ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 9 sources: “'gpg.fail' GnuPG retrospective reveals disputed printf format-string 0-day in gpgsm 2.4.9, sparks legacy-code debate” — merged summary and timeline →

Re: Retrospective by 'gpg.fail' authors

infoResearchimportance 15
AI summary · glm-5.3-flash

oss-security thread on the gpg.fail retrospective discusses legacy code removal and flaws surfaced by frontier AI models in open-source projects.

In a reply to Soatok Dreamseeker's gpg.fail retrospective thread on the oss-security mailing list, cryptographer Peter Gutmann argues it is often unclear which legacy code is obsolete or can be safely removed. He recounts a discussion with another well-known open-source project developer estimating, unscientifically, that around half of issues in such projects were found by frontier AI models. The exchange reflects on lessons from documenting weaknesses in GnuPG/OpenPGP implementations.

  • Peter Gutmann replies to the gpg.fail retrospective on oss-security
  • Anecdotal estimate: roughly half of issues in a well-known OSS project found by frontier AI models
  • Discusses difficulty of determining which legacy crypto code is safe to remove
Organizationsgpg.fail
Full article

Posted by Peter Gutmann on Sep 16 Soatok Dreamseeker writes: https://xkcd.com/1172/ there's the secondary problem that it's not clear which code is obsolete and/ or can be safely removed. I was recently talking with the developer of another well-known OSS project on issues found by frontier AI models in them and we both mentioned that, totally unscientifically, around half of all issues...

This source does not provide full text. Read it at seclists.org.