<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: rlopc</title><link>https://news.ycombinator.com/user?id=rlopc</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 09 Apr 2026 06:19:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=rlopc" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by rlopc in "Project Glasswing: Securing critical software for the AI era"]]></title><description><![CDATA[
<p>These issues are always found in the same kinds of projects that support an insane amount of largely unused protocols and features like ffmpeg, sudo, curl.<p>OpenBSD has many unexplored corners and also (irresponsibly IMO) maintains forks of other projects in base.<p>A motivated human could find all of these probably by writing 100% code coverage and fuzzing.<p>The market for these tools is very small. Good luck applying them to a <i>release</i> of sqlite or postfix.<p>I don't understand how people here are hyping this up, unless they work for AI related companies as probably 80% of them do. People have found these issues for decades without AI. Sure, you can generate fuzzing code and find one or two issues in the usual suspects. Better do it manually and understand your own code.</p>
]]></description><pubDate>Tue, 07 Apr 2026 22:50:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47682358</link><dc:creator>rlopc</dc:creator><comments>https://news.ycombinator.com/item?id=47682358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47682358</guid></item></channel></rss>