Comment by zachperkel

1 day ago

Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.

Scary but also cool

Did someone actually go through all of those and check if they are high-severity or did the AI just tell them that?

  • They mention that they have humans review the most crticial bugs before sending it to the maintainers in their dev blog.

Every piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org

  • Once you get the compartmentalization working well, and “all” of the vulnerabilities are out of it too, of course…

    But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.

    • > and “all” of the vulnerabilities are out of it too

      This is a good point; however the isolating code should be much smaller and easier to verify.