<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-27T05:31:43Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by Henri Sivonen</title>
  <author>
    <name>Henri Sivonen</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1q3nt0h5c99cdlwckxl7xc7u8lrgkzxhnwv48mffm85yky8cp4xwqrp4s72.rss" />
  <link href="https://nostr.ae/npub1q3nt0h5c99cdlwckxl7xc7u8lrgkzxhnwv48mffm85yky8cp4xwqrp4s72" />
  <id>https://nostr.ae/npub1q3nt0h5c99cdlwckxl7xc7u8lrgkzxhnwv48mffm85yky8cp4xwqrp4s72</id>
  <icon>https://files.mastodon.social/accounts/avatars/000/041/776/original/8640803411588802.jpeg</icon>
  <logo>https://files.mastodon.social/accounts/avatars/000/041/776/original/8640803411588802.jpeg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsqdzuxwd53evnq3vyvl9fs5xv3sye6f7d6r3h8smga29dutjzvxwgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ectra8jz</id>
    
      <title type="html">What going to happen first due to the situation with LLMs and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqdzuxwd53evnq3vyvl9fs5xv3sye6f7d6r3h8smga29dutjzvxwgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ectra8jz" />
    <content type="html">
      What going to happen first due to the situation with LLMs and security bug finding: Microsoft issues a patch to Windows 10 even for computers not enrolled into ESU to fix something really bad or a major LTS Linux distro declares kernel patch backporting bankruptcy and rolls the kernel forward instead of backporting?
    </content>
    <updated>2026-05-08T20:32:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgdeuyntfx424uutsuh6p62qys262tva3ffnt6pz6g75rsk5xn5aqzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecc9msda</id>
    
      <title type="html">Reminder that Mozilla has been bundling multiple memory-safety ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgdeuyntfx424uutsuh6p62qys262tva3ffnt6pz6g75rsk5xn5aqzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecc9msda" />
    <content type="html">
      Reminder that Mozilla has been bundling multiple memory-safety bugs under one CVE number for, *checks notes*, a couple of decades. &lt;a href=&#34;https://www.mozilla.org/en-US/security/advisories/mfsa2006-68/&#34;&gt;https://www.mozilla.org/en-US/security/advisories/mfsa2006-68/&lt;/a&gt;
    </content>
    <updated>2026-04-22T04:40:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxqu6p6kc9nf3k6m8vmg57hd9ls4qcvljsmt2a35mu3w43y695f4czyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ec5xfr3p</id>
    
      <title type="html">I keep seeing bad takes that express hostility towards security ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxqu6p6kc9nf3k6m8vmg57hd9ls4qcvljsmt2a35mu3w43y695f4czyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ec5xfr3p" />
    <content type="html">
      I keep seeing bad takes that express hostility towards security bug finding whether by Project Zero or by LLMs.&lt;br/&gt;&lt;br/&gt;It’s as if folks with these takes are ignoring two basic things:&lt;br/&gt;&lt;br/&gt;1) Google and Anthropic didn’t put the bugs in your code. The known risks of memory-unsafe programming languages are hitting the fan.&lt;br/&gt;&lt;br/&gt;2) Attacks that exploit memory-unsafety hurt _users_.&lt;br/&gt;&lt;br/&gt;(Take an ffmpeg vulnerability: Chances are that YouTube’s back end is already isolated but VLC users could have a very bad time.)
    </content>
    <updated>2026-04-21T09:21:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9k57fn2a8jgxwthxk722tkw72grudnwy63hx7hmfvulksapya8vqzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecqkuczn</id>
    
      <title type="html">Also, it looks to me that fuzzing requires more human setup of ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9k57fn2a8jgxwthxk722tkw72grudnwy63hx7hmfvulksapya8vqzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecqkuczn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr4ylygsfu3hydxp3cvt9emsfxr7658zypdhwe5ra0eqsdv5xed3s7xea8z&#39;&gt;nevent1q…ea8z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Also, it looks to me that fuzzing requires more human setup of what part of code to fuzz and how to deal with stuff like checksums whereas reportedly LLMs can deal with less specific harnesses and figure out how to fill in checksums.
    </content>
    <updated>2026-04-13T20:08:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy89pf65mm4ryjvn30xt4uq5mcryn8l6xhtkueeyppwgwrmu9j6jszyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecke8473</id>
    
      <title type="html">Then there’s the dismissal that, yes, LLMs now find security ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy89pf65mm4ryjvn30xt4uq5mcryn8l6xhtkueeyppwgwrmu9j6jszyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecke8473" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0czerk9s7x5ma0q6d2lm60p8pj4q76k0mdf0hpejyhn4awhuu7rga4wum8&#39;&gt;nevent1q…wum8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Then there’s the dismissal that, yes, LLMs now find security bugs, but the bugs could have been found by other methods. But evidently defenders hadn’t actually found them by other methods. (Unknown what attackers had already found.)&lt;br/&gt;&lt;br/&gt;Or folks find it objectionable that the new capability has been made available to attackers and the proposed cure is to pay for access to the same LLM. But that does make the existence of the capability untrue.
    </content>
    <updated>2026-04-13T17:24:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0czerk9s7x5ma0q6d2lm60p8pj4q76k0mdf0hpejyhn4awhuu7rgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5echt88cy</id>
    
      <title type="html">And, yes, the Anthropic Mythos post fits a previously-seen ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0czerk9s7x5ma0q6d2lm60p8pj4q76k0mdf0hpejyhn4awhuu7rgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5echt88cy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsftnz4z3gzdvq945679gc5jpkjj5eh3y34khhxlhwx6j88rgg9umgxwtmpc&#39;&gt;nevent1q…tmpc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;And, yes, the Anthropic Mythos post fits a previously-seen pattern of “AI” companies marketing by danger, but saying that it’s marketing does not refute what the models that are already generally offered can do.&lt;br/&gt;&lt;br/&gt;And people act like their own conjecture is more informative than what people from multiple projects that deal with security bug reports say. See e.g. &lt;a href=&#34;https://mastodon.social/@bagder/116363034479757682&#34;&gt;https://mastodon.social/@bagder/116363034479757682&lt;/a&gt; .
    </content>
    <updated>2026-04-13T17:24:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsftnz4z3gzdvq945679gc5jpkjj5eh3y34khhxlhwx6j88rgg9umgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ec7q0fxp</id>
    
      <title type="html">I’m seeing a lot of denial and logical fallacies on Mastodon ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsftnz4z3gzdvq945679gc5jpkjj5eh3y34khhxlhwx6j88rgg9umgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ec7q0fxp" />
    <content type="html">
      I’m seeing a lot of denial and logical fallacies on Mastodon about LLM capability to find security bugs.&lt;br/&gt;&lt;br/&gt;I get it that when folks have concluded that LLMs are harmful, they want to believe that LLMs fail at everything. But a list of correctly-identified bad things about LLMs does not logically imply that LLMs can’t find security bugs.
    </content>
    <updated>2026-04-13T17:24:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw4wzh3wz33c3lw9yxn47tm84rpejxpg4yumcn6zs0y8z3km7dkcgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecuzwxfr</id>
    
      <title type="html">Today in Web compat: Firefox and Safari are ahead of Chrome in ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw4wzh3wz33c3lw9yxn47tm84rpejxpg4yumcn6zs0y8z3km7dkcgzyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecuzwxfr" />
    <content type="html">
      Today in Web compat: Firefox and Safari are ahead of Chrome in ICU4C version and upsteam ICU4C changed the formatting of zero offset from GMT. This broke birthday date validation for a UK based site for birthdays before 1970 in Firefox and, on 26.x Apple OSs, in Safari, because the site performs a formatting-based check on the time zone of London on the date to be validated and the UK has changed time zone rules along the way.
    </content>
    <updated>2026-03-25T11:17:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz7r8lm3rzpxu0pe3mv2quwsg0v97pg6dlut2qmapu9s9augxh26szyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ectkfm5c</id>
    
      <title type="html">ISO isn’t that different from Elsevier: Others do the work ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz7r8lm3rzpxu0pe3mv2quwsg0v97pg6dlut2qmapu9s9augxh26szyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ectkfm5c" />
    <content type="html">
      ISO isn’t that different from Elsevier: Others do the work without funding from them and then they put the result behind a paywall.&lt;br/&gt;&lt;a href=&#34;https://meshed.cloud/@webmink/114058954485365970&#34;&gt;https://meshed.cloud/@webmink/114058954485365970&lt;/a&gt;
    </content>
    <updated>2025-02-24T13:33:15Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswfanc78h2zpf6wnd2fwkn6vvpgjt62udwlv7jht2a8g7g9e8ymeczyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecah003l</id>
    
      <title type="html">Our team (DOM Core) has an open position: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswfanc78h2zpf6wnd2fwkn6vvpgjt62udwlv7jht2a8g7g9e8ymeczyqzxdd77nq5hphamzcmlcmrmsludzcg67dej5ld98v7sjcslqx5ecah003l" />
    <content type="html">
      Our team (DOM Core) has an open position: &lt;a href=&#34;https://www.mozilla.org/en-US/careers/position/gh/6527472/&#34;&gt;https://www.mozilla.org/en-US/careers/position/gh/6527472/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Remote in any of Finland, Sweden, Denmark, Poland, Spain, Belgium, Netherlands, France, Germany, UK, Canada, or US.
    </content>
    <updated>2025-01-17T20:33:45Z</updated>
  </entry>

</feed>