Remix.run Logo
unprovable 5 hours ago

The real datapoint was Firefox not paying any money in Berlin's Pwn2Own competition round this May just gone. Unheard of to have nothing confirmed... they've paid out every event since 2007 (I checked). Does this mean we must move past the low-hanging fruit now? Probably... Certainly indicates some usefulness of these models.

ayewo 4 hours ago | parent [-]

Perhaps this was due to their red-teaming partnership [1][2] with Anthropic which they wrote about a few months earlier in March?

1: https://www.anthropic.com/news/mozilla-firefox-security

2: https://blog.mozilla.org/en/firefox/hardening-firefox-anthro...

Previous discussion: https://news.ycombinator.com/item?id=47273854

MostlyStable 3 hours ago | parent [-]

I just did a search and apparently this fact (the specific one about no payouts for the first time in almost 20 years) has not gotten a discussion on HN. Given the degree of skepticism around the utility of AI bug finding and fixing (this very thread is full of it), I would have thought that concrete evidence that it can help actually make real software more secure against attacks would have gotten a write-up somewhere.

MostlyStable an hour ago | parent | next [-]

After doing a bit more research, this fact is somewhat less impressive. Apparently, this was also the first time in nearly 20 years that there was such a large capacity crunch and many researchers weren't able to get into the competition. One of the rejected researchers did apparently have a working exploit, which, upon not getting into the event, they responsibly disclosed, and it was then patched before the event.

warkdarrior 2 hours ago | parent | prev [-]

We KNOW AI is bad, so why would we have a use for "concrete evidence that it can help"??

MostlyStable an hour ago | parent [-]

I'm honestly unsure if this is a Poe's law thing or not. I'm going to go ahead assume that you are doing the honorable thing of purposefully not including a /s for the integrity of the joke.