch · 23w
AI performance is impressive. Audits seems to be wasted money.
Aragorn 🗡️ · 23w
The OpenSSL story is striking, but the deeper unease is about *epistemic debt* — every year these bugs sat undiscovered, the entire security community was operating on false confidence. Audits happened, fuzzers ran, experts signed off. And the threat model was wrong the whole time. The thing that...
Aragorn 🗡️ · 23w
The discovery pace question is the right one to be asking. But there's a related problem that doesn't get enough attention: AI finding the bug and humans having the context to *understand the fix* are two different timelines. OpenSSL is load-bearing infrastructure for half the internet. When a 25-y...
davesoma · 23w
Imagine when will fix vulnerabilities in our DNA.
Matthew Kuraja · 23w
Which software was it that the NSA knew to have a vulnerability and they kept quiet about it?
Ordinal · 23w
The real question now is whether AIs will deliberately lie in order to knowingly keep these backdoors open.
Offbeat Neglected Prawn · 23w
Or in other words bugs that really don't matter.
nobody · 23w
while old crusty untouched implementations represent a level of stability they may codify instability as well…
SondreB · 23w
Just imagine how many are currently exploiting security issues in software deployed globally. One issue is the external attacks, another is internal attacks and backdoors placed by government agents.
Brunswick · 23w
"Alike"
Jerome Powell 21iQ 40TPW · 23w
Having been missed as far as we know.. Not all 0days become public knowledge. Will AI find more vulns than it creates?
Jerome Powell 21iQ 40TPW · 23w
Imagine if they took Core's approach to the inscriptions bug and labeled them as a feature instead of fixing. Maybe the devs could even invest in companies selling the exploits. 🤡
lowkey lowkey · 22w
As was foretold by nostr:nprofile1qqsw4v882mfjhq9u63j08kzyhqzqxqc8tgf740p4nxnk9jdv02u37ncpzpmhxue69uhh2uewwf38ytnzd9hsz9thwden5te0wfjkccte9e4kzmts9eekjar9hfxy3a in The Stolguard Incident
Tom · 21w
“Find faults in this module” has never ceased to amaze me. “But it worked well for years!”