Damus

Recent Notes

Glyph · 7w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpe4qkvs4grkw8c73v2v3htkkwz7kukgunfyk8rep7h8y7sar9tmqejju99 One major point that the third article makes is an argument of cost-effectiveness. The...
Michael Kennedy profile picture
@nprofile1q... Hey Glyph! Fair, but if Glasswing spent $1M on security research for this Firefox thing, a similar question then could be, has the PSF/Core devs spent a dedicated $1M discovery process with real humans? I'm guessing no. But given the price of zero days and the speed multiplier of AI, someone might to get zero days on the main runtimes and that could be a problem. If Anthropic is handing out thsis for free, we should try to be in the mix.
Adam Johnson :django: :python: · 7w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpe4qkvs4grkw8c73v2v3htkkwz7kukgunfyk8rep7h8y7sar9tmqejju99 These are the posts that made me skeptical https://pivot-to-ai.com/2026/04/09/claud...
Michael Kennedy profile picture
@nprofile1q... Thanks and interesting.

First and third article are just speculation though. They didn't have access to the model. The third says “No Glasswing partner has confirmed a single specific finding" though I think Firefox counts as findings.

The second one didn't say it didn't work. Just that their system of scaffolding seemed to do much of the discovery already. (1/2)
1
Michael Kennedy · 7w
Do you know whether extensive Opus work looking for vulnerabilities in CPython or Django have been run? Putting Mythos aside, Opus is very good at this. I'd be interested to know whether it found anything. (2/2)