Elixir Mentor

Peter Ullrich on Hunting CVEs


Listen Later

Peter Ullrich returns to talk about a CVE hunt across the most-downloaded Hex packages, run with Claude Code on Opus 4.7. After ElixirConf EU pulled him into AI security, he started pointing Opus at popular libraries day and night, and within half an hour of his first serious attempt he found the Decimal vulnerability, where raising 10 to a huge power can blow up an application's memory.

We get into what separates a real CVE from noise, how CVSS scoring works, and why reachability matters so much, since a flaw in Phoenix's default configuration is far more serious than a crash in a function nobody can call. Peter also walks through the process he runs with the EEF: verifying each issue, getting a second pair of eyes, coordinating a fix, and getting a number issued through a CNA, all while avoiding slop reports to maintainers. There's also a candid stretch on regulation and breach reporting.

From there it widens out, including how Opus compares to Mythos, why Peter keeps coming back to Claude, his first impressions of Opus 4.8, and the economics, with a simple scan costing about $10 in API tokens. He also shares his Session Watcher plugin, an update on Killswitch and its browser-side encryption, thoughts on AEO, and how he uses dev containers to sandbox coding agents.

Resources Mentioned:
- The blog post that started this:https://peterullrich.com/what-the-cve
- Peter's prompts:gist
- Scrutineer:github.com/alpha-omega-security/scrutineer
- Decimal advisory:GHSA-rhv4-8758-jx7v
- EEF CNA published CVEs:cna.erlef.org/cves
- EEF CNA security policy:cna.erlef.org/security-policy
- Responsible disclosure guidelines:security.erlef.org
- Anthropic article (the basis):red.anthropic.com

Connect with Peter:
- Website:peterullrich.com
- GitHub:github.com/pjullrich
- LinkedIn:linkedin.com/in/pjullrich
- Bluesky:@peterullrich.com

Thanks to our sponsors:
- BEAMOps:beamops.co.uk
- Paraxial.io:paraxial.io

SUPPORT ELIXIR MENTOR
- Elixir Mentor:elixirmentor.com

...more
View all episodesView all episodes
Download on the App Store

Elixir MentorBy Jacob Luetzow

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Elixir Mentor

View all
The Knowledge Project by Shane Parrish

The Knowledge Project

2,683 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

288 Listeners

Startups For the Rest of Us by Rob Walling

Startups For the Rest of Us

700 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

624 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

984 Listeners

REWORK by 37signals

REWORK

212 Listeners

CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

CoRecursive: Coding Stories

188 Listeners

Practical AI by Practical AI LLC

Practical AI

213 Listeners

Elixir Wizards by SmartLogic LLC

Elixir Wizards

22 Listeners

Thinking Elixir Podcast by ThinkingElixir.com

Thinking Elixir Podcast

32 Listeners

Huberman Lab by Scicomm Media

Huberman Lab

29,255 Listeners

Beam Radio by Lars Wikman

Beam Radio

11 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

65 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

689 Listeners

Limitless: An AI Podcast by Limitless

Limitless: An AI Podcast

76 Listeners