Mozilla says 271 vulnerabilities found by Mythos have “almost no false positives”



As noted earlier, Mozilla’s characterization of AI-assisted vulnerability discovery as a game changer has been met with massive, vocal skepticism in many quarters. Critics initially scoffed when Mozilla didn’t obtain CVE designations for any of the 271 vulnerabilities. Like many developers, however, Mozilla doesn’t obtain CVE listings for internally discovered security bugs. Instead, they are bundled into a single patch. Normally, Bugzilla reports detailing these “rollups” are hidden for several months after being fixed to protect those who are slow to patch. Now that Mozilla has revealed a dozen of them, the same critics will surely claim they too were cherry-picked and conceal less accurate results.

Of the 271 bugs found using Mythos, 180 were sec-high, Mozilla’s highest designation for internally reported vulnerabilities. These types of vulnerabilities can be exploited through normal user behavior, such as browsing to a web page. (The only higher rating, sec-critical, is reserved for zero-days.) Another 80 were sec-moderate, and 11 were sec-low.

The critics are right to keep pushing back. Hype is a key method for inflating the already high puffed-up valuations of AI companies. Given the extensive praise Mozilla has given to Mythos, it’s easy for even more trusting people to wonder: What’s it getting in return? Far from settling the debate, Thursday’s elaborations are likely to only further stoke the controversy.

To hear Grinstead tell it, however, the details are clear evidence of the usefulness of AI-assisted discovery, and Mozilla’s motivation is simple.

“People are a bit burned from the last year of these slop commits so we felt it was important to show some of our work, open up some of the bugs, and talk about it in a little more detail as a way to hopefully spur some action or continue the conversation,” he said. “There’s no sort of marketing angle here. Our team has completely bought in on this approach. We are trying to get a message out about this technique in general and not any specific model provider, company, or anything like that.”



Source link

  • Related Posts

    YouTube’s AI Deepfake Detection Tool Is Now Available To All Creators 18 And Older

    YouTube In the coming weeks, YouTube is giving all creators 18 and over access to a tool that can detect whether their…

    Today’s NYT Connections Hints, Answers for May 16 #1070

    Looking for the most recent Connections answers? Click here for today’s Connections hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle, Connections:…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    YouTube’s AI Deepfake Detection Tool Is Now Available To All Creators 18 And Older

    YouTube’s AI Deepfake Detection Tool Is Now Available To All Creators 18 And Older

    Ex-Saks CEO Marc Metrick Faces Rule 2004 in Bankruptcy Probe

    Ex-Saks CEO Marc Metrick Faces Rule 2004 in Bankruptcy Probe

    Senior IS leader killed by US and Nigerian forces

    Senior IS leader killed by US and Nigerian forces

    B.C. allowed logging in caribou habitat despite its own ministry’s recommendation

    B.C. allowed logging in caribou habitat despite its own ministry’s recommendation

    TetraMem Announces 22nm Multi-Level RRAM Analog In-Memory Computing SoC Milestone

    Qatar Airways To Launch 3 Exciting New Long-Haul Routes

    Qatar Airways To Launch 3 Exciting New Long-Haul Routes