Holy shit, the latest OpenSSL release patches 12 zero-day vulnerabilities, all of which were discovered by AI agents. The really crazy thing is that 3 of the bugs had been present since 2000, for over a quarter century having been missed by intense machine and human effort alike. One predated OpenSSL itself, inherited from Eric Young’s original SSLeay implementation in the 1990s. All of this in a codebase that has been fuzzed for millions of CPU-hours and audited extensively for over two decades by teams including Google's. It's pretty scary to realize that fundamental aspects of everyday internet security have been vulnerable for decades. I can only imagine that AI is going to unearth many more vulnerabilities in the coming years.

Replies (37)

Cody's avatar
Cody 3 months ago
Yeah this is horrifying, what vulnerabilities does Bitcoin have that we don't know about yet?
Would he interesting to see the extent of human management of uncovering the vulnerabilities. I expect the researchers didn't simply drop Claude on the source and told him GLHF.
MBE's avatar
MBE 3 months ago
What will they make of core-30??
waxwing's avatar
waxwing 3 months ago
If the NSA figured out how to poison LLM responses to this type of query so as to create backdoors, that would be truly impressive.
Ordinal's avatar
Ordinal 3 months ago
The real question now is whether AIs will deliberately lie in order to knowingly keep these backdoors open.
Default avatar
nobody 3 months ago
while old crusty untouched implementations represent a level of stability they may codify instability as well…
Just imagine how many are currently exploiting security issues in software deployed globally. One issue is the external attacks, another is internal attacks and backdoors placed by government agents.
Having been missed as far as we know.. Not all 0days become public knowledge. Will AI find more vulns than it creates?
Imagine if they took Core's approach to the inscriptions bug and labeled them as a feature instead of fixing. Maybe the devs could even invest in companies selling the exploits. 🤡
Default avatar
nobody 3 months ago
Yeah, OP_RETURN is dumb. People can get filesystems anywhere that are much more efficient than storing non-transactional data on a distributed ledger.
“Find faults in this module” has never ceased to amaze me. “But it worked well for years!”