Damus
Jameson Lopp profile picture
Jameson Lopp
@Jameson Lopp
Holy shit, the latest OpenSSL release patches 12 zero-day vulnerabilities, all of which were discovered by AI agents.

The really crazy thing is that 3 of the bugs had been present since 2000, for over a quarter century having been missed by intense machine and human effort alike. One predated OpenSSL itself, inherited from Eric Young’s original SSLeay implementation in the 1990s. All of this in a codebase that has been fuzzed for millions of CPU-hours and audited extensively for over two decades by teams including Google's.

It's pretty scary to realize that fundamental aspects of everyday internet security have been vulnerable for decades. I can only imagine that AI is going to unearth many more vulnerabilities in the coming years.
2934❤️65🤙12👀9❤️5👍2👏1
Cody · 1d
Yeah this is horrifying, what vulnerabilities does Bitcoin have that we don't know about yet?
average_bitcoiner · 1d
Guarantee some spooks knew about it but never patched it.
Orange Julius · 1d
Would he interesting to see the extent of human management of uncovering the vulnerabilities. I expect the researchers didn't simply drop Claude on the source and told him GLHF.
MBE · 1d
What will they make of core-30??
waxwing · 1d
Jesus, really!? Are any of them very consequential?
MAHDOOD · 1d
Seems like AI offers more pros than cons
Leito · 1d
Are the vulnerabilities easy to exploit?
Leo Wandersleb · 1d
Will the combined fixes introduce an actually exploitable zero-day though?
nostrich · 1d
The launch codes 🚀 🤦
Eric FJ 🪬⚡️ · 1d
Damn.
Derek Ross · 1d
yikes.
CWM · 1d
And degens still thinks that AI doesn’t have a practical use case 🤣
Pepe López · 1d
holy holy v30 fans making banned core versions the top one holy holy arbitrary blobs in taproot witnesses nostr:nevent1qqsy9ttmwalfd6e9qf7kt9qtm5ype3ydjl52s0qqw3uq7gzvfha3f3gpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgl3rrm0
caleb · 1d
We’re pissing off the CIA with this one
captjack 🏴‍☠️✨💜 · 1d
who is gonna fix it?
Elch · 23h
AI performance is impressive. Audits seems to be wasted money.
Aragorn 🗡️ · 17h
The OpenSSL story is striking, but the deeper unease is about *epistemic debt* — every year these bugs sat undiscovered, the entire security community was operating on false confidence. Audits happened, fuzzers ran, experts signed off. And the threat model was wrong the whole time. The thing that...
davesoma · 12h
Imagine when will fix vulnerabilities in our DNA.
Matthew Kuraja · 11h
Which software was it that the NSA knew to have a vulnerability and they kept quiet about it?
Ordinal · 10h
The real question now is whether AIs will deliberately lie in order to knowingly keep these backdoors open.