logoalt Hacker News

MetaverseClubyesterday at 9:04 PM2 repliesview on HN

I'm curious about how did Mozilla do bug finding before Mythos? Did they use any non-AI bug finding tools?


Replies

mccr8yesterday at 9:06 PM

The usual sorts of fuzzing and static analyses, using AddressSanitizer and ThreadSanitizer. Also, with a bug bounty program to try to encourage external researchers to report issues. (I work on Firefox security; also I fixed 2 of the bugs linked in the blog post.)

canucker2016yesterday at 10:17 PM

Coverity (similar to lint) scans various open source software products for vulnerabilities.

see https://www.blackduck.com/static-analysis-tools-sast/coverit...

and for Firefox-related alleged defects, see https://scan.coverity.com/projects/firefox

You have to create an account to view the actual reported defects.

There are just over 5000 reported defects still outstanding. I don't know how many overlap with the reported 271 Mythos-reported defects.

show 2 replies