Claude Mythos Preview を活用した Firefox の脆弱性対策の裏側
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Simon Willison Blog
Mozilla は Claude Mythos プレビュー版へのアクセス権を利用して、Firefox 内の数百件のセキュリティ脆弱性を特定し修正しました。これにより、AI が生成するバグ報告の質が劇的に向上したことが示されています。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Behind the Scenes Hardening Firefox with Claude Mythos Preview
Mozilla が Claude Mythos プレビューへのアクセス権を利用して、Firefox 内の数百の脆弱性を特定し、修正した方法に関する興味深く詳細な内容です。
突然、バグが非常に良くなった
数ヶ月前まで、オープンソースプロジェクトに対する AI 生成のセキュリティバグ報告は、主に不要なゴミとして知られていました。正しそうに見えるが実際には誤っている報告に対処することは、プロジェクトメンテナにとって非対称なコストを強いることになります。LLM(大規模言語モデル)にコード内の「問題」を見つけるようプロンプトするのは簡単で安価ですが、それに対応するのは時間がかかり高価です。
このダイナミクスが数ヶ月の間に私たちにとってどれほど変化したかを過大評価することは困難です。これは主に 2 つの要因の組み合わせによるものです。第一に、モデルの能力が大幅に向上しました。第二に、これらのモデルを*活用する*ための技術を劇的に改善しました——モデルを誘導し、スケーリングし、積み重ねて大量のシグナルを生成し、ノイズをフィルタリングする方法です。
これには詳細なバグ記述も含まれており、20 年前の XSLT バグや 15 年前の <element>(要素)内のバグなどがあります。
ハーンシング(活用システム)によって行われた試みの多くは、Firefox の既存のディフェンス・イン・デプス(多層防御)対策によってブロックされました。これは安心できることです。
Mozilla は 2025 年を通じて Firefox で月平均 20〜30 のセキュリティバグを修正していましたが、4 月には 423 に急増しました。

Via Lobste.rs
Tags: firefox, mozilla, security, ai, generative-ai, llms, anthropic, claude, ai-security-research
原文を表示
Behind the Scenes Hardening Firefox with Claude Mythos Preview
Fascinating, in-depth details on how Mozilla used their access to the Claude Mythos preview to locate and then fix hundreds of vulnerabilities in Firefox:
Suddenly, the bugs are very good
Just a few months ago, AI-generated security bug reports to open source projects were mostly known for being unwanted slop. Dealing with reports that look plausibly correct but are wrong imposes an asymmetric cost on project maintainers: it’s cheap and easy to prompt an LLM to find a “problem” in code, but slow and expensive to respond to it.
It is difficult to overstate how much this dynamic changed for us over a few short months. This was due to a combination of two main factors. First, the models got a lot more capable. Second, we dramatically improved our techniques for harnessing these models — steering them, scaling them, and stacking them to generate large amounts of signal and filter out the noise.
They include some detailed bug descriptions too, including a 20-year old XSLT bug and a 15-year-old bug in the `` element.
A lot of the attempts made by the harness were blocked by Firefox's existing defense-in-depth measures, which is reassuring.
Mozilla were fixing around 20-30 security bugs in Firefox per month through 2025. That jumped to 423 in April.

Via Lobste.rs
Tags: firefox, mozilla, security, ai, generative-ai, llms, anthropic, claude, ai-security-research
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み