

I respect your opinion here, but they will absolutely not shut down the AUR since its the reason anyone uses Arch. Just like how piefed.ca doesn’t shut down just because a few users upload illegal things.


I respect your opinion here, but they will absolutely not shut down the AUR since its the reason anyone uses Arch. Just like how piefed.ca doesn’t shut down just because a few users upload illegal things.


When were the tolls added to begin with?


Yeah, I bet the build process could also be sandboxed, but Im sure its not the default.


AUR packages can be sandboxed with many different solutions. Any pckage can be sandboxed really.


Is this like when he said he would end the Russia/Ukraine war within 24 hours upon returning to office?


Nah, keep talking. We need to free our communities of mods.


They didn’t take their ball and go home though. They left their ball there with the complainers and went home without the ball.
One thing you could deploy throughout all your internal networks are honeypots that send alerts upon ANY network activity. Nobody should be hitting those at all.


My threat model is anything vulnerable that can access a network should be gutted and smelted down if it has been abandoned from the manufacturer.
Don’t throw it in the trash. Recycle the materials instead to rebuild newer better hardware.


As long as it never touches any network ever again and there is never anything personal installed on it ever again then it should be OK. Be sure to rip out the GSM and/or CDMA chipset, wifi, bluetooth, and NFC. When connecting it to another device through USB, make sure that device is offline and ADB mode is disabled. Remove all sim cards as well.
There are much better devices for your purpose than some old ass phone tho


They are supported, but they only push updates to a few models (typically server models).
For desktop motherboards, its better to go to ASUS’s support website, look up your board, download the latest BIOS, and install it per their instructions.
Also, if you have ANY custom settings in your BIOS, such as overclocked CPU, mem timings, IOMMU enabled, SecureBoot keys, etc, BE SURE TO BACK THEM UP before upgrading your BIOS. I have a notes.txt file of all my BIOS settings because I have to reapply everything after an update since it sets everything to default.


You can port a lot of things to a Pixel 3a, but the firmware has been end of life for years now. At the hardware level, its always vulnerable. The OS alone can not protect you, even if its up to date.


Im sure FreeBSD probably appreciates the bug reports as well, and I don’t believe they are tied to LLMs. They have totally revamped their processes recently to accommodate for the influx of reports coming in.


Its debugging while you’re sleeping, eating, and enjoying other activities. And its working at a rate that is parallel to entire security research teams. Thats the “AI” part.


They already explained how they have placed hashes inside all their bug reports for Project Glasswing and will reveal their report once there has been time for patches to be applied.
Mozilla, developer of one of the most active and heavily scrutinized open source repositories in existence today, blogged about it with their product known as Firefox. They agree with you that it doesn’t do anything better that what a human researcher could find, but its perk is that it can relentlessly play that role and keep looking, while human researchers have to sleep, eat, and enjoy other activities:
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/


Its an end-of-life product regardless, so it should be recycled. Its not worth carrying around a forever-compromised device, at least not for me. Google offers a recycle program here:


Depends on the model, and the way you ask it, for sure.


Those are just the ones that Mythos has claimed so far. They stated that is only about 1% of all the vulnerabilities they discovered and were publicly announced. Firefox 150 had over 270 bug fixes, with 13 of them as high severity.
Mythos is also finding high severity vulnerabilities that have been in systems for over 20 years with no humans able to discover them during that time. Its patient, and can look at the entire repo and how it all works together.


They are all getting AI generated bug reports. Hate to say it, but AI is good at finding bugs/vulnerabilities, so most open source projects are heading into triage overload while the technical debt is caught up.
Any open source projects not merging or patching because “AI” discovered it will probably not be a secure place to store your passwords after a while.
Its a hypothetical assumption created by me. I should have said lemmy.world since im 100% sure there have been users that have uploaded illegal content.