So did they have five million experienced network engineers code test suites and run each against the code base? No, they did not.
Did they have a team design five million different test suites and run them? No, they did not.
In all likelihood, they ran a simple fuzzer against the running software for five million cycles.
That’s like trying to guess a password five million times and then saying that, because you couldn’t get it in five million guesses, anyone else who guesses it must be amazing.
I’m not impressed.
Oh! There was a bug in 300-year-old OpenBSD code!!! Well, all code has bugs.
I’m not impressed.
“We’d prove it to you if we could, but our software is JUST TOO INCREDIBLY DANGEROUS TO LET PEOPLE LIKE YOU WORK WITH IT!!!1!!”
This reminds me of all the proprietary cryptographic algorithms that were “just too good” to allow researchers to have access to the them. Spoiler: they all ended up being seriously flawed.
Maybe Mythos is everything people are ringing their hands about. Maybe it’s just another incremental step forward in exploit tools. The more I see hypetrain nonsense like “five million test suites” and “found a bug in ancient OpenBSD code” the more I think the emperor is probably wearing an off-the-rack Men’s Warehouse suit.
2026-04-15T12:58-10:00: edit to correct FreeBSD->OpenBSD