"[..] a security bug identified by
AI tools is subsequently independently discovered by a different
researcher. This suggests that adversaries who do not report bugs
to OSS projects are likely to be able to discover these bugs too.
Given this, the OpenSSH team will, for now, be making more frequent
releases to get bugfixes into users' hands more quickly rather than
batching them until the next planned release."
The AI boosters should look for evidence that they do allow AI contributions! Why would they mention in the release notes that AI security bug reports are welcome if they allowed AI in general anyway?
Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them.
So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release.
As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports.
> so using AI like ASAN etc. is welcome.
AddressSanitizer is not "AI", nor does it use AI. [0]
Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.
Glad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.
Is that the case? I see this note focusing on AI reports in the release notes, and I've poked around the OpenSSH project more generally and don't see any indication that they don't accept or welcome other AI inputs.
Oh, that's a nice new feature:)
Can you cite that? I see them specifically welcoming AI security reports; I don't see any evidence that other AI submissions are not welcome.
Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them.
So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release.
As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports.
> so using AI like ASAN etc. is welcome.
AddressSanitizer is not "AI", nor does it use AI. [0]
[0] https://static.googleusercontent.com/media/research.google.c...