
Will Harris
2.5K posts

Will Harris
@parityzero
Chrome Security gnome. I work on the sandbox and local data protection on Windows. @parityzero.99 on signal. Opinions here are my own!




6 Firefox entries at pwn2own. 5 withdrawals due to our 150.0.3 security release. 1 failed attempt. 0 Exploits. No incidents. Time to party :)



Try out the early alpha of Process Isolation in Chrome 138. chrome://flags/#enable-process-isolation-ui then chrome://settings/system for the switch. Read known issues issues.chromium.org/issues?q=hotli… and report bugs! Especially interested in App-Compat bugs.







this year's pwn2own isn't just interesting because there will be lots of entries with AI+human. it is also interesting because a) anthropic burned a ton of tokens on firefox, basically running claude in a loop until it found something for a month, probably exhausting whatever claude can one shot. b) if someone submits full chain without much use of ai, it tells you one shotting plateaus and these models are bit like fuzzers than seasoned security reseachers. c) even if they used an llm to find the bug, this tells us scaffolding/harnesss design, prompting, and the operator matters a lot.








The Internet Was Weeks Away From Disaster and No One Knew


@afneil @British_Airways Is there a big difference between gold and guest list ?





I just want to log in without being redirected 42 times or logged out every single day. I want to remain logged in on my device for at least months. We have machines that can mimic sentience and yet we can’t do log in for more than 24 hours. We’ve been played for fools.

