Something else happened, and that was *very* recently. Those reports grew in numbers.
if I see 1-2 valid reports in a major open source lib from an AI tool, I'm not impressed. If I had enough funding, I could find valid vulns in a variety of ways.
When the Mozilla/Antropic thing came out, that was what I was thinking. "Yeah, these are real bugs, but you know, if I had infinite funding like Antropic, and a team of top security people, you know how many bugs I could find in Firefox?"
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:59 JST
hanno